ブログ
/
Cloud
/
November 19, 2025

生成AIの保護: Darktrace / CLOUDでAmazon Bedrockのリスクを管理する

Amazon Bedrockのような生成AIサービスは、アクセス、可視性、データ露出に関連した新たなリスクをもたらしつつあります。 本稿では、Darktrace / CLOUDがBedrockおよびSageMaker環境において、コンフィギュレーションに対する深い可視性、権限の分析、設定ミスの検知、挙動の異常の検知により、これらのインシデントを防ぐのにどう役立つかを解説します。
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Adam Stevens
Senior Director of Product
Default blog image
19
Nov 2025

企業内生成AIのセキュリティリスクと課題

生成AIとAmazon Bedrockのようなマネージド型基盤モデルプラットフォームは、組織がインテリジェントなアプリケーションを構築し、展開する方法を大きく変化させています。チャットボットから要約ツールまで、Bedrockは基盤モデルを企業のデータとサービスに接続することにより、迅速なエージェント開発を可能にします。しかしこの柔軟性にはさまざまなセキュリティ課題が伴い、特に可視性、アクセス管理、そして意図しないデータ露出に関連したリスクがあります。

組織が生成AIの業務への導入を急ぐ中で、従来型のセキュリティコントロールは対応に遅れが目立ちます。Bedrockのエージェント、モデル、ガードレール、そしてベースとなるAWSサービスからなる多層的アーキテクチャは、標準的なポスチャ管理ツールでは想定されていなかった新たなブラインドスポットを作り出しています。可視性のギャップにより、エージェントがどのデータセットにアクセスできるのか、あるいはモデルの出力が機密性の高い情報を露出させる可能性がないかを知ることが難しくなります。その一方で、開発者はセキュリティチームがIAM権限を確認したり、ガードレールを検証したりできるよりも速いペースで進むことが多く、リスクの拡大につながる設定のミスが起こりがちです。AWSのような共有責任モデルにおいては、この複雑性によってオーナーシップの境界があいまいになる可能性があり、セキュリティチームにとってAIシステムが組織のデータとどのように相互動作しているかについて、情報を継続的かつ自動的に得られることがきわめて重要になります。

Darktrace / CLOUDはBedrock環境に対して包括的な可視性およびポスチャ管理を提供し、エージェントとナレッジベースを自動的に検知し積極的にスキャンすることにより、テクノロジーの拡大とイノベーションのペースを落とすことなく、AIインフラの保護に貢献します。

現実のシナリオ:行き過ぎたアクセス

たとえば、会社のナレッジベースを使用しビジネス上の質問にスタッフがすばやく回答できるようにするためのBedrockエージェントを展開しているとします。エージェントはAmazon S3に格納されている文書を参照するナレッジベースに接続され、APIを介して社内のサービスへのアクセス権を与えられています。

システムを早期に稼働させようと、開発者はエージェントに幅広い実行権限を持つロールを割り当てました。このロールは複数のS3バケットに対するアクセス権を付与されており、バケットの1つには機密性の顧客情報が含まれていました。この過剰な権限付与は悪意によるものではありませんでした。IAMポリシー作成の複雑性と、どのバケットに機密性の高いデータが含まれているかを特定するのが難しかったことが原因です。

チームはエージェントが意図した文書だけを使用すると思っていました。しかし、従業員がどのようにエージェントとやりとりするか、あるいはエージェントがどのようにデータを処理する可能性があるかについては十分に検討がされませんでした。  

ある従業員が顧客の四半期のアクティビティについていつものように質問をしたところ、エージェントは規制対象データを含む情報を出力し、適切なアクセス権を持たない人に開示してしまいました。

これはプロンプトインジェクションやモデルの不正操作が行われたケースではありません。エージェントは単に指示に従い、アクセスを許可されているリソースを使用したにすぎません。この開示はIAMポリシーに適合していましたが、まったく意図とは異なる結果となりました。

Darktrace / CLOUDによってこれらのリスクがどう防止されるか

Darktrace / CLOUDはBedrockおよびSageMaker環境に対して多層的な可視性とインテリジェントな分析能力を提供することで、意図しないデータ露出のようなシナリオを回避することができます。それぞれの機能は次のように使用されます:

コンフィギュレーションレベルの可視性

Bedrock環境にはしばしば複数のコンポーネント、たとえばエージェント、ガードレール、基盤モデルが含まれ、それぞれがコンフィギュレーションを持っています。Darktrace / CLOUDはこれらのコンフィギュレーションをインデックス化し、チームは次が可能になります:

  1. 展開されたエージェントを検査しそれらが承認されたデータソースにのみ接続されていることを確認する。
  2. 評価ジョブのセットアップおよびそれらのAmazon S3データセットへのリンクを追跡し、機密性の高い情報を露出させる可能性のある隠れたデータフローを明らかにする。
  3. すべてのAIコンポーネントに対する認識を維持し、見落としたアセットからリスクが発生する可能性を縮小する。

Bedrock、SageMakerおよびその他のAWSサービス全体のコンフィギュレーションデータを一元的に管理することでDarktrace / CLOUDはAIアセットの可視性に対する信頼できる唯一の情報源を提供します。チームは各コンポーネントがどのように設定されているか、および社内のセキュリティポリシーに合致しているかどうかを即座に確認することができます。これにより当て推量を排除し、監査を加速し、設定の不整合がデータ露出リスクを生むのを防止することができます。

 Agents for bedrock relationship views.
図1:Bedrockとエージェントの関係

アーキテクチャの認識

複雑なAI環境ではコンポーネント間の相互動作を理解するのが難しいことがあります。Darktrace / CLOUDはリアルタイムのアーキテクチャダイアグラムを作成することにより:

  1. エージェント、モデル、データセット間の関係を可視化します。  
  1. 相互接続されたサービス間の意図しないデータアクセス経路やリスクの伝播を特定します。

これにより、セキュリティチームは脆弱さが露出につながる前にそれらを発見することができます。これらの関係を動的に可視化することにより、Darktrace / CLOUDはプロアクティブなリスク管理を可能にし、アーキテクチャのドリフト、冗長なデータ接続、あるいは監視されていないエージェントを、攻撃者が悪用したり偶発的な誤使用が起こる前に発見することができます。これにより調査にかかる時間を短縮するとともに、AIワークロード全体のコンプライアンスへの自信を高めることができます。

Figure 2: Full Bedrock agent architecture including lambda and IAM permission mapping
図2:lambdaおよびIAM権限マッピングを含むBedrockエージェントアーキテクチャ全体図

アクセスおよび権限の分析

IAM権限はBedrockを含むあらゆるAWSサービスに適用されます。Bedrockエージェントが他のワークロードに対して広範に定義されたIAMロールを引き受けるとき、しばしば過剰な権限を継承します。最小権限のコントロールを厳密に行っていなければ、エージェントは必要なものよりも格段に多くのデータやサービスにアクセスできる可能性があり、防げるはずだったセキュリティ露出を作り出してしまいます。Darktrace / CLOUDは:

  1. 実行ロールおよびユーザー権限をレビューして過剰な権限を特定します。
  2. 権限昇格や承認されていないAPIアクションを可能にする可能性のある異常ににフラグを立てます。

これによりエージェントが最小権限の原則の枠内で運用されるようにし、アタックサーフェスを縮小することができます。リスクの高いロールを特定することに加えて、Darktrace / CLOUDは通常のアクセスのパターンを継続的に学習し、権限が悪用されたり、拡大されたりした場合にリアルタイムに識別することができます。セキュリティチームは、アクションがなぜ異常なのか、およびそれが接続されているアセットにどう影響する可能性があるのかについてのコンテキストを理解し、推奨された具体的な対策を取ることにより、生産性を維持しつつ露出を最小化することができます。

設定のミスの検知

設定ミスはクラウドセキュリティインシデントの主要な原因の1つです。Darktrace / CLOUDは以下を自動的に検知します:

  1. 機密性の高いトレーニングデータが含まれているかもしれない、公開アクセス可能なS3バケット
  2. 不適切なまたは機密情報を含む出力を許可する可能性のある、Bedrock環境のガードレール不足  
  3. 暗号化の欠如、直接インターネットアクセス、モデルへのrootアクセスなどその他の問題  

これらのリスクを早期に明らかにすることにより、チームはこれらが悪用可能になる前に修正を行うことができます。Darktrace / CLOUDは人手で行っていたレビューのプロセスを、自動化された、継続的なチェックに変え、発見までの時間を短縮するとともに、小さな見落としが大規模なインシデントにエスカレートするのを防止することができます。このような自動的な確認により、組織はAIシステムのコンプライアンスを維持し、安全を組み込んだ設計を維持しつつ、自信を持ってイノベーションを進めることができます。

Configuration data for Anthropic foundation model
 図3:Anthropic基盤モデルのコンフィギュレーションデータ

ビヘイビアベースの異常検知

コンフィギュレーションが正しい場合にも、その動作が脅威の発生の兆候を示すことがあります。AWS CloudTrailを使用して、Darktrace / CLOUDは:

  1. エージェントが予期しないデータセットをクエリーしているなど、通常と異なるデータアクセスのパターンを監視します。
  2. モデル汚染攻撃の試みかもしれない異常なトレーニングジョブの起動を検知します。

こうしたリアルタイムのビヘイビア分析により、組織は疑わしいアクティビティにすばやく対応することができます。それぞれのBedrockコンポーネントの"正常な”動作を継続的に学習することにより、Darktrace / CLOUDは正式な侵害インジケーターが発生する前に、脅威を示すものかもしれない微妙な変化を検知することができます。その結果、より早期の検知、調査の工数の削減、そしてAI駆動のワークロードが意図通りに機能することを継続的に保証することができます。

まとめ

生成AIはビジネスを変革するさまざまな機能を提供しますが、イノベーションと共に変化しつづける複雑なリスクも伴います。Amazon Bedrockのようなサービスの柔軟性は新たな効率化や理解を可能にしますが、正しい利用であっても意図せずに機密性の高いデータを露出させたり、セキュリティコントロールをすり抜けてしまう場合があります。多くの組織がAIの大規模な導入を進めるなかで、開発を遅らせることなくこれらの環境を包括的に監視し保護する能力はきわめて重要になってきます。

コンフィギュレーションに対する深い可視性、アーキテクチャの理解、権限と動作の分析、そしてリアルタイムの脅威検知を組み合わせることにより、DarktraceはBedrockやSageMaker等のAIツールに対する継続的な保証をセキュリティチームに提供します。組織は適応型のインテリジェントな保護によりAIシステムが管理されているという安心感を持ってイノベーションを続けることができます。

[related-resource]

企業内のAIを防御する方法についてさらに知る

組織を新たなアタックサーフェスに露出させることなく、AIによるイノベーションを安全に実現するための方法とは?ホワイトペーパーをお読みになり、AIが原因となる各種リスクを見つけ出す方法をご確認ください。

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Adam Stevens
Senior Director of Product

More in this series

No items found.

Blog

/

AI

/

August 26, 2026

AI Agents: Securing the Path from Intent to Action

Default blog imageDefault blog image

The UK’s National Cyber Security Centre (NCSC) recently published guidance on managing the cyber risk of agentic AI. While the document is framed as interim advice as more formal guidance is developed, the framing reflects the current state of the industry: organizations are already deploying agents into production environments while standards, controls, and operating models for autonomous systems remain unsettled. Governance is evolving alongside adoption rather than preceding it, a reality which underscores the importance of robust controls.  

The NCSC’s guidance recommends aligning controls to an agent's level of autonomy, assigning distinct identities, limiting permissions, constraining access to systems and data, monitoring activity, maintaining human oversight, and preserving the ability to intervene when necessary. Most of these recommendations will sound familiar to security teams. The challenge is not the novelty of the controls. It is the type of system those controls now need to govern.

The shift from model security to agent security

For several years, AI security discussions have focused heavily on models. Can a model be manipulated? Jailbroken? Trusted? Can it expose information it should not? Those questions remain important, but they capture only part of the problem. A model generating text is one thing. A system connected to identities, applications, tools, workflows, and business data is another.

The difference becomes clearer when comparing a chatbot that answers questions with an agent that can retrieve customer records, update tickets, invoke tools, trigger workflows, and interact with external systems. The underlying model may be identical. Its access is not. The security question begins to shift from what the model knows to what the system can do.

The same theme appears in the Five Eyes statement released earlier this year, describing AI as a force multiplier that is accelerating both offensive and defensive cyber operations. The NCSC guidance explores what that reality looks like when autonomous systems begin operating inside enterprise environments.

Securing AI agents in operation

The NCSC spends relatively little time debating model behavior and considerably more time discussing identity, permissions, monitoring, oversight, containment, and response. Agents are treated as participants within an environment rather than isolated pieces of technology.  

That's broadly consistent with how we think about the problem at Darktrace.

An agent should not be treated as an extension of a user account. It develops its own behavioral patterns. It accesses systems, interacts with data, invokes tools, and moves across workflows in ways that can be observed independently. Understanding what an agent is permitted to do matters. Understanding how it actually behaves once deployed, and whether that behavior aligns with business intent, matters just as much.

Identity provides an obvious example. The NCSC recommends assigning distinct identities to agents rather than allowing them to disappear into surrounding human or service accounts. Most importantly, assigning agents distinct identities enables independent behavioral monitoring.

Development assumptions vs. real-world behavior

The same principle extends to monitoring. NCSC guidance places agent activity within normal security operations rather than treating it as a separate AI governance function. Many of the controls described are put in place before an agent begins operating. Sandboxing, credential design, approval workflows and human oversight all reflect judgments about how the system is expected to behave and what risks it is likely to create.

Actual use may challenge those assumptions. Access patterns change. Workflows expand. Systems begin interacting with resources they have never touched before. Processes that appeared reasonable during design behave differently in production. Human oversight requirements may turn out to be either excessive or inadequate once the system is operating at scale and operating within the context of unique business processes.

The Five Eyes statement points to a similar issue: organizations need confidence that controls continue to work as intended once systems are exposed to real users, data, tools and operational pressures. Often, the question is not whether an agent is technically allowed to perform an action, but whether its behavior remains consistent with the role it was intended to play.

Monitoring and governance of AI agents go hand-in-hand

This problem is exactly why monitoring and governance should be treated as part of the same process. Governance sets the initial parameters for deployment, while monitoring provides evidence about whether those parameters remain appropriate. That evidence should, in turn, inform changes to permissions, controls and oversight.

This matters increasingly as autonomous systems are integrated into business processes. The relevant risk is shaped not only by the model or agent itself, but by what it can access, what actions it can take, and how its behavior changes in practice.

Developing continuous oversight of AI agent behavior

The implication is clear: governance cannot end at deployment. Organizations need a way to understand how agents behave after deployment, test whether controls remain appropriate, and adjust them as conditions change. That requires visibility not just into technical activity, but into whether that activity makes sense in the context of the business process the agent is intended to support.

This is where business-centric behavioral security can become critical. Risk does not emerge from the model itself: it emerges from the actions an autonomous system takes within the enterprise and the downstream consequences of those actions.  

An agent can operate exactly as intended and still create risk if it accesses sensitive information in an unexpected context, exercises permissions in ways that create unintended exposure, or influences business processes in ways that were not anticipated during design and review.

Traditional governance vs. behavioral security

Traditional governance frameworks provide assurance at a point in time. Behavioral security can provide ongoing visibility into how autonomous systems interact with the organization they are meant to serve. Rather than focusing exclusively on model performance or policy compliance, organizations need to understand whether an agent's behavior aligns with business intent, operational expectations, and acceptable risk tolerances as conditions change.

As enterprises move from isolated AI deployments to interconnected ecosystems of agents, visibility into behavior becomes as important as visibility into code. Governance determines what an autonomous system is permitted to do. Behavioral analytics helps determine what it is doing, what business outcomes it is producing, and whether those outcomes remain aligned with the organization's objectives.

[related-resource]

Continue reading
About the author
Margaret Cunningham, PhD
VP, Security & AI Strategy, Field CISO

Blog

/

AI

/

August 26, 2026

When AI Becomes the Lure: A Fake Gemini Installer Delivers Vidar

Default blog imageDefault blog image

Key takeaways

  • Darktrace observed a customer download a fake Google Gemini installer hosted on Google Colab, resulting in the execution of the Vidar information stealer.
  • Darktrace identified the compromise through behavioral indicators, including suspicious process activity, anomalous network communications, and indicators of credential theft, before autonomously containing the threat.
  • The incident highlights how threat actors are increasingly exploiting trusted platforms and a growing interest in AI tools to distribute malware through seemingly legitimate software acquisition workflows.

The Growing Abuse of Generative AI

As organizations are increasingly adopting generative AI tools into their daily workflows, attackers are adapting their distribution methods accordingly too. As part of their day-to-day work, users are now searching for AI assistants, programming tools, browser extensions, desktop applications, and productivity integrations.

Recent reports have highlighted campaigns that use fake AI software and AI-related installers to distribute malware and steal credentials [1]. Researchers have documented campaigns that exploit fake AI-themed websites and services to distribute information stealers and backdoors [2]. Security researchers have also observed attackers disguising malware as legitimate installers for AI software to increase the likelihood of victim interaction and execution [3].

In July 2026, Darktrace observed one such case within a customer environment in the Europe, Middle East and Africa (EMEA) region, where attackers used a fake generative AI installer to deliver the prolific information stealer Vidar. This incident highlights how threat actors are exploiting interest in AI services to distribute established malware using increasingly convincing social engineering techniques.

How a Fake Gemini Installer Delivered Vidar

Initial Access: From Search Result to Malware Download

Unlike many malware campaigns that begin with a phishing email, this activity appears to have originated from a user searching for and downloading software.

Darktrace first observed unusual activity on the customer network after a suspicious executable file was launched from a user’s Download folder. Further investigation revealed that the file purported to be a Google Gemini installer and was named “Download_Google_Gemini_For_Windows.exe”.

During the initial analysis, it was noted that the top search result for the suspicious filename associated pointed to a file hosted on Google Colab, a cloud-based Jupyter notebook platform, commonly used by developers, researchers, and data scientists to run code and machine learning workloads through a web browser. By leveraging another trusted Google platform, the attacker increased the likelihood that users would perceive the download as legitimate, making the lure more convincing to those searching for Gemini-related software.

Figure 1: The Google Colab page containing a download prompt for the fake Google Gemini installer.

Further investigation of the Google Colab page revealed that the download prompt redirected users to a secondary site, hxxps://micronsoftwares[.]com, which posed as a "Windows Software Hub" download page and offered the fake Gemini installer for download.

Figure 2: The secondary website posing as a "Windows Software Hub" download page, which likely hosted the fake Gemini installer.

While the investigation did not uncover any HTTP or file-download telemetry data that conclusively identified the download source, SSL communication sessions with Google Colab were detected immediately before the suspicious file was executed. The timing of these connections suggests that the user interacted with the Colab resource before being redirected to the secondary site from which the executable was downloaded.

The user was not simply tricked into opening an email attachment; instead, the attacker embedded malicious content into a process many users would consider entirely legitimate: searching for and downloading software associated with a trusted platform.

Weaponizing Trusted Platforms

At the time of review (July 15, 2026), Darktrace's Threat Research team confirmed that the Google Colab page was still active and prompting users to download a ZIP archive containing the binary file.

The archive also appeared to contain a README file instructing users to run the binary file with administrator privileges and add it to their antivirus software’s exception lists. These instructions suggest that the campaign relied heavily on social engineering, convincing users to take actions that would facilitate malware execution and potentially bypass security checks.

The use of a legitimate platform also complicates the user’s decision-making. Downloads associated with a trusted service are often perceived as less suspicious than those hosted on unfamiliar domains. When combined with the branding of a widely used AI tool, the lure becomes even more convincing.

Malware Analysis

Darktrace’s Threat Research team identified the executable file as the information-stealing malware Vidar. Analysis revealed that the binary file was a newer Go-compiled variant that communicated with Telegram-based infrastructure. Darktrace’s researchers also identified dtm[.]kijangturbo88[.]top as a command-and-control (C2) endpoint associated with the activity. While the malware itself was not novel, the lure and delivery mechanism was.

For a deeper look at the information stealer, see Darktrace’s 2023 analysis of Vidar.

Figure 3: Darktrace’s detection of the unusual outbound connection associated with the fake Gemini installer.

Shortly after execution, the process established communications with the external IP address 91.98.98[.]86 via port 443, directly linking the executable to suspicious network activity observed on the device. Subsequent open-source intelligence (OSINT) analysis of the revealed multiple malicious associations [5].

Additional Darktrace detections included unusual SSL activity from the affected device. Analysis of related SSL telemetry identified 91.98.111[.]49 as additional infrastructure associated  with the activity [6].

Subsequent alerts from the customer's Microsoft Defender for Endpoint integration later confirmed activity consistent with the theft of browser credentials and other sensitive data from the affected endpoint.

Taken together, these detections provided a clear picture of the attack, from the execution of a suspicious file and unusual network connections to indicators of C2 activity and credential theft.

Figure 4: Darktrace’s detection of anomalous activity following the execution of the fake Gemini installer, seen in the Model Alert Event Log.

Darktrace's Autonomous Response

Following the detection, Darktrace’s Autonomous Response took immediate containment action, including blocking communication with suspicious external infrastructure, including 91.98.98[.]86, and quarantining the compromised device.

Despite the apparent legitimacy of the activity, with the installer hosted on a trusted platform and resembling a routine software download, Darktrace was able to detect and contain the attack because the device's behavior deviated from its normal pattern.

Figure 5: Automated containment actions implemented by Darktrace's Autonomous Response following the detection of activity associated with the fake Gemini installer.

Conclusion

This investigation highlights how threat actors continue to adapt established malware delivery techniques to emerging technology trends. While the malware itself was not new, the distribution method was. By disguising Vidar as a Google Gemini installer and hosting the malicious content on a trusted platform, the attack aligned its lure with a growing behavioral trend: users actively searching for AI tools and services as part of their day-to-day work.

Although fake installers are not a new phenomenon, the rapid rise of generative AI has created new opportunities for threat actors. Rather than relying solely on traditional delivery methods, attackers can now target users who are actively searching for AI applications. As AI adoption continues to accelerate across enterprise environments, organizations should remain alert to campaigns that exploit this interest through fake applications, malicious websites, manipulated search results, the misuse of trusted platforms, and AI-themed social engineering.

Credit to Rushanth Ramanathan (Cyber Analyst) Joanna Ng (Detection Engineer)

Edited by Ryan Traill (Content Manager)

Appendices

Darktrace Model Detections

  • Security Integration / C2 Activity and Integration Detection
  • Endpoint / New Suspicious Executable Launched
  • Endpoint / Process Connection / Unusual Connection from New Process
  • Anomalous Connection / Rare External SSL Self-Signed
  • Security Integration / High Severity Integration Detection
  • Antigena / Network / Significant Anomaly /  Antigena Significant Security Integration and Network Activity Block

•Antigena / Network / Significant Anomaly /  Antigena Significant Anomaly from Client Block

List of Indicators of Compromise (IoCs)

IoC Type Description
Download_Google_Gemini_For_Windows.exe File Fake Gemini-themed installer observed during the investigation.
GoogleAppInstaller.exe File Related executable identified through endpoint telemetry.
91.98.98[.]86 IP Address External destination contacted by the malicious executable.
91.98.111[.]49 IP Address Related infrastructure identified through SSL certificate pivoting.
dtm[.]kijangturbo88[.]top Domain Command-and-control endpoint identified during malware analysis.
1e13c2c9eac72daf63fd00a9946878949e159ae6ec51b54ec64f942d79d61913 SHA256 Malware sample associated with the fake Gemini installer.

MITRE ATT@CK Mapping


MITRE ATT&CK Mapping Tactic Technique
Initial Access T1204 User Execution
Execution T1204.002 User Execution: Malicious File
Defence Evasion T1036 Masquerading
Credential Access T1555 Credentials from Password Stores
Credential Access T1555.003 Credentials from Web Browsers
Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel
Continue reading
About the author
Rushanth Ramanathan
Cyber Analyst
あなたのデータ × DarktraceのAI
唯一無二のDarktrace AIで、ネットワークセキュリティを次の次元へ