Trusted Design

Defending the White Elephant

概要

Myanmar is a country currently engaged in an important political process. A pro-democracy reform took place in 2011 which has helped the government create an atmopshere conducive to investor interest. APT groups from multiple countries – including China – have been known to target organizations of strategic interest with aggressive malware-based espionage campaigns. One of the malware families used in such a scenario is the well-known Remote Access Trojan PlugX, also known as Korplug, that enables full access to the victim’s machine and network. Multiple instances of PlugX and related downloader malware were recently observed to be hosted on a Myanmar government website. Arbor ASERT provided information to the Myanmar CERT to help remediate the situation at hand in early August of 2015.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 25.92
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1027.014 - Polymorphic Code
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1003.003 - NTDS
MITREへのリンク →

Sea Turtle

Score: 9.59
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Ember Bear

Score: 20.57
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1564.008 - Email Hiding Rules
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

Indrik Spider

Score: 10.62
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1498 - Network Denial of Service
  • T1622 - Debugger Evasion
MITREへのリンク →

Agrius

Score: 7.72
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

Contagious Interview

Score: 27.34
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1021.006 - Windows Remote Management
  • T1218.008 - Odbcconf
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1221 - Template Injection
  • T1547.008 - LSASS Driver
MITREへのリンク →

Sandworm Team

Score: 32.32
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1564.008 - Email Hiding Rules
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1187 - Forced Authentication
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
MITREへのリンク →

Star Blizzard

Score: 8.20
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
MITREへのリンク →

FIN13

Score: 7.63
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Moonstone Sleet

Score: 13.43
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1565 - Data Manipulation
  • T1573 - Encrypted Channel
  • T1547.008 - LSASS Driver
MITREへのリンク →

Lazarus Group

Score: 23.02
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
MITREへのリンク →

OilRig

Score: 21.89
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1212 - Exploitation for Credential Access
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
MITREへのリンク →

UNC3886

Score: 14.24
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

LuminousMoth

Score: 7.38
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Salt Typhoon

Score: 8.26
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1498 - Network Denial of Service
MITREへのリンク →

APT29

Score: 19.78
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1218.009 - Regsvcs/Regasm
  • T1537 - Transfer Data to Cloud Account
  • T1547.008 - LSASS Driver
MITREへのリンク →

Play

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Aoqin Dragon

Score: 6.49
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

RedCurl

Score: 7.59
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1122 - Component Object Model Hijacking
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Cleaver

Score: 5.29
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Turla

Score: 16.49
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
  • T1212 - Exploitation for Credential Access
  • T1199 - Trusted Relationship
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

Ke3chang

Score: 5.98
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Mustang Panda

Score: 25.95
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1136.001 - Local Account
  • T1569.001 - Launchctl
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1055.005 - Thread Local Storage
MITREへのリンク →

TeamTNT

Score: 7.69
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

FIN7

Score: 17.14
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

BRONZE BUTLER

Score: 11.01
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1159 - Launch Agent
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT39

Score: 7.59
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

WIRTE

Score: 5.16
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

APT38

Score: 6.24
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1059.012 - Hypervisor CLI
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Volt Typhoon

Score: 16.08
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1212 - Exploitation for Credential Access
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
  • T1159 - Launch Agent
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

Darkhotel

Score: 7.42
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

Earth Lusca

Score: 12.10
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Storm-1811

Score: 4.94
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

ZIRCONIUM

Score: 8.22
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1608.005 - Link Target
  • T1537 - Transfer Data to Cloud Account
  • T1578.001 - Create Snapshot
MITREへのリンク →

MuddyWater

Score: 10.14
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
MITREへのリンク →

Gamaredon Group

Score: 6.40
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
MITREへのリンク →

TA505

Score: 8.90
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Threat Group-3390

Score: 20.98
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

APT28

Score: 20.57
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1546.007 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Winter Vivern

Score: 4.80
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

menuPass

Score: 8.28
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

BlackByte

Score: 6.66
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

Leviathan

Score: 13.03
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1565 - Data Manipulation
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

Cinnamon Tempest

Score: 3.89
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Rocke

Score: 5.09
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Tropic Trooper

Score: 8.55
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1159 - Launch Agent
MITREへのリンク →

APT19

Score: 6.93
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Higaisa

Score: 5.65
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

TA2541

Score: 12.09
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Mustard Tempest

Score: 3.74
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

LazyScripter

Score: 6.44
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
MITREへのリンク →

SideCopy

Score: 4.72
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1159 - Launch Agent
MITREへのリンク →

BITTER

Score: 4.32
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

APT32

Score: 13.18
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

HEXANE

Score: 12.71
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1212 - Exploitation for Credential Access
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1159 - Launch Agent
  • T1622 - Debugger Evasion
MITREへのリンク →

Saint Bear

Score: 7.53
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

EXOTIC LILY

Score: 8.33
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1565 - Data Manipulation
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT42

Score: 5.57
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

BackdoorDiplomacy

Score: 4.78
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

GOLD SOUTHFIELD

Score: 7.14
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1573 - Encrypted Channel
MITREへのリンク →

BlackTech

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Magic Hound

Score: 16.45
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1187 - Forced Authentication
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
MITREへのリンク →

Medusa Group

Score: 21.79
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1128 - Netsh Helper DLL
  • T1598 - Phishing for Information
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Storm-0501

Score: 10.40
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.015 - Electron Applications
  • T1027.014 - Polymorphic Code
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Fox Kitten

Score: 5.46
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1565 - Data Manipulation
  • T1622 - Debugger Evasion
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Blue Mockingbird

Score: 11.25
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
  • T1001.001 - Junk Data
MITREへのリンク →

GALLIUM

Score: 4.37
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

INC Ransom

Score: 3.97
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Dragonfly

Score: 10.15
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

Axiom

Score: 10.91
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

APT41

Score: 10.44
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

HAFNIUM

Score: 10.07
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.008 - Odbcconf
  • T1608.005 - Link Target
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

APT5

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

Scattered Spider

Score: 15.27
Matched TTPs:
  • T1218.015 - Electron Applications
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1498 - Network Denial of Service
  • T1622 - Debugger Evasion
MITREへのリンク →

LAPSUS$

Score: 9.90
Matched TTPs:
  • T1218.008 - Odbcconf
  • T1136.002 - Domain Account
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
MITREへのリンク →

Metador

Score: 3.31
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

APT1

Score: 4.96
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Aquatic Panda

Score: 4.96
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Andariel

Score: 9.56
Matched TTPs:
  • T1136.002 - Domain Account
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Confucius

Score: 3.51
Matched TTPs:
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

POLONIUM

Score: 5.61
Matched TTPs:
  • T1608.005 - Link Target
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
MITREへのリンク →

APT33

Score: 6.48
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Wizard Spider

Score: 6.63
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Tonto Team

Score: 4.65
Matched TTPs:
  • T1212 - Exploitation for Credential Access
  • T1218.010 - Regsvr32
MITREへのリンク →

admin@338

Score: 4.65
Matched TTPs:
  • T1212 - Exploitation for Credential Access
  • T1218.010 - Regsvr32
MITREへのリンク →

Chimera

Score: 8.24
Matched TTPs:
  • T1212 - Exploitation for Credential Access
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

Inception

Score: 7.83
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
MITREへのリンク →

FIN8

Score: 5.24
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN6

Score: 7.77
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
MITREへのリンク →

Patchwork

Score: 7.81
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Cobalt Group

Score: 12.41
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
MITREへのリンク →

CURIUM

Score: 9.22
Matched TTPs:
  • T1565 - Data Manipulation
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
MITREへのリンク →

Daggerfly

Score: 4.69
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Sidewinder

Score: 6.83
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1578.001 - Create Snapshot
MITREへのリンク →

The White Company

Score: 6.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT37

Score: 3.26
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT3

Score: 5.19
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Transparent Tribe

Score: 3.26
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Elderwood

Score: 5.31
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Windshift

Score: 7.03
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1159 - Launch Agent
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dark Caracal

Score: 6.34
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1537 - Transfer Data to Cloud Account
  • T1547.008 - LSASS Driver
MITREへのリンク →

Windigo

Score: 4.51
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1159 - Launch Agent
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.84
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1005 - Data from Local System
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1573 - Encrypted Channel
  • T1122 - Component Object Model Hijacking
  • T1187 - Forced Authentication
  • T1564.008 - Email Hiding Rules
  • T1565 - Data Manipulation
  • T1218.010 - Regsvr32
MITREへのリンク →

Contagious Interview

Score: 0.71
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1221 - Template Injection
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1606.002 - SAML Tokens
  • T1218.008 - Odbcconf
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1021.006 - Windows Remote Management
  • T1565 - Data Manipulation
MITREへのリンク →

Kimsuky

Score: 0.70
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1565 - Data Manipulation
  • T1003.003 - NTDS
  • T1622 - Debugger Evasion
MITREへのリンク →

Mustang Panda

Score: 0.70
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1569.001 - Launchctl
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1136.001 - Local Account
  • T1055.005 - Thread Local Storage
MITREへのリンク →

Lazarus Group

Score: 0.64
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1608.005 - Link Target
  • T1578.001 - Create Snapshot
  • T1565 - Data Manipulation
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1055.005 - Thread Local Storage
MITREへのリンク →

Medusa Group

Score: 0.62
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
  • T1218.003 - CMSTP
  • T1598 - Phishing for Information
  • T1608.005 - Link Target
  • T1565 - Data Manipulation
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
MITREへのリンク →

OilRig

Score: 0.61
Matched TTPs:
  • T1212 - Exploitation for Credential Access
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1005 - Data from Local System
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
MITREへのリンク →

Threat Group-3390

Score: 0.60
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1218.003 - CMSTP
  • T1122 - Component Object Model Hijacking
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
MITREへのリンク →

APT28

Score: 0.58
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1566.003 - Spearphishing via Service
  • T1059.010 - AutoHotKey & AutoIT
  • T1122 - Component Object Model Hijacking
  • T1608.005 - Link Target
  • T1546.007 - Netsh Helper DLL
  • T1218.010 - Regsvr32
MITREへのリンク →

APT29

Score: 0.55
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1537 - Transfer Data to Cloud Account
  • T1547.008 - LSASS Driver
  • T1606.002 - SAML Tokens
  • T1122 - Component Object Model Hijacking
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1218.009 - Regsvcs/Regasm
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る