C
月内に
中東の製造業を標的とした「PAYLOAD」と呼ばれる特殊なランサムウェア攻撃
📌 一言でいうと
中東の製造業を標的とした「PAYLOAD」と呼ばれる特殊なランサムウェア攻撃が確認されました。攻撃者はFortiGate SSL VPNの侵害したアカウントを通じて侵入し、Windowsマシンでマルウェアを実行したりファイルを暗号化したりせず、Active Directoryのグループポリシーを利用してシステムをロックし、データを窃取しました。従来の暗号化型ランサムウェアとは異なる手法が用いられています。
🔍該当判定
- FortiGateのSSL VPN機能を外部からアクセス可能な状態で利用している
- Windows ServerでActive Directory(ドメイン管理)を運用している
- VPN接続に利用するアカウントに、特権管理者の権限を付与している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
VPNアカウントの多要素認証 (MFA) の強制適用、特権アカウントの監視強化、およびActive Directoryのグループポリシー変更履歴の監査を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Active Directoryグループポリシーを悪用したランサムウェア攻撃について
お疲れさまです。Active Directoryのグループポリシーを悪用した新しい攻撃手法に関する情報共有です。
■ 概要
「PAYLOAD」と呼ばれるキャンペーンにおいて、攻撃者がマルウェアの実行やファイルの暗号化を行わず、ADのグループポリシーを用いて端末をロックし、データを窃取する事例が報告されました。初期侵入経路はFortiGate SSL VPNの侵害済みアカウントであったとされています。
■ 影響範囲
- FortiGate SSL VPNを利用している環境
- Active Directoryによる端末管理を行っている組織
■ 対応手順
1. VPN接続における多要素認証 (MFA) の導入・強制適用を確認してください。
2. 特権管理者のアカウントにおける不審なログイン試行がないかログを確認してください。
3. グループポリシー (GPO) の変更履歴を監視し、意図しない設定変更が行われていないか監査してください。
■ 参考情報
- Xakep (Kaspersky report)
対応優先度: 中
対応期限: 随時
お疲れさまです。Active Directoryのグループポリシーを悪用した新しい攻撃手法に関する情報共有です。
■ 概要
「PAYLOAD」と呼ばれるキャンペーンにおいて、攻撃者がマルウェアの実行やファイルの暗号化を行わず、ADのグループポリシーを用いて端末をロックし、データを窃取する事例が報告されました。初期侵入経路はFortiGate SSL VPNの侵害済みアカウントであったとされています。
■ 影響範囲
- FortiGate SSL VPNを利用している環境
- Active Directoryによる端末管理を行っている組織
■ 対応手順
1. VPN接続における多要素認証 (MFA) の導入・強制適用を確認してください。
2. 特権管理者のアカウントにおける不審なログイン試行がないかログを確認してください。
3. グループポリシー (GPO) の変更履歴を監視し、意図しない設定変更が行われていないか監査してください。
■ 参考情報
- Xakep (Kaspersky report)
対応優先度: 中
対応期限: 随時
Subject: [Intel] Ransomware Attack Leveraging Active Directory Group Policies
Dear team,
We are sharing information regarding a new attack technique observed in the 'PAYLOAD' campaign.
■ Overview
Attackers targeted a Middle Eastern manufacturer, gaining access via compromised FortiGate SSL VPN credentials. Notably, the attackers did not use traditional encryption malware; instead, they utilized Active Directory Group Policies to lock systems and exfiltrate data.
■ Scope
- Environments utilizing FortiGate SSL VPN
- Organizations using Active Directory for endpoint management
■ Recommended Actions
1. Ensure Multi-Factor Authentication (MFA) is strictly enforced for all VPN access.
2. Review logs for suspicious login activity on privileged domain accounts.
3. Audit Group Policy Object (GPO) changes to detect unauthorized modifications.
■ Reference
- Xakep (Kaspersky report)
Priority: Medium
Deadline: Ongoing
Dear team,
We are sharing information regarding a new attack technique observed in the 'PAYLOAD' campaign.
■ Overview
Attackers targeted a Middle Eastern manufacturer, gaining access via compromised FortiGate SSL VPN credentials. Notably, the attackers did not use traditional encryption malware; instead, they utilized Active Directory Group Policies to lock systems and exfiltrate data.
■ Scope
- Environments utilizing FortiGate SSL VPN
- Organizations using Active Directory for endpoint management
■ Recommended Actions
1. Ensure Multi-Factor Authentication (MFA) is strictly enforced for all VPN access.
2. Review logs for suspicious login activity on privileged domain accounts.
3. Audit Group Policy Object (GPO) changes to detect unauthorized modifications.
■ Reference
- Xakep (Kaspersky report)
Priority: Medium
Deadline: Ongoing