Jacob Santos
10 articles
-
Blog信頼シグナルの悪用:Claude Codeの誘引とGitHubリリースを悪用したペイロード
AnthropicのClaude Codeのnpmリリースにおけるパッケージングミスにより、内部ソースコードが一時的に露出しました。本稿では、この注目を受けて攻撃者がどのように迅速に動き、既存のAI関連キャンペーンを転用してVidarおよびGhostSocksを拡散したのかを解説します。
April 3rd, 2026 18 minJacob Santos, Sophia Nilette Robles, Jeffrey Francis Bonaobra
Read article -
BlogAxios NPMパッケージ侵害:週1億以上のダウンロードを誇るJavaScript HTTPクライアントにサプライチェーン攻撃
Axiosに対してサプライチェーン攻撃が発生し、攻撃者は盗まれたnpm認証情報を使用して悪意のあるバージョンを公開しました。このバージョンにはファントム依存関係が含まれており、インストール時にクロスプラットフォームのRATを起動し、その後、検出を困難にするために自身のファイルをクリーンなデコイに置き換えました。
March 31st, 2026 10 minPeter Girnus, Jacob Santos
Read article -
BlogWeb Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack
Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC Yuze, and a persistent BYOVD technique leveraging the NSec driver.
March 16th, 2026 13 minMaristel Policarpio, Junestherry Dela Cruz, Sarah Pearl Camiling, Jacob Santos…
Read article -
BlogPureRAT Campaign Targets Job Seekers, Abuses Foxit PDF Reader for DLL Side-loading
Job seekers looking out for opportunities might instead find their personal devices compromised, as a PureRAT campaign propagated through email leverages Foxit PDF Reader for concealment and DLL side-loading for initial entry.
December 3rd, 2025 5 minSarah Pearl Camiling, Junestherry Dela Cruz, Jacob Santos, Sophia Nilette Robles…
Read article -
BlogQilinランサムウェアが、リモート管理ツールとBYOVD手法を利用し、Windowsシステム上でLinux版を展開
トレンドマイクロは、Windows環境においてLinux版のAgendaランサムウェアを展開する高度な攻撃を確認しました。このクロスプラットフォーム型の実行により、企業側にとって検出が困難な状況が生まれています。
October 23rd, 2025 13 minJacob Santos, Junestherry Dela Cruz, Sarah Pearl Camiling, Sophia Nilette Robles…
Read article -
Blogメッセージアプリ「WhatsApp」を通して拡散するマルウェアがブラジルの金融機関ユーザを攻撃
メッセージアプリ「WhatsApp」を通して拡散するマルウェア活動について解説します。このマルウェアは、被害者のWhatsAppアカウントを乗っ取り、その連絡先に自身の複製を配信します。
October 3rd, 2025 15 minJeffrey Francis Bonaobra, Maristel Policarpio, Sophia Nilette Robles, Cj Arsley Mateo…
Read article -
Blogランサムウェア「LockBit 5.0」の3つの新亜種(Windows・Linux・ESXi版)の分析結果を解説
トレンドマイクロは、悪名高いランサムウェアグループ「LockBit」が実際の攻撃に用いた新亜種「LockBit 5.0」のバイナリを分析しました。LockBit 5.0では高度な難読化、フォレンジック調査妨害機能、Windows・Linux・ESXi環境に対応させたクロスプラットフォーム戦略が確認されました。
September 25th, 2025 7 minSarah Pearl Camiling, Jacob Santos
Read article -
BlogThe Gentlemenランサムウェア攻撃の実態:戦術・手法・手順の全容を解説
新興のThe Gentlemenランサムウェアグループが標的環境に適応させた高度な戦術・手法・手順を駆使して世界中の主要産業を狙っています。
September 9th, 2025 12 minJacob Santos, Maristel Policarpio, Don Ovid Ladores, Junestherry Dela Cruz
Read article -
BlogCrypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks
Crypto24 is a ransomware group that stealthily blends legitimate tools with custom malware, using advanced evasion techniques to bypass security and EDR technologies.
August 14th, 2025 13 minMaristel Policarpio, Sarah Pearl Camiling, Don Ovid Ladores, Jacob Santos…
Read article -
BlogSilent Threat: Red Team Tool EDRSilencer Disrupting Endpoint Security Solutions
Trend Micro's Threat Hunting Team has observed EDRSilencer, a red team tool that threat actors are attempting to abuse for its ability to block EDR traffic and conceal malicious activity.
October 15th, 2024 8 minJacob Santos, Cj Arsley Mateo, Sarah Pearl Camiling
Read article