ç®æ¬¡
- ã©ã³ãµã ãŠã§ã¢ãšã¯ïŒ
- ã©ã³ãµã ãŠã§ã¢æ»æã®æŽå²
- ã©ã³ãµã ãŠã§ã¢ã®çš®é¡
- ã©ã³ãµã ãŠã§ã¢ã®äºäŸ
- ã©ã³ãµã ãŠã§ã¢ã«é¢ããçµ±èš
- ã©ã³ãµã ãŠã§ã¢æ»æã®ãã¬ã³ã
- ã©ã³ãµã ãŠã§ã¢ã®ä»çµã¿
- ã©ã³ãµã ãŠã§ã¢æ»æã®æµã
- ã©ã³ãµã ãŠã§ã¢ã®ãªã¹ã¯
- ã©ã³ãµã ãŠã§ã¢ã®è¢«å®³
- ã©ã³ãµã ãŠã§ã¢ã®æ¡æ£
- ã©ã³ãµã ãŠã§ã¢ã®éçºè
- ã©ã³ãµã ãŠã§ã¢ãšèº«ä»£é
- ã©ã³ãµã ãŠã§ã¢ã«ææãããïŒ
- ã©ã³ãµã ãŠã§ã¢ã®è åš
- ã©ã³ãµã ãŠã§ã¢å¯Ÿç
- ã©ã³ãµã ãŠã§ã¢ãµãã€ãã«ã¬ã€ã
- ã©ã³ãµã ãŠã§ã¢ã«é¢ãããããã質å
ã©ã³ãµã ãŠã§ã¢ãšã¯ïŒ
ã©ã³ãµã ãŠã§ã¢ãšã¯ãæªæã®ãããœãããŠã§ã¢ïŒãã«ãŠã§ã¢ïŒã®äžçš®ã§ãæ»æè ã¯è¢«å®³è ã身代éãæ¯æããŸã§ãããŒã¿ãã³ã³ãã¥ãŒã¿ã·ã¹ãã ãæå·åãããã®ã¢ã¯ã»ã¹ãå ¬éããããããã¯ããããããšè è¿«ããŸããå€ãã®å Žåã身代éèŠæ±ã«ã¯æéãèšããããŠããŸãã被害è ãæéå ã«æ¯æããªãå ŽåãããŒã¿ã¯æ°žä¹ ã«å€±ããããã身代éãå¢é¡ãããŸãã
ã©ã³ãµã ãŠã§ã¢ã¯åçŽãªæå·åãè¶ ããŠé²åããæå·åã©ã³ãµã ãŠã§ã¢ãCryptoWallãªã©ã®æ°ããªã¿ã€ããç»å Žããè åšã®ã¬ãã«ãäžãã£ãŠããŸããäžéšã®å€çš®ã¯çŸåšãäºéæåææ³ïŒã©ã³ãµã ãŠã§ã¢2.0ïŒãæ¡çšããŠãããããŒã¿ãæå·åããäžã§ã身代éãæ¯æãããªããã°æ©å¯æ å ±ãæµåºããããšè è¿«ããŸããããã«ãããç¹ã«è©å€ã®äœäžãèŠå¶ã³ã³ãã©ã€ã¢ã³ã¹ãæžå¿µããäŒæ¥ã«ãšã£ãŠããããªããã¬ãã·ã£ãŒãšãªã£ãŠããŸãã
ã©ã³ãµã ãŠã§ã¢æ»æã¯ãŸããŸãèå»¶ããããŸããŸãªæ¥çã®ããããèŠæš¡ã®çµç¹ãæšçã«ããŠããŸããäžå°äŒæ¥ããå€§äŒæ¥ãŸã§ã誰ãå ããããšã¯ã§ããŸããããããã®æ»æã«ã¯ãã°ãã°å³ããæéãèšããããã¹ãã¬ã¹ã®å€ãç¶æ³ã«ããã«ç·æ¥æ§ãå ãããŸããæéå ã«æ¯æããªããã°ãããŒã¿ãæ°žä¹ ã«å€±ããããã身代éã®èŠæ±é¡ãå¢å ããå¯èœæ§ããããŸãã
FBIãå«ãããã€ãã®æ¿åºæ©é¢ã¯ãNo More Ransom Projectãšåæ§ã«ãã©ã³ãµã ãŠã§ã¢ã®ãµã€ã¯ã«ãå©é·ããªãããã身代éã®æ¯æããæ§ããããå§åããŠããŸããããã«ã身代éãæ¯æã£ã被害è ã®åæ°ã¯ãç¹ã«ã·ã¹ãã ããã©ã³ãµã ãŠã§ã¢ãé§é€ãããªãã£ãå Žåãã©ã³ãµã ãŠã§ã¢æ»æã¯ç¹°ãè¿ãããå¯èœæ§ãé«ããšèšãããŠããŸãã
ãµã€ããŒã»ãã¥ãªãã£æè²ãšãã¬ãŒãã³ã°ãå§ããŸããã
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
ã©ã³ãµã ãŠã§ã¢æ»æã®æŽå²
ã©ã³ãµã ãŠã§ã¢ã®èµ·æºã¯1989幎ã«é¡ãããAIDSããŠã€ã«ã¹ãã©ã³ãµã ãŠã§ã¢ã®åä¿¡è ããè³éã匷èŠããããã«å©çšãããã®ãå§ãŸããšãããŠããŸãããã®æ»æãžã®æ¯æãã¯ããããžã®éµäŸ¿ã§è¡ããããã®æç¹ã§ã¯åŸ©å·åããŒããŠãŒã¶ãŒã«éµéãããŠããŸããã
1996幎ãã©ã³ãµã ãŠã§ã¢ã¯ã³ãã³ãã¢å€§åŠã®Moti YungãšAdam Youngã«ãã£ãŠç޹ä»ããããæå·ãŠã€ã«ã¹ã«ãã匷奪ããšããŠç¥ãããŠããŸãããåŠçã§çãŸãããã®ã¢ã€ãã¢ã¯ãçŸä»£ã®æå·åããŒã«ã®é²æ©ã匷床ãåµé æ§ãç©èªã£ãŠããŸããYoungãšYungã¯ã1996幎ã®IEEE Security and Privacyã«ã³ãã¡ã¬ã³ã¹ã§ãæåã®æå·ãŠã€ã«ã¹æ»æã«ã€ããŠçºè¡šããŸããããã®ãŠã€ã«ã¹ã«ã¯æ»æè ã®å ¬ééµãå«ãŸããŠããã被害è ã®ãã¡ã€ã«ãæå·åãããŠããŸããããã®åŸããã«ãŠã§ã¢ã¯è¢«å®³è ã«é察称æå·æãæ»æè ã«éä¿¡ããŠè§£èªããŠããããæéãæ¯æã£ãŠåŸ©å·åéµãè¿ãããä¿ããŸããã
æ»æè ã¯ããµã€ããŒç¯çœªè ã®å¿åæ§ã確ä¿ããããã«ã远跡ãã»ãŒäžå¯èœãªæ¯æããèŠæ±ããããšã§ãé·å¹Žã«ããã£ãŠåµé æ§ãé«ããŠããŸãããäŸãã°ãæªåé«ãã¢ãã€ã«åã©ã³ãµã ãŠã§ã¢ãFusobãã¯ã被害è ã«ãã«ãªã©ã®éåžžã®é貚ã§ã¯ãªããApple iTunesã®ããã«ãŒãã§ã®æ¯æããèŠæ±ããŸãã
ã©ã³ãµã ãŠã§ã¢æ»æã¯ããããã³ã€ã³ã«ä»£è¡šãããæå·éè²šã®æé·ãšãšãã«æ¥å¢ãå§ããŸãããæå·é貚ã¯ãæå·åæè¡ã䜿çšããŠãã©ã³ã¶ã¯ã·ã§ã³ã®æ€èšŒãå®å šæ§ã確ä¿ããæ°ãããŠãããã®äœæãå¶åŸ¡ããããžã¿ã«é貚ã§ãããããã³ã€ã³ä»¥å€ã«ããã€ãŒãµãªã¢ã ãã©ã€ãã³ã€ã³ããªããã«ãªã©ãæ»æè ã被害è ã«äœ¿çšãä¿ã人æ°ã®æå·é貚ãååšããŸãã
ã©ã³ãµã ãŠã§ã¢ã¯ãã»ãŒãã¹ãŠã®æ¥çš®ã®çµç¹ãæ»æããŠããŸããæãæåãªãŠã€ã«ã¹ã®1ã€ã¯ãPresbyterian Memorial Hospitalãžã®æ»æã§ãããã®æ»æã¯ãã©ã³ãµã ãŠã§ã¢ã®æœåšçãªè¢«å®³ãšãªã¹ã¯ãæµ®ã圫ãã«ããŸãããç 究宀ãè¬å±ãç·æ¥æ²»ç宀ã被害ã«éããŸããã
ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æè ã¯ãæãšãšãã«é©æ°çã«ãªã£ãŠããŠããŸããThe Guardianã¯ãæ°ããã©ã³ãµã ãŠã§ã¢ã®è¢«å®³è ãããã¡ã€ã«ã埩å·åããããã«ãä»ã®2人ã®ãŠãŒã¶ãŒã«ãªã³ã¯ãã€ã³ã¹ããŒã«ããã身代éãæ¯æãããæ±ããããç¶æ³ã«ã€ããŠèšèŒããŠããŸãã
ã©ã³ãµã ãŠã§ã¢ã®çš®é¡
ã©ã³ãµã ãŠã§ã¢ã®æ®åã«äŒŽããã©ã³ãµã ãŠã§ã¢æ»æã¯ãŸããŸãè€éåããŠããŸãã
- ã¹ã±ã¢ãŠã§ã¢: ã¹ã±ã¢ãŠã§ã¢ã¯ã被害è ã®ã³ã³ãã¥ãŒã¿ã«ãã«ãŠã§ã¢ãæ€åºããããšããåœã®èŠåã¡ãã»ãŒãžã衚瀺ããŸãããããã®æ»æã¯ãååšããªããã«ãŠã§ã¢ãåé€ããããã®æ¯æããèŠæ±ãããã¢ã³ããŠã€ã«ã¹ ãœãªã¥ãŒã·ã§ã³ãè£ ã£ãŠããããšããããããŸããã¹ã±ã¢ãŠã§ã¢ã¯æ¯èŒçè åšãå°ãªãããã«èŠãããããããŸããããããã§ã倧ããªã¹ãã¬ã¹ãçµæžçæå€±ãåŒãèµ·ããå¯èœæ§ããããŸããåãåãã»ãã¥ãªãã£èŠåã®æ£åœæ§ã確èªããä¿¡é Œã§ããã¢ã³ããŠã€ã«ã¹ ãœãããŠã§ã¢ã«äŸåããããšãéèŠã§ãã
- ã¹ã¯ãªãŒã³ããã«ãŒ: ã¹ã¯ãªãŒã³ããã«ãŒã¯ã被害è ãã³ã³ãã¥ãŒã¿ããããã¯ã¢ãŠããããã¡ã€ã«ãããŒã¿ãžã®ã¢ã¯ã»ã¹ã劚ããããã«èšèšãããŠããŸããéåžžãããã¯è§£é€ã®ããã®æ¯æããèŠæ±ããã¡ãã»ãŒãžã衚瀺ãããŸããã¹ã¯ãªãŒã³ããã«ãŒã¯éåžžã«ç Žå£çã§ãã·ã¹ãã å šäœã䜿çšã§ããªããªãå¯èœæ§ããããŸããããŒã¿ããã¯ã¢ãããæã¡ãããã¯ç»é¢ããã€ãã¹ããããã«ã·ã¹ãã ãå®å šã«èµ·åããæ¹æ³ãç¥ãããšãäžå¯æ¬ ã§ãã
- æå·åã©ã³ãµã ãŠã§ã¢: ãæå·åã©ã³ãµã ãŠã§ã¢ããšãåŒã°ããã©ã³ãµã ãŠã§ã¢ã¯è¢«å®³è ã®ãã¡ã€ã«ãæå·åãã埩å·ããŒãšåŒãæãã«æ¯æããèŠæ±ããŸãããã®ã¿ã€ãã®ã©ã³ãµã ãŠã§ã¢ã¯å£æ» çã§ããã¹ãŠã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããªããªãå¯èœæ§ããããŸãã宿çãªããã¯ã¢ãããšå ç¢ãªãµã€ã㌠ã»ãã¥ãªãã£å¯Ÿçããæå·åã©ã³ãµã ãŠã§ã¢ã«å¯Ÿããæè¯ã®é²åŸ¡çã§ãã
- DDoSæå: 忣åãµãŒãã¹æåŠæ»æã«ããæåã¯ã身代éãæ¯æãããªãéãã被害è ã®ãŠã§ããµã€ãããããã¯ãŒã¯ã«å¯ŸããŠDDoSæ»æãéå§ãããšè è¿«ããŸããDDoSæåã®è åšã¯ãããžã¿ã«ãã¬ãŒã³ã¹ã«å€§ããäŸåããŠããããžãã¹ã«ãšã£ãŠç¹ã«è¢«å®³ã倧ããå¯èœæ§ããããŸããDDoSä¿è·ãå®è£ ãããã®è åšã广çã«è»œæžããããã«ååã«æºåãããã€ã³ã·ãã³ãã¬ã¹ãã³ã¹èšç»ãæã€ããšãéèŠã§ãã
- ã¢ãã€ã« ã©ã³ãµã ãŠã§ã¢: ååã瀺ãããã«ãã¢ãã€ã« ã©ã³ãµã ãŠã§ã¢ã¯ã¹ããŒããã©ã³ãã¿ãã¬ãããªã©ã®ããã€ã¹ãæšçãšããããã€ã¹ã®ããã¯è§£é€ãããŒã¿ã®åŸ©å·åã®ããã®æ¯æããèŠæ±ããŸããã¢ãã€ã« ã©ã³ãµã ãŠã§ã¢ã¯ãå人çšããã³ããžãã¹çšéã§ã®ã¢ãã€ã«ããã€ã¹ã®äœ¿çšå¢å ã«äŒŽããæžå¿µãé«ãŸã£ãŠããŸããã¢ãã€ã«ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã宿çã«æŽæ°ããã¢ããªã®ããŠã³ããŒãã«æ³šæããããšã§ããã®è åšããä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã
- ããã¯ã¹ãŠã§ã¢: ããŸãäžè¬çã§ã¯ãããŸãããããã®æŽç·Žãããã©ã³ãµã ãŠã§ã¢ã¯ã身代éãæ¯æãããªãéãã被害è ã®ã³ã³ãã¥ãŒã¿ããæ©å¯æ å ±ãç§å¯æ å ±ãå ¬éãããšè è¿«ããŸãããªãŒã¯ãŠã§ã¢ãšãåŒã°ãããã®åœ¢åŒã®ã©ã³ãµã ãŠã§ã¢ã¯ããã©ã€ãã·ãŒãè©å€ãè ããããšã§ããããªããã¬ãã·ã£ãŒãå ããŸããå ç¢ãªããŒã¿ä¿è·å¯Ÿçã宿œããããžã¿ã«ã«ä¿åããæ å ±ã«æ³šæããããšããããã¯ã¹ãŠã§ã¢ã®ãªã¹ã¯ã軜æžããã®ã«åœ¹ç«ã¡ãŸãã
- ãµãŒãã¹ãšããŠã®ã©ã³ãµã ãŠã§ã¢ïŒRaaSïŒ: ãµã€ããŒç¯çœªè ã¯ã被害è ãæšçãšããããã®ããã°ã©ã ã䜿çšããä»ã®ããã«ãŒããµã€ããŒæ»æè ã«ã©ã³ãµã ãŠã§ã¢ ããã°ã©ã ãæäŸããŸããRaaSã¯ãã®ãããªè åšãžã®ã¢ã¯ã»ã·ããªãã£ãåçåããã©ã³ãµã ãŠã§ã¢æ»æãããèå»¶ãããŠããŸãããã®ã¢ãã«ã¯ãæ£åœãªãµãŒãã¹ãšããŠã®ãœãããŠã§ã¢ããžãã¹ãšåæ§ã«éå¶ãããç¯çœªçãªé¡§å®¢ã«ã«ã¹ã¿ã㌠ãµããŒããšå®æçãªæŽæ°ãæäŸããŠããŸãã
ãããã¯æãäžè¬çãªã©ã³ãµã ãŠã§ã¢ã®äžéšã«éããŸããããµã€ããŒç¯çœªè ããµã€ããŒã»ãã¥ãªãã£æŠç¥ã«é©å¿ããã«ã€ããŠãè匱æ§ãæªçšãã³ã³ãã¥ãŒã¿ ã·ã¹ãã ã«äŸµå ¥ããæ°ãã驿°çãªæ¹æ³ãžãšç§»è¡ããŠããŸãã
ã©ã³ãµã ãŠã§ã¢ã®äºäŸ
äž»èŠãªã©ã³ãµã ãŠã§ã¢æ»æã«ã€ããŠåŠã¶ããšã§ãçµç¹ã¯ãã»ãšãã©ã®ã©ã³ãµã ãŠã§ã¢æ»æã®æŠè¡ããšã¯ã¹ããã€ããããã³ç¹æ§ã«ã€ããŠã®ç¢ºããªåºç€ã身ã«ã€ããããšãã§ããŸããã©ã³ãµã ãŠã§ã¢ã®ã³ãŒããã¿ãŒã²ãããæ©èœã«ã¯ããªãšãŒã·ã§ã³ããããŸãããã©ã³ãµã ãŠã§ã¢æ»æã®ã€ãããŒã·ã§ã³ã¯éåžžãæŒžé²çãªãã®ã§ãã
- WannaCry: Microsoftã®åŒ·åãªãšã¯ã¹ããã€ããæªçšããŠäžçèŠæš¡ã®ã©ã³ãµã ãŠã§ã¢ã¯ãŒã ãéçºããããã«ã¹ã€ãããäœåããŠææãé£ãæ¢ãããŸã§ã«25äžå°ä»¥äžã®ã·ã¹ãã ã«ææããŸãããProofpointã¯ããã«ã¹ã€ãããèŠã€ããããã«äœ¿çšããããµã³ãã«ã®çºèŠãšãã©ã³ãµã ãŠã§ã¢ã®åè§£ã«æºãããŸãããWannaCryã®é»æ¢ã«ãããProofpointã®é¢äžã«ã€ããŠã詳现ãã芧ãã ããã
- CryptoLocker: ãã®ã©ã³ãµã ãŠã§ã¢ã¯ãæ¯æãã«æå·é貚ïŒãããã³ã€ã³ïŒãèŠæ±ãããŠãŒã¶ãŒã®ããŒããã£ã¹ã¯ãšæ¥ç¶ããããããã¯ãŒã¯ãã©ã€ããæå·åãããçŸäžä»£ã®ã©ã³ãµã ãŠã§ã¢ã®æåã®1ã€ã§ãããCryptolockerã¯ãFedExãUPSã®è¿œè·¡éç¥ãåä¹ãæ·»ä»ãã¡ã€ã«ä»ãã®ã¡ãŒã«ãä»ããŠæ¡æ£ãããŸãããããã«å¯Ÿãã埩å·åããŒã«ã¯2014幎ã«ãªãªãŒã¹ãããŸãããããããããŸããŸãªã¬ããŒãã«ãããšãCryptoLockerã«ãã£ãŠ2700äžãã«ä»¥äžã匷奪ããããšå ±åãããŠããŸãã
- NotPetya: NotPetyaã¯ãMicrosoft WindowsããŒã¹ã®ã·ã¹ãã ã®ãã¹ã¿ãŒããŒãã¬ã³ãŒãã«ææããŠæå·åãããªã©ãååã®Petyaã®æŠè¡ã掻çšãããæã被害ã倧ããã©ã³ãµã ãŠã§ã¢æ»æã®1ã€ãšèããããŠããŸããNotPetyaã¯ãWannaCryãšåãè匱æ§ãå©çšããŠæ¥éã«æ¡æ£ãã倿Žãå ã«æ»ãããã«ãããã³ã€ã³ã§ã®æ¯æããèŠæ±ããŸãããNotPetyaã¯ãã¹ã¿ãŒããŒãã¬ã³ãŒããžã®å€æŽãåãæ¶ãããšãã§ãããã¿ãŒã²ããã·ã¹ãã ãå埩äžèœã«ãããããäžéšã§ã¯ã¯ã€ããŒã«åé¡ãããŠããŸãã
- Bad Rabbit: NotPetyaãšé¡äŒŒããã³ãŒããšãšã¯ã¹ããã€ãã䜿çšããŠæ¡æ£ããBad Rabbitã¯ããã·ã¢ãšãŠã¯ã©ã€ããã¿ãŒã²ãããšããç®ã«èŠããã©ã³ãµã ãŠã§ã¢ã§ãäž»ã«ååœã®ã¡ãã£ã¢äŒæ¥ã«åœ±é¿ãäžããŸãããNotPetyaãšã¯ç°ãªããBad Rabbitã¯èº«ä»£éãæ¯æããšåŸ©å·åã§ããããã«ãªã£ãŠããŸãããå€ãã®å Žåãåœã®Flash Playerã®ã¢ããããŒãã«ãã£ãŠæ¡æ£ããããã©ã€ããã€ããŠã³ããŒãæ»æã«ãã£ãŠãŠãŒã¶ãŒã«åœ±é¿ãäžããå¯èœæ§ãããããšãææãããŠããŸãã
- REvil: REvilã¯ãééç®çã®æ»æè ã°ã«ãŒãã«ãã£ãŠéçºãããŸãããæå·åããåã«ããŒã¿ãæµåºãããæšçãšãªã£ã被害è ã身代éãéããªãããšãéžæããå Žåãè è¿«ããŠæ¯æãããããšãã§ããŸãããã®æ»æã¯ãWindowsãšMacã®ã€ã³ãã©ã«ããããé©çšããããã«äœ¿çšãããITãããžã¡ã³ããœãããŠã§ã¢ã䟵害ãããããšã«èµ·å ããŠããŸããæ»æè ã¯ãäŒæ¥ã®ã·ã¹ãã ã«REvilã©ã³ãµã ãŠã§ã¢ãæ³šå ¥ããããã«äœ¿çšãããKaseyaãœãããŠã§ã¢ã䟵害ããŸããã
- Ryuk: Ryukã¯ãäž»ã«ã¹ãã¢ãã£ãã·ã³ã°ã§äœ¿çšãããæåé åžã®ã©ã³ãµã ãŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ã§ããã¿ãŒã²ããã¯ãåµå¯ã«ãã£ãŠæ éã«éžã°ããŸããéžã°ãã被害è ã«ã¡ãŒã«ã¡ãã»ãŒãžãéä¿¡ãããææããã·ã¹ãã ã§ãã¹ããããŠãããã¹ãŠã®ãã¡ã€ã«ãæå·åãããŸãã
ã©ã³ãµã ãŠã§ã¢ã«é¢ããçµ±èš
ã©ã³ãµã ãŠã§ã¢æ»æã®éã¯å¹Žã å€åããŠãããã®ã®ããããã®ã¿ã€ãã®ãµã€ããŒæ»æã¯çµç¹ã«ãšã£ãŠæãäžè¬çã§æå€±ã倧ããæ»æã®äžã€ã§ããç¶ããŠããŸããã©ã³ãµã ãŠã§ã¢æ»æã«é¢ããçµ±èšã¯ãçµç¹ããµã€ã㌠ã»ãã¥ãªãã£å¯Ÿçãšã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ã匷åããããã®ç·æ¥ã®è¡åãä¿ãèŠéãšãªã£ãŠããŸãã
- Sophosã®ãThe State of Ransomware 2022ãã¬ããŒãã«ãããšã2021幎ã«ã©ã³ãµã ãŠã§ã¢æ»æã¯çµç¹ã®66%ã«åœ±é¿ãäžãã2020å¹Žãšæ¯èŒããŠå幎æ¯78%ã®åçãªå¢å ã瀺ããŠããŸãã
- åœç€Ÿã®ã2023 State of the Phishãã¬ããŒãã§ã¯ã調æ»å¯Ÿè±¡ã®çµç¹ã®64%ã2022幎ã«ã©ã³ãµã ãŠã§ã¢ã®åœ±é¿ãåãããšåçãããã®ã°ã«ãŒãã®3åã®2以äžãè€æ°ã®ã€ã³ã·ãã³ããå ±åããŠããŸãããã®ãããå°éå®¶ã¯æšå¹Žã®å®éã®ã€ã³ã·ãã³ãæ°ãšé¢é£ããæå€±ã¯å ±åãããŠãããããã¯ããã«é«ããšæšæž¬ããŠããŸãã
- BlackFogã®ã2022 Ransomware Reportãã«ãããšãå»çæ¥çã¯ã©ã³ãµã ãŠã§ã¢ã®æšçã«æããªãããããèº«ä»£éæ¯æãçã¯85%ã«éããŠããŸãããŸããæè²æ©é¢ã¯ã©ã³ãµã ãŠã§ã¢æ»æã®æå€§ã®å¢å ïŒ2021幎ã«28%ïŒãçµéšããŠããŸãã
- Googleã®VirusTotalãµãŒãã¹ã«ãããšãWindowsã·ã¹ãã ã¯åœ±é¿ãåããã·ã¹ãã ã®å€§å€æ°ãå ããã©ã³ãµã ãŠã§ã¢ ãã«ãŠã§ã¢æ»æã®95%ãå ããŠããŸãã
- Cybersecurity Venturesã«ãããšãã©ã³ãµã ãŠã§ã¢æ»æã¯2031幎ãŸã§ã«è¢«å®³è ã«å¹Žé2,650åãã«ä»¥äžã®æå®³ãäžãããšäºæž¬ãããŠããŸãã
ã©ã³ãµã ãŠã§ã¢ã®ãã¬ã³ã
ã©ã³ãµã ãŠã§ã¢ã®ãã¬ã³ãã¯ææ°ã®çµ±èšã«æ²¿ã£ãŠé²åãç¶ããŠããŸããæ³šç®ãã¹ããã¬ã³ãã«ã¯ä»¥äžãå«ãŸããŸãã
- ã°ããŒãã«åããè åšã®å¢å
- ããæšçãçµã£ãé«åºŠãªæ»æ
- 倿®µéæåãã¯ããã¯ã®æé·
- ã©ã³ãµã ãŠã§ã¢äŸµå®³ã®é »åºŠã®äžæ
- ã»ãã¥ãªãã£æ å¢ã®åŒ·åã«äŒŽã身代éäŸ¡æ Œã®æšªã°ã
æ¿åºã®ä»å ¥ã¯ãã©ã³ãµã ãŠã§ã¢æ»æã®å¯ŸåŠæ¹æ³ãå€ããå¯èœæ§ã®ããããäžã€ã®äž»èŠãªãã¬ã³ãã§ããGartnerã¯ã2025幎ãŸã§ã«äžçã®æ¿åºã®30%ãã©ã³ãµã ãŠã§ã¢æ¯æãæ³ãå¶å®ããå¯èœæ§ãé«ããšäºæž¬ããŠããŸãã
ã©ã³ãµã ãŠã§ã¢æ¯æãã®å¹³åå²åŒãå¢å ããŠããããã§ããææ°ã®ã©ã³ãµã ãŠã§ã¢ ãã¬ã³ãã«ãããšã被害è ã¯èº«ä»£éæ¯æãã«20%ãã25%ã®å²åŒãæåŸ ã§ããäžéšã§ã¯æå€§60%ã®å²åŒãèŠãããŸãã
ã©ã³ãµã ãŠã§ã¢ã®ä»çµã¿
ã©ã³ãµã ãŠã§ã¢ã¯ãã·ã¹ãã äžã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ããããã¯ãŸãã¯é²æ¢ããã被害è ããééã匷èŠããããã«èšèšããããã«ãŠã§ã¢ã®äžçš®ã§ããæãäžè¬çãªã©ã³ãµã ãŠã§ã¢ã¯ãæå·ååãšç»é¢ããã¯åã®2çš®é¡ã§ããæå·ååã¯ããã®åã®éããã·ã¹ãã äžã®ããŒã¿ãæå·åãã埩å·åããŒããªããã°ã³ã³ãã³ããå©çšã§ããªãããã«ããŸããäžæ¹ãç»é¢ããã¯åã¯ãã·ã¹ãã ãæå·åãããŠããããšã䞻匵ãããããã¯ãç»é¢ã§ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãåçŽã«ãããã¯ãããã®ã§ãã
å³1ïŒã©ã³ãµã ãŠã§ã¢ã被害è ãéšããŠã€ã³ã¹ããŒã«ãããããšããæå£
被害è ã¯ãããã¯ç»é¢ïŒæå·ååãšç»é¢ããã¯åã®äž¡æ¹ã«å ±éïŒã§ããããã³ã€ã³ãªã©ã®æå·é貚ãè³Œå ¥ããŠèº«ä»£éãæ¯æãããã«éç¥ãããããšããããããŸãã身代éã®æ¯æããå®äºãããšã被害è ã¯åŸ©å·åããŒãåãåãããã¡ã€ã«ã®åŸ©å·åã詊ã¿ãããšãã§ããŸãã身代éãæ¯æã£ãåŸã®åŸ©å·åã®æå床åããç°ãªãããšãè€æ°ã®æ å ±æºããå ±åãããŠããã埩å·åãä¿èšŒãããŠããããã§ã¯ãããŸããããŸãã被害è ãããŒãåãåããªãããšããããŸãã身代éãæ¯æãããããŒã¿ãè§£æŸãããåŸã§ããã³ã³ãã¥ãŒã¿ã·ã¹ãã ã«ãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ããæ»æããããŸãã
æå·ååã©ã³ãµã ãŠã§ã¢ã¯ãåœåã¯äž»ã«å人ã®ã³ã³ãã¥ãŒã¿ã察象ãšããŠããŸããããéèŠãªã·ã¹ãã ã®ããã¯ãè§£é€ããŠæ¥åžžæ¥åãåéããããã«ã¯ãå人ãããäŒæ¥ãããå€ãã®è²»çšãæ¯æãããšãå€ããããããžãã¹ãŠãŒã¶ãŒãã¿ãŒã²ããã«ãããã®ãå¢ããŠããŸãã
äŒæ¥ã®ã©ã³ãµã ãŠã§ã¢ã®ææããŠã€ã«ã¹ã¯ãéåžžãæªæã®ããã¡ãŒã«ããå§ãŸããŸããçãããšãç¥ããªããŠãŒã¶ãŒãæªæã®ããããŸãã¯å±éºã«ãããããæ·»ä»ãã¡ã€ã«ãéããããURLãã¯ãªãã¯ãããããŸãã
ãã®æç¹ã§ãã©ã³ãµã ãŠã§ã¢ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããã被害è ã®PCããã³æ·»ä»ãã¡ã€ã«äžã®äž»èŠãªãã¡ã€ã«ã®æå·åãéå§ããŸããããŒã¿ãæå·åããåŸãã©ã³ãµã ãŠã§ã¢ã¯ææããããã€ã¹ã«ã¡ãã»ãŒãžã衚瀺ããŸããã¡ãã»ãŒãžã«ã¯ãäœãèµ·ããã®ããæ»æè ãžã®æ¯æãæ¹æ³ãªã©ã説æãããŠããŸãã被害è ãæ¯æããè¡ã£ãå Žåãã©ã³ãµã ãŠã§ã¢ã¯ãããŒã¿ã®ããã¯ãè§£é€ããããã®ã³ãŒããååŸããããšãçŽæããŸãã
ã©ã³ãµã ãŠã§ã¢æ»æã®æµã
ã©ã³ãµã ãŠã§ã¢æ»æã«ã¯ããããåºæã®ç¹åŸŽãããå ŽåããããŸãããã»ãšãã©ã¯åæ§ã®ãã¿ãŒã³ã«åŸã£ãŠããŸããå žåçãªæ®µéã¯æ¬¡ã®ãšããã§ãã
- åæäŸµå ¥: æ»æã¯ããµã€ããŒç¯çœªè ãã·ã¹ãã ã«äŸµå ¥ãããšãã«å§ãŸããŸãããã®ã¢ã¯ã»ã¹ã¯ããã£ãã·ã³ã°ã¡ãŒã«ãæªçšãããè匱æ§ããããã¯æªæã®ãããªã³ã¯ã®ãã£ããããã¯ãªãã¯ãéããŠçºçããå¯èœæ§ããããŸããããã¯ãå®¶ã®çªãéãããŸãŸã«ãããããªãã®ã§ãæ»æè ã¯åžžã«ãããã®äŸµå ¥å£ãæ¢ããŠããŸãã
- è¶³å Žã®ç¢ºç«: äŸµå ¥åŸãæ»æè ã¯èªåã®ç«å Žã匷åããããã«è¡åããŸãã远å ã®ãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ããããå°æ¥ã®ã¢ã¯ã»ã¹ã®ããã®ããã¯ãã¢ãäœæããããããããããŸãããããã¯ãäŸµå ¥è ãããªããç¥ããªããã¡ã«å±æ ¹è£éšå±ã«ãã£ã³ããèšå¶ãããããªãã®ã§ãã
- åµå¯: ã·ã¹ãã å ã§èœã¡çããæ»æè ã¯æ¢çŽ¢ãéå§ããŸãã圌ãã¯äŸ¡å€ããããŒã¿ãæ¢ãããããã¯ãŒã¯æ§é ãçè§£ããæœåšçãªæšçãç¹å®ããŠããŸããããã¯ãæ³¥æ£ãéãã«ããªãã®å®¶ã®äžãç§»åããåéšå±ã®è²Žéåã確èªãããããªãã®ã§ãã
- æš©éææ Œ: æ»æè ã¯ããå€ãã®ã³ã³ãããŒã«ãåŸãããã«ã·ã¹ãã æš©éãå¢ããããšããŸããããã¯æ¬è³ªçã«ãããªãã®å®¶ã®ãã¹ã¿ãŒããŒãæã«å ¥ããããšããŠãããããªãã®ã§ã以åã¯ã¢ã¯ã»ã¹ã§ããªãã£ãé åãžã®ã¢ã¯ã»ã¹ãå¯èœã«ããŸãã
- ããŒã¿åé: ã¢ã¯ã»ã¹æš©ãææ Œãããšãæ»æè ã¯æ©å¯æ å ±ã®åéãéå§ããŸãããã¡ã€ã«ãã³ããŒããããèªèšŒæ å ±ãçãã ãã䟡å€ããããŒã¿ãæœåºãããããå¯èœæ§ããããŸãããã®æ®µéã¯ãæ³¥æ£ãããªãã®æã貎éãªææç©ã§ããã°ãæºãããããªãã®ã§ãã
- æ»æã®æºå: ã©ã³ãµã ãŠã§ã¢ãèµ·åããåã«ãæ»æè ã¯æå€§ã®åœ±é¿ã確ä¿ããããã®æé ãèžãããšããããããŸããããã«ã¯ãã»ãã¥ãªã㣠ãœãããŠã§ã¢ã®ç¡å¹åãããã¯ã¢ããã®åé€ãå«ãŸããå ŽåããããŸããããã¯ãå©ããæ±ããããšãã§ããªãããã«é»è©±ç·ãåæããã®ãšåãã§ãã
- ã©ã³ãµã ãŠã§ã¢ã®å±é: æçµçã«ãã©ã³ãµã ãŠã§ã¢ãèµ·åãããŸãããã¡ã€ã«ãæå·åãããã·ã¹ãã ãããã¯ããã身代éèŠæ±ã衚瀺ãããŸããããã¯ããªãããå®¶ãèããããæ³¥æ£ãããªãã®è³ç£ã®è¿åŽã®ããã«æ¯æããèŠæ±ããã¡ã¢ãæ®ããããšã«æ°ã¥ãç¬éãšåæ§ã§ãã
ã©ã³ãµã ãŠã§ã¢æ»æã¯ãããã®æ®µéãçŽ æ©ãé²è¡ããããšããããæã«ã¯æ°æéã§è¡ããŸããèŠæãæ ãããæ»æã®å段éã§å ç¢ãªã»ãã¥ãªãã£å¯Ÿçãè¬ããããšããçµç¹ã®ããžã¿ã«è³ç£ãä¿è·ããããã«æ¥µããŠéèŠã§ãã
ã©ã³ãµã ãŠã§ã¢ã®ãªã¹ã¯
ã€ã³ã¿ãŒãããã«æ¥ç¶ãããŠããããããããã€ã¹ããæ¬¡ã®ã©ã³ãµã ãŠã§ã¢ã®è¢«å®³è ãšãªãå±éºæ§ããããŸããã©ã³ãµã ãŠã§ã¢ã¯ãããŒã«ã«ããã€ã¹ãšãããã¯ãŒã¯ã«æ¥ç¶ãããã¹ãã¬ãŒãžãã¹ãã£ã³ããŸããã€ãŸããè匱ãªããã€ã¹ã¯ãããŒã«ã«ãããã¯ãŒã¯ãç ç²ãšãªãå¯èœæ§ããããŸããããŒã«ã«ãããã¯ãŒã¯ãäŒæ¥ã®å Žåãã©ã³ãµã ãŠã§ã¢ã¯éèŠãªææžãã·ã¹ãã ãã¡ã€ã«ãæå·åãããµãŒãã¹ãçç£æ§ã忢ãããå¯èœæ§ããããŸãã
ã€ã³ã¿ãŒãããã«æ¥ç¶ããããã€ã¹ã¯ãææ°ã®ãœãããŠã§ã¢ã»ãã¥ãªãã£ããããé©çšããã©ã³ãµã ãŠã§ã¢ãæ€åºã»åæ¢ãããã«ãŠã§ã¢å¯Ÿçãã€ã³ã¹ããŒã«ãããŠããå¿ èŠããããŸããWindows XPã®ãããªã¡ã³ããã³ã¹ãçµäºããå€ãOSã¯ãããé«ããªã¹ã¯ã䌎ããŸãã
ã©ã³ãµã ãŠã§ã¢ã®è¢«å®³
ã©ã³ãµã ãŠã§ã¢ã®è¢«å®³ã«éã£ãäŒæ¥ã¯ãçç£æ§ãããŒã¿ã®æå€±ã«ãããæ°åãã«ã®æå€±ã被ãå¯èœæ§ããããŸããããŒã¿ã«ã¢ã¯ã»ã¹ã§ããæ»æè ã¯ã被害è ãè è¿«ããŠããŒã¿ãå ¬éããããŒã¿æµåºãæŽé²ããããšã§èº«ä»£éãæ¯æããããããè¿ éã«æ¯æããªãçµç¹ã¯ããã©ã³ãã®æ¯æã蚎èšãªã©ã®äºæ¬¡çãªåœ±é¿ãããã«çããå¯èœæ§ããããŸãã
ã©ã³ãµã ãŠã§ã¢ã¯çç£æ§ãäœäžãããã®ã§ããŸãå°ã蟌ããå¿ èŠã§ããå°ã蟌ããåŸãçµç¹ã¯ããã¯ã¢ãããã埩å ãããã身代éãæ¯æããã®ã©ã¡ãããéžæããŸããæ³å·è¡æ©é¢ã¯ææ»ã«åœãããŸãããã©ã³ãµã ãŠã§ã¢ã®éçºè ã远跡ããã«ã¯èª¿æ»æéãå¿ èŠã§ã埩æ§ãé ãããã ãã§ããæ ¹æ¬çãªåå åæã«ããè匱æ§ãç¹å®ãããŸããã埩æ§ã®é ãã¯çç£æ§ãšäºæ¥åçã«åœ±é¿ãåãŒããŸãã
æ³å·è¡æ©é¢ã¯ææ»ã«é¢äžããŸãããã©ã³ãµã ãŠã§ã¢ã®äœæè ã远跡ããã«ã¯å埩ãé ãããèª¿æ»æéãå¿ èŠã§ãããã®é å»¶ã¯ãããŠã³ã¿ã€ã ã®1æéããšã«åçãšçç£æ§ã®æå€±ã«çŽçµããããã財æ¿ç圱é¿ãæªåãããå¯èœæ§ããããŸããããã«ãæ³å·è¡æ©é¢ã®é¢äžã«ããæ»æã®å ¬éé瀺ã«ã€ãªãããäŒæ¥ã®è©å€ãããã«æãªãå¯èœæ§ããããŸãã
æ ¹æ¬åå åæã¯è匱æ§ãç¹å®ããŸãããå埩ãé ãããå¯èœæ§ããããŸããåœé¢ã®å±æ©ã管çããããšãäŒæ¥ã¯å°æ¥ã®æ»æãé²ãããã«ã»ãã¥ãªãã£ã€ã³ãã©ã®ã¢ããã°ã¬ãŒãã«å€é¡ã®ã³ã¹ããè² æ ããããšããããããŸããããã«ã¯ãé«åºŠãªãµã€ã㌠ã»ãã¥ãªã㣠ãœãªã¥ãŒã·ã§ã³ãåŸæ¥å¡ãã¬ãŒãã³ã°ããã°ã©ã ãããã³ITã»ãã¥ãªãã£äººå¡ã®è¿œå éçšãžã®æè³ãå«ãŸããå ŽåããããŸãã
æ»æã®äœæ³¢ã¯äŒæ¥ã«é·æçãªåœ±é¿ãäžããå¯èœæ§ããããŸãã顧客ã®ä¿¡é Œãæãªãããããžãã¹ã®æå€±ã«ã€ãªããå¯èœæ§ããããŸããèŠå¶ã®å³ããæ¥çã§ã¯ãäŒæ¥ã¯éèŠãªããŒã¿ãä¿è·ã§ããªãã£ãããšã§çœ°éãæ³çæªçœ®ã«çŽé¢ããå¯èœæ§ããããŸããåŸæ¥å¡ãžã®å¿çç圱é¿ãéå°è©äŸ¡ãã¹ãã§ã¯ãªããæ»æã®ã¹ãã¬ã¹ãšäžç¢ºå®æ§ã¯ã·ã¹ãã ã埩æ§ããåŸãé·æã«ããã£ãŠã¢ã©ã«ãšçç£æ§ã«åœ±é¿ãäžããå¯èœæ§ããããŸãã
ã©ã³ãµã ãŠã§ã¢ã®æ¡æ£
åšå® å€åè ã®å¢å ã«ãããè åšã¢ã¯ã¿ãŒã¯ãã£ãã·ã³ã°ã®å©çšãå¢å ãããŸãããã©ã³ãµã ãŠã§ã¢ã®ææçµè·¯ã¯ããã£ãã·ã³ã°ãäž»ãªèµ·ç¹ãšãªã£ãŠããŸãããã£ãã·ã³ã°ã¡ãŒã«ã¯ãäœæš©éãŠãŒã¶ãŒãšé«æš©éãŠãŒã¶ãŒã®äž¡æ¹ã®åŸæ¥å¡ãã¿ãŒã²ããã«ããŠããŸããã¡ãŒã«ã¯å®äŸ¡ã§äœ¿ãããããããæ»æè ã«ãšã£ãŠã©ã³ãµã ãŠã§ã¢ãåºããããã®äŸ¿å©ãªææ®µãšãªã£ãŠããŸãã
éåžžãããã¥ã¡ã³ãã¯ã¡ãŒã«ã§åãæž¡ããããããããŠãŒã¶ãŒã¯ã¡ãŒã«ã®æ·»ä»ãã¡ã€ã«ã§ãã¡ã€ã«ãéãããšãäœãšãæã£ãŠããŸãããæªæã®ãããã¯ããå®è¡ãããã©ã³ãµã ãŠã§ã¢ãããŒã«ã«ããã€ã¹ã«ããŠã³ããŒãããããã€ããŒããé ä¿¡ãããŸããã©ã³ãµã ãŠã§ã¢ã¯é»åã¡ãŒã«ã§ç°¡åã«æ¡æ£ããããšãã§ãããããäžè¬çãªãã«ãŠã§ã¢æ»æãšãªã£ãŠããŸããããã«ãæ»æè ã¯æªæã®ãããã¡ã€ã«ãç·æ¥ãŸãã¯éèŠãªãã®ãšããŠåœè£ ãã人éã®å¥œå¥å¿ãšç·æ¥æ§ãæªçšããŠææã®å¯èœæ§ãé«ããããšããããããŸãã
ãã«ãŠã§ã¢ãããã®å ¥æå¯èœæ§ãåºç¯ãªã©ã³ãµã ãŠã§ã¢æ»æã«å¯äžããŠããŸãããããã®ãšã¯ã¹ããã€ããããã¯ããã€ã¹ã®ãœãããŠã§ã¢è匱æ§ãã¹ãã£ã³ããããã€ã¹ã«ããã«ææãããããã«è¿œå ã®ãã«ãŠã§ã¢ãå±éãããªã³ããã³ãã§ãã«ãŠã§ã¢ãµã³ãã«ãçæããŸãããµãŒãã¹ãšããŠã®ãã«ãŠã§ã¢ã®ãã¬ã³ãããããã®ãããã®äººæ°ãé«ããŠããŸãããã®ã©ã³ãµã ãŠã§ã¢ã®ãæ°äž»åãã«ããããµã€ããŒç¯çœªè ã®ããŒãã«ãäžãããæè¡çã¹ãã«ãéãããŠãã人ã§ãé«åºŠãªæ»æã仿ããããšãå¯èœã«ãªããŸããã
ã¡ãŒã«ãšãšã¯ã¹ããã€ãããããè¶ ããŠãã©ã³ãµã ãŠã§ã¢ã¯ä»ã®ãã¯ãã«ãéããŠæ¡æ£ããå¯èœæ§ããããŸãã
- ãªã¢ãŒã ãã¹ã¯ããã ãããã³ã«ïŒRDPïŒã®æªçš: æ»æè ã¯ãç¹ã«ãªã¢ãŒãã¯ãŒã¯ã®å¢å ã«äŒŽããã»ãã¥ãªãã£ãäžååãªRDPæ¥ç¶ãæšçã«ããããšããããããŸãã
- ãœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°: ã©ã³ãµã ãŠã§ã¢ã¯ãåœã®ãœãããŠã§ã¢ ã¢ããããŒããæªæã®ãããŠã§ããµã€ããªã©ãããŸããŸãªåœ¢åŒã®ãœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°ãéããŠæ¡æ£ããå¯èœæ§ããããŸãã
- ãµãã©ã€ ãã§ãŒã³æ»æ: ä¿¡é ŒãããŠãããœãããŠã§ã¢ ãããã€ããŒã䟵害ããããšã§ãæ»æè ã¯äžèŠæ£åœãªãœãããŠã§ã¢ ã¢ããããŒããéããŠã©ã³ãµã ãŠã§ã¢ãé åžããããšãã§ããŸãã
ã©ã³ãµã ãŠã§ã¢ã®æ¥éãªæ¡æ£ã¯ãããžã¿ã«äŸåã®å¢å ã远跡ãå°é£ãªæå·éè²šæ¯æãã®å°é ããããŠé«ãç¥å床ãæã€æ»æã®æåã«ãã£ãŠå€ãã®ãµã€ããŒç¯çœªè ããã®æ¹æ³ãæ¡çšããããä¿ããããªã©ã®èŠå ã«ãã£ãŠããã«ä¿é²ãããŠããŸãã
ã©ã³ãµã ãŠã§ã¢ã®éçºè
é«åºŠãªæ»æã§ã¯ãç¬èªã®ããŒãžã§ã³ãæ§ç¯ããéçºè ã®ã©ã³ãµã ãŠã§ã¢ã䜿çšãããããšããããŸããäºçš®ã¯ãæ¢åã®ã©ã³ãµã ãŠã§ã¢ã®ã³ãŒãããŒã¹ã䜿çšãããã€ããŒããšæ»ææ¹æ³ã倿Žããããã«å¿ èŠãªæ©èœã ãã倿ŽããŸããã©ã³ãµã ãŠã§ã¢ã®éçºè ã¯ããã«ãŠã§ã¢ãã«ã¹ã¿ãã€ãºããŠä»»æã®ã¢ã¯ã·ã§ã³ãå®è¡ãã奜ã¿ã®æå·ã䜿çšããããšãã§ããŸãã
æ»æè ã¯åžžã«éçºè ãšã¯éããŸãããã©ã³ãµã ãŠã§ã¢ã®éçºè ã®äžã«ã¯ããœãããŠã§ã¢ãä»è ã«è²©å£²ãããããªãŒã¹ããŠäœ¿çšãããããè ãããŸããã©ã³ãµã ãŠã§ã¢ã¯ã顧客ãããã·ã¥ããŒãã«èªèšŒããŠç¬èªã®ãã£ã³ããŒã³ãéå§ããMalware-as-a-ServiceïŒMaaSïŒãšããŠè²žãåºãããããšããããŸãããããã£ãŠãæ»æè ã¯ãå¿ ãããã³ãŒããŒããã«ãŠã§ã¢ã®å°éå®¶ãšã¯éããŸããã圌ãã¯ãã©ã³ãµã ãŠã§ã¢ããªãŒã¹ããããã«éçºè ã«ãéãæãå人ã§ããããŸãã
ã©ã³ãµã ãŠã§ã¢ãšèº«ä»£é
ã©ã³ãµã ãŠã§ã¢ã¯ãã¡ã€ã«ãæå·åããåŸããŠãŒã¶ãŒã«å¯ŸããŠãã¡ã€ã«ãæå·åãããŠããããšãšãæ¯æããªããã°ãªããªãéé¡ãåç¥ããç»é¢ã衚瀺ããŸããéåžžã被害è ã¯ç¹å®ã®æ¯ææéãäžãããããã身代éãå¢é¡ãããŸãããŸããæ»æè ã¯äŒæ¥ãè ããŠãã©ã³ãµã ãŠã§ã¢ã®è¢«å®³è ã§ããããšãå ¬ã«çºè¡šããããšããããŸãã
æ¯æãã®æå€§ã®ãªã¹ã¯ã¯ãããŒã¿ã埩å·ããããã®æå·éµãåãåããªãããšã§ããçµç¹ã¯ãéãæã£ãŠãã埩å·åããŒãæã«å ¥ããªãããšããããŸããã»ãšãã©ã®å°éå®¶ã¯ãæ»æè ã«ééçãªå©çãæ°žç¶ãããªãããã«èº«ä»£éã®æ¯æãã«å察ããããå©èšããŠããŸãããå€ãã®çµç¹ã¯éžæã®äœå°ã倱ã£ãŠããŸããã©ã³ãµã ãŠã§ã¢ã®éçºè ã¯æå·é貚ã§ã®æ¯æããèŠæ±ãããããééã®æåãåãæ¶ãããšã¯ã§ããŸããã
ã©ã³ãµã ãŠã§ã¢ã«ææãããïŒ
ã©ã³ãµã ãŠã§ã¢ããã®ãã€ããŒãã¯å³åº§ã«çºçããŸãããã«ãŠã§ã¢ã¯ãæ¯æãã®æç€ºãšãã¡ã€ã«ã«äœãèµ·ãã£ããã«ã€ããŠã®æ å ±ãå«ãã¡ãã»ãŒãžããŠãŒã¶ãŒã«è¡šç€ºããŸããã©ã³ãµã ãŠã§ã¢ã®äžã«ã¯ããããã¯ãŒã¯äžã®ä»ã®å Žæã«æ¡æ£ãã远å ã®ã¹ãã£ã³ã§éèŠãªãã¡ã€ã«ãèŠã€ããããšãããã®ãããããã管çè ã¯è¿ éã«å¯Ÿå¿ããããšãéèŠã§ããã©ã³ãµã ãŠã§ã¢ã«é©åã«å¯Ÿå¿ããããã«ãããã€ãã®åºæ¬çãªã¹ããããèžãããšãã§ããŸãããæ ¹æ¬åå ã®åæãã¯ãªãŒã³ã¢ããã調æ»ã«ã¯ãéåžžãå°éå®¶ã®ä»å ¥ãå¿ èŠã§ããããšã«æ³šæããŠãã ããã
- ã©ã®ã·ã¹ãã ã圱é¿ãåããŠãããã倿ããã ä»ã®ç°å¢ã«åœ±é¿ãäžããªãããã«ãã·ã¹ãã ãåé¢ããå¿ èŠããããŸãããã®ã¹ãããã¯ãç°å¢ãžã®ãã¡ãŒãžãæå°éã«æããå°ã蟌ãã®äžéšã§ãã
- ã·ã¹ãã ã®æ¥ç¶ãè§£é€ããå¿ èŠã«å¿ããŠé»æºãèœãšããã©ã³ãµã ãŠã§ã¢ã¯ãããã¯ãŒã¯äžã§æ¥éã«æ¡æ£ããããããããã¯ãŒã¯ã¢ã¯ã»ã¹ãç¡å¹ã«ãããã黿ºãèœãšããŠãã·ã¹ãã ãåãé¢ãå¿ èŠããããŸãã
- æãéèŠãªã·ã¹ãã ãããæ©ãæ£åžžãªç¶æ ã«æ»ãããã«ã埩æ§ã®åªå é äœãã€ãããéåžžãåªå é äœã¯çç£æ§ãåçãžã®åœ±é¿ã«åºã¥ããŠæ±ºå®ãããŸãã
- ãããã¯ãŒã¯ããè åšãæ ¹çµ¶ãããæ»æè ã¯ããã¯ãã¢ã䜿çšããå¯èœæ§ããããããæ ¹çµ¶ã¯ä¿¡é Œã§ããå°éå®¶ã«ãã£ãŠè¡ãããå¿ èŠããããŸããå°éå®¶ã¯ãæ ¹æ¬åå ã®åæã§è匱æ§ãšåœ±é¿ãåãããã¹ãŠã®ã·ã¹ãã ãç¹å®ããããã«ããã°ã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãã
- å°éå®¶ã«ç°å¢ãèŠçŽããŠããããã»ãã¥ãªãã£ã¢ããã°ã¬ãŒãã®å¯èœæ§ãæ¢ããã©ã³ãµã ãŠã§ã¢ã®è¢«å®³è ã2床ç®ã®æ»æã®æšçã«ãªãããšã¯ããããããšã§ããè匱æ§ãçºèŠãããªããšãåã³æªçšãããå¯èœæ§ããããŸãã
ã©ã³ãµã ãŠã§ã¢ã®è åš
éçºè ã¯ãæ€åºãé¿ããããã«ãåžžã«æ°ããäºçš®ã«ã³ãŒãã倿ŽããŸãã管çè ãšãã«ãŠã§ã¢å¯Ÿçéçºè ã¯ããããã®æ°ããææ³ã«å¯Ÿå¿ããè åšããããã¯ãŒã¯ã«äŒæããåã«è¿ éã«æ€åºã§ããããã«ããå¿ èŠããããŸããããã§ã¯ãããã€ãã®æ°ããè åšãã玹ä»ããŸãã
- DLLãµã€ãããŒãã£ã³ã°: ãã«ãŠã§ã¢ã¯ãæ£èŠã®æ©èœã®ããã«èŠããDLLããµãŒãã¹ã䜿çšããããšã§ãæ€ç¥ãéããããšããŸãã
- ã¿ãŒã²ãããšãªãWebãµãŒããŒ: å ±æãã¹ãã£ã³ã°ç°å¢äžã®ãã«ãŠã§ã¢ã¯ããã®ãµãŒããŒã§ãã¹ããããŠãããã¹ãŠã®ãµã€ãã«åœ±é¿ãäžããå¯èœæ§ããããŸããRyukã®ãããªã©ã³ãµã ãŠã§ã¢ã¯ãäž»ã«ãã£ãã·ã³ã°ã¡ãŒã«ã䜿ã£ãŠããã¹ããããŠãããµã€ããã¿ãŒã²ããã«ããŠããŸãã
- æšæºçãªãã£ãã·ã³ã°ããã奜ãŸããã¹ãã¢ãã£ãã·ã³ã°: æ»æè ã¯ãäœåãã®ã¿ãŒã²ããã«ãã«ãŠã§ã¢ãéãã€ãã代ããã«ãé«ãæš©éãæã€ãããã¯ãŒã¯ã¢ã¯ã»ã¹ãè¡ãæœåšçãªã¿ãŒã²ããã«å¯ŸããŠåµå¯ãè¡ããŸãã
- Ransomware as a Service (RaaS): Raasã¯ãŠãŒã¶ãŒããµã€ããŒã»ãã¥ãªãã£ã®ç¥èãæããã«æ»æã仿ããããšãã§ãããµãŒãã¹ã§ããRaaSã®å°å ¥ã«ãããã©ã³ãµã ãŠã§ã¢ã®æ»æã¯å¢å ããŠããŸãã
ã©ã³ãµã ãŠã§ã¢ã䜿ã£ãè åšãå¢å ããäž»ãªçç±ã¯ããªã¢ãŒãã¯ãŒã¯ã§ãããã³ãããã¯ã«ãããäžççã«æ°ããåãæ¹ãå°å ¥ãããŸãããåšå® å€åè ã¯ãè åšã«å¯ŸããŠããè匱ãªååšã§ããããŒã ãŠãŒã¶ãŒã¯ãé«åºŠãªæ»æããä¿è·ããããã«å¿ èŠãªäŒæ¥ã¬ãã«ã®ãµã€ããŒã»ãã¥ãªãã£ãåããŠãããããããã®ãŠãŒã¶ãŒã®å€ãã¯ãå人çšããã€ã¹ãšä»äºçšããã€ã¹ãæ··åšãããŠããŸããã©ã³ãµã ãŠã§ã¢ã¯ãããã¯ãŒã¯äžã®è匱ãªããã€ã¹ãã¹ãã£ã³ããããããã«ãŠã§ã¢ã«ææããå人PCããããã¯ãŒã¯ã«æ¥ç¶ãããæ¥åçšæ©åšã«ãææããå¯èœæ§ããããŸãã
ã©ã³ãµã ãŠã§ã¢å¯Ÿç
ã©ã³ãµã ãŠã§ã¢ã®æ»æãé²ãã«ã¯ãããã¯ã¢ããã®èšå®ãšãã¹ããããã³ã»ãã¥ãªãã£ããŒã«ã®ã©ã³ãµã ãŠã§ã¢ä¿è·æ©èœãé©çšããããšãäžè¬çã§ããã¡ãŒã«ä¿è·ã²ãŒããŠã§ã€ãªã©ã®ã»ãã¥ãªãã£ããŒã«ã¯ç¬¬äžã®é²åŸ¡ææ®µã§ããããšã³ããã€ã³ãã¯ç¬¬äºã®é²åŸ¡ææ®µã§ããäŸµå ¥æ€ç¥ã·ã¹ãã ïŒIDSïŒã¯ãã©ã³ãµã ãŠã§ã¢ã®ã³ãã³ãïŒã³ã³ãããŒã«ãæ€ç¥ããã©ã³ãµã ãŠã§ã¢ã·ã¹ãã ãã³ã³ãããŒã«ãµãŒããŒãåŒã³åºãããšã«å¯ŸããŠèŠåããããã«äœ¿çšãããããšããããŸãããŠãŒã¶ãŒãã¬ãŒãã³ã°ã¯éèŠã§ãããã©ã³ãµã ãŠã§ã¢ããä¿è·ããããã®ããã€ãã®é²åŸ¡å±€ã®äžã€ã«éãããã¡ãŒã«ãã£ãã·ã³ã°ã§ã©ã³ãµã ãŠã§ã¢ãé ä¿¡ãããåŸã«æŽ»èºãããã®ã§ãã
ä»ã®ã©ã³ãµã ãŠã§ã¢ã®é²åŸ¡çã«å€±æããå Žåã®äºåçãšããŠããããã³ã€ã³ãåèããŠããããšããããŸããããã¯ã被害ãåããäŒæ¥ã®é¡§å®¢ããŠãŒã¶ãŒã«çŽæ¥çãªåœ±é¿ãäžããå¯èœæ§ãããå Žåã«ãããäžè¬çãªæ¹æ³ã§ããç é¢ããã¹ãã¿ãªãã£ã¯ãæ£è ã®çåœã«åœ±é¿ãäžãããã人ã ãæœèšã«éã蟌ããããããå€ã«åºãããªããªã£ããããå¯èœæ§ããããããç¹ã«ã©ã³ãµã ãŠã§ã¢ã®ãªã¹ã¯ãé«ããšèšããŸãã
ã©ã³ãµã ãŠã§ã¢æ»æã®é²æ¢æ¹æ³
- ã©ã³ãµã ãŠã§ã¢ããã¡ãŒã«ãå®ã: ã©ã³ãµã ãŠã§ã¢ã®æ»æã¯ãäž»ã«ãã£ãã·ã³ã°ã¡ãŒã«ãã¹ãã ã¡ãŒã«ã«ãã£ãŠé ä¿¡ãããŸããã©ã³ãµã ãŠã§ã¢ãé ä¿¡ããæªæã®ããã¡ãŒã«ãæ€ç¥ã»ãããã¯ããããã«ã¯ãæšçåæ»æå¯Ÿçãåããã»ãã¥ã¢ã¡ãŒã«ã²ãŒããŠã§ã€ãäžå¯æ¬ ã§ãããããã®ãœãªã¥ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ã«é ä¿¡ãããã¡ãŒã«ã«å«ãŸããæªæã®ããæ·»ä»ãã¡ã€ã«ãæªæã®ããããã¥ã¡ã³ããããã³URLããä¿è·ããŸãã
- ã©ã³ãµã ãŠã§ã¢ããã¢ãã€ã«ç«¯æ«ãé²åŸ¡ãã: ã¢ãã€ã«æ»æå¯Ÿç補åã¯ãã¢ãã€ã«ããã€ã¹ç®¡çïŒMDMïŒããŒã«ãšäœµçšããããšã§ããŠãŒã¶ãŒã®ããã€ã¹äžã®ã¢ããªã±ãŒã·ã§ã³ãåæããç°å¢ã䟵害ããå¯èœæ§ã®ããã¢ããªã±ãŒã·ã§ã³ã«ã€ããŠãŠãŒã¶ãŒãšITéšéã«å³åº§ã«èŠåãçºããããšãã§ããŸãã
- ã©ã³ãµã ãŠã§ã¢ããWebãµãŒãã£ã³ãå®ã: ã»ãã¥ã¢Webã²ãŒããŠã§ã€ã¯ããŠãŒã¶ãŒã®WebãµãŒãã£ã³ã®ãã©ãã£ãã¯ãã¹ãã£ã³ããŠãã©ã³ãµã ãŠã§ã¢ã«èªå°ããå¯èœæ§ã®ããæªæã®ããWebåºåãç¹å®ããããšãã§ããŸãã
- ãµãŒããŒããããã¯ãŒã¯ãç£èŠããäž»èŠãªã·ã¹ãã ãããã¯ã¢ãããã: ç£èŠããŒã«ã¯ãç°åžžãªãã¡ã€ã«ã¢ã¯ã»ã¹ããŠã€ã«ã¹ããããã¯ãŒã¯C&Cãã©ãã£ãã¯ãCPUè² è·ãæ€åºããã©ã³ãµã ãŠã§ã¢ã®èµ·åã黿¢ããããšãã§ããŸãããŸããéèŠãªã·ã¹ãã ã®ãã«ã€ã¡ãŒãžã³ããŒãä¿åããŠããã°ãã¯ã©ãã·ã¥ãããæå·åããããã·ã³ãéèŠãªæ¥åã®ããã«ããã¯ãšãªããªã¹ã¯ã軜æžã§ããŸãã
ã©ã³ãµã ãŠã§ã¢ãé€å»ããæ¹æ³
- é£éŠããã³å°åã®æ³å·è¡æ©é¢ã«é£çµ¡ãã: èªæäºä»¶ã§é£éŠææ»æ©é¢ã«é£çµ¡ããããã«ãã©ã³ãµã ãŠã§ã¢ã®å Žåãåãããã«é£éŠææ»æ©é¢ã«é£çµ¡ããå¿ èŠããããŸãããã©ã¬ã³ãžãã¯æè¡è ã¯ãã·ã¹ãã ãä»ã®æ¹æ³ã§äŸµå®³ãããŠããªãããšã確èªããä»åŸã®çµç¹ãããè¯ãä¿è·ããããã®æ å ±ãåéããæ»æè ãèŠã€ããããšããŸãã
ã©ã³ãµã ãŠã§ã¢ããã®åŸ©æ§
- ã©ã³ãµã ãŠã§ã¢å¯Ÿçã®ãªãœãŒã¹ã«ã€ããŠåŠã¶: ãNo More RansomãããŒã¿ã«ãšBleeping Computerã§ã¯ãç¹å®ã®ã©ã³ãµã ãŠã§ã¢æ»æã«å¯Ÿãããã³ããææ¡ãããã³åŸ©å·åããŒã«ãæäŸããŠããŸãã
- ããŒã¿ã埩å ãã: ãã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠã·ã¹ãã ã®ããã¯ã¢ããããšã£ãŠããã°ãã·ã¹ãã ã埩å ããŠéåžžæ¥åãåéããããšãã§ããŸãã
ã©ã³ãµã ãŠã§ã¢ãµãã€ãã«ã¬ã€ã
ã©ã³ãµã ãŠã§ã¢æ»æè ã¯2019幎ã«å¹³åã§1ä»¶ããã115,123ãã«ãåéããŸãããã2020幎ã«ã¯ã³ã¹ãã312,493ãã«ã«æ¥äžæããŸãããèšé²ããã1ã€ã®äºäŸã§ã¯ãçµç¹ã«4,000äžãã«ã®æå€±ããããããŸããã身代éãã®ãã®ã«å ããŠããããã®æ»æã¯æ¥åã®äžæã修埩ã³ã¹ãããã©ã³ã䟡å€ã®äœäžãªã©ãé倧ãªã³ã¹ããããããå¯èœæ§ããããŸãã
ã©ã³ãµã ãŠã§ã¢ã«é¢ãããããã質å
ã©ã³ãµã ãŠã§ã¢ã¯ãŠã€ã«ã¹ïŒ
ã©ã³ãµã ãŠã§ã¢ãšãŠã€ã«ã¹ã¯ãã©ã¡ãããã«ãŠã§ã¢ã®äžçš®ã§ãããã©ã³ãµã ãŠã§ã¢ã¯ãŠã€ã«ã¹ã§ã¯ãããŸãããã©ã³ãµã ãŠã§ã¢ã¯ããã«ãŠã§ã¢ã®äžã§ãç¬èªã®ã«ããŽãªãŒãšãããŠããŸããããŠã€ã«ã¹ã®ããã«èªå·±è€è£œããããšã¯ãããŸããããŠã€ã«ã¹ãã©ã³ãµã ãŠã§ã¢ããã¡ã€ã«ã«ãã¡ãŒãžãäžããŸããããã€ããŒããé ä¿¡ããããšç°ãªãåäœãããŸãã
WannaCryã©ã³ãµã ãŠã§ã¢æ»æãšã¯ïŒ
ã©ã³ãµã ãŠã§ã¢ãWannaCryãã¯ãMicrosoft Windowsã®è匱æ§ãå©çšããŠã€ã³ã¿ãŒãããäžã§æ¥éã«æ¡æ£ãããã¡ã€ã«ãæå·åããŠäººè³ªã«ããŸããæå·åŠçã«å®å šãªã¢ã«ãŽãªãºã ã§ãã¡ã€ã«ãæå·åãããããæšçãšãªã£ã被害è ã¯ããããã³ã€ã³ã§èº«ä»£éãæ¯æã£ãŠç§å¯éµãå ¥æããããããã¯ã¢ãããã埩å ããããšãäœåãªããããŸãããã¡ã€ã«ã¯åŸ©å·åã§ããªããããå€ãã®çµç¹ããããåŸã身代éãæ¯æãããšã«ãªããŸããã
DarkSideã©ã³ãµã ãŠã§ã¢ãšã¯ïŒ
DarkSideãšããŠç¥ããããããã³ã°ã°ã«ãŒãã¯ãRaaSãšããŠæ©èœãããã«ãŠã§ã¢ãDarkSideããéçºããŸããããã®ãã«ãŠã§ã¢ã¯ããã¡ã€ã«ã埩å·åããããã«æ¯æããèŠæ±ããæ¬¡ã«ãæŒæŽ©ããæ©å¯ããŒã¿ã®æ¯æããèŠæ±ããããšã§ãã¿ãŒã²ãããã2éã®è è¿«ãè¡ããŸãããã®ãã«ãŠã§ã¢ã¯ããªã¢ãŒãã»ãã¹ã¯ãããã»ãããã³ã«ïŒRDPïŒããã¹ããããµãŒããŒãæšçãšãããã¹ã¯ãŒããç·åœããã§å ¥åããŠããã·ã³ã®ããŒã«ã«ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããŸãã
ã©ã³ãµã ãŠã§ã¢ããã®åŸ©æ§æéã«ãããæéã¯ïŒ
åŸ©æ§æéã¯ã被害ã®çšåºŠãçµç¹ã®ãã£ã¶ã¹ã¿ãªã«ããªèšç»ã®å¹çæ§ãã¬ã¹ãã³ã¹ã¿ã€ã ãå°ã蟌ãã»æ²æ» ã®ã¿ã€ã ãã¬ãŒã ã«ãã£ãŠå€§ããç°ãªããŸããåªããããã¯ã¢ãããšãã£ã¶ã¹ã¿ãªã«ããªèšç»ããªããã°ãçµç¹ã¯äœæ¥ããªãã©ã€ã³ã®ç¶æ ãç¶ãããšã«ãªããåçã«æ·±å»ãªåœ±é¿ãäžããŸãã