Trusted Design

Fidelis Threat Advisory #1017: Phishing in Plain Sight

概要

Fidelis Cybersecurity analysis has identified unrelated cyber criminal activity leveraging the vulnerability cited in CVE-2014-4114, which was initially exploited by advanced persistent threat (APT) actors in October 2014. Notably, some of this recent activity demonstrated actors implementing a technique that bypassed antivirus detection by saving a PowerPoint document in which malware executed once the document was opened in Slide Show presentation format. The identification of cyber crime actors, particularly Nigerian 419 scam operators, attempting to exploit CVE-2014-4114 demonstrates how quickly cyber criminals are trying to exploit a vulnerability previously associated with espionage actors, using similar tactics, techniques, and procedures (TTP) to maximize their chances of success, with additional innovation as seen with these samples.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

LAPSUS$

Score: 20.02
Matched TTPs:
  • T1216.001 - PubPrn
  • T1019 - System Firmware
  • T1193 - Spearphishing Attachment
  • T1199 - Trusted Relationship
  • T1030 - Data Transfer Size Limits
  • T1065 - Uncommonly Used Port
MITREへのリンク →

Contagious Interview

Score: 30.81
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1021.006 - Windows Remote Management
  • T1552.003 - Shell History
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1690 - Prevent Command History Logging
  • T1030 - Data Transfer Size Limits
  • T1221 - Template Injection
MITREへのリンク →

Ember Bear

Score: 17.67
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

Sandworm Team

Score: 44.59
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1114 - Email Collection
  • T1606.002 - SAML Tokens
  • T1484.002 - Trust Modification
  • T1686.003 - Windows Host Firewall
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1193 - Spearphishing Attachment
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
MITREへのリンク →

APT41

Score: 17.70
Matched TTPs:
  • T1539 - Steal Web Session Cookie
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1030 - Data Transfer Size Limits
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

TA551

Score: 4.13
Matched TTPs:
  • T1539 - Steal Web Session Cookie
MITREへのリンク →

Mustard Tempest

Score: 7.96
Matched TTPs:
  • T1682 - Query Public AI Services
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Silent Librarian

Score: 6.59
Matched TTPs:
  • T1114 - Email Collection
  • T1566.002 - Spearphishing Link
  • T1199 - Trusted Relationship
MITREへのリンク →

Kimsuky

Score: 50.98
Matched TTPs:
  • T1114 - Email Collection
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1152 - Launchctl
  • T1683.001 - Written Content
  • T1552.003 - Shell History
  • T1057 - Process Discovery
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1690 - Prevent Command History Logging
  • T1030 - Data Transfer Size Limits
  • T1506 - Web Session Cookie
  • T1197 - BITS Jobs
  • T1003.003 - NTDS
MITREへのリンク →

Volt Typhoon

Score: 35.19
Matched TTPs:
  • T1114 - Email Collection
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1164 - Re-opened Applications
  • T1057 - Process Discovery
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1584.002 - DNS Server
  • T1065 - Uncommonly Used Port
  • T1159 - Launch Agent
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

EXOTIC LILY

Score: 12.04
Matched TTPs:
  • T1114 - Email Collection
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1690 - Prevent Command History Logging
  • T1218.010 - Regsvr32
MITREへのリンク →

TA578

Score: 3.29
Matched TTPs:
  • T1114 - Email Collection
MITREへのリンク →

FIN13

Score: 6.94
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

Moonstone Sleet

Score: 13.25
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1057 - Process Discovery
  • T1197 - BITS Jobs
MITREへのリンク →

Lazarus Group

Score: 17.15
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1606.001 - Web Cookies
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
MITREへのリンク →

OilRig

Score: 11.70
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

UNC3886

Score: 13.32
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
  • T1547.015 - Login Items
  • T1218.010 - Regsvr32
MITREへのリンク →

LuminousMoth

Score: 6.36
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
MITREへのリンク →

Salt Typhoon

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

APT29

Score: 18.33
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1592.004 - Client Configurations
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Play

Score: 8.84
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

Aoqin Dragon

Score: 4.44
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 3.54
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Turla

Score: 6.29
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

Ke3chang

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Mustang Panda

Score: 25.02
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1102.003 - One-Way Communication
  • T1169 - Sudo
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1055.005 - Thread Local Storage
MITREへのリンク →

TeamTNT

Score: 8.56
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1562.004 - Disable or Modify System Firewall
  • T1506 - Web Session Cookie
MITREへのリンク →

FIN7

Score: 19.28
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1011.001 - Exfiltration Over Bluetooth
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1065 - Uncommonly Used Port
MITREへのリンク →

Leviathan

Score: 11.13
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1543.003 - Windows Service
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1218.010 - Regsvr32
MITREへのリンク →

Storm-0501

Score: 13.87
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1506 - Web Session Cookie
  • T1090.004 - Domain Fronting
MITREへのリンク →

BlackTech

Score: 5.26
Matched TTPs:
  • T1543.003 - Windows Service
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

MuddyWater

Score: 9.90
Matched TTPs:
  • T1543.003 - Windows Service
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
  • T1159 - Launch Agent
MITREへのリンク →

Confucius

Score: 6.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Sidewinder

Score: 13.67
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
  • T1159 - Launch Agent
MITREへのリンク →

FIN8

Score: 4.19
Matched TTPs:
  • T1543.003 - Windows Service
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

APT32

Score: 12.07
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1592.004 - Client Configurations
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

APT33

Score: 3.79
Matched TTPs:
  • T1543.003 - Windows Service
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

ZIRCONIUM

Score: 7.34
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1197 - BITS Jobs
MITREへのリンク →

Magic Hound

Score: 17.20
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1187 - Forced Authentication
  • T1098.002 - Additional Email Delegate Permissions
MITREへのリンク →

Windshift

Score: 6.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1506 - Web Session Cookie
  • T1159 - Launch Agent
MITREへのリンク →

Cobalt Group

Score: 5.69
Matched TTPs:
  • T1543.003 - Windows Service
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
MITREへのリンク →

TA2541

Score: 6.17
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

Earth Lusca

Score: 8.33
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
MITREへのリンク →

Storm-1811

Score: 9.87
Matched TTPs:
  • T1543.003 - Windows Service
  • T1199 - Trusted Relationship
  • T1486 - Data Encrypted for Impact
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

Wizard Spider

Score: 4.19
Matched TTPs:
  • T1543.003 - Windows Service
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

Patchwork

Score: 8.15
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
MITREへのリンク →

TA505

Score: 4.27
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
MITREへのリンク →

LazyScripter

Score: 3.42
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
MITREへのリンク →

APT42

Score: 9.20
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1030 - Data Transfer Size Limits
  • T1506 - Web Session Cookie
MITREへのリンク →

APT39

Score: 3.77
Matched TTPs:
  • T1543.003 - Windows Service
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Scattered Spider

Score: 20.57
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1019 - System Firmware
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1030 - Data Transfer Size Limits
  • T1197 - BITS Jobs
  • T1090.004 - Domain Fronting
MITREへのリンク →

APT28

Score: 27.00
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1152 - Launchctl
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1197 - BITS Jobs
  • T1200 - Hardware Additions
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Star Blizzard

Score: 12.19
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
MITREへのリンク →

Dragonfly

Score: 19.48
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1193 - Spearphishing Attachment
  • T1657 - Financial Theft
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Gamaredon Group

Score: 11.72
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1606.001 - Web Cookies
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1200 - Hardware Additions
MITREへのリンク →

Threat Group-3390

Score: 9.92
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

SideCopy

Score: 14.37
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
  • T1584.002 - DNS Server
  • T1506 - Web Session Cookie
  • T1159 - Launch Agent
MITREへのリンク →

BlackByte

Score: 9.19
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1606.001 - Web Cookies
  • T1506 - Web Session Cookie
MITREへのリンク →

BITTER

Score: 4.32
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

HEXANE

Score: 9.19
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1065 - Uncommonly Used Port
  • T1159 - Launch Agent
MITREへのリンク →

Saint Bear

Score: 6.50
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

Rocke

Score: 3.37
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1506 - Web Session Cookie
MITREへのリンク →

GOLD SOUTHFIELD

Score: 4.76
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Medusa Group

Score: 10.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

Sea Turtle

Score: 7.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1218.010 - Regsvr32
MITREへのリンク →

Cinnamon Tempest

Score: 4.84
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

ToddyCat

Score: 3.37
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1506 - Web Session Cookie
MITREへのリンク →

Winter Vivern

Score: 8.60
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1548 - Abuse Elevation Control Mechanism
MITREへのリンク →

Volatile Cedar

Score: 4.06
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
MITREへのリンク →

INC Ransom

Score: 8.13
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Axiom

Score: 6.25
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1218.010 - Regsvr32
MITREへのリンク →

HAFNIUM

Score: 6.01
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059 - Command and Scripting Interpreter
MITREへのリンク →

Aquatic Panda

Score: 5.34
Matched TTPs:
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
MITREへのリンク →

BRONZE BUTLER

Score: 8.93
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
MITREへのリンク →

Malteiro

Score: 4.42
Matched TTPs:
  • T1552.003 - Shell History
  • T1506 - Web Session Cookie
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1552.003 - Shell History
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

PROMETHIUM

Score: 4.13
Matched TTPs:
  • T1547.015 - Login Items
MITREへのリンク →

Inception

Score: 8.24
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1159 - Launch Agent
MITREへのリンク →

DarkHydrus

Score: 4.00
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1200 - Hardware Additions
MITREへのリンク →

Andariel

Score: 5.34
Matched TTPs:
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
MITREへのリンク →

The White Company

Score: 3.39
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
MITREへのリンク →

Tropic Trooper

Score: 9.29
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
  • T1200 - Hardware Additions
  • T1159 - Launch Agent
MITREへのリンク →

Darkhotel

Score: 3.39
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.83
Matched TTPs:
  • T1114 - Email Collection
  • T1030 - Data Transfer Size Limits
  • T1057 - Process Discovery
  • T1197 - BITS Jobs
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1506 - Web Session Cookie
  • T1552.003 - Shell History
  • T1543.003 - Windows Service
  • T1683.001 - Written Content
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1690 - Prevent Command History Logging
  • T1003.003 - NTDS
  • T1152 - Launchctl
  • T1566.002 - Spearphishing Link
MITREへのリンク →

Sandworm Team

Score: 0.76
Matched TTPs:
  • T1114 - Email Collection
  • T1564.008 - Email Hiding Rules
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1193 - Spearphishing Attachment
  • T1091 - Replication Through Removable Media
  • T1543.003 - Windows Service
  • T1484.002 - Trust Modification
  • T1562.004 - Disable or Modify System Firewall
  • T1102.003 - One-Way Communication
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1187 - Forced Authentication
  • T1566.002 - Spearphishing Link
  • T1606.002 - SAML Tokens
MITREへのリンク →

Volt Typhoon

Score: 0.59
Matched TTPs:
  • T1114 - Email Collection
  • T1057 - Process Discovery
  • T1159 - Launch Agent
  • T1574.002 - DLL Side-Loading
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1584.002 - DNS Server
  • T1065 - Uncommonly Used Port
  • T1102.003 - One-Way Communication
  • T1164 - Re-opened Applications
  • T1199 - Trusted Relationship
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る