B
今週中
カンボジアを標的としたSpark RATの配布キャンペーン
📌 一言でいうと
カンボジアを標的としたSpark RATの配布キャンペーンが確認されました。攻撃者は政府通知や公衆衛生などの多様なルアーを用いたフィッシングメールを送信し、圧縮アーカイブ内の実行ファイルを配布します。特筆すべきは、OPSWAT AppRemoverの脆弱なドライバー(ardrv.sys)を悪用するBYOVD手法を用いて権限昇格を行い、セキュリティソフトを無効化する点です。
🔍該当判定
- OPSWAT社の製品(AppRemoverなど)を社内で利用している
- カンボジアの政府機関や企業と取引があり、現地からメールを受信している
- 不審な添付ファイル(圧縮ファイルや実行ファイル)を社員が開封する環境にある
- Windows端末で、セキュリティソフトを強制停止させる攻撃への対策が未実施である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
不審なメールの添付ファイルやリンクを開かないよう注意喚起を行うとともに、エンドポイント保護製品で未知のドライバーのロードを監視・制限することを推奨します。
📧 メール案を見る (社員向け + 管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【注意喚起】不審なメールの添付ファイル開封に関する注意について
お疲れさまです。情報システム担当です。
カンボジアなどの地域を標的とした、政府通知や健康診断結果などを装った巧妙なフィッシングメールによる攻撃が確認されています。
ご協力をお願いしたいこと:
1. 心当たりのない送信元からのメールや、不自然な添付ファイル(特に圧縮ファイル)は絶対に開かないでください。
2. 万が一、不審なファイルを実行してしまった場合は、すぐにPCをネットワークから切り離し、情報システム担当まで報告してください。
対応期限: 本日中
お疲れさまです。情報システム担当です。
カンボジアなどの地域を標的とした、政府通知や健康診断結果などを装った巧妙なフィッシングメールによる攻撃が確認されています。
ご協力をお願いしたいこと:
1. 心当たりのない送信元からのメールや、不自然な添付ファイル(特に圧縮ファイル)は絶対に開かないでください。
2. 万が一、不審なファイルを実行してしまった場合は、すぐにPCをネットワークから切り離し、情報システム担当まで報告してください。
対応期限: 本日中
Subject: [Security Alert] Caution Regarding Suspicious Email Attachments
Dear employees,
We have observed a series of phishing attacks using lures such as government notices and public health materials to deliver malware.
Requested Actions:
1. Do not open attachments or click links in emails from unknown or suspicious senders, especially compressed archives.
2. If you have accidentally executed a suspicious file, please disconnect your device from the network immediately and report it to the IT security team.
Deadline: Immediate
Dear employees,
We have observed a series of phishing attacks using lures such as government notices and public health materials to deliver malware.
Requested Actions:
1. Do not open attachments or click links in emails from unknown or suspicious senders, especially compressed archives.
2. If you have accidentally executed a suspicious file, please disconnect your device from the network immediately and report it to the IT security team.
Deadline: Immediate
件名: 【共有】Spark RATによるBYOVD攻撃の観測について
お疲れさまです。Spark RATを用いた新キャンペーンに関する情報共有です。
■ 概要
攻撃者はフィッシングメールを通じてSpark RATを配布し、OPSWAT AppRemoverの脆弱なドライバー(ardrv.sys)をロードするBYOVD (Bring Your Own Vulnerable Driver) 手法を用いて権限昇格およびセキュリティソフトの無効化を試みます。
■ 影響範囲
- Windows OS 環境(特にOPSWAT AppRemoverの脆弱なドライバーをロード可能な環境)
■ 対応手順
1. EDR/AVにおいて、不審なドライバー(ardrv.sys等)のロードを検知・ブロックする設定を確認してください。
2. 権限昇格を伴う不審なプロセスの挙動を監視してください。
3. ユーザーに対し、政府通知等を装ったフィッシングメールへの注意喚起を実施してください。
■ 参考情報
- Acronis Threat Research Unit (TRU) Analysis
対応優先度: 中
対応期限: 今週中
お疲れさまです。Spark RATを用いた新キャンペーンに関する情報共有です。
■ 概要
攻撃者はフィッシングメールを通じてSpark RATを配布し、OPSWAT AppRemoverの脆弱なドライバー(ardrv.sys)をロードするBYOVD (Bring Your Own Vulnerable Driver) 手法を用いて権限昇格およびセキュリティソフトの無効化を試みます。
■ 影響範囲
- Windows OS 環境(特にOPSWAT AppRemoverの脆弱なドライバーをロード可能な環境)
■ 対応手順
1. EDR/AVにおいて、不審なドライバー(ardrv.sys等)のロードを検知・ブロックする設定を確認してください。
2. 権限昇格を伴う不審なプロセスの挙動を監視してください。
3. ユーザーに対し、政府通知等を装ったフィッシングメールへの注意喚起を実施してください。
■ 参考情報
- Acronis Threat Research Unit (TRU) Analysis
対応優先度: 中
対応期限: 今週中
Subject: [Intel] Spark RAT Campaign utilizing BYOVD Technique
Dear Security Team,
We are sharing information regarding a new campaign delivering Spark RAT.
■ Overview
The attack chain involves phishing emails delivering a malicious executable. It utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique by loading a vulnerable OPSWAT AppRemover driver (ardrv.sys) to escalate privileges and neutralize security software.
■ Scope
- Windows environments susceptible to vulnerable driver loading.
■ Mitigation Steps
1. Configure EDR/AV to monitor and block the loading of known vulnerable drivers, specifically ardrv.sys.
2. Monitor for anomalous privilege escalation patterns and security tool termination.
3. Issue a phishing warning to users regarding lures mimicking government or health notices.
■ Reference
- Acronis Threat Research Unit (TRU) Analysis
Priority: Medium
Deadline: End of week
Dear Security Team,
We are sharing information regarding a new campaign delivering Spark RAT.
■ Overview
The attack chain involves phishing emails delivering a malicious executable. It utilizes the Bring Your Own Vulnerable Driver (BYOVD) technique by loading a vulnerable OPSWAT AppRemover driver (ardrv.sys) to escalate privileges and neutralize security software.
■ Scope
- Windows environments susceptible to vulnerable driver loading.
■ Mitigation Steps
1. Configure EDR/AV to monitor and block the loading of known vulnerable drivers, specifically ardrv.sys.
2. Monitor for anomalous privilege escalation patterns and security tool termination.
3. Issue a phishing warning to users regarding lures mimicking government or health notices.
■ Reference
- Acronis Threat Research Unit (TRU) Analysis
Priority: Medium
Deadline: End of week