Trusted Design

South Korea NIS’s use of Hacking Team’s RCS

概要

This research note outlines what we know about the use of Hacking Team’s Remote Control System (RCS) by South Korea’s National Intelligence Service (NIS). The note synthesizes information found in publicly leaked materials, as well as our own research. The data available in the leaked Hacking Team files provides circumstantial evidence pointing to an interest in compromising individuals with ties to South Korea (i.e., Korean language speakers who use software or apps popular in South Korea, or South Korean editions of Samsung phones). The leaked data alone cannot identify specific individuals targeted by NIS, nor prove misuse of the technology; further investigation and research is necessary to make those determinations. Moreover, the presence of intrusion software does not necessarily equate to its misuse, as such software may be utilized by intelligence or law enforcement agencies in a manner that conforms with rule of law and democratic principles.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

OilRig

Score: 14.67
Matched TTPs:
  • T1025 - Data from Removable Media
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Gamaredon Group

Score: 18.12
Matched TTPs:
  • T1025 - Data from Removable Media
  • T1001 - Data Obfuscation
  • T1039 - Data from Network Shared Drive
  • T1102.002 - Bidirectional Communication
  • T1070.004 - File Deletion
  • T1027.015 - Compression
MITREへのリンク →

APT28

Score: 21.04
Matched TTPs:
  • T1025 - Data from Removable Media
  • T1040 - Network Sniffing
  • T1039 - Data from Network Shared Drive
  • T1102.002 - Bidirectional Communication
  • T1030 - Data Transfer Size Limits
  • T1070.004 - File Deletion
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Turla

Score: 8.61
Matched TTPs:
  • T1025 - Data from Removable Media
  • T1102.002 - Bidirectional Communication
  • T1124 - System Time Discovery
MITREへのリンク →

Sandworm Team

Score: 13.03
Matched TTPs:
  • T1040 - Network Sniffing
  • T1593 - Search Open Websites/Domains
  • T1195.002 - Compromise Software Supply Chain
  • T1102.002 - Bidirectional Communication
  • T1070.004 - File Deletion
MITREへのリンク →

Kimsuky

Score: 15.03
Matched TTPs:
  • T1040 - Network Sniffing
  • T1593 - Search Open Websites/Domains
  • T1102.002 - Bidirectional Communication
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Velvet Ant

Score: 12.31
Matched TTPs:
  • T1040 - Network Sniffing
  • T1573.002 - Asymmetric Cryptography
  • T1569.002 - Service Execution
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Salt Typhoon

Score: 5.78
Matched TTPs:
  • T1040 - Network Sniffing
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT33

Score: 5.78
Matched TTPs:
  • T1040 - Network Sniffing
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

UNC3886

Score: 7.01
Matched TTPs:
  • T1040 - Network Sniffing
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

DarkVishnya

Score: 3.03
Matched TTPs:
  • T1040 - Network Sniffing
MITREへのリンク →

Fox Kitten

Score: 11.81
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1039 - Data from Network Shared Drive
  • T1021.001 - Remote Desktop Protocol
  • T1213.005 - Messaging Applications
MITREへのリンク →

Volt Typhoon

Score: 16.73
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1590.006 - Network Security Appliances
  • T1593 - Search Open Websites/Domains
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

APT38

Score: 10.69
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1070.004 - File Deletion
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Scattered Spider

Score: 8.78
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1021.001 - Remote Desktop Protocol
  • T1213.005 - Messaging Applications
MITREへのリンク →

Moonstone Sleet

Score: 11.13
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1195.002 - Compromise Software Supply Chain
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Chimera

Score: 14.34
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1039 - Data from Network Shared Drive
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Winter Vivern

Score: 4.54
Matched TTPs:
  • T1056.003 - Web Portal Capture
MITREへのリンク →

Mustang Panda

Score: 7.41
Matched TTPs:
  • T1593 - Search Open Websites/Domains
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Contagious Interview

Score: 9.94
Matched TTPs:
  • T1593 - Search Open Websites/Domains
  • T1070.004 - File Deletion
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Star Blizzard

Score: 3.29
Matched TTPs:
  • T1593 - Search Open Websites/Domains
MITREへのリンク →

RedCurl

Score: 7.16
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

BRONZE BUTLER

Score: 10.29
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

menuPass

Score: 6.06
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT41

Score: 15.08
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1030 - Data Transfer Size Limits
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Cobalt Group

Score: 8.70
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Dragonfly

Score: 5.96
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Threat Group-3390

Score: 10.90
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1030 - Data Transfer Size Limits
  • T1070.004 - File Deletion
  • T1027.015 - Compression
MITREへのリンク →

FIN7

Score: 11.96
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1102.002 - Bidirectional Communication
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1124 - System Time Discovery
MITREへのリンク →

APT37

Score: 6.02
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Lazarus Group

Score: 16.91
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT39

Score: 7.82
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Magic Hound

Score: 7.95
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

HEXANE

Score: 4.05
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

ZIRCONIUM

Score: 4.99
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1124 - System Time Discovery
MITREへのリンク →

TA2541

Score: 5.90
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1027.015 - Compression
MITREへのリンク →

Tropic Trooper

Score: 4.13
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

Medusa Group

Score: 16.33
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
  • T1218.014 - MMC
MITREへのリンク →

FIN6

Score: 13.44
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN8

Score: 8.52
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Ke3chang

Score: 6.02
Matched TTPs:
  • T1614.001 - System Language Discovery
  • T1569.002 - Service Execution
MITREへのリンク →

BlackByte

Score: 9.05
Matched TTPs:
  • T1614.001 - System Language Discovery
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Storm-0501

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

Malteiro

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

Play

Score: 4.82
Matched TTPs:
  • T1030 - Data Transfer Size Limits
  • T1070.004 - File Deletion
MITREへのリンク →

LuminousMoth

Score: 3.44
Matched TTPs:
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

Aquatic Panda

Score: 3.03
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

FIN10

Score: 3.03
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT29

Score: 3.90
Matched TTPs:
  • T1070.004 - File Deletion
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Wizard Spider

Score: 8.17
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT32

Score: 6.53
Matched TTPs:
  • T1070.004 - File Deletion
  • T1569.002 - Service Execution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT5

Score: 3.03
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT3

Score: 3.03
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

The White Company

Score: 3.97
Matched TTPs:
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

Patchwork

Score: 6.31
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

INC Ransom

Score: 5.43
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Silence

Score: 5.43
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Rocke

Score: 4.67
Matched TTPs:
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Mustard Tempest

Score: 4.54
Matched TTPs:
  • T1608.006 - SEO Poisoning
MITREへのリンク →

Blue Mockingbird

Score: 4.05
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Leviathan

Score: 4.80
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1027.015 - Compression
MITREへのリンク →

Higaisa

Score: 5.74
Matched TTPs:
  • T1124 - System Time Discovery
  • T1027.015 - Compression
MITREへのリンク →

CURIUM

Score: 5.12
Matched TTPs:
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

LAPSUS$

Score: 3.84
Matched TTPs:
  • T1213.005 - Messaging Applications
MITREへのリンク →

Molerats

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.82
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1025 - Data from Removable Media
  • T1030 - Data Transfer Size Limits
  • T1211 - Exploitation for Defense Evasion
  • T1070.004 - File Deletion
  • T1040 - Network Sniffing
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Lazarus Group

Score: 0.72
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1529 - System Shutdown/Reboot
  • T1566.003 - Spearphishing via Service
  • T1124 - System Time Discovery
  • T1070.004 - File Deletion
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Gamaredon Group

Score: 0.71
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1025 - Data from Removable Media
  • T1001 - Data Obfuscation
  • T1027.015 - Compression
  • T1070.004 - File Deletion
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Volt Typhoon

Score: 0.69
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1590.006 - Network Security Appliances
  • T1217 - Browser Information Discovery
  • T1593 - Search Open Websites/Domains
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

Kimsuky

Score: 0.69
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1593 - Search Open Websites/Domains
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
  • T1040 - Network Sniffing
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Medusa Group

Score: 0.66
Matched TTPs:
  • T1218.014 - MMC
  • T1021.001 - Remote Desktop Protocol
  • T1573.002 - Asymmetric Cryptography
  • T1529 - System Shutdown/Reboot
  • T1070.004 - File Deletion
  • T1569.002 - Service Execution
MITREへのリンク →

APT41

Score: 0.64
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1030 - Data Transfer Size Limits
  • T1195.002 - Compromise Software Supply Chain
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
  • T1569.002 - Service Execution
MITREへのリンク →

Chimera

Score: 0.58
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1021.001 - Remote Desktop Protocol
  • T1217 - Browser Information Discovery
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
  • T1569.002 - Service Execution
MITREへのリンク →

OilRig

Score: 0.58
Matched TTPs:
  • T1025 - Data from Removable Media
  • T1573.002 - Asymmetric Cryptography
  • T1021.001 - Remote Desktop Protocol
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1566.003 - Spearphishing via Service
  • T1070.004 - File Deletion
MITREへのリンク →

FIN6

Score: 0.56
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1573.002 - Asymmetric Cryptography
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1566.003 - Spearphishing via Service
  • T1070.004 - File Deletion
  • T1569.002 - Service Execution
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る