APT Group Wekby Leveraging Adobe Flash Exploit
概要
As if the recent breach and subsequent public data dump involving the Italian company Hacking Team wasn’t bad enough, it all gets just a little bit worse. Emerging from the bowels of Hacking Team data dump was a Flash 0-day exploit (CVE-2015-5119) that was just patched today by Adobe as covered in APSB15-16. The exploit has since been added into the Angler Exploit Kit and integrated into Metasploit. However, not to be out done, APT attackers have also started leveraging the exploit in targeted spear phishing attacks as well. Before we start dishing the details, there is going to be one main takeaway from this blog post: If you haven’t already, update/patch your Adobe Flash now.
Created: 2026-02-23
Indicators
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 6.14
Matched TTPs:
- T1567 - Exfiltration Over Web Service
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 8.89
Matched TTPs:
- T1567 - Exfiltration Over Web Service
- T1566.003 - Spearphishing via Service
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Score: 11.60
Matched TTPs:
- T1567 - Exfiltration Over Web Service
- T1598 - Phishing for Information
- T1498 - Network Denial of Service
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1567 - Exfiltration Over Web Service
MITREへのリンク →
Score: 6.88
Matched TTPs:
- T1552.006 - Group Policy Preferences
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Score: 6.88
Matched TTPs:
- T1552.006 - Group Policy Preferences
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1218.010 - Regsvr32
- T1573.002 - Asymmetric Cryptography
MITREへのリンク →
Score: 10.32
Matched TTPs:
- T1218.010 - Regsvr32
- T1598 - Phishing for Information
- T1588.005 - Exploits
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1218.010 - Regsvr32
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Score: 8.02
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1566.003 - Spearphishing via Service
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Score: 8.02
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1566.003 - Spearphishing via Service
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1573.002 - Asymmetric Cryptography
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1598 - Phishing for Information
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1598 - Phishing for Information
MITREへのリンク →
Score: 5.96
Matched TTPs:
- T1598 - Phishing for Information
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1564.005 - Hidden File System
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1564.005 - Hidden File System
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1056.004 - Credential API Hooking
MITREへのリンク →
Score: 5.27
Matched TTPs:
- T1566.003 - Spearphishing via Service
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.82
Matched TTPs:
- T1567 - Exfiltration Over Web Service
- T1598 - Phishing for Information
- T1498 - Network Denial of Service
MITREへのリンク →
Score: 0.73
Matched TTPs:
- T1218.010 - Regsvr32
- T1588.005 - Exploits
- T1598 - Phishing for Information
MITREへのリンク →
Score: 0.62
Matched TTPs:
- T1567 - Exfiltration Over Web Service
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 0.61
Matched TTPs:
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
- T1573.002 - Asymmetric Cryptography
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 0.59
Matched TTPs:
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
- T1573.002 - Asymmetric Cryptography
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 0.56
Matched TTPs:
- T1552.006 - Group Policy Preferences
- T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →
Related CVEs
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る