B
今週中
パキスタン系のAPTグループSideCopyが、インドの政府機関に続き、学術機関を標的としたスピアフィッシング攻撃を展開しています
📌 一言でいうと
パキスタン系のAPTグループSideCopyが、インドの政府機関に続き、学術機関を標的としたスピアフィッシング攻撃を展開しています。攻撃者はmshta.exeを悪用して悪意のあるスクリプトを実行し、リモートアクセスツール(RAT)を配備して機密情報を窃取します。このグループは2019年から活動しており、Transparent Tribeとの関連が指摘されています。
🔍該当判定
- インドの政府機関または教育・研究機関(大学など)と取引がある、あるいは所属している
- インド国内に拠点や事業所を展開している
- 不特定多数ではなく、特定の担当者宛に届いた「身に覚えのない添付ファイル付きメール」を最近受信した
- Windows端末で、標準機能の「mshta.exe」というプログラムの動作を制限せずに利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
不審なメールの添付ファイルやリンクを開かないこと。mshta.exeなどの不審なプロセスの起動を監視し、エンドポイントセキュリティ製品で検知・遮断設定を行うことを推奨します。
📧 メール案を見る (社員向け + 管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【注意喚起】不審なメールによるウイルス感染への注意について
お疲れさまです。情報システム担当です。
現在、大学や研究機関などを狙った、巧妙ななりすましメールによる攻撃が確認されています。
ご協力をお願いしたいこと:
1. 心当たりのない送信元からのメールにあるリンクや添付ファイルを絶対に開かないでください。
2. 万が一、不審なファイルを開いてしまった場合は、すぐにPCをネットワークから切り離し、情シス担当までご連絡ください。
対応期限: 本日中(継続的な注意をお願いします)
お疲れさまです。情報システム担当です。
現在、大学や研究機関などを狙った、巧妙ななりすましメールによる攻撃が確認されています。
ご協力をお願いしたいこと:
1. 心当たりのない送信元からのメールにあるリンクや添付ファイルを絶対に開かないでください。
2. 万が一、不審なファイルを開いてしまった場合は、すぐにPCをネットワークから切り離し、情シス担当までご連絡ください。
対応期限: 本日中(継続的な注意をお願いします)
Subject: [Security Alert] Beware of Suspicious Emails and Phishing
Dear employees,
We have received reports of sophisticated spear-phishing attacks targeting academic and government institutions.
What we need from you:
1. Do not click on links or open attachments from unknown or unexpected senders.
2. If you suspect you have opened a malicious file, please disconnect your device from the network and notify the IT security team immediately.
Deadline: Immediate and ongoing attention.
Dear employees,
We have received reports of sophisticated spear-phishing attacks targeting academic and government institutions.
What we need from you:
1. Do not click on links or open attachments from unknown or unexpected senders.
2. If you suspect you have opened a malicious file, please disconnect your device from the network and notify the IT security team immediately.
Deadline: Immediate and ongoing attention.
件名: 【共有】APTグループ SideCopy によるスピアフィッシング攻撃について
お疲れさまです。SideCopyによる新キャンペーンに関する情報共有です。
■ 概要
パキスタン系APTグループSideCopyが、インドの学術機関を標的にスピアフィッシングを展開しています。mshta.exeを悪用して悪意のあるスクリプトを実行し、ReverseRATを配備する手法が確認されています。
■ 影響範囲
- Windows環境(mshta.exeを利用したスクリプト実行)
- インド国内の政府・教育機関
■ 対応手順
1. EDR/AVにて mshta.exe による不審な子プロセスの生成や外部通信を監視・ブロックする。
2. ユーザーへのフィッシング対策トレーニングの実施。
■ 参考情報
- Trellix Technical Report
対応優先度: 中
対応期限: 随時
お疲れさまです。SideCopyによる新キャンペーンに関する情報共有です。
■ 概要
パキスタン系APTグループSideCopyが、インドの学術機関を標的にスピアフィッシングを展開しています。mshta.exeを悪用して悪意のあるスクリプトを実行し、ReverseRATを配備する手法が確認されています。
■ 影響範囲
- Windows環境(mshta.exeを利用したスクリプト実行)
- インド国内の政府・教育機関
■ 対応手順
1. EDR/AVにて mshta.exe による不審な子プロセスの生成や外部通信を監視・ブロックする。
2. ユーザーへのフィッシング対策トレーニングの実施。
■ 参考情報
- Trellix Technical Report
対応優先度: 中
対応期限: 随時
Subject: [Threat Intel] SideCopy Spear-Phishing Campaign Targeting Academia
Dear Security Team,
This is a technical update regarding the threat actor SideCopy.
■ Overview
SideCopy (TAG-140), a Pakistan-linked APT, is targeting Indian academic institutions. The attack chain involves spear-phishing lures that abuse mshta.exe to execute malicious scripts, leading to the deployment of a Remote Access Trojan (RAT).
■ Scope
- Windows systems (via mshta.exe abuse)
- Academic and government sectors in India
■ Mitigation Steps
1. Monitor and block suspicious child processes spawned by mshta.exe using EDR tools.
2. Implement strict monitoring for unusual outbound connections from system binaries.
■ Reference
- Trellix Technical Report
Priority: Medium
Deadline: Ongoing
Dear Security Team,
This is a technical update regarding the threat actor SideCopy.
■ Overview
SideCopy (TAG-140), a Pakistan-linked APT, is targeting Indian academic institutions. The attack chain involves spear-phishing lures that abuse mshta.exe to execute malicious scripts, leading to the deployment of a Remote Access Trojan (RAT).
■ Scope
- Windows systems (via mshta.exe abuse)
- Academic and government sectors in India
■ Mitigation Steps
1. Monitor and block suspicious child processes spawned by mshta.exe using EDR tools.
2. Implement strict monitoring for unusual outbound connections from system binaries.
■ Reference
- Trellix Technical Report
Priority: Medium
Deadline: Ongoing