Trusted Design

Satellite Turla: APT Command and Control in the Sky

概要

Also known as Snake or Uroburos, names which come from its top class rootkit, the Turla cyber-espionage group has been active for more than 8 years. Several papers have been published about the group’s operations, but until the Epic Turla research was published by Kaspersky Lab, little information was available about the more unusual aspects of their operations, such as the first stages of infection through watering-hole attacks. What makes the Turla group special is not just the complexity of its tools, which include the Uroboros rootkit, aka “Snake”, as well as mechanisms designed to bypass air gaps through multi-stage proxy networks inside LANs, but the exquisite satellite-based C&C mechanism used in the latter stages of the attack.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 10.12
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Sea Turtle

Score: 6.00
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 6.00
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Indrik Spider

Score: 3.81
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Agrius

Score: 4.50
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Contagious Interview

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Sandworm Team

Score: 9.11
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

Star Blizzard

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Winnti Group

Score: 4.06
Matched TTPs:
  • T1014 - Rootkit
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT41

Score: 17.48
Matched TTPs:
  • T1014 - Rootkit
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1104 - Multi-Stage Channels
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

Rocke

Score: 8.97
Matched TTPs:
  • T1014 - Rootkit
  • T1071 - Application Layer Protocol
  • T1190 - Exploit Public-Facing Application
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TeamTNT

Score: 7.50
Matched TTPs:
  • T1014 - Rootkit
  • T1071 - Application Layer Protocol
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT28

Score: 21.19
Matched TTPs:
  • T1014 - Rootkit
  • T1190 - Exploit Public-Facing Application
  • T1090.002 - External Proxy
  • T1203 - Exploitation for Client Execution
  • T1498 - Network Denial of Service
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1669 - Wi-Fi Networks
MITREへのリンク →

UNC3886

Score: 10.94
Matched TTPs:
  • T1014 - Rootkit
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

HAFNIUM

Score: 8.43
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

APT5

Score: 5.31
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Ke3chang

Score: 10.83
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

Magic Hound

Score: 11.40
Matched TTPs:
  • T1071 - Application Layer Protocol
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1036.010 - Masquerade Account Name
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

INC Ransom

Score: 11.71
Matched TTPs:
  • T1071 - Application Layer Protocol
  • T1190 - Exploit Public-Facing Application
  • T1074 - Data Staged
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Velvet Ant

Score: 11.51
Matched TTPs:
  • T1071 - Application Layer Protocol
  • T1573.002 - Asymmetric Cryptography
  • T1569.002 - Service Execution
  • T1090.001 - Internal Proxy
MITREへのリンク →

Threat Group-3390

Score: 7.87
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN7

Score: 9.33
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Volt Typhoon

Score: 17.01
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1074 - Data Staged
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

BackdoorDiplomacy

Score: 4.34
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN13

Score: 9.61
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1090.001 - Internal Proxy
MITREへのリンク →

Medusa Group

Score: 13.86
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

Storm-0501

Score: 6.31
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
MITREへのリンク →

Fox Kitten

Score: 9.97
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

BlackByte

Score: 4.64
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

menuPass

Score: 10.62
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090.002 - External Proxy
  • T1036.003 - Rename Legitimate Utilities
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

Blue Mockingbird

Score: 6.61
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
  • T1569.002 - Service Execution
MITREへのリンク →

GALLIUM

Score: 8.28
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090.002 - External Proxy
  • T1036.003 - Rename Legitimate Utilities
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Winter Vivern

Score: 4.34
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT29

Score: 6.49
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090.002 - External Proxy
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Leviathan

Score: 6.49
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Dragonfly

Score: 9.70
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

Axiom

Score: 7.50
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1001.002 - Steganography
MITREへのリンク →

MuddyWater

Score: 10.11
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090.002 - External Proxy
  • T1104 - Multi-Stage Channels
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT39

Score: 10.32
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090.002 - External Proxy
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1090.001 - Internal Proxy
MITREへのリンク →

APT38

Score: 9.75
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1036.003 - Rename Legitimate Utilities
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Scattered Spider

Score: 10.02
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1074 - Data Staged
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

Moonstone Sleet

Score: 6.46
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Chimera

Score: 11.39
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Tonto Team

Score: 5.02
Matched TTPs:
  • T1090.002 - External Proxy
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Lazarus Group

Score: 19.54
Matched TTPs:
  • T1090.002 - External Proxy
  • T1036.004 - Masquerade Task or Service
  • T1104 - Multi-Stage Channels
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

APT3

Score: 12.26
Matched TTPs:
  • T1090.002 - External Proxy
  • T1104 - Multi-Stage Channels
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Silence

Score: 5.92
Matched TTPs:
  • T1090.002 - External Proxy
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

APT32

Score: 12.80
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Wizard Spider

Score: 15.37
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1074 - Data Staged
  • T1552.006 - Group Policy Preferences
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

BITTER

Score: 4.37
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN6

Score: 9.58
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1573.002 - Asymmetric Cryptography
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

ZIRCONIUM

Score: 5.46
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
MITREへのリンク →

Higaisa

Score: 9.11
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

APT33

Score: 6.40
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Gamaredon Group

Score: 5.31
Matched TTPs:
  • T1001 - Data Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TA551

Score: 3.52
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Cobalt Group

Score: 7.76
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Inception

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

WIRTE

Score: 3.52
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Daggerfly

Score: 4.06
Matched TTPs:
  • T1036.003 - Rename Legitimate Utilities
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Sidewinder

Score: 4.86
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
MITREへのリンク →

The White Company

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Mustang Panda

Score: 4.61
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

BRONZE BUTLER

Score: 4.86
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
MITREへのリンク →

Tropic Trooper

Score: 5.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Darkhotel

Score: 4.86
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
MITREへのリンク →

OilRig

Score: 5.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TA2541

Score: 3.52
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN8

Score: 3.52
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Storm-1811

Score: 4.40
Matched TTPs:
  • T1036.010 - Masquerade Account Name
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 7.06
Matched TTPs:
  • T1564.005 - Hidden File System
  • T1090.001 - Internal Proxy
MITREへのリンク →

Mustard Tempest

Score: 5.31
Matched TTPs:
  • T1608.006 - SEO Poisoning
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Turla

Score: 6.30
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.82
Matched TTPs:
  • T1090.002 - External Proxy
  • T1669 - Wi-Fi Networks
  • T1498 - Network Denial of Service
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1014 - Rootkit
MITREへのリンク →

Lazarus Group

Score: 0.75
Matched TTPs:
  • T1090.002 - External Proxy
  • T1104 - Multi-Stage Channels
  • T1124 - System Time Discovery
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1090.001 - Internal Proxy
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT41

Score: 0.70
Matched TTPs:
  • T1104 - Multi-Stage Channels
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1569.002 - Service Execution
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
  • T1014 - Rootkit
MITREへのリンク →

Volt Typhoon

Score: 0.69
Matched TTPs:
  • T1074 - Data Staged
  • T1217 - Browser Information Discovery
  • T1190 - Exploit Public-Facing Application
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

Wizard Spider

Score: 0.62
Matched TTPs:
  • T1074 - Data Staged
  • T1569.002 - Service Execution
  • T1036.004 - Masquerade Task or Service
  • T1552.006 - Group Policy Preferences
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

Medusa Group

Score: 0.58
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1190 - Exploit Public-Facing Application
  • T1573.002 - Asymmetric Cryptography
  • T1569.002 - Service Execution
  • T1105 - Ingress Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

APT32

Score: 0.56
Matched TTPs:
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1569.002 - Service Execution
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る