Trusted Design

Tracing Pony’s Threat Cycle and Multi-Stage Infection Chain

概要

From the beginning of 2015, a malicious spear-phishing campaign dubbed Pony, has been actively luring victims. The spam e-mails are enticing users by impersonating well known companies, using their logos and known subject lines to further sell the deception. These e-mails kick off a multi-stage infection chain. The first stage would be a malicious link within the e-mail or attachment, containing malicious code, in this case Pony. Pony will infect the victim computer and download an additional malware. Pony was originally configured to download different malware families, however, due to criminal strategy changes, it currently only downloads Dyre. Every Pony domain appears to belong to the same group, the infrastructure is mainly in Russia and Ukraine. Most of the IP addresses belong to known bulletproof hosting networks that advertise their services on different forums. The criminals are also relying on a network of hacked servers to perform the multi-stage infection chain.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 54.82
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1534 - Internal Spearphishing
  • T1566 - Phishing
  • T1218.010 - Regsvr32
  • T1102.002 - Bidirectional Communication
  • T1656 - Impersonation
  • T1598 - Phishing for Information
  • T1585 - Establish Accounts
  • T1204.001 - Malicious Link
  • T1588.005 - Exploits
  • T1102.001 - Dead Drop Resolver
  • T1584.001 - Domains
MITREへのリンク →

Sea Turtle

Score: 7.84
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1583.001 - Domains
  • T1566 - Phishing
MITREへのリンク →

Ember Bear

Score: 21.04
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1588.001 - Malware
  • T1585 - Establish Accounts
  • T1588.005 - Exploits
MITREへのリンク →

Indrik Spider

Score: 8.15
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1585.002 - Email Accounts
  • T1584.004 - Server
MITREへのリンク →

Agrius

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Contagious Interview

Score: 27.55
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1657 - Financial Theft
  • T1480 - Execution Guardrails
  • T1583.006 - Web Services
  • T1656 - Impersonation
  • T1585 - Establish Accounts
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Sandworm Team

Score: 38.25
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1491.002 - External Defacement
  • T1586.001 - Social Media Accounts
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1584.005 - Botnet
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

Star Blizzard

Score: 18.43
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

APT41

Score: 13.67
Matched TTPs:
  • T1568.002 - Domain Generation Algorithms
  • T1566.001 - Spearphishing Attachment
  • T1656 - Impersonation
  • T1003.003 - NTDS
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

TA551

Score: 7.75
Matched TTPs:
  • T1568.002 - Domain Generation Algorithms
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
MITREへのリンク →

Mustard Tempest

Score: 12.60
Matched TTPs:
  • T1583.008 - Malvertising
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
  • T1584.001 - Domains
MITREへのリンク →

Leviathan

Score: 27.62
Matched TTPs:
  • T1586.001 - Social Media Accounts
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1102.003 - One-Way Communication
  • T1534 - Internal Spearphishing
  • T1218.010 - Regsvr32
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

BlackTech

Score: 3.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

MuddyWater

Score: 8.09
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

LuminousMoth

Score: 9.90
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1564.001 - Hidden Files and Directories
  • T1204.001 - Malicious Link
MITREへのリンク →

Confucius

Score: 5.69
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1204.001 - Malicious Link
MITREへのリンク →

Mofang

Score: 3.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

Sidewinder

Score: 9.76
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

Elderwood

Score: 3.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

Machete

Score: 3.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN7

Score: 18.79
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1674 - Input Injection
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1564.001 - Hidden Files and Directories
  • T1204.001 - Malicious Link
MITREへのリンク →

Transparent Tribe

Score: 11.15
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1564.001 - Hidden Files and Directories
  • T1204.001 - Malicious Link
  • T1584.001 - Domains
MITREへのリンク →

Mustang Panda

Score: 25.73
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1583.006 - Web Services
  • T1027.007 - Dynamic API Resolution
  • T1564.001 - Hidden Files and Directories
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN8

Score: 6.43
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

APT32

Score: 20.90
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1550.003 - Pass the Ticket
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1564.001 - Hidden Files and Directories
  • T1204.001 - Malicious Link
MITREへのリンク →

APT1

Score: 11.87
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1588.001 - Malware
  • T1584.001 - Domains
MITREへのリンク →

Lazarus Group

Score: 22.69
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
  • T1564.001 - Hidden Files and Directories
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT33

Score: 7.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1552.006 - Group Policy Preferences
  • T1204.001 - Malicious Link
MITREへのリンク →

ZIRCONIUM

Score: 14.63
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1204.001 - Malicious Link
MITREへのリンク →

EXOTIC LILY

Score: 11.98
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Molerats

Score: 3.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

Magic Hound

Score: 21.95
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
  • T1584.001 - Domains
MITREへのリンク →

OilRig

Score: 18.95
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1583.001 - Domains
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Windshift

Score: 6.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Cobalt Group

Score: 9.17
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

APT29

Score: 19.27
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1550.003 - Pass the Ticket
  • T1583.006 - Web Services
  • T1090.004 - Domain Fronting
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN4

Score: 3.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

TA2541

Score: 14.39
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Earth Lusca

Score: 17.22
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

RedCurl

Score: 9.09
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1573.002 - Asymmetric Cryptography
  • T1564.001 - Hidden Files and Directories
  • T1204.001 - Malicious Link
MITREへのリンク →

Storm-1811

Score: 13.06
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1583.001 - Domains
  • T1667 - Email Bombing
  • T1656 - Impersonation
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Turla

Score: 16.13
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Wizard Spider

Score: 16.06
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1585.002 - Email Accounts
  • T1074 - Data Staged
  • T1552.006 - Group Policy Preferences
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

TA577

Score: 5.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1204.001 - Malicious Link
MITREへのリンク →

Patchwork

Score: 9.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1204.001 - Malicious Link
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

TA505

Score: 9.63
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1588.001 - Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

LazyScripter

Score: 11.64
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1204.001 - Malicious Link
MITREへのリンク →

APT42

Score: 13.00
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1573.002 - Asymmetric Cryptography
  • T1656 - Impersonation
MITREへのリンク →

APT39

Score: 6.08
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Scattered Spider

Score: 33.50
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1087 - Account Discovery
  • T1588.001 - Malware
  • T1074 - Data Staged
  • T1657 - Financial Theft
  • T1656 - Impersonation
  • T1598 - Phishing for Information
  • T1556.009 - Conditional Access Policies
  • T1578.002 - Create Cloud Instance
  • T1003.003 - NTDS
MITREへのリンク →

Silent Librarian

Score: 6.26
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
MITREへのリンク →

APT28

Score: 34.94
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1498 - Network Denial of Service
  • T1564.001 - Hidden Files and Directories
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
  • T1550.001 - Application Access Token
  • T1669 - Wi-Fi Networks
MITREへのリンク →

Moonstone Sleet

Score: 15.07
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

CURIUM

Score: 13.28
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1584.006 - Web Services
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 13.65
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1598.002 - Spearphishing Attachment
  • T1584.004 - Server
  • T1003.003 - NTDS
MITREへのリンク →

Saint Bear

Score: 9.25
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1656 - Impersonation
  • T1204.001 - Malicious Link
MITREへのリンク →

Tropic Trooper

Score: 6.29
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1573.002 - Asymmetric Cryptography
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

FIN6

Score: 8.48
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 8.00
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1550.003 - Pass the Ticket
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

WIRTE

Score: 3.62
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
MITREへのリンク →

menuPass

Score: 4.73
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1003.003 - NTDS
MITREへのリンク →

Threat Group-3390

Score: 4.36
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
MITREへのリンク →

Gamaredon Group

Score: 21.73
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1480 - Execution Guardrails
  • T1583.006 - Web Services
  • T1102.003 - One-Way Communication
  • T1534 - Internal Spearphishing
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

BITTER

Score: 4.36
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
MITREへのリンク →

Inception

Score: 3.62
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

RTM

Score: 4.16
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Winter Vivern

Score: 7.37
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1584.006 - Web Services
  • T1204.001 - Malicious Link
MITREへのリンク →

APT12

Score: 3.27
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT19

Score: 3.62
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
MITREへのリンク →

Malteiro

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1657 - Financial Theft
MITREへのリンク →

SideCopy

Score: 9.75
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
  • T1584.001 - Domains
MITREへのリンク →

Andariel

Score: 3.33
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.001 - Malware
MITREへのリンク →

APT37

Score: 3.27
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

IndigoZebra

Score: 7.07
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1583.001 - Domains
  • T1583.006 - Web Services
MITREへのリンク →

APT38

Score: 8.29
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1036.006 - Space after Filename
  • T1204.001 - Malicious Link
MITREへのリンク →

HEXANE

Score: 14.46
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1534 - Internal Spearphishing
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

LAPSUS$

Score: 14.63
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1588.001 - Malware
  • T1656 - Impersonation
  • T1578.002 - Create Cloud Instance
  • T1003.003 - NTDS
MITREへのリンク →

TeamTNT

Score: 3.49
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
MITREへのリンク →

BlackByte

Score: 5.82
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1480 - Execution Guardrails
MITREへのリンク →

RedEcho

Score: 4.26
Matched TTPs:
  • T1583.001 - Domains
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Medusa Group

Score: 16.45
Matched TTPs:
  • T1585.002 - Email Accounts
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
  • T1218.014 - MMC
MITREへのリンク →

Aquatic Panda

Score: 6.30
Matched TTPs:
  • T1087 - Account Discovery
  • T1588.001 - Malware
MITREへのリンク →

FIN13

Score: 11.37
Matched TTPs:
  • T1087 - Account Discovery
  • T1657 - Financial Theft
  • T1564.001 - Hidden Files and Directories
  • T1003.003 - NTDS
MITREへのリンク →

Volt Typhoon

Score: 12.42
Matched TTPs:
  • T1074 - Data Staged
  • T1584.005 - Botnet
  • T1584.004 - Server
  • T1003.003 - NTDS
MITREへのリンク →

INC Ransom

Score: 9.43
Matched TTPs:
  • T1074 - Data Staged
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

HAFNIUM

Score: 14.77
Matched TTPs:
  • T1584.005 - Botnet
  • T1583.006 - Web Services
  • T1564.001 - Hidden Files and Directories
  • T1003.003 - NTDS
  • T1550.001 - Application Access Token
MITREへのリンク →

Axiom

Score: 6.91
Matched TTPs:
  • T1584.005 - Botnet
  • T1566 - Phishing
MITREへのリンク →

Storm-0501

Score: 9.40
Matched TTPs:
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

APT17

Score: 5.45
Matched TTPs:
  • T1583.006 - Web Services
  • T1585 - Establish Accounts
MITREへのリンク →

POLONIUM

Score: 4.41
Matched TTPs:
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

TA578

Score: 3.37
Matched TTPs:
  • T1583.006 - Web Services
  • T1204.001 - Malicious Link
MITREへのリンク →

GOLD SOUTHFIELD

Score: 3.29
Matched TTPs:
  • T1566 - Phishing
MITREへのリンク →

Fox Kitten

Score: 5.78
Matched TTPs:
  • T1585 - Establish Accounts
  • T1003.003 - NTDS
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Daggerfly

Score: 4.19
Matched TTPs:
  • T1584.004 - Server
  • T1204.001 - Malicious Link
MITREへのリンク →

Rocke

Score: 5.95
Matched TTPs:
  • T1564.001 - Hidden Files and Directories
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.79
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1598.003 - Spearphishing Link
  • T1584.001 - Domains
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1586.002 - Email Accounts
  • T1585.002 - Email Accounts
  • T1585 - Establish Accounts
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
  • T1102.001 - Dead Drop Resolver
  • T1534 - Internal Spearphishing
  • T1598 - Phishing for Information
  • T1566.001 - Spearphishing Attachment
  • T1566.002 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1566 - Phishing
  • T1583 - Acquire Infrastructure
  • T1656 - Impersonation
  • T1657 - Financial Theft
  • T1588.005 - Exploits
MITREへのリンク →

Sandworm Team

Score: 0.61
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1583.001 - Domains
  • T1585.002 - Email Accounts
  • T1586.001 - Social Media Accounts
  • T1598.003 - Spearphishing Link
  • T1584.005 - Botnet
  • T1566.001 - Spearphishing Attachment
  • T1195 - Supply Chain Compromise
  • T1608.001 - Upload Malware
  • T1003.003 - NTDS
  • T1566.002 - Spearphishing Link
  • T1204.001 - Malicious Link
  • T1583 - Acquire Infrastructure
  • T1491.002 - External Defacement
  • T1584.004 - Server
MITREへのリンク →

APT28

Score: 0.56
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1598 - Phishing for Information
  • T1586.002 - Email Accounts
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
  • T1498 - Network Denial of Service
  • T1550.001 - Application Access Token
  • T1669 - Wi-Fi Networks
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る