Trusted Design

Operation Potao Express

概要

ESET presented our initial findings based on research into the Win32/Potao malware family in June, in our CCCC 2015 presentation in Copenhagen. Today, we are releasing the full whitepaper on the Potao malware with additional findings, the cyberespionage campaigns where it was employed, and its connection to a backdoor in the form of a modified version of the TrueCrypt encryption software. Like BlackEnergy, the malware used by the so-called Sandworm APT group (also known as Quedagh), Potao is an example of targeted espionage malware directed mostly at targets in Ukraine and a number of other post-Soviet countries, including Russia, Georgia and Belarus.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

FIN6

Score: 8.42
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

CopyKittens

Score: 3.15
Matched TTPs:
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

Mustang Panda

Score: 11.35
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Kimsuky

Score: 11.44
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
MITREへのリンク →

UNC3886

Score: 13.31
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1205.001 - Port Knocking
MITREへのリンク →

Lotus Blossom

Score: 3.15
Matched TTPs:
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

Lazarus Group

Score: 14.30
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1587.001 - Malware
  • T1571 - Non-Standard Port
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN13

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Moonstone Sleet

Score: 6.59
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 8.99
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1571 - Non-Standard Port
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 13.18
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

LuminousMoth

Score: 6.53
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
MITREへのリンク →

Sandworm Team

Score: 11.78
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1571 - Non-Standard Port
MITREへのリンク →

Salt Typhoon

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

APT29

Score: 9.71
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1573 - Encrypted Channel
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Play

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1587.001 - Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Moses Staff

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Turla

Score: 4.55
Matched TTPs:
  • T1587.001 - Malware
  • T1588.001 - Malware
MITREへのリンク →

Ke3chang

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

TeamTNT

Score: 4.07
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
MITREへのリンク →

FIN7

Score: 7.94
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1571 - Non-Standard Port
MITREへのリンク →

TA2541

Score: 7.18
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Earth Lusca

Score: 8.94
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1027.003 - Steganography
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1608.006 - SEO Poisoning
MITREへのリンク →

LazyScripter

Score: 4.43
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
MITREへのリンク →

Gamaredon Group

Score: 4.37
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1571 - Non-Standard Port
MITREへのリンク →

Threat Group-3390

Score: 3.44
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

TA505

Score: 4.43
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
MITREへのリンク →

BlackByte

Score: 3.44
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

BITTER

Score: 5.59
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1573 - Encrypted Channel
MITREへのリンク →

APT32

Score: 7.12
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1571 - Non-Standard Port
  • T1218.010 - Regsvr32
MITREへのリンク →

EXOTIC LILY

Score: 4.50
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT42

Score: 4.72
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Ember Bear

Score: 10.17
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1571 - Non-Standard Port
MITREへのリンク →

Rocke

Score: 3.87
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1571 - Non-Standard Port
MITREへのリンク →

APT28

Score: 5.60
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

BackdoorDiplomacy

Score: 3.93
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
MITREへのリンク →

Magic Hound

Score: 10.01
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1571 - Non-Standard Port
  • T1573 - Encrypted Channel
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Medusa Group

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Storm-0501

Score: 8.35
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Blue Mockingbird

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
MITREへのリンク →

Leviathan

Score: 7.25
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
  • T1027.003 - Steganography
MITREへのリンク →

Axiom

Score: 6.01
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1001.002 - Steganography
MITREへのリンク →

MuddyWater

Score: 4.50
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1027.003 - Steganography
MITREへのリンク →

Andariel

Score: 5.49
Matched TTPs:
  • T1588.001 - Malware
  • T1027.003 - Steganography
MITREへのリンク →

Scattered Spider

Score: 6.59
Matched TTPs:
  • T1588.001 - Malware
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

PROMETHIUM

Score: 4.13
Matched TTPs:
  • T1205.001 - Port Knocking
MITREへのリンク →

APT33

Score: 6.53
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1571 - Non-Standard Port
MITREへのリンク →

Wizard Spider

Score: 4.13
Matched TTPs:
  • T1552.006 - Group Policy Preferences
MITREへのリンク →

WIRTE

Score: 5.14
Matched TTPs:
  • T1571 - Non-Standard Port
  • T1218.010 - Regsvr32
MITREへのリンク →

RedEcho

Score: 5.14
Matched TTPs:
  • T1571 - Non-Standard Port
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Velvet Ant

Score: 9.28
Matched TTPs:
  • T1571 - Non-Standard Port
  • T1573.002 - Asymmetric Cryptography
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Tropic Trooper

Score: 9.40
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1573.002 - Asymmetric Cryptography
  • T1027.003 - Steganography
MITREへのリンク →

TA551

Score: 5.78
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1027.003 - Steganography
MITREへのリンク →

Cobalt Group

Score: 5.49
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

APT37

Score: 3.03
Matched TTPs:
  • T1027.003 - Steganography
MITREへのリンク →

BRONZE BUTLER

Score: 3.03
Matched TTPs:
  • T1027.003 - Steganography
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

UNC3886

Score: 0.82
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1205.001 - Port Knocking
  • T1587.001 - Malware
  • T1588.001 - Malware
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

Lazarus Group

Score: 0.81
Matched TTPs:
  • T1587.001 - Malware
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1560.003 - Archive via Custom Method
  • T1571 - Non-Standard Port
MITREへのリンク →

OilRig

Score: 0.77
Matched TTPs:
  • T1587.001 - Malware
  • T1195 - Supply Chain Compromise
  • T1566.003 - Spearphishing via Service
  • T1573.002 - Asymmetric Cryptography
  • T1608.001 - Upload Malware
MITREへのリンク →

Sandworm Team

Score: 0.72
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
  • T1195 - Supply Chain Compromise
  • T1608.001 - Upload Malware
  • T1571 - Non-Standard Port
MITREへのリンク →

Kimsuky

Score: 0.69
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
  • T1560.003 - Archive via Custom Method
  • T1608.001 - Upload Malware
  • T1218.010 - Regsvr32
MITREへのリンク →

Mustang Panda

Score: 0.67
Matched TTPs:
  • T1027.007 - Dynamic API Resolution
  • T1560.003 - Archive via Custom Method
  • T1608.001 - Upload Malware
  • T1587.001 - Malware
MITREへのリンク →

Magic Hound

Score: 0.63
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1571 - Non-Standard Port
  • T1190 - Exploit Public-Facing Application
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 0.59
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1573 - Encrypted Channel
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
MITREへのリンク →

Velvet Ant

Score: 0.58
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1573.002 - Asymmetric Cryptography
  • T1571 - Non-Standard Port
MITREへのリンク →

Ember Bear

Score: 0.58
Matched TTPs:
  • T1571 - Non-Standard Port
  • T1195 - Supply Chain Compromise
  • T1588.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Tropic Trooper

Score: 0.58
Matched TTPs:
  • T1027.003 - Steganography
  • T1573.002 - Asymmetric Cryptography
  • T1573 - Encrypted Channel
MITREへのリンク →

Earth Lusca

Score: 0.58
Matched TTPs:
  • T1027.003 - Steganography
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Storm-0501

Score: 0.56
Matched TTPs:
  • T1556.009 - Conditional Access Policies
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る