Trusted Design

APT Group Wekby Leveraging Adobe Flash Exploit

概要

As if the recent breach and subsequent public data dump involving the Italian company Hacking Team wasn’t bad enough, it all gets just a little bit worse. Emerging from the bowels of Hacking Team data dump was a Flash 0-day exploit (CVE-2015-5119) that was just patched today by Adobe as covered in APSB15-16. The exploit has since been added into the Angler Exploit Kit and integrated into Metasploit. However, not to be out done, APT attackers have also started leveraging the exploit in targeted spear phishing attacks as well. Before we start dishing the details, there is going to be one main takeaway from this blog post: If you haven’t already, update/patch your Adobe Flash now.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Magic Hound

Score: 6.14
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 8.89
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT28

Score: 11.60
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1598 - Phishing for Information
  • T1498 - Network Denial of Service
MITREへのリンク →

BlackByte

Score: 3.62
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
MITREへのリンク →

APT33

Score: 6.88
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Wizard Spider

Score: 6.88
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Darkhotel

Score: 4.13
Matched TTPs:
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

FIN7

Score: 4.13
Matched TTPs:
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

Cobalt Group

Score: 5.49
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Kimsuky

Score: 10.32
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1598 - Phishing for Information
  • T1588.005 - Exploits
MITREへのリンク →

APT32

Score: 5.49
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

OilRig

Score: 8.02
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN6

Score: 8.02
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN8

Score: 5.49
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Scattered Spider

Score: 3.44
Matched TTPs:
  • T1598 - Phishing for Information
MITREへのリンク →

ZIRCONIUM

Score: 3.44
Matched TTPs:
  • T1598 - Phishing for Information
MITREへのリンク →

Moonstone Sleet

Score: 5.96
Matched TTPs:
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Ember Bear

Score: 4.13
Matched TTPs:
  • T1588.005 - Exploits
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

Lazarus Group

Score: 5.27
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.82
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1598 - Phishing for Information
  • T1498 - Network Denial of Service
MITREへのリンク →

Kimsuky

Score: 0.73
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1588.005 - Exploits
  • T1598 - Phishing for Information
MITREへのリンク →

Contagious Interview

Score: 0.62
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 0.61
Matched TTPs:
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN6

Score: 0.59
Matched TTPs:
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT33

Score: 0.56
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る