C
月内に
ランサムウェアの戦術が、データの暗号化からデータ窃取と心理的な威圧へと移行している傾向
📌 一言でいうと
ランサムウェアの戦術が、データの暗号化からデータ窃取と心理的な威圧へと移行している傾向が報告されました。具体的に「GPOを悪用するランサムウェアキャンペーン名">PAYLOAD」キャンペーンでは、暗号化を行わずにActive Directoryを掌握し、GPO(グループポリシーオブジェクト)を用いて身代金要求の通知や壁紙の変更を行う手法が確認されました。攻撃者は同時にローカル管理者のアカウントを無効化し、管理者の操作を妨害しています。
🔍該当判定
- Windows ServerでActive Directory(AD)を構築してユーザー管理を行っている
- グループポリシー(GPO)を使用して、社内PCの設定を一括管理している
- 社内PCの壁紙やログイン画面を、サーバー側から一括で制御・変更する運用をしている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Active Directoryの特権アカウント管理の徹底、GPOの変更監視、および不審なログイン試行の検知体制を強化してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Active Directoryを悪用した新手のランサムウェア手法について
お疲れさまです。ランサムウェアの戦術変更に関する情報共有です。
■ 概要
最近の「PAYLOAD」キャンペーンでは、従来のデータ暗号化を行わず、Active Directory (AD) の権限を奪取した後にGPO(グループポリシーオブジェクト)を悪用して身代金要求を表示させる手法が確認されています。また、復旧を妨げるためにローカル管理者のアカウントを無効化する挙動が見られます。
■ 影響範囲
- Active Directory を運用している Windows 環境
■ 対応手順
1. AD特権アカウント(Domain Admins等)の多要素認証 (MFA) 導入と監視強化
2. GPOの変更履歴を定期的に監査し、意図しないポリシー作成がないか確認
3. ローカル管理者アカウントの無効化などの異常な設定変更を検知する仕組みの構築
■ 参考情報
- Kaspersky Securelist / GERT 調査レポート
対応優先度: 中
対応期限: 継続的な監視を推奨
お疲れさまです。ランサムウェアの戦術変更に関する情報共有です。
■ 概要
最近の「PAYLOAD」キャンペーンでは、従来のデータ暗号化を行わず、Active Directory (AD) の権限を奪取した後にGPO(グループポリシーオブジェクト)を悪用して身代金要求を表示させる手法が確認されています。また、復旧を妨げるためにローカル管理者のアカウントを無効化する挙動が見られます。
■ 影響範囲
- Active Directory を運用している Windows 環境
■ 対応手順
1. AD特権アカウント(Domain Admins等)の多要素認証 (MFA) 導入と監視強化
2. GPOの変更履歴を定期的に監査し、意図しないポリシー作成がないか確認
3. ローカル管理者アカウントの無効化などの異常な設定変更を検知する仕組みの構築
■ 参考情報
- Kaspersky Securelist / GERT 調査レポート
対応優先度: 中
対応期限: 継続的な監視を推奨
Subject: [Info] New Ransomware Tactic utilizing Active Directory GPO
Dear Team,
We are sharing information regarding a shift in ransomware tactics observed in the 'PAYLOAD' campaign.
■ Overview
Attackers are moving away from traditional data encryption. Instead, they seize control of Active Directory (AD) and use Group Policy Objects (GPO) to deploy ransom notes and modify system settings (e.g., wallpapers) across workstations. They also disable local administrator accounts to impede incident response.
■ Scope
- Windows environments utilizing Active Directory
■ Recommended Actions
1. Enforce MFA for all privileged AD accounts and enhance monitoring.
2. Regularly audit GPO changes for unauthorized or suspicious policy creations.
3. Implement detection for unauthorized modifications to local administrator accounts.
■ Reference
- Kaspersky Securelist / GERT Investigation Report
Priority: Medium
Deadline: Ongoing monitoring recommended
Dear Team,
We are sharing information regarding a shift in ransomware tactics observed in the 'PAYLOAD' campaign.
■ Overview
Attackers are moving away from traditional data encryption. Instead, they seize control of Active Directory (AD) and use Group Policy Objects (GPO) to deploy ransom notes and modify system settings (e.g., wallpapers) across workstations. They also disable local administrator accounts to impede incident response.
■ Scope
- Windows environments utilizing Active Directory
■ Recommended Actions
1. Enforce MFA for all privileged AD accounts and enhance monitoring.
2. Regularly audit GPO changes for unauthorized or suspicious policy creations.
3. Implement detection for unauthorized modifications to local administrator accounts.
■ Reference
- Kaspersky Securelist / GERT Investigation Report
Priority: Medium
Deadline: Ongoing monitoring recommended