Trusted Design

Wild Neutron – Economic espionage threat actor returns

概要

A powerful threat actor known as “Wild Neutron” (also known as “Jripbot” and “Morpho“) has been active since at least 2011, infecting high profile companies for several years by using a combination of exploits, watering holes and multi-platform malware. The latest round of attacks in 2015 uses a stolen code signing certificate belonging to Taiwanese electronics maker Acer and an unknown Flash Player exploit. Wild Neutron hit the spotlight in 2013, when it successfully infected companies such as Apple, Facebook, Twitter and Microsoft. This attack took advantage of a Java zero-day exploit and used hacked forums as watering holes. The 2013 incident was highly publicized and, in the aftermath, the threat actor went dark for almost one year.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 16.88
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1071.003 - Mail Protocols
  • T1218.010 - Regsvr32
  • T1588.003 - Code Signing Certificates
  • T1588.005 - Exploits
MITREへのリンク →

FIN13

Score: 5.91
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

Lazarus Group

Score: 8.82
Matched TTPs:
  • T1587.001 - Malware
  • T1027.007 - Dynamic API Resolution
  • T1124 - System Time Discovery
MITREへのリンク →

Contagious Interview

Score: 9.51
Matched TTPs:
  • T1587.001 - Malware
  • T1071.003 - Mail Protocols
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

OilRig

Score: 7.99
Matched TTPs:
  • T1587.001 - Malware
  • T1573.002 - Asymmetric Cryptography
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

UNC3886

Score: 10.29
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1681 - Search Threat Vendor Data
  • T1124 - System Time Discovery
MITREへのリンク →

Sandworm Team

Score: 5.91
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

Salt Typhoon

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

APT29

Score: 7.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Play

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1587.001 - Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Moses Staff

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Turla

Score: 7.97
Matched TTPs:
  • T1587.001 - Malware
  • T1071.003 - Mail Protocols
  • T1124 - System Time Discovery
MITREへのリンク →

Ke3chang

Score: 5.91
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

Mustang Panda

Score: 11.72
Matched TTPs:
  • T1587.001 - Malware
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
  • T1003.003 - NTDS
MITREへのリンク →

FIN7

Score: 6.16
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1124 - System Time Discovery
MITREへのリンク →

Threat Group-3390

Score: 7.77
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.003 - Code Signing Certificates
  • T1027.015 - Compression
MITREへのリンク →

Volt Typhoon

Score: 6.40
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
  • T1124 - System Time Discovery
MITREへのリンク →

APT28

Score: 16.17
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1071.003 - Mail Protocols
  • T1498 - Network Denial of Service
  • T1137.002 - Office Test
  • T1003.003 - NTDS
MITREへのリンク →

Ember Bear

Score: 5.60
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.005 - Exploits
MITREへのリンク →

BlackTech

Score: 4.62
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Medusa Group

Score: 6.56
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
MITREへのリンク →

Storm-0501

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
MITREへのリンク →

Fox Kitten

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

menuPass

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

Blue Mockingbird

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
MITREへのリンク →

Leviathan

Score: 7.37
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
  • T1027.015 - Compression
MITREへのリンク →

Dragonfly

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

Axiom

Score: 6.01
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1001.002 - Steganography
MITREへのリンク →

APT41

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

HAFNIUM

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

SilverTerrier

Score: 3.29
Matched TTPs:
  • T1071.003 - Mail Protocols
MITREへのリンク →

APT32

Score: 9.88
Matched TTPs:
  • T1071.003 - Mail Protocols
  • T1550.003 - Pass the Ticket
  • T1218.010 - Regsvr32
MITREへのリンク →

BRONZE BUTLER

Score: 6.44
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1124 - System Time Discovery
MITREへのリンク →

Gamaredon Group

Score: 7.69
Matched TTPs:
  • T1001 - Data Obfuscation
  • T1027.015 - Compression
MITREへのリンク →

Cobalt Group

Score: 5.49
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

TA2541

Score: 5.90
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1027.015 - Compression
MITREへのリンク →

FIN6

Score: 5.09
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
MITREへのリンク →

FIN8

Score: 5.90
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Wizard Spider

Score: 5.49
Matched TTPs:
  • T1588.003 - Code Signing Certificates
  • T1003.003 - NTDS
MITREへのリンク →

Chimera

Score: 4.93
Matched TTPs:
  • T1003.003 - NTDS
  • T1124 - System Time Discovery
MITREへのリンク →

Higaisa

Score: 5.74
Matched TTPs:
  • T1124 - System Time Discovery
  • T1027.015 - Compression
MITREへのリンク →

Molerats

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.81
Matched TTPs:
  • T1588.005 - Exploits
  • T1218.010 - Regsvr32
  • T1587.001 - Malware
  • T1588.003 - Code Signing Certificates
  • T1071.003 - Mail Protocols
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

APT28

Score: 0.79
Matched TTPs:
  • T1498 - Network Denial of Service
  • T1003.003 - NTDS
  • T1071.003 - Mail Protocols
  • T1190 - Exploit Public-Facing Application
  • T1137.002 - Office Test
MITREへのリンク →

Mustang Panda

Score: 0.60
Matched TTPs:
  • T1588.003 - Code Signing Certificates
  • T1587.001 - Malware
  • T1027.007 - Dynamic API Resolution
  • T1003.003 - NTDS
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る