Skip to main content

【イベント】TrendAI™ Spark 2026 開催

AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

TrendAI™
セキュリティブログ

TrendAI Security Blog

注目のブログ

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
マルウェア

SHADOW-WATER-084の内幕:Remcos、LXBASEなどを配信するステガノグラフィ型ローダー・アズ・ア・サービス

TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。

Read article
New Golang Ransomware Agenda Customizes Attacks

A new piece of ransomware written in the Go language has been targeting healthcare and education enterprises in Asia and Africa. This ransomware is called Agenda and is customized per victim.

Read Article
ランサムウェアと恐喝
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus

We investigate mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game Genshin Impact. The driver is currently being abused by a ransomware actor to kill antivirus processes and services for mass-deploying ransomware.

Read Article
Analyzing The ForcedEntry Zero-Click iPhone Exploit Used By Pegasus

Citizen Lab has released a report on a new iPhone threat dubbed ForcedEntry. This zero-click exploit seems to be able to circumvent Apple's BlastDoor security, and allow attackers access to a device without user interaction.

Read Article
フィッシングとBEC
APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs

We have continued tracking APT-C-36, also known as Blind Eagle, since our research on this threat actor in 2019. We share new findings of APT-C-36’s ongoing spam campaign targeting South American entities.

Read Article
サイバー脅威
Instagramアカウントを乗っ取る手口:最新事例や防止策を解説

この記事では、個人またはハッキンググループによって行われたInstagramアカウントを乗っ取る手口や悪用方法について最新の事例とともに検証します。また、Instagramアカウントの乗っ取りを防ぐ方法も紹介します。

Read Article
SHAREit Flaw Could Lead to Remote Code Execution

We discovered vulnerabilities in the SHAREit application. These vulnerabilities can be abused to leak a user’s sensitive data, execute arbitrary code, and possibly lead to remote code execution. The app has over 1 billion downloads.

Read Article
XCSSET Mac Malware: Infects Xcode Projects, Uses 0Days

Further investigation led us to a developer’s Xcode project that contained XCSSET source malware, which leads to a rabbit hole of malicious payloads. Most notable in our investigation is the discovery of two zero-day exploits.

Read Article
マルウェア
IoTマルウェア「Bashlite」、新たにUPnPを利用しスマートホーム機器を狙う

IoTデバイスを狙うマルウェア「Bashlite」の更新が確認されました。Bashliteは、DDoS攻撃のためにIoTデバイスを感染させてボットネットを構築するマルウェアです。

Read Article
IoTとスマートデバイスマルウェア
Beauty Camera Apps Send Users Porn, Collects Pictures

We discovered several beauty camera apps (detected as AndroidOS_BadCamera.HRX) on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes. Some of these have been downloaded millions of times.

Read Article
マルウェア
Google Playで偽銀行アプリを確認、スペイン語圏ユーザを狙うスミッシングに利用

ユーザが銀行の提供するアプリやサービスを利用するようになるにつれ、詐欺師にとっての機会も拡大しています。その最近の一例が、スペイン語圏のユーザを狙ったスミッシング詐欺の一環として利用されたアプリ「Movil Secure」です。

Read Article