ブログ
/
Email
/
November 27, 2025

Phishing attacks surge by 620% in the lead-up to Black Friday

Black Friday continues to be a prime opportunity for threat actors, with early analysis from Darktrace showing a significant spike in attackers impersonating well-known brands, as well as the brands most frequently impersonated by scammers. Plus, check out our top tips to stay safe while filling your basket with deals.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Carlos Gray
Senior Product Marketing Manager, Email
Default blog image
27
Nov 2025

Black Friday deals are rolling in, and so are the phishing scams

As the world gears up for Black Friday and the festive shopping season, inboxes flood with deals and delivery notifications, creating a perfect storm for phishing attackers to strike.

Contributing to the confusion, legitimate brands often rely on similar urgency cues, limited-time offers, and high-volume email campaigns used by scammers, blurring the lines between real deals and malicious lookalikes. While security teams remain extra vigilant during this period, the risk of phishing emails slipping in unnoticed remains high, as does the risk of individuals clicking to take advantage of holiday shopping offers.

Analysis conducted by Darktrace’s global analyst team revealed that phishing attacks taking advantage of Black Friday jumped by 620% in the weeks leading up to the holiday weekend, with the volume of phishing attacks expected to jump a further 20-30% during Black Friday week itself.

First observation: Brand impersonation

Brand impersonation was one of the techniques that stood out, with threat actors creating convincing emails – likely assisted by generative AI – purporting to be from household brands including special offers and promotions.

The week before Thanksgiving (15-21 November) saw 201% more phishing attempts mimicking US retailers than the same week in October, as attackers sought to profit off the back of the busy holiday shopping season. It’s not just about volume, either – attackers are spoofing brands people love to shop with during the holidays. Fake emails that look like they’re from well-known retailers like Macy’s, Walmart, and Target were up by 54% just across last week1. Even so, Amazon is the most impersonated brand, making up 80% of phishing attempts in Darktrace’s analysis of global consumer brands like Apple, Alibaba and Netflix.  

While major brands invest heavily in protecting their organizations and customers from cyber-attacks, impersonation is a complicated area as it falls outside of a brand’s legitimate infrastructure and security remit. Retail brands have a huge attack surface, creating plenty of vectors for impersonation, while fake domains, social profiles, and promotional messages can be created quickly and at scale.

Second observation: Fake marketing domains

One prominent Black Friday phishing campaign observed landing in many inboxes uses fake domains purporting to be from marketing sites, like “Pal.PetPlatz.com” and “Epicbrandmarketing.com”.

These emails tend to operate in one of two ways. Some contain “deals” for luxury items such as Rolex watches or Louis Vuitton handbags, designed to tempt readers into clicking. However, the majority are tied to a made-up brand called Deal Watchdogs, which promotes “can’t-miss” Amazon Black Friday offers – designed to lure readers into acting fast to secure legitimate time-sensitive deals. Any user who clicks a link is taken to a fake Amazon website where they are tricked into inputting sensitive data and payment details.

Third observation: The impact of generative AI

The biggest shift seen in phishing in recent years is how much more convincing scam emails are thanks to generative AI. 27% of phishing emails observed by Darktrace in 2024 contained over 1,000 characters2, suggesting LLM use in their creation. Tools like ChatGPT and Gemini lower the barrier to entry for cyber-criminals, allowing them to create phishing campaigns that humans find it difficult to spot.  

Let’s take a look at a dummy email created by a member of our team without a technical background to illustrate how easy it is to spin up an email that looks and feels like a genuine Black Friday offer. With two prompts, generative AI created a convincing “sale” email that could easily pass as the real thing without requiring any technical skill.

A fake Black Friday deal email created using generative AI, with only two prompts. The image has been pixelated for marketing purposes.

Anyone can now create convincing brand spoofs, and they can do it at scale. That makes it even more important for email users to pause, check the sender, and think before they click.

Why phishing scams hurt consumers and brands

These spoofs don’t just drain shoppers’ bank accounts and grab their personal data. They erode trust, drive people away from real sites, and ultimately hurt brands’ sales. And the fakes keep getting sharper, more convincing, and harder to spot.

Though brands should implement email controls like DMARC to help reduce spoofing, they can’t stop attackers from registering new look-alike domains or using other channels. At the end of the day, human users remain vulnerable to well-crafted scams, particularly when the element of trust from a well-known brand is involved. And while brands can’t prevent all impersonation scams, the fallout can still erode consumer trust and damage their reputation.

In order to limit the impact of these scams, two things need to work together: better education so consumers know when to slow down and look twice, and email security (plus a DMARC solution and an attack surface management tool) that can adapt faster than the attackers – protecting both shoppers and the brands they love.

Tips to stay safe while Black Friday shopping online

On top of retailers implementing robust email security, there are some simple steps shoppers can take to stay safer while shopping this holiday season.

  • Check every website (twice). Scammers make tiny changes you can barely see. They’ll switch Walmart.com for Waimart.com and most people won’t notice. If something looks even slightly off, check the URL carefully and, if you’re unsure, search for reviews of that exact address.
  • Santa keeps the real gifts in the workshop. Don’t just click through from sales emails. Use them as a prompt to log in directly to the official app or site, where any genuine notifications will appear.
  • Look at the payment options. Real retailers usually offer a handful of recognizable ways to pay; if a site pushes only odd methods or upfront transfers, don’t use it.
  • Be skeptical of Christmas miracles. If a deal on a big-ticket item looks too good to be true, it usually is.
  • Leave the rushing to the elves. Countdown timers and “last chance” banners are designed to make you click before you think. Take a breath, double-check the sender and the site, and then decide whether to buy.

Email security you can trust this holiday season

The heightened holiday shopping season shines a spotlight on an uncomfortable reality: now that phishing emails are harder than ever to distinguish from legitimate brand communication, traditional spam filters and Secure Email Gateways struggle to keep up. In order to protect against communication-based attacks, organizations require email security that can evaluate the full context of an email – not just surface-level indicators – and stop malicious messages before they reach inboxes.

Darktrace / EMAIL uses Self-Learning AI to understand the behavior and patterns of every user, so it can detect the subtle inconsistencies that reveal a message isn’t genuine, from shifts in tone and writing style to unexpected links, unfamiliar senders, or off-brand visual cues. By identifying these anomalies automatically – and either holding them entirely, or neutralizing malicious elements – it removes the burden from employees to catch near-imperceptible errors and reinforces protection for the entire organization, from staff to customers to brand reputation.

Join our live broadcast on 9 December, where Darktrace will reveal new, industry-first innovations in email security keeping organizations safe this Christmas – from DMARC to DLP. Sign up to the live launch event now.

For a deeper dive into some specific Black Friday phishing campaigns surfaced by the Darktrace threat analysis team, read the follow-up blog here.

A note on methodology

Insights derive from anonymous live data across 6,500 customers protected by Darktrace / EMAIL. Darktrace created models tracking verified phishing emails that:

  • Explicitly mentioned Black Friday
  • Impersonated US retailers popular during the holiday season (Walmart, Target, Best Buy, Macy's, Old Navy, 1800-Flowers)
  • Impersonated major global brands (Apple, eBay, Netflix, Alibaba and PayPal)

Tracking ran from October 1 to November 21.

References

[1] Based on live tracking of phishing emails spoofing Walmart, Target, Best Buy, Macy's, Old Navy, 1800-Flowers across email inboxes protected by Darktrace.  November 15 – November 21, 2025

[2] Based on analysis of 30.4 million phishing emails between December 21, 2023, and December 18, 2024. Darktrace Annual Threat Report 2024.

[related-resource]

Replace your SEG with context-aware email security

A practical guide for CISOs for replacing outdated SEGs with AI-driven email security, optimized for Microsoft 365.

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Carlos Gray
Senior Product Marketing Manager, Email

More in this series

No items found.

Blog

/

AI

/

July 13, 2026

Security After Signatures: Operating in a World of Pre‑CVE Disclosure Exploitation, Collapsed Trust Boundaries, and Autonomous Systems

Default blog imageDefault blog image

Three shifts have reshaped what it means to defend an enterprise securely.  

First, exploitation often begins before defenders have a Common Vulnerabilities and Exposures (CVE) identifier, a security advisory, or an entry in the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog.

Secondly, the trust boundary has moved beyond the network edge into identities, tokens, APIs, and Software-as-a-Service (SaaS) workflows.  

Third, an increasing share of business activity is executed through automation, integrations, and AI agent-like systems that can act faster than teams can verify intent.  

If your security model still relies on detecting known bad artefacts, triaging isolated alerts, and waiting for confirmation before acting, you are already behind the threat.  

This is not a failure of security teams; it’s a failure of the operating model to keep pace with how the environment has changed.

A SOC built around alerts and signatures assumes that malicious activity will eventually surface as an event. In real incidents, however, the decisive evidence is rarely a single event. Instead, it is a chain of individually explainable actions that only appears malicious once you connect the dots across identity, non-human identity, cloud, email, SaaS, operational technology (OT), and network telemetry.

The defenders succeeding today observe behaviors, link them into sequences, understand what those sequences mean, and contain impact before the full story unfolds. That is the operating model the current threat environment demands.  

Exploitation before disclosure

The first shift is the straightforward: the time to exploit has dropped to nearly zero.  

In one example, Darktrace observed a sequence of subtle but strategically significant anomalies within a customer environment that later aligned with exploitation of CVE‑2025‑0994 in Trimble Cityworks by likely Chinese-nexus threat actors. Behavioral indicators were visible at least 18 days before public disclosure, with related anomalies emerging 40 to 50 days earlier during the intrusion window.  

This case illustrates a familiar pattern: clusters of weak‑signal anomalies combing to form an actionable picture of intrusion long before a CVE is published. Such activity reflects long‑horizon, option‑preserving operator models often associated with mature state‑linked activity.  

Figure 1: Darktrace’s detection of malicious exploitation of CVE 2025-0994, later tied to Chinese-nexus threat actors targeting critical national infrastructure (CNI) in the US, weeks before public disclosure.

Throughout 2025 and 2026, Darktrace has continued to observe the value of anomaly-based detections across a range of incidents.

CVE CVE Public Disclosure Date Darktrace Detection Date Days Between Detection of Exploitation and CVE Public Disclosure
CVE 2025 0994
(Trimble City Works)
2025-02-06 2025-01-19 18 Days
CVE 2025-24183
(Apache)
2025-03-10 2025-02-18 20 days
CVE 2025-10035
(Fortra GoAnywhere)
2025-09-18 2025-09-11 7 days

Identity is the real control plane

The second shift is that identity has replaced perimeter as the primary control plane. As Darktrace’s Annual Threat Report 2026 illustrated, identity remains the main challenge in defending against modern intrusions. A clear example is the Adversary-in-the-Middle (AiTM) case published by Darktrace in December 2025. A phishing email led to the compromise of an Office 365 account. Session hijacking bypassed multi-factor authentication (MFA), and the compromised account was used for follow-on phishing and persistence activities including the creation of malicious email rules.  

Every step in that sequence mattered. A successful login alone does not prove legitimacy. An inbox rule, on its own, may not appear catastrophic. Mail activity, viewed in isolation, may seem operationally normal. But the behavioral chain tells a different story: credential theft, token abuse, persistence, and onward compromise through a trusted identity.  

This is why the question is no longer “Did the user authenticate successfully”. The more important question is, “Does this identity action make sense right now, in this context, given what came before it?” The AiTM case shows how identity can be compromised. In practice, however, attacks rarely remained confined to identity alone.  

In another Darktrace case, a compromised SaaS account triggered activity across the email, SaaS, and network layers, including inbox rule changes, phishing propagation, and connections to suspicious infrastructure. Viewed in isolation, none of these events were decisive. Together, however,  they formed a behavioral sequence that revealed the intrusion, with the full attack story automatically correlated and surfaced to defenders by Darktrace’s Cyber AI Analyst.  

Figure 2: Cyber AI Analyst correlated and appended additional events to the incident, including other users who connected to the suspicious redirect link after outbound phishing emails were sent.

AI accelerates the threat  

The third shift is the one many teams still underestimate: trusted tooling, integrations, and AI agent-like systems can create actions that appear legitimate but are strategically dangerous.  

The shift becomes clearer when examining how governments are now framing AI risk. In 2026, guidance published by CISA, UK’s National Cyber Security Centre (NCSC) and Five Eyes partners warned that agentic systems expand attack surfaces, accumulate privilege, and can behave in ways that are difficult to predict or explain [1]. The advice is simple: assume unexpected behavior and design controls around it.  

The real risk is not AI usage. It is unknown autonomy: systems with credentials, data access, and action paths that can execute workflow steps without sufficient behavioral validation, traceability, or human oversight. Darktrace’s Model Context Protocol (MCP) risk analysis provides a useful framework for understanding this challenge. Over-privileged agents, content injection, and tool abuse become high-consequence risks when connected systems can dynamically retrieve data, execute actions, and communicate externally.  

Whether security teams like it or not, AI is already in the enterprise. It will help drive innovation, but it will also be abused, whether accidentally or maliciously. In each of the cases below, AI either scaled the attacker, built the tooling, or existed within the environment as something to exploit or misuse.

1. AI as an Attack Multiplier

In one campaign targeting Mexican government entities, a single operator used commercial AI platforms to generate exploits, automate reconnaissance, and process large volumes of data, compressing work that would traditionally have required an entire team into a single workflow [2].  

Darktrace is also observing this trend further down the stack. In one case, Darktrace identified AI-generated malware exploiting React2Shell, where an attacker used a Large Language Model (LLM) to produce working exploit code and deploy it at scale.  

[darktrace.com], [darktrace.com]

2. AI as an Attack Surface

Attempted AI exploitation is now appearing within customer environments. In one case involving an automation technology manufacturer, a compromised LLM proxy was seemingly used as a stepping stone to access additional AI services. When that attempt failed, the attacker pivoted to cryptomining.

What is clear is that the AI layer has already become an asset worth probing, exploiting, and pivoting through. It is also clear that defenders benefit from rapidly understanding how these activities connect. In this case, Cyber AI Analyst automatically pieced together the intrusion, while Darktrace’s Managed Threat Detection service alerted to the customer, enabling the activity to be contained before it could progress further.

Figure 3: Cyber AI Analyst's investigation into a compromised LLM proxy that was abused for cryptomining activity.

AI as a trusted but dangerous actor

This does not require a cinematic vision of “rogue AI.” The Salesloft incident provides a more grounded example, where AI and automation operate with legitimate access but served malicious intent. In that case, attackers abused compromised OAuth tokens associated with the Drift AI chat agent to export significant volumes of data from Salesforce environments.  

The activity resembled legitimate API usage and relied on trusted SaaS integrations rather than malware or other obvious signs of intrusion. That is precisely the challenge. Traditional security controls are good at detecting forced entry, but far less effective when a trusted application integration behaves in a way that is technically permitted yet operationally harmful.  

In these scenarios, the security challenge shifts from validating access to validating behavior.

This is what that looks like in practice: AI-linked identities executing legitimate actions that require behavioral validation rather than access validation.

Figure 4: Darktrace / SECURE AI highlights anomalous activity across AI identities, surfacing critical behavior that requires validation and containment.

Early observations from Darktrace / SECURE AI deployments reinforce this reality. Across Darktrace's observed fleet, AI service connections per deployment increased 13% during the first half of 2026, reaching over 16 million connections overall. The typical organisation now interacts with seven different AI providers, evidence that AI is no longer operating at the edges of the enterprise. It is increasingly woven into day-to-day business activity.

The most common risks are not compromised models or advanced AI attacks. Instead, they stem from employees and business functions exposing sensitive information through entirely legitimate-looking interactions. Darktrace has observed repeated submission of personally identifiable information (PII), tax information, identification documents, and medical data into LLM prompts, alongside widespread use of unsanctioned (shadow) AI services and growing AI activity from mobile devices.  

For defenders, the challenge is increasingly one of context: understanding when legitimate business use crosses into material risk, while preserving privacy and user trust.

Conclusion

Across all three shifts, the pattern is the same: behavior precedes understanding. Security teams are not losing because adversaries have become invisible. An increasingly outdated security model assumes that malicious activity will reveal itself cleanly and early. It no longer does.  

In 2026 and beyond, defenders win by understanding behavioral sequences, continuously validating trust, and acting before certainty becomes hindsight. That is security after signatures. That is security in the AI era.

Credit to: Daniel Levy, Threat Hunting Data Scientist

Edited by: Ryan Traill, Content Manager

References

[1] https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services  

[2]https://www.latimes.com/business/story/2026-02-26/hacker-used-anthropics-claude-ai-to-steal-mexican-government-data

Continue reading
About the author
Nathaniel Jones
VP, Security & AI Strategy, Field CISO

Blog

/

AI

/

July 10, 2026

AIインフラがアタックサーフェスの一部に

Default blog imageDefault blog image

AIインフラとアタックサーフェスの進化

多くの組織が生成AIを実運用環境に導入するなかで、企業のクラウド環境内に新たなインフラのレイヤーが出現しています。それはAIゲートウェイです。AIゲートウェイはユーザー、アプリケーション、基盤モデルの間に位置し、多くの場合クラウドの特権アクセスを保持し、さまざまなAIサービスへのアクセスを大規模に管理しています。

AIゲートウェイとは?

AIゲートウェイはユーザー、アプリケーション、基盤モデルの間に位置し、多くの場合クラウドの特権アクセスを保持し、さまざまなAIサービスへのアクセスを大規模に管理しています。

こうした役割から、AIゲートウェイは企業のアタックサーフェスのますます重要な一部になりつつあります。AIゲートウェイが侵害されれば、攻撃者に対して計算リソースへのアクセスだけでなく、クラウドアイデンティティ、モデルサービス、機密性の高いプロンプト、そして他の接続されたシステムへのアクセスも提供してしまいます。

このブログでは、Amazon Bedrock サービスに接続されたAIゲートウェイが侵害され、その後暗号通貨マイニングインフラとの通信が観測された事例をダークトレースがどのように調査したかを解説します。問題のインスタンスは、その構成、ならびに関連するIAM(Identity and Access Management)ロールから、Amazon BedrockでホスティングされるAIサービスへのゲートウェイとして機能していることがわかりました。疑わしい侵害アクティビティが発生した後、このホストは既知の暗号通貨マイニングインフラに繰り返し通信を行い、その後シャットダウンされた様子が観測されました。Darktrace はこのアクティビティを検知し、Enhanced MonitoringおよびManaged Threat Detectionサービスを通じてエスカレーションを行いました。

この事例では最終的影響は不正な暗号通貨マイニングでしたが、このインシデントが注目に値するのはその発生場所です。侵害されたアセットは、クラウドインフラ、アイデンティティ、各種AIサービスの交差する場所に位置していました。最近の調査では、LiteLLM等のAIゲートウェイが、認証情報、モデルへのアクセス、クラウド権限を中央管理するその能力から、攻撃者にとって魅力的な標的となる可能性が明らかになっています。このアクティビティと公開されているLiteLLM脆弱性を直接結びつける証拠は見つかっていませんが、このインシデントは、AIインフラを個別のアプリケーション層として見るのではなく、重要なアタックサーフェスの一部として扱う必要性があることを表しています[1]。

暗号通貨マイニングがクラウド侵害後のアクティビティとしてよく見られる背景

暗号通貨マイニングはクラウド環境において、侵害後のアクティビティとして収益性の高いものとなり得ます。クラウド資産にアクセスできるようになった後、攻撃者はマイニングソフトウェアを展開して被害者の計算リソースを悪用し金銭的利益を得ることができます。この種のアクティビティは多くの場合機会主義的なものであり、露出したサービス、弱い認証情報、漏洩したアクセスキー、脆弱なアプリケーション、あるいはクラウドワークロードの設定ミスなどを標的として実行されます。

典型的なクラウド上での暗号通貨マイニング侵入には次のようなアクティビティが含まれます:

  • 露出したあるいは脆弱なクラウドインフラの特定
  • 露出したサービス、認証情報、またはアプリケーションの脆弱性を通じたアクセスの獲得
  • マイニングソフトウェアのダウンロードおよび実行
  • マイニングプールインフラへのアウトバウンド接続を繰り返し確立
  • アクティビティが検知され停止されるまで継続して計算リソースを消費

この事例において注目すべき要素は暗号通貨マイニングだけではありません。それが発生した場所が、AI関連アクティビティをサポートするクラウドインフラ上だったことです。この事例は、AIサービスを実現するためのアセットも、よくあるクラウド侵害リスクにさらされる可能性があることを示しています。

Amazon Bedrockに接続されたAIゲートウェイの侵害を調査

2026年6月12日、DarktraceはLiteLLM-Proxyという名前のAmazon Web Service (AWS) EC2インスタンスから暗号通貨マイニング発生中とみられるアクティビティを観測しました。このインスタンスはLiteLLMアクティビティをサポートしており、Amazon Bedrockリソースへのアクセス権を有するインスタンスプロファイルと関連付けられていました。  

AIゲートウェイは大規模言語モデルへのアクセスを中央管理するよう設計されており、多くの場合AIアプリケーションに対する認証、ルーティング、ログ、ポリシー適用を扱っています。セキュリティの視点から見ると、クラウド権限、モデルアクセス、アプリケーションワークフローを単一の制御ポイントに集約する役割も果たしています。その結果、AIゲートウェイの侵害は、侵害されたホストだけにとどまらない影響を及ぼす可能性があります。

確定的な初期アクセスベクトルは確認できませんでしたが、このアクティビティはインターネットに接続されているシステムの侵害でよく見られる次のような順序に従っていました。ブルートフォースアクセス、ペイロードの投下、そしてマイニングプールインフラに対する繰り返しのアウトバウンド接続です。

ステージ1: インターネットに露出したSSHからの初期アクセス

暗号通貨マイニングアクティビティが観測される前、LiteLLM-Proxy EC2インスタンスはSSH(ポート22)が0.0.0.0/0に対して開かれ、外部に公開されていました。

図1:EC2インスタンスがSSHポート22に対してすべてのインバウンドトラフィックを許可している設定ミスをDarktraceが警告

暗号通貨マイニングアクティビティに先立って、Darktraceはこのインスタンスに対する大量のインバウンド接続の試みが外部IPアドレス(主に145.241.123[.]102)からポート22に対して行われていることを観測しました。これはブルートフォースアクティビティを示唆するものです [2]。これらの接続の多くは短命であり、数秒しか続いておらず、スキャニングまたはログインの失敗を示していました。

図2:Darktraceがデバイスのポート22に対する不審なインバウンド接続試行を検知

入手できたテレメトリーではこれらのインバウンドSSH接続のいずれかが認証の成功につながったかどうかの確認に至らず、このアクティビティが初期アクセスベクトルであると断定することはできませんでした。しかしながら、SSHの露出、外部IPアドレスからのインバウンド接続、それに続くマイニングアクティビティは、SSHがアクセス経路の可能性が高いことを示唆しています。

ステージ2: AIゲートウェイへのXMRigマルウェアのダウンロード

最初に観測されたマイニングプールへの接続の後、このEC2インスタンスは3.42 MBのデータをポート80上のHTTP接続を介して外部エンドポイント185.62.1[.]8にダウンロードしました。このエンドポイントは暗号通貨マイニングマルウェアXMRigを含むZIPファイルをホスティングしていました[3][4]。ホストレベルのログは入手できなかったため、ダークトレースはマイニングツールがどのように実行されたか、あるいは前のSSHアクティビティがペイロード投下を直接的に可能にしたかどうかを確認できませんでした。しかしながら、ダウンロードのタイミングとその後ほどなくマイニングプールへの接続が繰り返されたことは、このインスタンスが侵害されて不正な計算アクティビティに使われたという評価を裏付けています。

ステージ3 – 侵害されたAIゲートウェイが暗号通貨マイニングインフラと通信

わずか数分後、DarktraceはLiteLLM-ProxyEC2インスタンスがHTTPs(ポート443)でホスト名pool.hasvault[.]proに対して接続していることを確認しました。最初の接続の後、同じホスト名に対して繰り返しアウトバウンド接続が観測されました。これは、侵害されたホストがマイニングインフラと通信しワークを受け取り、結果を送信するという、暗号通貨マイニングプールとの通信のパターンと一致しています。

このアクティビティがDarktraceのEnhanced Monitoringモデル“Compromise / HighPriority Crypto Currency Mining”をトリガーし、ダークトレースのSOCにより顧客に対してエスカレーションされました。また、このアクティビティはCyber AI Analystによって分析され、関連するイベントが1つの調査ナラティブにまとめられました。これにより、影響を受けたクラウドアセットからマニングプールへの繰り返しの接続を特定することができました。

図3:CyberAI Analystによる暗号通貨マイニングアクティビティの調査  

ポート443上のHTTPSの使用にも注目すべきです。なぜならば、単独で見れば、このトラフィックそのものは疑わしく見えないかもしれないからです。しかしこのケースでは、接続先、接続の量、そして類似のアクティビティが他にないことなどが、この通信を疑わしいものとして特定するのに必要な、動作のコンテキストを提供することになりました。

ステージ4: Managed Threat Detectionサービスによるリソース乱用の特定

暗号通貨マイニングアクティビティがダークトレースのManaged Threat Detectionサービスにより検知され、ダークトレースのSOCによりレビューされました。レビューの結果、このアクティビティは顧客向けにエスカレーションされました。このエスカレーションにより、顧客はAWS環境で現在発生中のリソースの乱用について、タイムリーな通知を受けることができました。

ステージ5: クラウド認証情報の不正使用とみられる疑わしいIAMアクティビティ

これとは別に、6月13日、Darktraceは別のIAMユーザーから発生した疑わしいアクティビティを検知しました。

図4: DarktraceのAdvanced Search機能が別のIAMユーザーが実行した疑わしいアクティビティをハイライト

まず、このユーザーは “GetSendQuota”イベントを試行している様子が見られました。このアクションは少なくとも過去3か月間にこのアカウントによって実行されたことのないアクションです。また、このコマンドのソースIPアドレスは14.176.1[.]47でした。地理位置情報はベトナムであり、このユーザーのアクティビティがAmazon IPアドレスから最も多く見られた場所です。さらに、このアクティビティに対してAWS CLIが使用されており、これもこのユーザーにとって通常とは異なる振る舞いでした。このことは、Darktraceの“IaaS / Unusual Activity / UnusualAWS CLI Activity”モデルによって検知されました。

図5: Darktraceによる “GetSendQuota” イベントの検知

このIAMユーザーからは、長期アクセスキーを使った疑わしいアクティビティがさらに観測されました。中でも、“InvokeModel” および “ListFoundationModels”コマンドの失敗が検知されており、モデル列挙や起動などAmazon Bedrockサービスとのやり取りを試行したことがわかります。これは前日観測されたLiteLLM侵害への関連を思わせますが、2つのイベントを確定的に結びつける証拠は不十分でした。

“CreateUser”コマンドの試行も注目に値します。なぜなら要求されたユーザー名は意味が薄いものであり、新しいアカウントを作成することにより永続性を確立する試みと見られるからです。このアクティビティはDarktraceのモデル“IaaS / Admin / New AWS UserAccount Creation”をトリガーしました。

図6:Darktraceによる“CreateUser” イベントの検知

2つのインシデント間に結びつきは確認できなかったものの、このIAMアクティビティには重要な意味があります。これは、クラウド侵害の調査においてワークロードのテレメトリーとコントロールプレーンのテレメトリーの両方を取り入れることの重要性を表しています。EC2暗号通貨マイニングアクティビティが計算リソースの乱用を示す一方、IAMアクティビティは認証情報の侵害や長期アクセスキーの不正使用、そしてクラウトサービスの不正使用の可能性を示唆しているからです。

AIインフラ保護のための重要な教訓

このインシデントの重大性は暗号通貨マイニングアクティビティそのものではなく、それが発生した場所にあります。侵害されたシステムはAmazon Bedrockサービスへのアクセス権を持つAIゲートウェイとして機能し、クラウドインフラ、アイデンティティ、そしてさまざまなAIオペレーションの交差する場所に位置していました。組織がAI機能を実運用環境に導入していくなかで、これらのプラットフォームは、露出したサービス、認証情報窃取、クラウドの設定ミスなどを通じて攻撃者がすでに狙っているアタックサーフェスの一部となりつつあるのです。

このケースでは詳細な侵入経路は特定されておらず、ワークロードの侵害と調査中に検知された疑わしいIAMアクティビティの間に決定的なつながりは確認されませんでしたが、これらのイベントは全体的な現状を裏付けています。つまり、AIインフラは個別のテクノロジースタックとして扱うのではなく、クラウド環境全体の一部として保護しなければならないとうことです。

このケースでは、最も目立った侵害の兆候は暗号通貨マイニングインフラとの通信でした。しかしここで得られたより重要な教訓は、このインシデントの全貌が理解される前にDarktraceのビヘイビア分析により明らかになった、高い権限を持つAI関連アセットを取り巻くリスクです。AIゲートウェイによりクラウド権限、モデルアクセス、アプリケーションワークフローがますます集約されるなかで、防御者は個別のアラートに集中するよりも、ワークロード、アイデンティティ、サービスの間でどのように動作がつながっているかを理解することに重点を置く必要があるでしょう。

協力:Angel Arribas Lopez (Associate Principal Cyber Analyst)、Nathaniel Jones (Field CISO/VP Threat Research)、Emma Foulger (Global Threat Ops)、Mark Turner(Security Researcher)

編集:Ryan Traill (Content Manager)

付録

Darktraceによるモデル検知結果

·       Compromise / High Priority Crypto Currency Mining

·       Compromise / Monero Mining

·       Device / Internet Facing Device with High Priority Alert

·       IaaS / Unusual Activity / Unusual AWS CLI Activity

·       IaaS / Admin / New AWS User Account Creation

MITRE ATT&CK マッピング

初期アクセス – 外部リモートサービス – T1133

初期アクセス – 有効なアカウント – T1078

実行 – コマンドおよびスクリプトインタプリタ – T1059

永続化 – アカウント作成 – T1136

探索 – クラウドサービス探索 – T1526

影響 – リソースハイジャッキング– T1496

参考資料

[1] https://docs.litellm.ai/blog/security-update-march-2026

[2] https://www.abuseipdb.com/check/145.241.123.102

[3] https://urlscan.io/search/#185.62.1.8

[4] https://www.virustotal.com/gui/file/85de36ff66fae9f4b059cbedf6d36e017ebc26c828f99f911a96e78636f21200/community

Continue reading
About the author
Angel Arribas Lopez
Associate Principal Cyber Analyst
あなたのデータ × DarktraceのAI
唯一無二のDarktrace AIで、ネットワークセキュリティを次の次元へ