SHADOW-WATER-084の内幕:Remcos、LXBASEなどを配信するステガノグラフィ型ローダー・アズ・ア・サービス
TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。
【イベント】TrendAI™ Spark 2026 開催
AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。
TrendAI™のエージェント型エクスプロイト修復エンジン「AESIR」に、新たな脅威ハンティングコンポーネントが加わりました。脆弱性の開示後も可視性を維持し、1年以上にわたるハニーポットのデータを、ローダフレームワーク「LF3」へと結び付けた初の調査結果を紹介します。
The TrendAI™ agentic exploit-remediation engine, code name AESIR, ranks first on CyberGym at 97% — more than 12 points ahead of both GPT-5.6 Sol and Claude Mythos 5. AI system architecture beats raw model capability.
2026年7月、英国の発電施設がサイバー攻撃を受けたと報じられました。単一施設の停止であっても、産業インフラ全体のレジリエンスをめぐる幅広い問題が浮き彫りになります。
Through AI-driven code conversion and a layered infection chain involving different file formats and scripting languages, the threat actors behind Water Saci are quickly upgrading their malware delivery and propagation methods across WhatsApp in Brazil.
Shai-hulud 2.0キャンペーンでは、主要なクラウド基盤や開発者向けサービスから認証情報やシークレットを盗み取る高度な亜種が使われています。被害者が管理するNPMパッケージに自動でバックドアを仕掛ける機能も備えており、攻撃者はソフトウェアサプライチェーン全体で迅速かつ秘匿性の高い拡散を実現します。この挙動により、多くの下流利用者が影響を受ける危険性が生じています。
In this blog entry, Trend™ Research explores how ransomware actors are shifting their focus to cloud-based assets, including the tactics used to compromise business-critical data in AWS environments.
Launching at NVIDIA GTC 2025 - Transforming AI Security with Trend Vision One™ on NVIDIA BlueField
トレンドマイクロは、Windows環境においてLinux版のAgendaランサムウェアを展開する高度な攻撃を確認しました。このクロスプラットフォーム型の実行により、企業側にとって検出が困難な状況が生まれています。
Trend™ Research examines the complex collaborative relationship between China-aligned APT groups via the new “Premier Pass-as-a-Service” model, exemplified by the recent activities of Earth Estries and Earth Naga.
あらゆる大規模言語モデルの中心にはトークナイザーがあります。これがわずかにずれていくとき、見過ごされた欠陥や悪意ある干渉のいずれによってであれ、コストは上昇し、性能は低下します。この新たなリスクの実態と影響、そしてそれを防ぐための手立てについて考察します。
TrendAI™ Research examines the latest version of the Vidar stealer, which features a full rewrite in C, a multithreaded architecture, and several enhancements that warrant attention. Its timely evolution suggests that Vidar is positioning itself to occupy the space left after Lumma Stealer’s decline.
A targeted underground doxxing campaign exposed alleged core members of Lumma Stealer (Water Kurita), resulting in a sharp decline in its activity and a migration of customers to rival infostealer platforms.
Cisco SNMPの脆弱性「CVE-2025-20352」を用いて遠隔からコードを実行し、ルートキットを送り込む攻撃活動が行われています。Ciscoの9400、9300、レガシー3750Gシリーズに対する影響が確認されました。