Trusted Design

GamaPoS: The Andromeda Botnet Connection

概要

The Andromeda botnet is a well-known botnet that surfaced around 2011 and has delivered well-known backdoor variants like Gamarue. In past revivals, the botnet has been distributed through malicious emails containing attachments or links to compromised websites hosting exploit kit content. What makes this botnet successful is its highly configurable and modular design that can fit any malicious intent, like distributing Zeus or, more recently, distributing a Lethic bot. Earlier this year, the Andromeda botnet was seen using macro-based malware, which is yet again an old trick. What makes this interesting is how the dated botnet and macro malware trick are used together. Indeed, the past few months seem to be quite busy for the Andromeda botnet and its recent activity indicates intent in the United States.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 16.44
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1588.005 - Exploits
MITREへのリンク →

Sea Turtle

Score: 4.53
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 15.25
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1491.002 - External Defacement
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1588.005 - Exploits
MITREへのリンク →

Indrik Spider

Score: 7.96
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1584.004 - Server
MITREへのリンク →

Agrius

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Contagious Interview

Score: 17.13
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1588.007 - Artificial Intelligence
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1681 - Search Threat Vendor Data
  • T1204.001 - Malicious Link
MITREへのリンク →

Sandworm Team

Score: 24.39
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1491.002 - External Defacement
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1584.005 - Botnet
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Star Blizzard

Score: 5.01
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
MITREへのリンク →

Scattered Spider

Score: 11.13
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1588.001 - Malware
  • T1538 - Cloud Service Dashboard
MITREへのリンク →

FIN4

Score: 6.94
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1566.002 - Spearphishing Link
  • T1204.001 - Malicious Link
MITREへのリンク →

Moonstone Sleet

Score: 4.07
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
MITREへのリンク →

Lazarus Group

Score: 20.01
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1491.001 - Internal Defacement
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

OilRig

Score: 11.12
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

UNC3886

Score: 10.18
Matched TTPs:
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

LuminousMoth

Score: 9.33
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

APT29

Score: 14.78
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1090.004 - Domain Fronting
  • T1204.001 - Malicious Link
MITREへのリンク →

Aoqin Dragon

Score: 3.59
Matched TTPs:
  • T1587.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 7.65
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Turla

Score: 14.36
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1588.001 - Malware
  • T1102.002 - Bidirectional Communication
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Ke3chang

Score: 5.94
Matched TTPs:
  • T1587.001 - Malware
  • T1583.005 - Botnet
MITREへのリンク →

Mustang Panda

Score: 12.50
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1204.001 - Malicious Link
MITREへのリンク →

TeamTNT

Score: 4.07
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
MITREへのリンク →

FIN7

Score: 9.27
Matched TTPs:
  • T1587.001 - Malware
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

BlackTech

Score: 4.30
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

MuddyWater

Score: 6.70
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

Confucius

Score: 4.30
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

Sidewinder

Score: 4.30
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

Elderwood

Score: 6.07
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Machete

Score: 4.57
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Mustard Tempest

Score: 6.55
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Transparent Tribe

Score: 6.07
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN8

Score: 5.55
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

APT32

Score: 11.88
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

APT3

Score: 4.30
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

APT1

Score: 3.91
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1588.001 - Malware
MITREへのリンク →

Leviathan

Score: 8.90
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

APT33

Score: 4.30
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

ZIRCONIUM

Score: 5.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

EXOTIC LILY

Score: 6.27
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

Magic Hound

Score: 6.97
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Windshift

Score: 4.57
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Cobalt Group

Score: 7.05
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

TA2541

Score: 9.98
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Earth Lusca

Score: 11.84
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Patchwork

Score: 6.07
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

TA505

Score: 7.24
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

LazyScripter

Score: 7.24
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

APT42

Score: 6.17
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

APT39

Score: 5.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

HAFNIUM

Score: 7.47
Matched TTPs:
  • T1583.005 - Botnet
  • T1584.005 - Botnet
MITREへのリンク →

APT5

Score: 3.84
Matched TTPs:
  • T1583.005 - Botnet
MITREへのリンク →

Gamaredon Group

Score: 14.11
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1491.001 - Internal Defacement
  • T1001 - Data Obfuscation
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Threat Group-3390

Score: 5.23
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

BlackByte

Score: 5.82
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1491.001 - Internal Defacement
MITREへのリンク →

BITTER

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

HEXANE

Score: 4.37
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Saint Bear

Score: 4.83
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

Andariel

Score: 5.72
Matched TTPs:
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

BRONZE BUTLER

Score: 7.10
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Axiom

Score: 11.42
Matched TTPs:
  • T1584.005 - Botnet
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1001.002 - Steganography
MITREへのリンク →

Volt Typhoon

Score: 6.45
Matched TTPs:
  • T1584.005 - Botnet
  • T1584.004 - Server
MITREへのリンク →

APT37

Score: 5.66
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

APT12

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT28

Score: 7.02
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Dragonfly

Score: 6.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
MITREへのリンク →

Tropic Trooper

Score: 4.24
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Darkhotel

Score: 3.26
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Medusa Group

Score: 7.28
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1218.014 - MMC
MITREへのリンク →

APT38

Score: 3.13
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Winter Vivern

Score: 3.13
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1204.001 - Malicious Link
MITREへのリンク →

Daggerfly

Score: 5.96
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.82
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1491.002 - External Defacement
  • T1203 - Exploitation for Client Execution
  • T1584.005 - Botnet
  • T1587.001 - Malware
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1584.004 - Server
  • T1204.001 - Malicious Link
  • T1566.002 - Spearphishing Link
MITREへのリンク →

Lazarus Group

Score: 0.69
Matched TTPs:
  • T1491.001 - Internal Defacement
  • T1102.002 - Bidirectional Communication
  • T1189 - Drive-by Compromise
  • T1203 - Exploitation for Client Execution
  • T1587.001 - Malware
  • T1584.004 - Server
  • T1566.002 - Spearphishing Link
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Contagious Interview

Score: 0.58
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1588.007 - Artificial Intelligence
  • T1587.001 - Malware
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

Kimsuky

Score: 0.58
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1587.001 - Malware
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
  • T1566.002 - Spearphishing Link
  • T1588.005 - Exploits
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る