B
今週中
Active Directoryのグループポリシー(GPO)を悪用してランサムウェアを配布する「PAYLOAD」の攻撃手法
📌 一言でいうと
Active Directoryのグループポリシー(GPO)を悪用してランサムウェアを配布する「PAYLOAD」の攻撃手法が確認されました。攻撃者はGPOをハイジャックし、ドメイン内の全端末に悪意のあるスクリプトを強制的に実行させ、ファイアウォールの無効化やバックアップの削除を行います。特に、検知を回避するために実行を1日遅らせる時間差攻撃などの高度な手法が用いられています。
🔍該当判定
- Windows ServerでActive Directory(ドメインコントローラー)を運用している
- グループポリシー(GPO)を使用して、社内PCの一括設定や管理を行っている
- 社内ネットワークにWindowsベースのサーバーとクライアントPCが混在して接続されている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ドメインコントローラーの特権アカウント管理の徹底、GPOの変更履歴の監視、不審なスケジュール済みタスクやスクリプトの実行を検知するEDRの導入、およびバックアップのオフライン保存を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Active Directory GPOを悪用したPAYLOADランサムウェアへの対応について
お疲れさまです。GPOを配布経路とする新しいランサムウェア攻撃に関する情報共有です。
■ 概要
攻撃者がActive Directoryのグループポリシー(GPO)をハイジャックし、ドメイン内の全端末にランサムウェアを強制配布する手法が確認されました。ファイアウォールの無効化やVSS削除、BYOVD(脆弱な署名済みドライバの悪用)によるセキュリティソフト停止などの高度な回避策が組み込まれています。
■ 影響範囲
- Active Directory環境を利用している全Windows端末
■ 対応手順
1. GPOの変更履歴および新規作成されたポリシーの監査を実施し、不審なスクリプトやタスクがないか確認してください。
2. ドメイン管理者権限を持つアカウントのパスワード変更および多要素認証(MFA)の強制適用を検討してください。
3. EDR等の監視ツールにて、不審なPowerShell実行やBYOVDによるドライバロードを検知するルールを適用してください。
■ 参考情報
- Kaspersky Securelist: Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。GPOを配布経路とする新しいランサムウェア攻撃に関する情報共有です。
■ 概要
攻撃者がActive Directoryのグループポリシー(GPO)をハイジャックし、ドメイン内の全端末にランサムウェアを強制配布する手法が確認されました。ファイアウォールの無効化やVSS削除、BYOVD(脆弱な署名済みドライバの悪用)によるセキュリティソフト停止などの高度な回避策が組み込まれています。
■ 影響範囲
- Active Directory環境を利用している全Windows端末
■ 対応手順
1. GPOの変更履歴および新規作成されたポリシーの監査を実施し、不審なスクリプトやタスクがないか確認してください。
2. ドメイン管理者権限を持つアカウントのパスワード変更および多要素認証(MFA)の強制適用を検討してください。
3. EDR等の監視ツールにて、不審なPowerShell実行やBYOVDによるドライバロードを検知するルールを適用してください。
■ 参考情報
- Kaspersky Securelist: Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
対応優先度: 高
対応期限: 速やかに確認
Subject: [Security Alert] PAYLOAD Ransomware Weaponizing Active Directory GPO
Dear IT/Security Team,
We are sharing critical intelligence regarding a ransomware family named 'PAYLOAD' that leverages Group Policy Objects (GPOs) for lateral movement and execution.
■ Overview
Attackers hijack GPOs to push malicious payloads to all domain-joined machines. The attack chain includes disabling Windows Firewall via GPO, utilizing BYOVD (Bring Your Own Vulnerable Driver) to terminate security processes, and implementing a 24-hour delay before detonation to evade detection.
■ Scope
- All Windows endpoints managed via Active Directory GPOs.
■ Recommended Actions
1. Audit GPO changes and review any newly created or modified policies for unauthorized scripts or scheduled tasks.
2. Enforce strict privilege management for Domain Admin accounts and implement MFA.
3. Configure EDR/SIEM to alert on suspicious PowerShell activity and the loading of known vulnerable drivers.
■ Reference
- Kaspersky Securelist: Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Priority: High
Deadline: Immediate review
Dear IT/Security Team,
We are sharing critical intelligence regarding a ransomware family named 'PAYLOAD' that leverages Group Policy Objects (GPOs) for lateral movement and execution.
■ Overview
Attackers hijack GPOs to push malicious payloads to all domain-joined machines. The attack chain includes disabling Windows Firewall via GPO, utilizing BYOVD (Bring Your Own Vulnerable Driver) to terminate security processes, and implementing a 24-hour delay before detonation to evade detection.
■ Scope
- All Windows endpoints managed via Active Directory GPOs.
■ Recommended Actions
1. Audit GPO changes and review any newly created or modified policies for unauthorized scripts or scheduled tasks.
2. Enforce strict privilege management for Domain Admin accounts and implement MFA.
3. Configure EDR/SIEM to alert on suspicious PowerShell activity and the loading of known vulnerable drivers.
■ Reference
- Kaspersky Securelist: Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Priority: High
Deadline: Immediate review