B
今週中
勒索軟體グループ「Aurora」が、AIコードエディタのCursorを利用して攻撃計画を策定し、攻撃活動を行っていること
📌 一言でいうと
勒索軟體グループ「Zig言語を悪用する勒索軟體グループ">Aurora」が、AIコードエディタのCursorを利用して攻撃計画を策定し、攻撃活動を行っていることが判明しました。このグループはZig言語で作成されたWindowsおよびLinux/ESXi向けの暗号化プログラムを使用し、Cloudflare R2ストレージから配信しています。これまでに9カ国、20以上の組織が被害に遭い、一部ではドメインレベルの権限が奪取されています。
🔍該当判定
- 社内でWindows ServerのActive Directory(AD)を利用してユーザー管理を行っている
- VMware ESXiなどの仮想化サーバーを運用している
- 外部から社内サーバーへSCP(セキュアコピー)プロトコルによるファイル転送を許可している
- Cloudflare R2などのクラウドストレージから直接ファイルをダウンロードして実行する運用がある
上記いずれにも該当しない → 静観でOK
✅該当時の対応
AD(Active Directory)の権限管理の徹底、不審なSCP通信の監視、およびAIツールを利用した攻撃コードの傾向を把握し、エンドポイント保護製品(EDR)での検知ルールを最適化することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】勒索軟體AuroraによるAI活用攻撃について
お疲れさまです。勒索軟體グループ「Aurora」の活動に関する情報共有です。
■ 概要
攻撃者がAIコードエディタ「Cursor」を用いて攻撃計画を策定し、Zig言語で開発されたランサムウェアを配信していることが報告されました。攻撃者はCloudflare R2からSCPプロトコルを用いてマルウェアを配布し、AD(Active Directory)への侵入を試みます。
■ 影響範囲
- Windows および Linux/ESXi サーバー
- Active Directory 環境
■ 対応手順
1. 外部ストレージ(Cloudflare R2等)からの不審なSCP通信の監視および遮断
2. AD特権アカウントの監査と、不審なインタラクティブアクセスの検知設定の確認
3. Zig言語でコンパイルされた未知のバイナリ実行に対するEDR監視の強化
■ 参考情報
- CloudSEK / TRM Labs レポート
対応優先度: 中
対応期限: 随時
お疲れさまです。勒索軟體グループ「Aurora」の活動に関する情報共有です。
■ 概要
攻撃者がAIコードエディタ「Cursor」を用いて攻撃計画を策定し、Zig言語で開発されたランサムウェアを配信していることが報告されました。攻撃者はCloudflare R2からSCPプロトコルを用いてマルウェアを配布し、AD(Active Directory)への侵入を試みます。
■ 影響範囲
- Windows および Linux/ESXi サーバー
- Active Directory 環境
■ 対応手順
1. 外部ストレージ(Cloudflare R2等)からの不審なSCP通信の監視および遮断
2. AD特権アカウントの監査と、不審なインタラクティブアクセスの検知設定の確認
3. Zig言語でコンパイルされた未知のバイナリ実行に対するEDR監視の強化
■ 参考情報
- CloudSEK / TRM Labs レポート
対応優先度: 中
対応期限: 随時
Subject: [Intel] AI-Assisted Attacks by Aurora Ransomware Group
Dear Team,
We are sharing intelligence regarding the activities of the 'Aurora' ransomware group.
■ Overview
Aurora is utilizing the AI code editor 'Cursor' to plan attacks and deploying ransomware written in the Zig language. The malware is distributed via Cloudflare R2 storage buckets using the SCP protocol, targeting both Windows and Linux/ESXi environments to achieve domain-level access.
■ Scope
- Windows and Linux/ESXi servers
- Active Directory (AD) environments
■ Recommended Actions
1. Monitor and block suspicious SCP traffic originating from public cloud storage (e.g., Cloudflare R2).
2. Audit AD privileged accounts and review logs for unauthorized interactive access.
3. Enhance EDR detection for unknown binaries compiled with the Zig language.
■ Reference
- CloudSEK / TRM Labs Report
Priority: Medium
Deadline: Ongoing
Dear Team,
We are sharing intelligence regarding the activities of the 'Aurora' ransomware group.
■ Overview
Aurora is utilizing the AI code editor 'Cursor' to plan attacks and deploying ransomware written in the Zig language. The malware is distributed via Cloudflare R2 storage buckets using the SCP protocol, targeting both Windows and Linux/ESXi environments to achieve domain-level access.
■ Scope
- Windows and Linux/ESXi servers
- Active Directory (AD) environments
■ Recommended Actions
1. Monitor and block suspicious SCP traffic originating from public cloud storage (e.g., Cloudflare R2).
2. Audit AD privileged accounts and review logs for unauthorized interactive access.
3. Enhance EDR detection for unknown binaries compiled with the Zig language.
■ Reference
- CloudSEK / TRM Labs Report
Priority: Medium
Deadline: Ongoing