Trusted Design

UPATRE/DYRE MALSPAM -SUBJ: SCANNED IMAGE FROM A XEROX WORKCENTRE

概要

Malicious spam (malspam) delivering Upatre/Dyre has been an ongoing issue for quite some time. Many organizations have posted articles about this malware. Upatre is the malware downloader that retrieves Dyre (Dyreza), an information stealer described as a "Zeus-like banking Trojan". Earlier this year, EmergingThreats reported Upatre and Dyre are under constant development , while SecureWorks told us banking botnets continue to deliver this malspam despite previous takedowns. Botnets sending waves of malspam with Upatre as zip file attachments are a near-daily occurrence. Most organizations won't see these emails, because the messages are almost always blocked by spam filters. Because security researchers find Upatre/Dyre malspam nearly every day, it's a bit tiresome to write about, and we sometimes gloss over the information when it comes our way. After all, the malspam is being blocked, right?

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Lazarus Group

Score: 20.56
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1070.006 - Timestomp
  • T1102.002 - Bidirectional Communication
  • T1027.007 - Dynamic API Resolution
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TA577

Score: 5.29
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1566.002 - Spearphishing Link
MITREへのリンク →

Moonstone Sleet

Score: 22.24
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1217 - Browser Information Discovery
  • T1598 - Phishing for Information
  • T1587 - Develop Capabilities
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Scattered Spider

Score: 15.84
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1598.003 - Spearphishing Link
  • T1217 - Browser Information Discovery
  • T1657 - Financial Theft
  • T1598 - Phishing for Information
MITREへのリンク →

FIN4

Score: 6.45
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Ember Bear

Score: 4.13
Matched TTPs:
  • T1491.002 - External Defacement
MITREへのリンク →

Sandworm Team

Score: 23.50
Matched TTPs:
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1584.005 - Botnet
  • T1199 - Trusted Relationship
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Mustard Tempest

Score: 12.50
Matched TTPs:
  • T1583.008 - Malvertising
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1608.006 - SEO Poisoning
MITREへのリンク →

BlackTech

Score: 5.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

MuddyWater

Score: 4.72
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

LuminousMoth

Score: 3.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
MITREへのリンク →

Mofang

Score: 5.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1027.015 - Compression
MITREへのリンク →

Kimsuky

Score: 28.14
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1070.006 - Timestomp
  • T1657 - Financial Theft
  • T1566 - Phishing
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1588.003 - Code Signing Certificates
  • T1587 - Develop Capabilities
MITREへのリンク →

Sidewinder

Score: 10.99
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1124 - System Time Discovery
MITREへのリンク →

FIN7

Score: 9.28
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1124 - System Time Discovery
MITREへのリンク →

Mustang Panda

Score: 16.78
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1070.006 - Timestomp
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN8

Score: 5.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

APT32

Score: 9.50
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1070.006 - Timestomp
MITREへのリンク →

Leviathan

Score: 5.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1027.015 - Compression
MITREへのリンク →

ZIRCONIUM

Score: 12.33
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1124 - System Time Discovery
MITREへのリンク →

EXOTIC LILY

Score: 6.82
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Molerats

Score: 5.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1027.015 - Compression
MITREへのリンク →

Magic Hound

Score: 12.67
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 9.97
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1588.003 - Code Signing Certificates
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Windshift

Score: 4.84
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 14.87
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1070.006 - Timestomp
  • T1199 - Trusted Relationship
  • T1027.006 - HTML Smuggling
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TA2541

Score: 7.45
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1027.015 - Compression
MITREへのリンク →

Earth Lusca

Score: 3.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
MITREへのリンク →

RedCurl

Score: 5.07
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1199 - Trusted Relationship
MITREへのリンク →

Storm-1811

Score: 8.51
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1667 - Email Bombing
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Turla

Score: 6.44
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
  • T1124 - System Time Discovery
MITREへのリンク →

Wizard Spider

Score: 5.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Patchwork

Score: 4.78
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

TA505

Score: 4.29
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
MITREへのリンク →

LazyScripter

Score: 4.29
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
MITREへのリンク →

APT42

Score: 3.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
MITREへのリンク →

APT39

Score: 4.72
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT28

Score: 18.80
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1070.006 - Timestomp
  • T1199 - Trusted Relationship
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Star Blizzard

Score: 8.93
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

CURIUM

Score: 8.45
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 6.95
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

FIN6

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 3.47
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1124 - System Time Discovery
MITREへのリンク →

menuPass

Score: 3.62
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1199 - Trusted Relationship
MITREへのリンク →

Threat Group-3390

Score: 11.90
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1199 - Trusted Relationship
  • T1588.003 - Code Signing Certificates
  • T1027.015 - Compression
MITREへのリンク →

Gamaredon Group

Score: 8.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1027.015 - Compression
MITREへのリンク →

Darkhotel

Score: 3.47
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1124 - System Time Discovery
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Higaisa

Score: 6.62
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1124 - System Time Discovery
  • T1027.015 - Compression
MITREへのリンク →

APT12

Score: 3.27
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Malteiro

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1657 - Financial Theft
MITREへのリンク →

SideCopy

Score: 6.47
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

Andariel

Score: 4.72
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1592.002 - Software
MITREへのリンク →

APT37

Score: 3.27
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT38

Score: 6.91
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1070.006 - Timestomp
  • T1217 - Browser Information Discovery
MITREへのリンク →

The White Company

Score: 3.47
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1124 - System Time Discovery
MITREへのリンク →

HEXANE

Score: 4.37
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Contagious Interview

Score: 10.86
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1657 - Financial Theft
  • T1587 - Develop Capabilities
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 5.34
Matched TTPs:
  • T1070.006 - Timestomp
  • T1124 - System Time Discovery
MITREへのリンク →

Chimera

Score: 8.62
Matched TTPs:
  • T1070.006 - Timestomp
  • T1217 - Browser Information Discovery
  • T1124 - System Time Discovery
MITREへのリンク →

Fox Kitten

Score: 3.29
Matched TTPs:
  • T1217 - Browser Information Discovery
MITREへのリンク →

Volt Typhoon

Score: 9.50
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1584.005 - Botnet
  • T1124 - System Time Discovery
MITREへのリンク →

HAFNIUM

Score: 6.37
Matched TTPs:
  • T1584.005 - Botnet
  • T1199 - Trusted Relationship
MITREへのリンク →

Axiom

Score: 6.91
Matched TTPs:
  • T1584.005 - Botnet
  • T1566 - Phishing
MITREへのリンク →

INC Ransom

Score: 5.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

Medusa Group

Score: 7.06
Matched TTPs:
  • T1657 - Financial Theft
  • T1218.014 - MMC
MITREへのリンク →

GOLD SOUTHFIELD

Score: 6.03
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1566 - Phishing
MITREへのリンク →

POLONIUM

Score: 5.14
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Sea Turtle

Score: 6.03
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1566 - Phishing
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.82
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1588.003 - Code Signing Certificates
  • T1587 - Develop Capabilities
  • T1566.001 - Spearphishing Attachment
  • T1566 - Phishing
  • T1070.006 - Timestomp
  • T1598 - Phishing for Information
  • T1608.001 - Upload Malware
  • T1657 - Financial Theft
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Sandworm Team

Score: 0.71
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1584.005 - Botnet
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1592.002 - Software
  • T1491.002 - External Defacement
  • T1199 - Trusted Relationship
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Moonstone Sleet

Score: 0.69
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1587 - Develop Capabilities
  • T1566.001 - Spearphishing Attachment
  • T1027.009 - Embedded Payloads
  • T1598 - Phishing for Information
  • T1608.001 - Upload Malware
  • T1566.003 - Spearphishing via Service
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Lazarus Group

Score: 0.61
Matched TTPs:
  • T1027.007 - Dynamic API Resolution
  • T1102.002 - Bidirectional Communication
  • T1566.001 - Spearphishing Attachment
  • T1070.006 - Timestomp
  • T1027.009 - Embedded Payloads
  • T1566.003 - Spearphishing via Service
  • T1566.002 - Spearphishing Link
  • T1124 - System Time Discovery
MITREへのリンク →

APT28

Score: 0.58
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1566.001 - Spearphishing Attachment
  • T1070.006 - Timestomp
  • T1598 - Phishing for Information
  • T1199 - Trusted Relationship
  • T1211 - Exploitation for Defense Evasion
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る