資料
ホワイトペーパー

時代の変化と共に、サイバー脅威はより高度で多様なものになっています。攻撃者は常に、既存の防御方法を凌駕する新しい攻撃方法を考え出し、セキュリティシステムを狙い続けています。 このような脅威から身を守るには、攻撃者が何を考え、どのように行動するかを理解することが極めて重要です。脅威インテリジェンスは、企業がサイバー攻撃を事前に阻止、被害を軽減することに役立ちます。 このホワイトペーパーでは、脅威インテリジェンスと、企業がそれを簡単に活用する方法をご紹介します。 目次 - 脅威インテリジェンスの紹介 *脅威インテリジェンスとは? *なぜ脅威インテリジェンスが重要なのか? *脅威インテリジェンスを効果的に活用するには? - 脅威インテリジェンスの実用 - 使用事例 : APAC諸国政府 - まとめ 脅威インテリジェンスの活用とサイバー攻撃対策の全文は、TeamT5公式ウェブサイトの下記リンクより取得することが可能です。

サイバー攻撃はますます複雑化しており、アジア太平洋地域は攻撃者が活発に活動する主要な舞台となっています。国家支援グループ、商業系の請負業者、組織的なサイバー犯罪集団まで、攻撃者は国家機密の窃取から金銭的利益の獲得まで多様な目的を持ち、手法を素早く変化させ、既存のバックドアや攻撃基盤を再利用しながら攻撃を遂行しています。 CISO にとっての課題は、アラートが不足していることではなく、攻撃の背後にある文脈を理解するための情報が不足していることです。 本ホワイトペーパーでは、アジア太平洋地域において「攻撃者中心」のインテリジェンスアプローチが不可欠である理由を解説します。より多くの指標を集めるのではなく、攻撃者の正体、行動パターン、動機、目的を理解することが防御効果を高める鍵となります。TeamT5 が長年蓄積してきた地域研究に基づき、中国の i-Soon 請負業者漏洩事件や台湾の馬偕紀念医院ランサムウェア攻撃などの実例を通じて、攻撃者エコシステムの実像を明らかにします。 ホワイトペーパーをダウンロードいただくことで、アジア太平洋地域の脅威アクターを包括的に把握し、新たな視点から長期的な安全確保に向けた防御戦略を描くための知見を得ることができます。

企業はますます複雑で深刻なセキュリティ課題に直面していますが、「ゼロ トラスト」は、サイバー セキュリティを強化し、企業全体のリスクを軽減するために組織が追求すべき重要な戦略です。 ガートナーの調査によると、世界中の組織の 63% がゼロ トラスト戦略を実装しています。ただし、ほとんどの組織では、ゼロ トラスト戦略は環境の半分以下しかカバーしていません。 「侵害を想定し、常に検証する」というゼロ トラストの原則に従い、組織は常に侵害がすでに発生している可能性があるという前提で活動する必要があります。この文脈では、組織がデータと資産の安全を確保するために、プロアクティブな脅威ハンティングが不可欠になります。 このホワイトペーパーでは、脅威ハンティング の全体的な理解が得られます。内容は次のとおりです。 脅威ハンティングとは? なぜ脅威ハンティングが必要なのか? 脅威ハンティングを実装するには? TeamT5 はどのように役立つのか?

TeamT5は、アジア太平洋地域(APAC)における脅威インテリジェンスを専門とするセキュリティベンダーです。 本記事では、2024年のAPACにおけるAPT(Advanced Persistent Threats:高度標的型攻撃)の脅威状況をまとめ、毎年恒例のレビューだけでなく、今後1年間注意すべきセキュリティ脅威についてもご紹介します。 本記事は、主要データと脅威インテリジェンス分析を要約したものです。 「2024年脅威ランドスケープのレビュー:曖昧になるサイバー攻撃の境界線」全文の閲覧をご希望の方は、下部のフォームにご記入ください 。 アジア太平洋地域の脅威インテリジェンスについてさらに詳しく知りたい方は、国際的なコンサルタントから受賞歴のある脅威インテリジェンスプラットフォームThreatVisionのトライアルを申し込むことが出来ます。お問い合わせ: /jp/contact 。 Threat Statistics in 2024: Data & Observations In 2024, until the end of November, TeamT5 actively tracked 30 new vulnerabilities being exploited in the wild, along with around 500 attack operations across 42 countries, which we attributed to 73 known adversaries and more than 200 malware / hacking tools being used. We also identified 45 victims being compromised in 9 countries and tried to notify through our trustworthy partners. And helped 33 IR cases for our customers. You could imagine all the above data contributing to our intelligence reports. Generally speaking, most of them show a tendency of increasing. TeamT5 is actively tracking vulnerability exploitation attacks in the wild. In 2024, 30 widespread attacks were tracked by TeamT5, around 400 victim hosts across 21 countries were identified to be compromised. We would like to highlight that 5 of them are email system related and 14 are exploiting edge devices, indicating they are high priorities of threat actors to access targets. Our research also shows EtherBei (aka Flax Typhoon) to be the most active threat actors to adopt these exploits. During the course of our research, we also discovered some threat actors built their botnet or so called Operation Relay Box network by implanting malware like GobRAT, NatWalk and GenSeven. Lastly, there’s also a tendency that more management services of edge devices are being exploited, such as FortiManager, Versa Director or Palo Alto Firewall, e.t.c., meaning that threat actors might compromise multiple entities by intruding on one device. We believe this is a threat that management service providers or big enterprises should be aware of.

2024年台湾総統選挙とその後のサイバーセキュリティの課題 2024年は世界各地で選挙が行われる記録的な年であり、世界人口の約半数を占める60カ国以上で国政選挙が実施されます。2024年1月13日、台湾では総統選挙と立法委員選挙が行われ、世界的な選挙イヤーの幕開けとなりました。 TeamT5は、この選挙がサイバー攻撃による妨害を受けることなく、スムーズに終了したことを喜ばしく思います。そして、この成果は多くの個人や組織の努力と献身の賜物であり、彼らの努力の積み重ねこそが、選挙の安全性と信頼性を確保したと確信しています。 しかし、どんなに成功を収めたとしても、国家支援によるサイバー脅威がもたらす課題を見過ごしてはなりません。当社は、国家と連携した影響工作(Infuluence Operation)や標的型攻撃(Advanced Persistant Threat)グループに関連する、数多くの悪意のある活動や偽情報キャンペーンの特定および分析を精力的に続けてきました。本稿では、これらの攻撃者が使用する具体的な戦術、技術、手順(Tactics / Techniques / Procedures)について詳述し、彼らの活動に関する貴重な知見を共有いたします。 また、サイバー脅威の状況は常に変化しており、攻撃者は常に新しい攻撃手法を考案しています。今回の選挙期間中、これらの攻撃者が能力を強化し、より洗練された革新的なテクニックを駆使して、更に広範なプラットフォームを標的にしていることが発覚しました。本稿は、当社の発見を共有するだけでなく、潜在的な脅威に先んじるためにサイバー防衛戦略を継続的に更新することの重要性についても説明します。 最後に、当社は上記のようなサイバー脅威に対抗するため、脅威インテリジェンスを強化させることを約束します。 本稿を通じて、当社の戦略的知見を共有し、他の民主主義国家、特に選挙を間近に控えた国家が、民主主義プロセスの混乱を目的としたサイバー攻撃についてより深く理解できることを目指します。そして、本稿が民主主義諸国のサイバー脅威インテリジェンス専門家にとって実用的なリソースとなり、サイバー脅威を効果的に予測し、軽減する一助となることを願っています。 Research Highlights 2024年の選挙を前に、台湾は数多くの巧妙なサイバー脅威に直面してきました。いずれも民主的プロセスを不安定にし、選挙制度に対する国民の信頼を損なわせることが目的でした。また、全体的に見ると、標的型攻撃の大部分を中国系の攻撃者が占めていました。 中国のAPTグループは、台湾の複数の団体、特にジャーナリズムとメディア業界を標的にしています。ここで注目すべき点は、民主派や泛緑のメディアだけがサイバー攻撃の餌食になっているわけではないことです。当社データベースによれば、統一派や親中派と認識されている台湾国内のテレビ局や新聞社も主要な標的となっています。 一方で、中国はソーシャルメディアプラットフォームを駆使し、台湾に対する偽情報やプロパガンダを広めています。2023年初頭から、与党を攻撃する不審な活動がまばらに観測されましたが、重大な影響工作が確認されたのは11月以降です。選挙期間中の中国の影響工作について、3つの主要な傾向は以下の通りです。: (1). 対象範囲の拡大 (2). 様々なプラットフォームのAIを活用したキャンペーン (3). フェイクニュースサイトと内部告発サイト 2023年11月下旬以降、台湾の現与党である民進党に対し、国民の信頼を低下させることを目的とした上記のような影響力工作に準じて、中国が関与したハッキングやリーク事件が確認されました。 これらのキャンペーンは「ハック・アンド・リーク」の手法を戦略的に採用したことを示しており、ハイブリッド戦争の戦術における顕著な転換であると見なせます。また、当社は「オペレーションスクープスパイ」と呼ばれる重大なキャンペーンを注視しています。彼らの目的は、選挙でどの候補者や政党が勝とうとも、混乱を巻き起こし、民主化推進派の政治家の信用を失墜させることである可能性が高いです。 台湾の政治情勢に影響を与えようとする中国のアプローチ、特に2024年の選挙前後は、長期的な戦略を強調しています。更に、中国とつながりのあるAPTグループや影響工作は、標的を深く理解しており、徹底的な準備と調査を行っていることがわかります。このような綿密な下準備が、サイバースパイ活動と影響工作との間に厄介な相乗効果をもたらしています。 2024年台湾総統選挙に対するサイバー脅威の全文(英語)は、TeamT5公式ウェブサイトの下記リンクより取得することが可能です。

TeamT5 is a leading brand in delivering Asia Pacific intelligence. In this article, we summarize the threat landscape of advanced persistent threats (APT) in the Asia-Pacific region in 2023, not only provide annual observations, but also point out the cyber threats worth paying attention to in 2024. This article is an excerpt version which summarizes key statistics. To obtain the complete threat intelligence report, you may fill up the form at the bottom to obtain the “APT Threat Landscape in APAC 2023” report. This article is adapted from "2023 H2 Campaign Tracking Report: APT Threat Landscape in Asia". To discover similar cyber threat intelligence which is focused in Asia-Pacific region, please sign up for the trial of our threat intelligence platform ThreatVision. Please indicate on the ThreatVision page that you would like to apply for trial. Preface TeamT5’s cyber threat intelligence research based on well-built data collection and analysis flow. We collect data from multiple sources - malware databases, sandboxes, crawlers, and our threat forensic analysis platform ThreatSonar etc. With careful and rigorous analysis, we come up with intelligence reports for clients and the public to notify potential threats. For 2023, based on TeamT5 data collection and analysis, we found: 411 attack operations in 39 countries 60 known adversary groups tracked 210 malware / hacking tools used Closer Look at Exploits In 2023, we have observed at least 37 CVE exploits that were abused in the wild by threat actors. We see a tendency that more and more exploits targeting edge devices appear, which we marked with color yellow in the right table. These edge devices have no security products to monitor them so threat actors could effectively intrude their target network environments. There are still lots of attacks achieved spear phishing emails but the corresponding tricks are old fashioned, such as: Template Injection Microsoft LNK CHM Macro documents Phishing CVE-2018-0798, CVE-2022-30190, CVE-2023-38831 Closer Look at Malwares We listed the malware distribution in all attacks. Below is the ranking of Top 10 Malwares in 2023 H1 and Top 15 Malwares in 2023 H2 . We compare these two ranks with 4 aspects - Shared tools, Webshell, Cross platform RAT, Shared Quartermaster of Chinese APT. Here is our analysis. 1. About shared tools There are more and more threat actors adopting public or open source tools in their operations. This could effectively reduce their effort to develop their own weapons and also increase the barrier for researchers like us to achieve an effective attribution. 2. About Webshell Web server exploitations have become more and more common nowadays and the importance of webshell keeps increasing. Godzilla, a full featured webshell made by Chinese threat actors, has become the favorite of Chinese APT. It is usually deployed jointly with a small webshell like China Chopper to effectively bypass detections. 3. About Cross Platform RAT There are more and more cross platform or multi platform RAT. The reason behind is nowadays threat actors don’t only focus on Windows platform but will intrude from every possible platform like Linux, MacOS or even Android or iOS. 4. Shared Quartermaster of Chinese APT We have observed an interesting code or feature sharing between different malware used by Chinese APT. This kind of finding makes us highly suspect there is an entity or even private company that is responsible for producing all these remote administration tools and distributing them secretly to various Chinese APT groups. Closer Look at Targeted Countries / Regions by APT Groups From countries / regions aspects, our data shows Taiwan, South Korea, and Japan are the most targeted countries by APT groups. Following them are countries in South or Southeast Asia, such as Vietnam, Philippine, Thailand, or Malaysia, etc. Based on this statistic, we will discuss 3 different victim areas and corresponding active threat actors, they are Taiwan, Northeast Asia, and South/Southeast Asia. No.1 Targeted Country / Region: Taiwan Taiwan is the most targeted country in Asia Pacific. This chart shows the distribution of targeted industry sectors. Compared with our data in the past 2 years (2021-2022), we don’t see dramastic changes. Government, IT, education, or critical infrastructure are still on the top list. People might wonder why APT actors are so interested in the IT sector. We believe the reason is that there are more and more supply chain attacks and these IT companies possess good channels or privileges to access big companies or government entities. It makes the IT sector a perfect hopping point. And one interesting phenomena we have observed is the surging attack against the healthcare industry. We suspect the reason behind the attacks are the Taiwanese government’s effort to join WHA, or China’s ambition to collect personal identification information. In the threat actors' part, there are at least 21 known groups aiming at Taiwan in 2023. Among them are Huapi, Amoeba, and Polaris - they are old faces that are on the top list hitting Taiwan. In the meantime, there is a new face, SLIME13 (also known as FlaxTyphoon by Microsoft). SLIME13’s operations became so wild in 2023 that we have observed more than 100 victim entities in Taiwan. This APT group also aggressively expands their attacks to other countries such as Hong Kong, Japan or South Korea, etc. No.2 Targeted Country / Region: Northeast Asia In the Northeast Asia region, the geopolitical situation has changed dramatically in the past 2 years because Japan and South Korea are united together with the U.S. to defend against their enemies in the neighborhood. For this reason, the topmost targeted sectors include government, think tank, and education. These sectors often hold political documents or do sensitive research for their governments. Another interesting phenomena would be China’s attacks against South Korea which were stealthy and low profile in the past. But now China’s attacks turned to become high profile and public, threat actors such as 曉騎營 or 騰蛇 are some good example. Cryptocurrency sectors in this area are targeted and infiltrated by North Korean actors. For the threat actors part, China and North Korea actors dominate this area. North Korean actors are busy collecting geopolitical intelligence and another mission: earning money for their country. In contrast, Chinese APT operations become more stealthy and harder to detect; there are several big campaigns of Barracuda, Fortigate, Citrix or ArrayVPN vulnerabilities. Many of the events are still under investigation or even uncovered yet. No.3 Targeted Country / Region: South Asia & Southeast Asia The third target country / region is the South Asia and Southeast Asia region. Our observations show attacks in this area are driven by issues of the South China Sea, border issues or belt & road and shift of international organization’s factory. That was reflected in the most targeted sectors - military and critical infrastructure are all closely bundled with these issues. In the southeast Asia region, threat actors from China such as Polaris, Amoeba, Gudiao and Vietnam originated groups such as SLIME43 or OceanLotus are very active in these regions. The interesting part regarding Vietnamese APT groups is that they are not only a big concern of neighboring countries but also the domestic people in Vietnam. Our engagement with Vietnamese customers shows their great fear of being intruded by OceanLotus. In the South Asia region, China is also busy attacking and monitoring their neighbors. People might consider Pakistan to be a good friend of China so they could be spared. In contrast, our data shows Pakistan to be highly targeted and infiltrated by China. Another interesting thing is that India and Pakistan both have their own cyber actors and they are fighting with each other a lot. Conclusion 2023 is a busy year, both for threat actors and defenders. Also, more tensions in geopolitics will keep bringing more cyber attacks. New technology might solve human’s problems, but not for attack and defense scenarios. New technology becomes a new opportunity for attackers as well (e.g. cloud services, AI). The reason is that targeted attacks are human-driven; defenders should address human problems by adopting threat intelligence. No one can be spared in the war in the cyber world, so be prepared! This article is an excerpt version which summarizes key statistics. To obtain the complete threat intelligence report, you may fill up the form at the bottom to obtain the “APT Threat Landscape in APAC 2023” report. This article is adapted from "2023 H2 Campaign Tracking Report: APT Threat Landscape in Asia". To discover similar cyber threat intelligence which is focused in Asia-Pacific region, please sign up for the trial of our threat intelligence platform ThreatVision. Please indicate on the ThreatVision page that you would like to apply for trial.

In the final part of our Information Operation White Paper, we will demonstrate China's Information Operations (InfoOps) targeting the global audience. The first part of the report displays a brief overview of its overt operations which are carried out by state media, embassies, and diplomats. Then we look into the covert operations, which can be observed in pro-China fan pages, content farms, and spam botnet. Last but not least, we provide the case study of "Operation Juiker" on Taiwan's largest forum PTT, which suggests the possibility of the APT (Advanced Persistent Threat) actors entering the threat landscape. Key Takeaways 1. China has escalated the level of overt InfoOps via state-media and diplomats. Chinese state media, diplomats, and embassies are the main actors of Chinese overt InfoOps. They shoulder the task to polish the image of the regime and propagate the narrative of the Chinese Communist Party (CCP). It is noteworthy that their official accounts have obtained an unexpected number of followers in recent years. For instance, four Chinese state media are included in the top 20 most-followed pages on Facebook. Their main audience, apart from the Chinese citizens, are overseas Chinese diaspora, which many of them have rights to vote in countries such as the U.S., Canada, and Australia, thus having the ability to influence a country's politics. 2. Covert InfoOps remain active on Western social media platforms. 2020 is a year which has set many records. This year, the takedowns of covert Chinese social media accounts by Facebook, Twitter, and Google are more frequent than ever. However, even with such efforts, we observed that there are new covert actors emerging across the platforms, while the banned actors keep coming back to the scene by registering new domains and new accounts. We spotted that there is a huge number of Facebook pages with admins located in China dedicated to disseminating Chinese propaganda content originated from Chinese social media platform, Weibo. Besides, there are sophisticated actors that create websites and subtle content to help the Chinese government shaping the narrative for the Hong Kong protest. We also detected numerous networks of pro-China political accounts that demonstrated strong signs of automated behavior. 3. APT actors might have entered the InfoOps threat landscape. The situation is become more alarming as we discovered that the Advanced Persistent Threat (APT) actors might have entered the InfoOps threat landscape. APT actors, typically a state-sponsored group, usually conduct prolonged and targeted cyberattacks to mine highly sensitive data. However, in mid-2020, we identified an InfoOp that can be linked to a notorious Chinese APT group which TeamT5 intelligence team has tracked for years. We discovered that the threat actors had disseminated disinformation about "Juiker," a messaging app developed by Taiwan's research institute and widely used by government units, on Taiwan's largest forum PTT. The operation, which we dub as "Operation Juiker," aimed to discredit Taiwan's intelligence agency and government-backed research institute by spreading disinformation of the messaging app being hacked. 4. It is more crucial than ever to adopt threat intelligence solutions to combat the issue. The abovementioned Operation Juiker has well demonstrated the possibility of "APT + InfoOp" attack model, which involves targeted social media campaigns disseminating disinformation based on highly confidential data. Such situation is super tricky, and it could pose a great threat to democratic countries. In this case, threat intelligence can help provide instant analysis of actor methodologies, suspicious indicators, and potential risks. We suggest that it is crucial for government units, critical infrastructure operators, and major business vendors to apply threat intelligence to combat this issue. If you are interested in this white paper, please fill out the form below and get the full-text PDF.