Trusted Design

Regin

概要

Regin is a multi-purpose data collection tool which dates back several years. Symantec first began looking into this threat in the fall of 2013. Multiple versions of Regin were found in the wild, targeting several corporations, institutions, academics, and individuals. Regin has a wide range of standard capabilities, particularly around monitoring targets and stealing data. It also has the ability to load custom features tailored to individual targets. Some of Regin’s custom payloads point to a high level of specialist knowledge in particular sectors, such as telecoms infrastructure software, on the part of the developers.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Sandworm Team

Score: 5.69
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
MITREへのリンク →

Patchwork

Score: 13.44
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1665 - Hide Infrastructure
  • T1008 - Fallback Channels
MITREへのリンク →

APT42

Score: 7.32
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

BRONZE BUTLER

Score: 9.47
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1199 - Trusted Relationship
  • T1578.001 - Create Snapshot
  • T1008 - Fallback Channels
MITREへのリンク →

TA551

Score: 5.49
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Lazarus Group

Score: 18.62
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1665 - Hide Infrastructure
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Tropic Trooper

Score: 7.48
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1506 - Web Session Cookie
  • T1665 - Hide Infrastructure
MITREへのリンク →

MuddyWater

Score: 5.49
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

APT19

Score: 8.17
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

APT33

Score: 6.34
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT28

Score: 9.11
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1199 - Trusted Relationship
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 9.60
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

Kimsuky

Score: 24.77
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1570 - Lateral Tool Transfer
  • T1506 - Web Session Cookie
  • T1526 - Cloud Service Discovery
  • T1126 - Network Share Connection Removal
  • T1665 - Hide Infrastructure
  • T1008 - Fallback Channels
MITREへのリンク →

Moonstone Sleet

Score: 8.46
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1126 - Network Share Connection Removal
  • T1547.008 - LSASS Driver
MITREへのリンク →

Indrik Spider

Score: 6.16
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.009 - Cloud API
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Contagious Interview

Score: 12.06
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1126 - Network Share Connection Removal
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

OilRig

Score: 19.97
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1592.002 - Software
  • T1570 - Lateral Tool Transfer
  • T1526 - Cloud Service Discovery
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

UNC3886

Score: 4.69
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1578.001 - Create Snapshot
MITREへのリンク →

LuminousMoth

Score: 4.77
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
MITREへのリンク →

Salt Typhoon

Score: 10.23
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1608.002 - Upload Tool
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

Play

Score: 4.84
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

RedCurl

Score: 6.23
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1608.004 - Drive-by Target
MITREへのリンク →

Turla

Score: 11.50
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1506 - Web Session Cookie
  • T1578.001 - Create Snapshot
MITREへのリンク →

Mustang Panda

Score: 8.84
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1526 - Cloud Service Discovery
  • T1556 - Modify Authentication Process
MITREへのリンク →

TeamTNT

Score: 6.83
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1506 - Web Session Cookie
  • T1665 - Hide Infrastructure
MITREへのリンク →

FIN7

Score: 5.54
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT32

Score: 14.54
Matched TTPs:
  • T1608.004 - Drive-by Target
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1570 - Lateral Tool Transfer
  • T1556 - Modify Authentication Process
MITREへのリンク →

Wizard Spider

Score: 15.01
Matched TTPs:
  • T1038 - DLL Search Order Hijacking
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1526 - Cloud Service Discovery
  • T1556 - Modify Authentication Process
MITREへのリンク →

Medusa Group

Score: 8.71
Matched TTPs:
  • T1218.003 - CMSTP
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

Threat Group-3390

Score: 12.20
Matched TTPs:
  • T1218.003 - CMSTP
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1526 - Cloud Service Discovery
MITREへのリンク →

APT38

Score: 4.58
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

BlackByte

Score: 5.96
Matched TTPs:
  • T1059.009 - Cloud API
  • T1570 - Lateral Tool Transfer
  • T1506 - Web Session Cookie
MITREへのリンク →

Lotus Blossom

Score: 4.91
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Gamaredon Group

Score: 6.81
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1506 - Web Session Cookie
MITREへのリンク →

Aquatic Panda

Score: 4.58
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

Blue Mockingbird

Score: 5.43
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Volt Typhoon

Score: 10.34
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1665 - Hide Infrastructure
  • T1578.001 - Create Snapshot
MITREへのリンク →

Dragonfly

Score: 4.91
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

APT41

Score: 8.20
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1008 - Fallback Channels
MITREへのリンク →

Magic Hound

Score: 5.20
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN8

Score: 10.48
Matched TTPs:
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1526 - Cloud Service Discovery
  • T1556 - Modify Authentication Process
MITREへのリンク →

Inception

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

BlackTech

Score: 4.00
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1526 - Cloud Service Discovery
MITREへのリンク →

Storm-1811

Score: 3.37
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT39

Score: 3.08
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

FIN6

Score: 6.12
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

WIRTE

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Cobalt Group

Score: 5.49
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1506 - Web Session Cookie
MITREへのリンク →

Thrip

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

Chimera

Score: 8.51
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1665 - Hide Infrastructure
  • T1578.001 - Create Snapshot
MITREへのリンク →

Storm-0501

Score: 4.65
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1506 - Web Session Cookie
MITREへのリンク →

ZIRCONIUM

Score: 4.83
Matched TTPs:
  • T1570 - Lateral Tool Transfer
  • T1578.001 - Create Snapshot
MITREへのリンク →

Darkhotel

Score: 4.49
Matched TTPs:
  • T1506 - Web Session Cookie
  • T1578.001 - Create Snapshot
MITREへのリンク →

Sidewinder

Score: 4.49
Matched TTPs:
  • T1506 - Web Session Cookie
  • T1578.001 - Create Snapshot
MITREへのリンク →

Windshift

Score: 4.42
Matched TTPs:
  • T1506 - Web Session Cookie
  • T1547.008 - LSASS Driver
MITREへのリンク →

The White Company

Score: 4.49
Matched TTPs:
  • T1506 - Web Session Cookie
  • T1578.001 - Create Snapshot
MITREへのリンク →

ToddyCat

Score: 7.26
Matched TTPs:
  • T1506 - Web Session Cookie
  • T1665 - Hide Infrastructure
  • T1547.008 - LSASS Driver
MITREへのリンク →

Rocke

Score: 5.18
Matched TTPs:
  • T1506 - Web Session Cookie
  • T1008 - Fallback Channels
MITREへのリンク →

Higaisa

Score: 5.43
Matched TTPs:
  • T1665 - Hide Infrastructure
  • T1578.001 - Create Snapshot
MITREへのリンク →

CURIUM

Score: 5.12
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1008 - Fallback Channels
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.78
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1008 - Fallback Channels
  • T1570 - Lateral Tool Transfer
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1027.014 - Polymorphic Code
  • T1126 - Network Share Connection Removal
  • T1059.009 - Cloud API
  • T1526 - Cloud Service Discovery
  • T1665 - Hide Infrastructure
MITREへのリンク →

OilRig

Score: 0.65
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1570 - Lateral Tool Transfer
  • T1199 - Trusted Relationship
  • T1592.002 - Software
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
  • T1059.009 - Cloud API
  • T1526 - Cloud Service Discovery
MITREへのリンク →

Lazarus Group

Score: 0.63
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1570 - Lateral Tool Transfer
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
  • T1161 - LC_LOAD_DYLIB Addition
  • T1665 - Hide Infrastructure
  • T1578.001 - Create Snapshot
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る