Trusted Design

Operation Iron Tiger

概要

Key individuals, who are believed to be part of a China-based attack group, have been stealing years of valuable government and corporate information from defense and high technology organizations in the US since 2013 and political and government-related entities in China, Hong Kong, and the Philippines since 2010. This shift in targets is highly notable for the active cyber espionage operation we dubbed as “Operation Iron Tiger.” We believe that the threat actors have simply moved up in the food chain and were assigned new, high-level targets to spy on–all as part of a bigger espionage campaign. US defense contractors were only fairly recent targets based on the operation’s history, which we traced to spear-phishing in 2010. “Foreign policy,” “future of the US Army Officer Corps,” and “economic development” are only a few of the keywords that threat actors have been using in spear-phishing attacks against directors and project managers of technology-inclined US government contractors.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

LAPSUS$

Score: 22.58
Matched TTPs:
  • T1216.001 - PubPrn
  • T1193 - Spearphishing Attachment
  • T1136.002 - Domain Account
  • T1122 - Component Object Model Hijacking
  • T1030 - Data Transfer Size Limits
  • T1065 - Uncommonly Used Port
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Contagious Interview

Score: 31.57
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1021.006 - Windows Remote Management
  • T1552.003 - Shell History
  • T1562.010 - Downgrade Attack
  • T1102.003 - One-Way Communication
  • T1690 - Prevent Command History Logging
  • T1030 - Data Transfer Size Limits
  • T1126 - Network Share Connection Removal
  • T1547.008 - LSASS Driver
MITREへのリンク →

Ember Bear

Score: 10.44
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1005 - Data from Local System
  • T1136.002 - Domain Account
MITREへのリンク →

Sandworm Team

Score: 29.78
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1114 - Email Collection
  • T1566.002 - Spearphishing Link
  • T1005 - Data from Local System
  • T1193 - Spearphishing Attachment
  • T1546.008 - Accessibility Features
  • T1122 - Component Object Model Hijacking
  • T1102.003 - One-Way Communication
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Silent Librarian

Score: 9.59
Matched TTPs:
  • T1114 - Email Collection
  • T1566.002 - Spearphishing Link
  • T1546.008 - Accessibility Features
MITREへのリンク →

Kimsuky

Score: 39.28
Matched TTPs:
  • T1114 - Email Collection
  • T1566.002 - Spearphishing Link
  • T1546.008 - Accessibility Features
  • T1552.003 - Shell History
  • T1057 - Process Discovery
  • T1102.003 - One-Way Communication
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1690 - Prevent Command History Logging
  • T1030 - Data Transfer Size Limits
  • T1197 - BITS Jobs
  • T1526 - Cloud Service Discovery
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Volt Typhoon

Score: 23.80
Matched TTPs:
  • T1114 - Email Collection
  • T1057 - Process Discovery
  • T1552.008 - Chat Messages
  • T1102.003 - One-Way Communication
  • T1065 - Uncommonly Used Port
  • T1574.002 - DLL Side-Loading
  • T1548.006 - TCC Manipulation
MITREへのリンク →

EXOTIC LILY

Score: 14.19
Matched TTPs:
  • T1114 - Email Collection
  • T1149 - LC_MAIN Hijacking
  • T1690 - Prevent Command History Logging
  • T1547.008 - LSASS Driver
MITREへのリンク →

TA578

Score: 3.29
Matched TTPs:
  • T1114 - Email Collection
MITREへのリンク →

Sidewinder

Score: 6.08
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
MITREへのリンク →

Scattered Spider

Score: 20.79
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1136.002 - Domain Account
  • T1552.003 - Shell History
  • T1030 - Data Transfer Size Limits
  • T1197 - BITS Jobs
  • T1027.002 - Software Packing
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Mustang Panda

Score: 11.24
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1102.003 - One-Way Communication
  • T1526 - Cloud Service Discovery
  • T1548.006 - TCC Manipulation
MITREへのリンク →

ZIRCONIUM

Score: 5.90
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1197 - BITS Jobs
MITREへのリンク →

APT32

Score: 8.70
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1592.004 - Client Configurations
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Magic Hound

Score: 9.52
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1098.002 - Additional Email Delegate Permissions
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT28

Score: 23.35
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1057 - Process Discovery
  • T1122 - Component Object Model Hijacking
  • T1197 - BITS Jobs
  • T1146 - Clear Command History
  • T1588.003 - Code Signing Certificates
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Star Blizzard

Score: 9.37
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
  • T1102.003 - One-Way Communication
MITREへのリンク →

Moonstone Sleet

Score: 17.95
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1057 - Process Discovery
  • T1197 - BITS Jobs
  • T1126 - Network Share Connection Removal
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 4.98
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dragonfly

Score: 12.27
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1193 - Spearphishing Attachment
  • T1657 - Financial Theft
  • T1548.006 - TCC Manipulation
MITREへのリンク →

OilRig

Score: 13.36
Matched TTPs:
  • T1005 - Data from Local System
  • T1055.012 - Process Hollowing
  • T1526 - Cloud Service Discovery
  • T1547.008 - LSASS Driver
MITREへのリンク →

UNC3886

Score: 6.59
Matched TTPs:
  • T1021.006 - Windows Remote Management
  • T1136.002 - Domain Account
MITREへのリンク →

Turla

Score: 6.30
Matched TTPs:
  • T1136.002 - Domain Account
  • T1055.012 - Process Hollowing
MITREへのリンク →

APT29

Score: 9.11
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1122 - Component Object Model Hijacking
  • T1547.008 - LSASS Driver
MITREへのリンク →

BRONZE BUTLER

Score: 3.84
Matched TTPs:
  • T1592.004 - Client Configurations
MITREへのリンク →

INC Ransom

Score: 8.21
Matched TTPs:
  • T1552.003 - Shell History
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN13

Score: 4.86
Matched TTPs:
  • T1552.003 - Shell History
  • T1548.006 - TCC Manipulation
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1552.003 - Shell History
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Medusa Group

Score: 7.26
Matched TTPs:
  • T1552.003 - Shell History
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BlackByte

Score: 6.24
Matched TTPs:
  • T1562.010 - Downgrade Attack
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Gamaredon Group

Score: 3.84
Matched TTPs:
  • T1562.010 - Downgrade Attack
MITREへのリンク →

SideCopy

Score: 3.62
Matched TTPs:
  • T1657 - Financial Theft
MITREへのリンク →

APT33

Score: 4.13
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
MITREへのリンク →

Wizard Spider

Score: 12.02
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1526 - Cloud Service Discovery
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Lazarus Group

Score: 5.81
Matched TTPs:
  • T1057 - Process Discovery
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN7

Score: 9.30
Matched TTPs:
  • T1057 - Process Discovery
  • T1065 - Uncommonly Used Port
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Indrik Spider

Score: 3.84
Matched TTPs:
  • T1552.008 - Chat Messages
MITREへのリンク →

HAFNIUM

Score: 8.93
Matched TTPs:
  • T1552.008 - Chat Messages
  • T1122 - Component Object Model Hijacking
  • T1548.006 - TCC Manipulation
MITREへのリンク →

GOLD SOUTHFIELD

Score: 6.03
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Threat Group-3390

Score: 5.90
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1526 - Cloud Service Discovery
MITREへのリンク →

menuPass

Score: 5.09
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Sea Turtle

Score: 6.03
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Axiom

Score: 3.29
Matched TTPs:
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Chimera

Score: 8.58
Matched TTPs:
  • T1055.012 - Process Hollowing
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Storm-1811

Score: 5.56
Matched TTPs:
  • T1030 - Data Transfer Size Limits
  • T1547.008 - LSASS Driver
MITREへのリンク →

Saint Bear

Score: 3.03
Matched TTPs:
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

APT42

Score: 3.03
Matched TTPs:
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

APT41

Score: 11.91
Matched TTPs:
  • T1030 - Data Transfer Size Limits
  • T1574.002 - DLL Side-Loading
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1065 - Uncommonly Used Port
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

BlackTech

Score: 3.15
Matched TTPs:
  • T1526 - Cloud Service Discovery
MITREへのリンク →

FIN8

Score: 3.15
Matched TTPs:
  • T1526 - Cloud Service Discovery
MITREへのリンク →

FIN6

Score: 7.26
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Ke3chang

Score: 4.74
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.85
Matched TTPs:
  • T1126 - Network Share Connection Removal
  • T1552.003 - Shell History
  • T1102.003 - One-Way Communication
  • T1057 - Process Discovery
  • T1546.008 - Accessibility Features
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1690 - Prevent Command History Logging
  • T1566.002 - Spearphishing Link
  • T1197 - BITS Jobs
  • T1030 - Data Transfer Size Limits
  • T1526 - Cloud Service Discovery
  • T1114 - Email Collection
MITREへのリンク →

Sandworm Team

Score: 0.68
Matched TTPs:
  • T1102.003 - One-Way Communication
  • T1564.008 - Email Hiding Rules
  • T1546.008 - Accessibility Features
  • T1122 - Component Object Model Hijacking
  • T1005 - Data from Local System
  • T1548.006 - TCC Manipulation
  • T1193 - Spearphishing Attachment
  • T1566.002 - Spearphishing Link
  • T1114 - Email Collection
MITREへのリンク →

Contagious Interview

Score: 0.67
Matched TTPs:
  • T1021.006 - Windows Remote Management
  • T1552.003 - Shell History
  • T1126 - Network Share Connection Removal
  • T1102.003 - One-Way Communication
  • T1690 - Prevent Command History Logging
  • T1562.010 - Downgrade Attack
  • T1547.008 - LSASS Driver
  • T1030 - Data Transfer Size Limits
  • T1044 - File System Permissions Weakness
MITREへのリンク →

Volt Typhoon

Score: 0.57
Matched TTPs:
  • T1102.003 - One-Way Communication
  • T1057 - Process Discovery
  • T1574.002 - DLL Side-Loading
  • T1548.006 - TCC Manipulation
  • T1552.008 - Chat Messages
  • T1114 - Email Collection
  • T1065 - Uncommonly Used Port
MITREへのリンク →

APT28

Score: 0.55
Matched TTPs:
  • T1146 - Clear Command History
  • T1057 - Process Discovery
  • T1122 - Component Object Model Hijacking
  • T1548.006 - TCC Manipulation
  • T1566.002 - Spearphishing Link
  • T1197 - BITS Jobs
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る