SHADOW-WATER-084の内幕:Remcos、LXBASEなどを配信するステガノグラフィ型ローダー・アズ・ア・サービス
TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。
【イベント】TrendAI™ Spark 2026 開催
AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

TrendAI™ Researchは、まったく異なるおとりアプリケーションと互いに無関係なペイロードを、共通のツールキットで配信する3つのキャンペーンを追跡しました。本稿では、第1段階をピクセルデータに隠す手法から、複数のペイロードを配信できる柔軟な共通ローダーまで、攻撃チェーンの全体像を分析し、攻撃者が配信メカニズムを標準化している実態を明らかにします。
TrendAI™のエージェント型エクスプロイト修復エンジン「AESIR」に、新たな脅威ハンティングコンポーネントが加わりました。脆弱性の開示後も可視性を維持し、1年以上にわたるハニーポットのデータを、ローダフレームワーク「LF3」へと結び付けた初の調査結果を紹介します。
The TrendAI™ agentic exploit-remediation engine, code name AESIR, ranks first on CyberGym at 97% — more than 12 points ahead of both GPT-5.6 Sol and Claude Mythos 5. AI system architecture beats raw model capability.
2026年7月、英国の発電施設がサイバー攻撃を受けたと報じられました。単一施設の停止であっても、産業インフラ全体のレジリエンスをめぐる幅広い問題が浮き彫りになります。
A new variant of Android Remote Access Tool can inject root exploits to perform malicious tasks such as silent installation, shell command execution, WiFi password collection, and more. It targets CVE-2015-1805, a vulnerability disclosed in 2016.
On January 24, 2018, we observed that the number of Coinhive web miner detections tripled due to a malvertising campaign. Attackers seem to have abused Google’s DoubleClick, which provides internet ad serving services, for traffic distribution.
A new cryptocurrency-mining bot is spreading through Facebook Messenger. We named this Digmine based on the moniker (비트코인 채굴기 bot) it was referred to in a report of recent related incidents in South Korea.