Trusted Design

Compromised TV and Government-Related Sites Lead to PoisonIvy

概要

A recent campaign compromised Taiwan and Hong Kong sites to deliver Flash exploits related to Hacking Team and eventually download PoisonIvy and other payloads in user systems. This campaign started on July 9, a few days after the Hacking Team announced it was hacked. The actors compromised the sites of a local television network, educational organizations, a religious institute, and a known political party in Taiwan; and a popular news site in Hong Kong. Note that the affected sites have consistent followers given the nature of their content. The affected educational organizations, for instance, are used to deliver employment exams for government employees. The Taiwanese television network involved has been producing and importing TV shows and movies for a decade.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Ember Bear

Score: 8.26
Matched TTPs:
  • T1491.002 - External Defacement
  • T1588.005 - Exploits
MITREへのリンク →

Sandworm Team

Score: 30.55
Matched TTPs:
  • T1491.002 - External Defacement
  • T1586.001 - Social Media Accounts
  • T1608.001 - Upload Malware
  • T1589.003 - Employee Names
  • T1199 - Trusted Relationship
  • T1593 - Search Open Websites/Domains
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Leviathan

Score: 8.33
Matched TTPs:
  • T1586.001 - Social Media Accounts
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

TA2541

Score: 6.08
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Earth Lusca

Score: 6.17
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Mustang Panda

Score: 10.75
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1593 - Search Open Websites/Domains
  • T1027.007 - Dynamic API Resolution
  • T1204.001 - Malicious Link
MITREへのリンク →

LuminousMoth

Score: 3.33
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

Kimsuky

Score: 26.03
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1589.003 - Employee Names
  • T1657 - Financial Theft
  • T1593 - Search Open Websites/Domains
  • T1593.001 - Social Media
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1588.005 - Exploits
  • T1078.003 - Local Accounts
MITREへのリンク →

Mustard Tempest

Score: 3.33
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

OilRig

Score: 6.08
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

LazyScripter

Score: 3.33
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

Gamaredon Group

Score: 9.58
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1491.001 - Internal Defacement
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Star Blizzard

Score: 5.26
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1593 - Search Open Websites/Domains
MITREへのリンク →

Threat Group-3390

Score: 4.72
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1199 - Trusted Relationship
MITREへのリンク →

TA505

Score: 3.33
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

BlackByte

Score: 5.82
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1491.001 - Internal Defacement
MITREへのリンク →

BITTER

Score: 5.59
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1573 - Encrypted Channel
MITREへのリンク →

APT32

Score: 6.00
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
  • T1078.003 - Local Accounts
MITREへのリンク →

HEXANE

Score: 4.37
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Saint Bear

Score: 3.33
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

Contagious Interview

Score: 12.99
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1657 - Financial Theft
  • T1593 - Search Open Websites/Domains
  • T1593.001 - Social Media
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN7

Score: 8.40
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1078.003 - Local Accounts
MITREへのリンク →

EXOTIC LILY

Score: 7.18
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1593.001 - Social Media
  • T1204.001 - Malicious Link
MITREへのリンク →

APT42

Score: 4.72
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Silent Librarian

Score: 3.84
Matched TTPs:
  • T1589.003 - Employee Names
MITREへのリンク →

Medusa Group

Score: 8.89
Matched TTPs:
  • T1657 - Financial Theft
  • T1573.002 - Asymmetric Cryptography
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Play

Score: 5.19
Matched TTPs:
  • T1657 - Financial Theft
  • T1078.003 - Local Accounts
MITREへのリンク →

Lazarus Group

Score: 16.83
Matched TTPs:
  • T1491.001 - Internal Defacement
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT28

Score: 15.17
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1550.001 - Application Access Token
  • T1669 - Wi-Fi Networks
MITREへのリンク →

RedCurl

Score: 6.85
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

APT29

Score: 10.39
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1204.001 - Malicious Link
  • T1078.003 - Local Accounts
MITREへのリンク →

POLONIUM

Score: 5.14
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

HAFNIUM

Score: 9.54
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1550.001 - Application Access Token
  • T1078.003 - Local Accounts
MITREへのリンク →

Sea Turtle

Score: 5.41
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1078.003 - Local Accounts
MITREへのリンク →

Volt Typhoon

Score: 6.12
Matched TTPs:
  • T1593 - Search Open Websites/Domains
  • T1584.004 - Server
MITREへのリンク →

Tropic Trooper

Score: 9.03
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1573.002 - Asymmetric Cryptography
  • T1078.003 - Local Accounts
MITREへのリンク →

Magic Hound

Score: 11.22
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Andariel

Score: 3.84
Matched TTPs:
  • T1592.002 - Software
MITREへのリンク →

APT37

Score: 6.02
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT39

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Turla

Score: 9.26
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1204.001 - Malicious Link
  • T1078.003 - Local Accounts
MITREへのリンク →

MuddyWater

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

ZIRCONIUM

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Velvet Ant

Score: 5.41
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1078.003 - Local Accounts
MITREへのリンク →

Cobalt Group

Score: 4.11
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN8

Score: 4.11
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Daggerfly

Score: 4.19
Matched TTPs:
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Axiom

Score: 4.54
Matched TTPs:
  • T1001.002 - Steganography
MITREへのリンク →

APT38

Score: 4.98
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.81
Matched TTPs:
  • T1589.003 - Employee Names
  • T1199 - Trusted Relationship
  • T1593 - Search Open Websites/Domains
  • T1586.001 - Social Media Accounts
  • T1592.002 - Software
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1491.002 - External Defacement
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Kimsuky

Score: 0.72
Matched TTPs:
  • T1657 - Financial Theft
  • T1204.001 - Malicious Link
  • T1589.003 - Employee Names
  • T1593 - Search Open Websites/Domains
  • T1588.005 - Exploits
  • T1102.002 - Bidirectional Communication
  • T1078.003 - Local Accounts
  • T1608.001 - Upload Malware
  • T1593.001 - Social Media
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る