Skip to main content

【イベント】TrendAI™ Spark 2026 開催

AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

TrendAI™
セキュリティブログ

TrendAI Security Blog

注目のブログ

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
マルウェア

SHADOW-WATER-084の内幕:Remcos、LXBASEなどを配信するステガノグラフィ型ローダー・アズ・ア・サービス

TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。

Read article
フィッシングとBEC
Unraveling Water Saci's New Multi-Format, AI-Enhanced Attacks Propagated via WhatsApp

Through AI-driven code conversion and a layered infection chain involving different file formats and scripting languages, the threat actors behind Water Saci are quickly upgrading their malware delivery and propagation methods across WhatsApp in Brazil.

Read Article
Cloud security
Shai-hulud 2.0キャンペーンがクラウドと開発者エコシステムを標的に

Shai-hulud 2.0キャンペーンでは、主要なクラウド基盤や開発者向けサービスから認証情報やシークレットを盗み取る高度な亜種が使われています。被害者が管理するNPMパッケージに自動でバックドアを仕掛ける機能も備えており、攻撃者はソフトウェアサプライチェーン全体で迅速かつ秘匿性の高い拡散を実現します。この挙動により、多くの下流利用者が影響を受ける危険性が生じています。

Read Article
ランサムウェアと恐喝
Breaking Down S3 Ransomware: Variants, Attack Paths and Trend Vision One™ Defenses

In this blog entry, Trend™ Research explores how ransomware actors are shifting their focus to cloud-based assets, including the tactics used to compromise business-critical data in AWS environments.

Read Article
情報技術(IT)
AI Security: NVIDIA BlueField Now with Vision One™

Launching at NVIDIA GTC 2025 - Transforming AI Security with Trend Vision One™ on NVIDIA BlueField

Read Article
Qilinランサムウェアが、リモート管理ツールとBYOVD手法を利用し、Windowsシステム上でLinux版を展開

トレンドマイクロは、Windows環境においてLinux版のAgendaランサムウェアを展開する高度な攻撃を確認しました。このクロスプラットフォーム型の実行により、企業側にとって検出が困難な状況が生まれています。

Read Article
標的型攻撃
The Rise of Collaborative Tactics Among China-aligned Cyber Espionage Campaigns

Trend™ Research examines the complex collaborative relationship between China-aligned APT groups via the new “Premier Pass-as-a-Service” model, exemplified by the recent activities of Earth Estries and Earth Naga.

Read Article
大規模言語モデル(LLM)
トークナイザーのズレが招くLLM運用のコストとセキュリティの危機

あらゆる大規模言語モデルの中心にはトークナイザーがあります。これがわずかにずれていくとき、見過ごされた欠陥や悪意ある干渉のいずれによってであれ、コストは上昇し、性能は低下します。この新たなリスクの実態と影響、そしてそれを防ぐための手立てについて考察します。

Read Article
サイバー犯罪マルウェア
Fast, Broad, and Elusive: How Vidar Stealer 2.0 Upgrades Infostealer Capabilities

TrendAI™ Research examines the latest version of the Vidar stealer, which features a full rewrite in C, a multithreaded architecture, and several enhancements that warrant attention. Its timely evolution suggests that Vidar is positioning itself to occupy the space left after Lumma Stealer’s decline.

Read Article
Shifts in the Underground: The Impact of Water Kurita’s (Lumma Stealer) Doxxing

A targeted underground doxxing campaign exposed alleged core members of Lumma Stealer (Water Kurita), resulting in a sharp decline in its activity and a migration of customers to rival infostealer platforms.

Read Article
Cisco SNMPプロトコルの脆弱性を悪用してルートキットを送り込む攻撃活動「Zero Disco」

Cisco SNMPの脆弱性「CVE-2025-20352」を用いて遠隔からコードを実行し、ルートキットを送り込む攻撃活動が行われています。Ciscoの9400、9300、レガシー3750Gシリーズに対する影響が確認されました。

Read Article