ブログ
/
AI
/
February 3, 2026

Darktrace / SECURE AI の概要: 企業全体にわたる包括的なAIセキュリティ

ダークトレースは企業内のAIを防御する新製品をリリースします。 Darktrace / SECURE AIは組織をサイバー脅威や新たなリスクから保護する新時代を築く製品です。 完全な可視性、インテリジェントな動作の監視、リアルタイムコントロールを組み合わせることにより、企業内へのAIの安全な導入、管理、構築を可能にします。
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Brittany Woodsmall
Product Marketing Manager, AI
Default blog image
03
Feb 2026

AIの保護が急務である理由

AIはITおよびセキュリティチームの対応が追い付かないスピードで企業内に浸透しつつあります。SaaSツールで使用され、コアプラットフォームに組み込まれ、新しい技術を取り入れたいさまざまなチームによって立ち上げが進んでいます。

しかしこの導入が加速するにつれ、スタートアップ、プラットフォームを問わず既存のセキュリティツールでは監視や制御ができない、予測不可能な挙動が発生し、アタックサーフェスが拡大しています。これらの新しいタイプのリスクは、ビジネスの確実性から規制への対応まで幅広い影響を及ぼし、セキュリティチームと経営層両方の注意が必要な問題です。

AIの保護には今までとは根本的に異なるアプローチが必要です。AIがどのように動作するか、データやユーザーとどのように相互動作し、リスクがリアルタイムにどう発生するかを理解するアプローチでなければなりません。企業全体でAIを保護するにあたり組織がどう考えるべきかの中心はこうした変化にあります。

AI保護の現状は?

ダークトレースが1,500名のサイバーセキュリティプロフェッショナルを対象とした調査の結果をまとめた最新の”AIサイバーセキュリティの現状”レポートでは、AI導入ポリシーを持っていないと答えた組織の割合は前年度の55%から増大し63%となっています。

さらに心配なことに、AIポリシーを作成する計画がない組織の割合も3%から8%と、3倍近く増加しています。明確なポリシーがないということは、多くの企業は目隠しされたまま加速しているようなものです。

ダークトレースの顧客ベースにおいてアクティビティを分析したところ、同様のパターンが発生していることが観察されました。昨年10月だけでも生成AIサービスへの異常なデータアップロードが前月比で39%増加し、アップロードの平均サイズは75MBでした。これらのアップロードのサイズと頻度を考えると、おそらくこれらのデータのかなりの部分は、企業の外へ出すべきものではなかったはずです。

多くのセキュリティチームは依然として、ビジネス内でAIがどのように使われているか、つまりどのように振る舞い、何にアクセスし、そして最も重要なこととして、安全に業務を行っているかについての可視性を持っていません。こうした管理されていない利用が静かに広がり、設定済みのセキュリティコントロールから完全にはずれたAIアクティビティがあちこちで発生しています。その結果、ほとんど可視性のない状態で深刻な露出が起こることになり、正式なポリシーが存在していてもAIの利用がそれ以上に広がっている現実があります。

この問題は組織内部の問題にとどまりません。シャドーAIははサードパーティ製ツールやベンダーのプラットフォーム、パートナーのシステムなどにも存在します。AI機能がはっきりした監視なしに組み込まれているケースです。

その一方で、攻撃者はAIの特性を悪用する方法を習得し始めており、組織がすでに管理に苦労しているリスクをさらに悪化させています。

サイバーセキュリティのリーダーがAIを保護  

ダークトレースは、10年以上にわたり構築してきたビヘイビアAIの専門技術を、今日のAIが存在する、複雑で曖昧な環境で機能するように設計された、組織全体をカバーするプラットフォームで提供します。

他のサイバーセキュリティ技術は、過去の攻撃に基づいて新しい攻撃を予測しようとします。しかし問題は、AIが人間のように動作することです。すべての行動は新しい情報を作り出し、それがAIの動作を変えます。これは予測不可能であり、過去に見られた攻撃の戦術はもはや方程式の小さな部分に過ぎません。その結果多くのベンダーは実証されていない技術を買収し、改修してAIの保護を行おうとしています。

ダークトレースのアプローチは他とは根本的に異なります。ダークトレースの自己学習型AIはそれぞれの組織にとって何が正常な状態かを理解します。ユーザーやシステム、アプリケーション、そしてAIエージェントがどのように動作し、どのようにやりとりし、データがどのように流れるかを学習します。これにより、何かが意味のある変化をしたときに、そのかすかな動きを見つけ出すことができます。AIエージェントが登場するずっと前から、ダークトレースのテクノロジーはネットワーク、クラウド、SaaS、Eメール、OT、アイデンティティ、エンドポイントにわたりニュアンスを解釈し、逸脱を検知し、隠れた関係を明らかにし、あいまいなアクティビティの意味を理解してきました。

AIが新たな動作、非構造的やりとり、目に見えない経路を作り出し、シャドーAIが拡大する状況において、セキュリティ課題はますます深刻化しています。しかしダークトレースのプラットフォームはまさにこうした環境のために設計されています。AIの保護はダークトレースにとって新しい方向性ではありません。すでに世界中で何千もの組織に提供してきたビヘイビアインテリジェンスの自然な進化の延長線上にあります。

企業全体にわたる包括的なAIセキュリティ、Darktrace / SECURE AI 

このような背景から、私たちは Darktrace / SECURE AI を自信を持ってご提供します。Darktrace ActiveAI Security Platformの新製品であり、組織全体のAIを保護するよう設計されています。

これは組織をサイバー脅威や新たなリスクから保護する私たちのミッションの新たな章となる製品です。完全な可視性、インテリジェントな動作の監視、リアルタイムコントロールを組み合わせることにより、企業内へのAIの安全な導入、管理、構築を可能にします。これによりAIの使用、データアクセスおよび動作を、セキュリティベースライン、コンプライアンス、そしてビジネスの目標に整合した状態に維持することができます。

Darktrace / SECURE AIは、AIとのあらゆる相互動作を単一のビューで可視化し、セキュリティチームは人間とAIエージェント両方のアクティビティに対して、その意図を理解し、リスクを評価し、機密性の高いデータを保護し、ポリシーを徹底することができます。これにより組織は、AIが安全かつ責任ある形で、セキュリティおよびコンプライアンスのニーズに沿って動作しているかどうかを確認するための可視性とともに、自信を持ってAIを取り入れることができます。  

AIの保護は複数の分野にわたり多層的な複雑さがあるためDarktrace / SECURE AIは自社が所有するAIとサードパーティから提供されるものを含め、組織全体ビジネスに影響するすべてのAI使用を保護するための、次の4つの基盤となるユースケースに基づいて構築されています:

  • 生成AIエージェントおよびアシスタントを駆動するプロンプトを監視する
  • ビジネスAIエージェントのアイデンティティをリアルタイムに保護
  • 開発時、運用時のAIリスクを評価する
  • シャドーAIを見つけ出し、統制する

生成AIエージェントおよびアシスタントを駆動するプロンプトを監視する

AIシステムにおいて、プロンプトは最も活発で敏感なインタラクションのポイントの1つです。これには、ユーザーが意図を伝える人間とAIのやり取り、そしてエージェントが内部プロンプトを生成して推論や調整を行うAI同士の相互動作が含まれます。プロンプトに使われる言語は実質的に動作を示すものであり、固定された有限の構文ではなく自然言語に依存しているため、アタックサーフェスは無限に広がります。そのため、プロンプト駆動のリスクは、CVEに結びつけられた従来のAPIベースの脆弱性よりもはるかに複雑になります。

攻撃者が弱点を探ろうとしているケース、従業員が意図せずに機密データを露出させてしまうケース、エージェントが複雑なワークフローを実行するために自身のサブタスクを生成するケースなど、どのようなケースにおいても、セキュリティチームはプロンプトの動作がモデルの挙動をどのように形成するか、そしてその挙動が問題となる可能性について理解しなければなりません。このような動作についての理解がなければ、組織はAIシステムのエクスプロイト、ドリフト、エラーの連鎖によるリスクの増大に直面することになります。

Darktrace / SECURE AIは、Microsoft CopilotやChatGPT Enterprise等のエンタープライズAIシステム、Microsoft CopilotやStudio等のローコード環境、SalesforceやMicrosoft 365のようなSaaSプロバイダー、AWS、Bedrock、SageMakerなどのハイコードプラットフォームなど、すべてのプロンプトアクティビティを一元的な可視性のレイヤーに統合します。 

可視化だけでなく、Darktraceはビヘイビア分析により、プロンプトがユーザー、その仲間そして組織全体のコンテキストで通常とは異なるあるいはリスクが高いかどうかを理解することができます。AI攻撃は固定されたAPIに対する従来のエクスプロイトよりも格段に複雑であり会話を利用するものである – EメールやTeams/Slackの会話により近い – ため、ビヘイビアの理解はきわめて重要です。プロンプトを動作のシグナルとして扱うことにより、Darktraceは会話型攻撃、悪意あるチェイニング、わかりにくいプロンプトインジェクションの試みを検知することができます。そしてインテグレーションの設定によっては、安全でないプロンプトをリアルタイムにブロックしたり、有害なモデルアクションを発生と同時に阻止することができます。

ビジネスAIエージェントのアイデンティティをリアルタイムに保護

多くの組織がAI駆動のワークフローを導入していくなかで、ビジネスのさまざまな場所で自律型または半自律型のエージェントが急速に拡大しています。これらのエージェントは既存のアイデンティティ内で動作し、システムにアクセスしてデータを読み取り、書き込み、クラウドプラットフォームや社内インフラ、アプリケーション、API、サードパーティサービスに対してアクションをトリガーする能力を持っています。ユーザーのようにコントロールされているアイデンティティもありますが、前述のような、どこに出現するかわからないものもあります。これらのアイデンティティがどのように構成されているか、またその権限がどのように変化していくかに対しての可視性が限定的なためです。

Darktrace SECURE / AIは、AIエージェントの設計上の動作だけでなく、実際に何を行っているかについてアイデンティティを中心としたリアルタイムの理解を提供します。SaaS、クラウド、ネットワークエンドポイント、OT、Eメールこれらの環境でのエージェントのリアルタイムのアイデンティティを、サードパーティ環境内で動作しているものを含めて自動的に検知します。

各エージェントがどのように設定されているか、どのシステムにアクセスしているか、どのように通信しているかを、MCPの使用や機密性の高いデータが保存されているストレージとのやり取りを含めてマッピングします。

エージェントの振る舞いをすべてのドメインに渡り継続的に観察することにより、Darktrace SECURE / AIは不必要またはリスクのある権限の付与、アクティビティパターンの逸脱、あるいは意図されていない方法でエージェントがアクションのチェイニングを始めたときに、これらを識別することができます。このリアルタイムの監査証跡により、組織はエージェントのアクションが意図したオペレーションのパラメーターと整合しているかどうかを評価し、異常な、またはリスクの高い振る舞いを早期にキャッチすることができます。  

開発時、運用時のAIリスクを評価する

AIの構築時には、新たなアイデンティティが作成され、権限が積み重ねられ、さまざまなコンポーネントがSaaS、クラウドそして社内の環境でつなぎ合わされ、プロンプトやコンフィギュレーションを通じてロジックが形成されていきます。 

これは非常にダイナミックかつ多くの場合断片的なプロセスであり、ここでのほんのわずかな手違い、たとえば作成したアイデンティティの設定ミスなどが、システムがデプロイされた後で大きなセキュリティ問題になる可能性があります。AIリスクを開発時に評価することがきわめて重要なのはこのためです。

Darktrace / SECURE AIは、AIシステムの形成が始まった瞬間からライブになるまでのライフサイクル全体に、明確性とコントロールを提供します。作成されたアイデンティとそれらのハイパースケーラー、ローコードSaaS、社内ラボへのアクセスへの可視性を提供するとともに、AIセキュリティポスチャ管理により設定ミス、過剰な権限付与、異常なビルドイベント等を明らかにします。Darktrace/ SECURE AI はこれらの開発環境の情報をプロンプトの監視に直接結びつけ、AIがどのように構築されているかという情報を、運用開始後の挙動とリンクさせます。その結果、より安全で、より予測可能なAIライフサイクルが実現され、リスクを早期に発見し、一貫してガードレールを適用し、当て推量ではなく自信を持ってイノベーションを前進させることができます。

シャドーAIを見つけ出し、統制する

シャドーAIは今や組織のあらゆる場所に出現しています。これは単に従業員が外部チャットボットに内部データを貼り付けてしまう問題だけではありません。これには、管理されていないエージェントビルダー、隠れたMCPサーバー、不正なモデルのデプロイ、そして誰もAIが使われていると思っていなかったデバイスやサービス上のAIワークフローが含まれます。

Darktrace SECURE / AIは、クラウド、ネットワーク、エンドポイント、OTそしてSaaS環境にわたる相互動作を継続的に分析することにより、この新たなリスクを可視化します。承認されていないAIの使用をそれがどこで出現しようとも検知し、正規のアクティビティや承認されているツールを、誤った使用や高リスクのアクティビティと区別します。システムは隠れたAIコンポーネントや不正なエージェントを識別し、承認されていないデプロイメントや、外部AIシステムへの予期しない接続を明らかにします。そして通常のビジネスから逸脱したリスキーなデータフローを特定します。

対応が必要な挙動については、Darktrace SECURE / AIは安全ではないまたは管理されていない使用を封じ込めるとともに、管理されている方法にユーザーを誘導することでポリシーの徹底を可能にします。これにより、企業にとって最も急速に拡大しているセキュリティギャップの1つを解消し、シャドーAIにより作り出されるアタックサーフェスを大幅に削減することができます。

まとめ

AIの導入にポリシーやフレームワークとともに今必要なのは、AIの隠れた使用、プロンプトリスク、アイデンティティの不正使用、および開発全体に渡り、AIの挙動に基づいて脅威を検知する適切なツールです。

ダークトレースはAIの保護を実現する上で他にはない強みがあります。AIエージェントが登場するずっと以前から、それぞれのビジネスから学習し、組織全体にわたり微妙な動作を理解するAIを、10年以上にわたり構築してきました。他のツールでは見逃されてしまう脅威を捕捉する防御の最終ラインとして10,000社以上の顧客がDarktraceを使用しており、AIの保護は私たちにとって方向転換でも新たな技術の取得でもなく、当初からプラットフォームの基盤であったビヘイビア分析技術と、組織全体のインテリジェンスの自然な延長線上にあります。

組織内のAIを保護する方法についてさらに詳しく知りたいお客様のために、プログラムをご用意しました。ITリーダーおよびセキュリティリーダーが共にこの問題に取り組み、大きな意思決定に備え、ガードレールを検討し、不透明性とプレッシャーのなかでビジネスを導くためのフォーラムをご提供します。

Secure AI Readiness Programへの参加はこちらから: AI脅威の最新ニュース、AIセキュリティを取り巻く新たなアプローチ、この分野におけるダークトレースの開発情報を含めた最新イノベーションに関する考察をお届けします。

AIの保護についてダークトレースのエキスパートへのお問い合わせはこちらから: お客様のビジネスにとって最も問題となるAIリスクについて、ガバナンス、可視性、リスク削減、長期的な準備など、どの部分に集中すべきかを含め、実務的な情報をご提供します。

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Brittany Woodsmall
Product Marketing Manager, AI

More in this series

No items found.

Blog

/

AI

/

August 21, 2026

AI Agents: Securing the Path from Intent to Action

Default blog imageDefault blog image

The UK’s National Cyber Security Centre (NCSC) recently published guidance on managing the cyber risk of agentic AI. While the document is framed as interim advice as more formal guidance is developed, the framing reflects the current state of the industry: organizations are already deploying agents into production environments while standards, controls, and operating models for autonomous systems remain unsettled. Governance is evolving alongside adoption rather than preceding it, a reality which underscores the importance of robust controls.  

The NCSC’s guidance recommends aligning controls to an agent's level of autonomy, assigning distinct identities, limiting permissions, constraining access to systems and data, monitoring activity, maintaining human oversight, and preserving the ability to intervene when necessary. Most of these recommendations will sound familiar to security teams. The challenge is not the novelty of the controls. It is the type of system those controls now need to govern.

The shift from model security to agent security

For several years, AI security discussions have focused heavily on models. Can a model be manipulated? Jailbroken? Trusted? Can it expose information it should not? Those questions remain important, but they capture only part of the problem. A model generating text is one thing. A system connected to identities, applications, tools, workflows, and business data is another.

The difference becomes clearer when comparing a chatbot that answers questions with an agent that can retrieve customer records, update tickets, invoke tools, trigger workflows, and interact with external systems. The underlying model may be identical. Its access is not. The security question begins to shift from what the model knows to what the system can do.

The same theme appears in the Five Eyes statement released earlier this year, describing AI as a force multiplier that is accelerating both offensive and defensive cyber operations. The NCSC guidance explores what that reality looks like when autonomous systems begin operating inside enterprise environments.

Securing AI agents in operation

The NCSC spends relatively little time debating model behavior and considerably more time discussing identity, permissions, monitoring, oversight, containment, and response. Agents are treated as participants within an environment rather than isolated pieces of technology.  

That's broadly consistent with how we think about the problem at Darktrace.

An agent should not be treated as an extension of a user account. It develops its own behavioral patterns. It accesses systems, interacts with data, invokes tools, and moves across workflows in ways that can be observed independently. Understanding what an agent is permitted to do matters. Understanding how it actually behaves once deployed, and whether that behavior aligns with business intent, matters just as much.

Identity provides an obvious example. The NCSC recommends assigning distinct identities to agents rather than allowing them to disappear into surrounding human or service accounts. Most importantly, assigning agents distinct identities enables independent behavioral monitoring.

Development assumptions vs. real-world behavior

The same principle extends to monitoring. NCSC guidance places agent activity within normal security operations rather than treating it as a separate AI governance function. Many of the controls described are put in place before an agent begins operating. Sandboxing, credential design, approval workflows and human oversight all reflect judgments about how the system is expected to behave and what risks it is likely to create.

Actual use may challenge those assumptions. Access patterns change. Workflows expand. Systems begin interacting with resources they have never touched before. Processes that appeared reasonable during design behave differently in production. Human oversight requirements may turn out to be either excessive or inadequate once the system is operating at scale and operating within the context of unique business processes.

The Five Eyes statement points to a similar issue: organizations need confidence that controls continue to work as intended once systems are exposed to real users, data, tools and operational pressures. Often, the question is not whether an agent is technically allowed to perform an action, but whether its behavior remains consistent with the role it was intended to play.

Monitoring and governance of AI agents go hand-in-hand

This problem is exactly why monitoring and governance should be treated as part of the same process. Governance sets the initial parameters for deployment, while monitoring provides evidence about whether those parameters remain appropriate. That evidence should, in turn, inform changes to permissions, controls and oversight.

This matters increasingly as autonomous systems are integrated into business processes. The relevant risk is shaped not only by the model or agent itself, but by what it can access, what actions it can take, and how its behavior changes in practice.

Developing continuous oversight of AI agent behavior

The implication is clear: governance cannot end at deployment. Organizations need a way to understand how agents behave after deployment, test whether controls remain appropriate, and adjust them as conditions change. That requires visibility not just into technical activity, but into whether that activity makes sense in the context of the business process the agent is intended to support.

This is where business-centric behavioral security can become critical. Risk does not emerge from the model itself: it emerges from the actions an autonomous system takes within the enterprise and the downstream consequences of those actions.  

An agent can operate exactly as intended and still create risk if it accesses sensitive information in an unexpected context, exercises permissions in ways that create unintended exposure, or influences business processes in ways that were not anticipated during design and review.

Traditional governance vs. behavioral analytics

Traditional governance frameworks provide assurance at a point in time. Behavioral security can provide ongoing visibility into how autonomous systems interact with the organization they are meant to serve. Rather than focusing exclusively on model performance or policy compliance, organizations need to understand whether an agent's behavior aligns with business intent, operational expectations, and acceptable risk tolerances as conditions change.

As enterprises move from isolated AI deployments to interconnected ecosystems of agents, visibility into behavior becomes as important as visibility into code. Governance determines what an autonomous system is permitted to do. Behavioral analytics helps determine what it is doing, what business outcomes it is producing, and whether those outcomes remain aligned with the organization's objectives.

[related-resource]

Continue reading
About the author
Margaret Cunningham, PhD
VP, Security & AI Strategy, Field CISO

Blog

/

AI

/

August 19, 2026

When AI Becomes the Lure: A Fake Gemini Installer Delivers Vidar

Default blog imageDefault blog image

Key takeaways

  • Darktrace observed a customer download a fake Google Gemini installer hosted on Google Colab, resulting in the execution of the Vidar information stealer.
  • Darktrace identified the compromise through behavioral indicators, including suspicious process activity, anomalous network communications, and indicators of credential theft, before autonomously containing the threat.
  • The incident highlights how threat actors are increasingly exploiting trusted platforms and a growing interest in AI tools to distribute malware through seemingly legitimate software acquisition workflows.

The Growing Abuse of Generative AI

As organizations are increasingly adopting generative AI tools into their daily workflows, attackers are adapting their distribution methods accordingly too. As part of their day-to-day work, users are now searching for AI assistants, programming tools, browser extensions, desktop applications, and productivity integrations.

Recent reports have highlighted campaigns that use fake AI software and AI-related installers to distribute malware and steal credentials [1]. Researchers have documented campaigns that exploit fake AI-themed websites and services to distribute information stealers and backdoors [2]. Security researchers have also observed attackers disguising malware as legitimate installers for AI software to increase the likelihood of victim interaction and execution [3].

In July 2026, Darktrace observed one such case within a customer environment in the Europe, Middle East and Africa (EMEA) region, where attackers used a fake generative AI installer to deliver the prolific information stealer Vidar. This incident highlights how threat actors are exploiting interest in AI services to distribute established malware using increasingly convincing social engineering techniques.

How a Fake Gemini Installer Delivered Vidar

Initial Access: From Search Result to Malware Download

Unlike many malware campaigns that begin with a phishing email, this activity appears to have originated from a user searching for and downloading software.

Darktrace first observed unusual activity on the customer network after a suspicious executable file was launched from a user’s Download folder. Further investigation revealed that the file purported to be a Google Gemini installer and was named “Download_Google_Gemini_For_Windows.exe”.

During the initial analysis, it was noted that the top search result for the suspicious filename associated pointed to a file hosted on Google Colab, a cloud-based Jupyter notebook platform, commonly used by developers, researchers, and data scientists to run code and machine learning workloads through a web browser. By leveraging another trusted Google platform, the attacker increased the likelihood that users would perceive the download as legitimate, making the lure more convincing to those searching for Gemini-related software.

Figure 1: The Google Colab page containing a download prompt for the fake Google Gemini installer.

Further investigation of the Google Colab page revealed that the download prompt redirected users to a secondary site, hxxps://micronsoftwares[.]com, which posed as a "Windows Software Hub" download page and offered the fake Gemini installer for download.

Figure 2: The secondary website posing as a "Windows Software Hub" download page, which likely hosted the fake Gemini installer.

While the investigation did not uncover any HTTP or file-download telemetry data that conclusively identified the download source, SSL communication sessions with Google Colab were detected immediately before the suspicious file was executed. The timing of these connections suggests that the user interacted with the Colab resource before being redirected to the secondary site from which the executable was downloaded.

The user was not simply tricked into opening an email attachment; instead, the attacker embedded malicious content into a process many users would consider entirely legitimate: searching for and downloading software associated with a trusted platform.

Weaponizing Trusted Platforms

At the time of review (July 15, 2026), Darktrace's Threat Research team confirmed that the Google Colab page was still active and prompting users to download a ZIP archive containing the binary file.

The archive also appeared to contain a README file instructing users to run the binary file with administrator privileges and add it to their antivirus software’s exception lists. These instructions suggest that the campaign relied heavily on social engineering, convincing users to take actions that would facilitate malware execution and potentially bypass security checks.

The use of a legitimate platform also complicates the user’s decision-making. Downloads associated with a trusted service are often perceived as less suspicious than those hosted on unfamiliar domains. When combined with the branding of a widely used AI tool, the lure becomes even more convincing.

Malware Analysis

Darktrace’s Threat Research team identified the executable file as the information-stealing malware Vidar. Analysis revealed that the binary file was a newer Go-compiled variant that communicated with Telegram-based infrastructure. Darktrace’s researchers also identified dtm[.]kijangturbo88[.]top as a command-and-control (C2) endpoint associated with the activity. While the malware itself was not novel, the lure and delivery mechanism was.

For a deeper look at the information stealer, see Darktrace’s 2023 analysis of Vidar.

Figure 3: Darktrace’s detection of the unusual outbound connection associated with the fake Gemini installer.

Shortly after execution, the process established communications with the external IP address 91.98.98[.]86 via port 443, directly linking the executable to suspicious network activity observed on the device. Subsequent open-source intelligence (OSINT) analysis of the revealed multiple malicious associations [5].

Additional Darktrace detections included unusual SSL activity from the affected device. Analysis of related SSL telemetry identified 91.98.111[.]49 as additional infrastructure associated  with the activity [6].

Subsequent alerts from the customer's Microsoft Defender for Endpoint integration later confirmed activity consistent with the theft of browser credentials and other sensitive data from the affected endpoint.

Taken together, these detections provided a clear picture of the attack, from the execution of a suspicious file and unusual network connections to indicators of C2 activity and credential theft.

Figure 4: Darktrace’s detection of anomalous activity following the execution of the fake Gemini installer, seen in the Model Alert Event Log.

Darktrace's Autonomous Response

Following the detection, Darktrace’s Autonomous Response took immediate containment action, including blocking communication with suspicious external infrastructure, including 91.98.98[.]86, and quarantining the compromised device.

Despite the apparent legitimacy of the activity, with the installer hosted on a trusted platform and resembling a routine software download, Darktrace was able to detect and contain the attack because the device's behavior deviated from its normal pattern.

Figure 5: Automated containment actions implemented by Darktrace's Autonomous Response following the detection of activity associated with the fake Gemini installer.

Conclusion

This investigation highlights how threat actors continue to adapt established malware delivery techniques to emerging technology trends. While the malware itself was not new, the distribution method was. By disguising Vidar as a Google Gemini installer and hosting the malicious content on a trusted platform, the attack aligned its lure with a growing behavioral trend: users actively searching for AI tools and services as part of their day-to-day work.

Although fake installers are not a new phenomenon, the rapid rise of generative AI has created new opportunities for threat actors. Rather than relying solely on traditional delivery methods, attackers can now target users who are actively searching for AI applications. As AI adoption continues to accelerate across enterprise environments, organizations should remain alert to campaigns that exploit this interest through fake applications, malicious websites, manipulated search results, the misuse of trusted platforms, and AI-themed social engineering.

Credit to Rushanth Ramanathan (Cyber Analyst) Joanna Ng (Detection Engineer)

Edited by Ryan Traill (Content Manager)

Appendices

Darktrace Model Detections

  • Security Integration / C2 Activity and Integration Detection
  • Endpoint / New Suspicious Executable Launched
  • Endpoint / Process Connection / Unusual Connection from New Process
  • Anomalous Connection / Rare External SSL Self-Signed
  • Security Integration / High Severity Integration Detection
  • Antigena / Network / Significant Anomaly /  Antigena Significant Security Integration and Network Activity Block

•Antigena / Network / Significant Anomaly /  Antigena Significant Anomaly from Client Block

List of Indicators of Compromise (IoCs)

IoC Type Description
Download_Google_Gemini_For_Windows.exe File Fake Gemini-themed installer observed during the investigation.
GoogleAppInstaller.exe File Related executable identified through endpoint telemetry.
91.98.98[.]86 IP Address External destination contacted by the malicious executable.
91.98.111[.]49 IP Address Related infrastructure identified through SSL certificate pivoting.
dtm[.]kijangturbo88[.]top Domain Command-and-control endpoint identified during malware analysis.
1e13c2c9eac72daf63fd00a9946878949e159ae6ec51b54ec64f942d79d61913 SHA256 Malware sample associated with the fake Gemini installer.

MITRE ATT@CK Mapping


MITRE ATT&CK Mapping Tactic Technique
Initial Access T1204 User Execution
Execution T1204.002 User Execution: Malicious File
Defence Evasion T1036 Masquerading
Credential Access T1555 Credentials from Password Stores
Credential Access T1555.003 Credentials from Web Browsers
Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel
Continue reading
About the author
Rushanth Ramanathan
Cyber Analyst
あなたのデータ × DarktraceのAI
唯一無二のDarktrace AIで、ネットワークセキュリティを次の次元へ