SHADOW-WATER-084の内幕:Remcos、LXBASEなどを配信するステガノグラフィ型ローダー・アズ・ア・サービス
TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。
【イベント】TrendAI™ Spark 2026 開催
AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。
TrendAI™のエージェント型エクスプロイト修復エンジン「AESIR」に、新たな脅威ハンティングコンポーネントが加わりました。脆弱性の開示後も可視性を維持し、1年以上にわたるハニーポットのデータを、ローダフレームワーク「LF3」へと結び付けた初の調査結果を紹介します。
The TrendAI™ agentic exploit-remediation engine, code name AESIR, ranks first on CyberGym at 97% — more than 12 points ahead of both GPT-5.6 Sol and Claude Mythos 5. AI system architecture beats raw model capability.
2026年7月、英国の発電施設がサイバー攻撃を受けたと報じられました。単一施設の停止であっても、産業インフラ全体のレジリエンスをめぐる幅広い問題が浮き彫りになります。
Anubis is an emerging ransomware-as-a-service (RaaS) group that adds a destructive edge to the typical double-extortion model with its file-wiping feature. We explore its origins and examine the tactics behind its dual-threat approach.
Trend™ Research uncovered a campaign on TikTok that uses videos to lure victims into downloading information stealers, a tactic that can be automated using AI tools.
We have detected a new tactic involving fake CAPTCHA pages that trick users into executing harmful commands in Windows. This scheme uses disguised files sent via phishing and other malicious methods.
トレンドマイクロのZero Day Initiative™(ZDI)は、ZDI-CAN-25373と識別されるWindowsの.lnkファイルの未修正の脆弱性が、国家背景の攻撃グループやサイバー犯罪組織によって以前から広範に悪用されていることを明らかにしました。この脆弱性を利用すると、隠れたコマンドの実行が可能になります。
This article explains the invisible prompt injection, including how it works, an attack scenario, and how users can protect themselves.
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
Trend Micro's Threat Hunting Team has observed EDRSilencer, a red team tool that threat actors are attempting to abuse for its ability to block EDR traffic and conceal malicious activity.
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
ディープフェイク技術を用いた偽のビデオ会議にだまされた香港の金融関係者が詐欺グループに多額の送金を行いました。ディープフェイク技術の悪用に対抗するためには、技術的側面と心理的側面の両面において対策を講じる必要があります。
An overview of the Lemon Group’s use of preinfected mobile devices, and how this scheme is potentially being developed and expanded to other internet of things (IoT) devices. This research was presented in full at the Black Hat Asia 2023 Conference in Singapore in May 2023.