インフォスティーラーが21億件の認証情報を窃取、2300万ホストに感染

サイバー犯罪が急増し、2025年初頭には認証情報の窃取が33%増加、2億件の認証情報が盗まれた。組織を取り巻く脅威環境の深刻さが浮き彫りになっている。

Written By
Sunny Yadav
Sunny Yadav
Mar 20, 2025
1 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

サイバー犯罪活動は前例のない水準に達している。2024年にはマルウェアを駆使した攻撃が劇的に増加し、組織はデータの保護に奔走することとなった。

Flashpointの最新レポートは、インフォスティーラー、認証情報の窃取、深刻化する脆弱性によって形作られた脅威環境の厳しい実態を描き、こうした執拗な攻撃者への防御を強化するよう組織に促している。

インフォスティーラー:高まるサイバー脅威

インフォスティーラーは、低コストで導入も容易なことから、サイバー犯罪者に好まれるツールとなっている。昨年は2300万台のホストに感染し、そのうち1つの系統であるRedlineが、約990万台のデバイスを侵害して43%を占めた。

この急増により21億件の認証情報が窃取され、2024年に盗まれた認証情報32億件の約75%に相当した。Flashpoint 2025 Global Threat Intelligence Reportはさらに、こうした単純ながら効果的なツールが、アカウント乗っ取りとそれに続くランサムウェア展開の主要な手段となっていると指摘し、脅威が広範に及び、急速に進化していることを強調している。

認証情報の窃取とマルウェアの手口

レポートは、侵害された認証情報が前年比で33%という驚異的な増加を示したことを明らかにし、サイバー犯罪者が手口を洗練させている実態を浮き彫りにしている。2025年最初の2カ月ですでに2億件を超える認証情報が盗まれており、攻撃者は収集したデータを利用して企業ネットワークに侵入し、セキュリティ制御を回避して活動範囲を広げている。

アンダーグラウンドマーケットプレースでは、こうしたツールに月額約200ドルで簡単にアクセスできるため、スキルの低い脅威アクターでさえ大規模なキャンペーンを実行し、甚大な被害をもたらせる。

脆弱性の悪用とランサムウェアの動向

インフォスティーラーに加え、脅威環境では、悪用可能な脆弱性の大幅な増加によって状況がさらに悪化している。Flashpointのレポートによると、2024年には3万7000件を超える脆弱性が確認され、その39%超には公開されたエクスプロイトコードが伴っていた。

防御が弱体化したこの環境は、ランサムウェア攻撃の10%増加と、全業種におけるデータ侵害の6%増加を招いている。こうした動向は、攻撃者が手口を多様化し、組織のデジタルインフラにおける最も脆弱な箇所を狙っていることを示している。

組織にとっての意味

組織にとって、これらの憂慮すべき動向は行動を起こすよう促す警鐘だ。インフォスティーラーによる認証情報の窃取、広範な脆弱性の悪用、ランサムウェア被害の増加が相まって、先を見据えた包括的なセキュリティ戦略が求められている。

企業は高度な脅威インテリジェンス、継続的な脆弱性評価、強固なインシデント対応フレームワークを導入して重要資産を保護しなければならない。常に情報を収集し警戒を怠らなければ、組織は高度化するサイバー脅威の時代にリスクを軽減し、レジリエンスを確保できる。

いくつかの主要な脆弱性管理ツールを活用してネットワークやクラウド環境のセキュリティ上の欠陥を見つけ、ハッカーに悪用される前に修正できるようにしましょう。

Sunny Yadav

Sunny Yadav

Content Writer

Sunny is a content writer for eSecurity Planet (eSP) with a bachelor’s degree in technology and experience writing for leading cybersecurity brands like Panda Security, Upwind, and Vanta. At eSP, he covers the latest news on cyberattacks, cryptography, data protection, and emerging threats and vulnerabilities. He also explores security policies, governance, and endpoint and mobile security. Sunny enjoys hands-on testing, rigorously evaluating tools to assess their capabilities and real-world performance. He also has extensive experience working with AI tools like ChatGPT and Gemini, experimenting with their applications in cybersecurity, content creation, and research.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.