Trusted Design

Inside the spyware campaign against Argentine troublemakers

概要

Alberto Nisman, the Argentine prosecutor known for doggedly investigating a 1994 Buenos Aires bombing, was targeted by invasive spy software downloaded onto his cellular phone shortly before his mysterious death. The software masqueraded as a confidential document and was intended to infect a Windows computer. An investigation by The Intercept indicates that this targeting was likely not an isolated event. The person or persons behind the attempted monitoring appear to have run other surveillance operations involving various locations throughout South America, at least one apparently targeting a rabble-rousing Argentine journalist. In the process, they created at least four distinct spyware bundles, all communicating with the same server set to receive Nisman’s data. They also left traces showing that their operations were active as recently as March, raising the possibility that the online spying continues today.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 8.61
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1218.010 - Regsvr32
  • T1680 - Local Storage Discovery
MITREへのリンク →

Sea Turtle

Score: 4.53
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 4.53
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Indrik Spider

Score: 6.88
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1136 - Create Account
MITREへのリンク →

Agrius

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Contagious Interview

Score: 12.44
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1681 - Search Threat Vendor Data
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Sandworm Team

Score: 10.71
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
MITREへのリンク →

Star Blizzard

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1659 - Content Injection
MITREへのリンク →

UNC3886

Score: 5.63
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Volt Typhoon

Score: 13.84
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1614 - System Location Discovery
  • T1003.003 - NTDS
  • T1680 - Local Storage Discovery
MITREへのリンク →

APT29

Score: 7.86
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT32

Score: 10.83
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

BRONZE BUTLER

Score: 5.34
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Darkhotel

Score: 5.63
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

FIN7

Score: 4.13
Matched TTPs:
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

Gamaredon Group

Score: 7.69
Matched TTPs:
  • T1001 - Data Obfuscation
  • T1221 - Template Injection
MITREへのリンク →

Cobalt Group

Score: 6.99
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Blue Mockingbird

Score: 7.28
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1574.012 - COR_PROFILER
MITREへのリンク →

Leviathan

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Inception

Score: 7.39
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Magic Hound

Score: 6.37
Matched TTPs:
  • T1592.002 - Software
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Andariel

Score: 5.34
Matched TTPs:
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT28

Score: 11.12
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1003.003 - NTDS
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Dragonfly

Score: 6.99
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1003.003 - NTDS
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Lazarus Group

Score: 13.73
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1680 - Local Storage Discovery
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Confucius

Score: 7.48
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1680 - Local Storage Discovery
MITREへのリンク →

Patchwork

Score: 4.33
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1680 - Local Storage Discovery
MITREへのリンク →

Higaisa

Score: 4.33
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1680 - Local Storage Discovery
MITREへのリンク →

Mustang Panda

Score: 10.71
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1003.003 - NTDS
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Tropic Trooper

Score: 10.22
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1221 - Template Injection
  • T1680 - Local Storage Discovery
MITREへのリンク →

APT41

Score: 3.83
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
MITREへのリンク →

OilRig

Score: 14.05
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1137.004 - Outlook Home Page
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT33

Score: 4.24
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Medusa Group

Score: 5.09
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
MITREへのリンク →

FIN6

Score: 10.36
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN8

Score: 5.49
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

SideCopy

Score: 4.13
Matched TTPs:
  • T1614 - System Location Discovery
MITREへのリンク →

DarkHydrus

Score: 3.15
Matched TTPs:
  • T1221 - Template Injection
MITREへのリンク →

Scattered Spider

Score: 10.72
Matched TTPs:
  • T1136 - Create Account
  • T1538 - Cloud Service Dashboard
  • T1003.003 - NTDS
MITREへのリンク →

Salt Typhoon

Score: 6.59
Matched TTPs:
  • T1136 - Create Account
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Chimera

Score: 5.17
Matched TTPs:
  • T1003.003 - NTDS
  • T1680 - Local Storage Discovery
MITREへのリンク →

Wizard Spider

Score: 5.09
Matched TTPs:
  • T1003.003 - NTDS
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

ToddyCat

Score: 5.36
Matched TTPs:
  • T1680 - Local Storage Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.83
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1203 - Exploitation for Client Execution
  • T1680 - Local Storage Discovery
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Volt Typhoon

Score: 0.81
Matched TTPs:
  • T1614 - System Location Discovery
  • T1680 - Local Storage Discovery
  • T1003.003 - NTDS
  • T1590.006 - Network Security Appliances
MITREへのリンク →

OilRig

Score: 0.78
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1203 - Exploitation for Client Execution
  • T1137.004 - Outlook Home Page
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Contagious Interview

Score: 0.73
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1583 - Acquire Infrastructure
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

APT28

Score: 0.68
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
  • T1221 - Template Injection
MITREへのリンク →

APT32

Score: 0.66
Matched TTPs:
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Sandworm Team

Score: 0.65
Matched TTPs:
  • T1003.003 - NTDS
  • T1583 - Acquire Infrastructure
  • T1203 - Exploitation for Client Execution
  • T1592.002 - Software
MITREへのリンク →

Scattered Spider

Score: 0.65
Matched TTPs:
  • T1136 - Create Account
  • T1538 - Cloud Service Dashboard
  • T1003.003 - NTDS
MITREへのリンク →

Mustang Panda

Score: 0.64
Matched TTPs:
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1003.003 - NTDS
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN6

Score: 0.62
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
MITREへのリンク →

Tropic Trooper

Score: 0.60
Matched TTPs:
  • T1680 - Local Storage Discovery
  • T1573.002 - Asymmetric Cryptography
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Kimsuky

Score: 0.56
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1680 - Local Storage Discovery
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る