Trusted Design

Operation Iron Tiger

概要

Key individuals, who are believed to be part of a China-based attack group, have been stealing years of valuable government and corporate information from defense and high technology organizations in the US since 2013 and political and government-related entities in China, Hong Kong, and the Philippines since 2010. This shift in targets is highly notable for the active cyber espionage operation we dubbed as “Operation Iron Tiger.” We believe that the threat actors have simply moved up in the food chain and were assigned new, high-level targets to spy on–all as part of a bigger espionage campaign. US defense contractors were only fairly recent targets based on the operation’s history, which we traced to spear-phishing in 2010. “Foreign policy,” “future of the US Army Officer Corps,” and “economic development” are only a few of the keywords that threat actors have been using in spear-phishing attacks against directors and project managers of technology-inclined US government contractors.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

LAPSUS$

Score: 22.58
Matched TTPs:
  • T1597.002 - Purchase Technical Data
  • T1591.002 - Business Relationships
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1656 - Impersonation
  • T1591.004 - Identify Roles
  • T1003.003 - NTDS
MITREへのリンク →

Contagious Interview

Score: 31.57
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1681 - Search Threat Vendor Data
  • T1657 - Financial Theft
  • T1480 - Execution Guardrails
  • T1593 - Search Open Websites/Domains
  • T1593.001 - Social Media
  • T1656 - Impersonation
  • T1587 - Develop Capabilities
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ember Bear

Score: 10.44
Matched TTPs:
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1588.001 - Malware
MITREへのリンク →

Sandworm Team

Score: 29.78
Matched TTPs:
  • T1491.002 - External Defacement
  • T1594 - Search Victim-Owned Websites
  • T1598.003 - Spearphishing Link
  • T1195 - Supply Chain Compromise
  • T1591.002 - Business Relationships
  • T1589.003 - Employee Names
  • T1199 - Trusted Relationship
  • T1593 - Search Open Websites/Domains
  • T1003.003 - NTDS
MITREへのリンク →

Silent Librarian

Score: 9.59
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1598.003 - Spearphishing Link
  • T1589.003 - Employee Names
MITREへのリンク →

Kimsuky

Score: 39.28
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1598.003 - Spearphishing Link
  • T1589.003 - Employee Names
  • T1657 - Financial Theft
  • T1591 - Gather Victim Org Information
  • T1593 - Search Open Websites/Domains
  • T1566 - Phishing
  • T1593.001 - Social Media
  • T1656 - Impersonation
  • T1598 - Phishing for Information
  • T1588.003 - Code Signing Certificates
  • T1587 - Develop Capabilities
MITREへのリンク →

Volt Typhoon

Score: 23.80
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1591 - Gather Victim Org Information
  • T1590 - Gather Victim Network Information
  • T1593 - Search Open Websites/Domains
  • T1591.004 - Identify Roles
  • T1596.005 - Scan Databases
  • T1003.003 - NTDS
MITREへのリンク →

EXOTIC LILY

Score: 14.19
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1597 - Search Closed Sources
  • T1593.001 - Social Media
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TA578

Score: 3.29
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
MITREへのリンク →

Sidewinder

Score: 6.08
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

Scattered Spider

Score: 20.79
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1588.001 - Malware
  • T1657 - Financial Theft
  • T1656 - Impersonation
  • T1598 - Phishing for Information
  • T1538 - Cloud Service Dashboard
  • T1003.003 - NTDS
MITREへのリンク →

Mustang Panda

Score: 11.24
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1593 - Search Open Websites/Domains
  • T1588.003 - Code Signing Certificates
  • T1003.003 - NTDS
MITREへのリンク →

ZIRCONIUM

Score: 5.90
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1598 - Phishing for Information
MITREへのリンク →

APT32

Score: 8.70
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1550.003 - Pass the Ticket
  • T1569.002 - Service Execution
MITREへのリンク →

Magic Hound

Score: 9.52
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1591.001 - Determine Physical Locations
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT28

Score: 23.35
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1591 - Gather Victim Org Information
  • T1199 - Trusted Relationship
  • T1598 - Phishing for Information
  • T1498 - Network Denial of Service
  • T1137.002 - Office Test
  • T1003.003 - NTDS
MITREへのリンク →

Star Blizzard

Score: 9.37
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1598.002 - Spearphishing Attachment
  • T1593 - Search Open Websites/Domains
MITREへのリンク →

Moonstone Sleet

Score: 17.95
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1591 - Gather Victim Org Information
  • T1598 - Phishing for Information
  • T1587 - Develop Capabilities
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

CURIUM

Score: 4.98
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 12.27
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1591.002 - Business Relationships
  • T1598.002 - Spearphishing Attachment
  • T1003.003 - NTDS
MITREへのリンク →

OilRig

Score: 13.36
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1201 - Password Policy Discovery
  • T1588.003 - Code Signing Certificates
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 6.59
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1588.001 - Malware
MITREへのリンク →

Turla

Score: 6.30
Matched TTPs:
  • T1588.001 - Malware
  • T1201 - Password Policy Discovery
MITREへのリンク →

APT29

Score: 9.11
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1199 - Trusted Relationship
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 3.84
Matched TTPs:
  • T1550.003 - Pass the Ticket
MITREへのリンク →

INC Ransom

Score: 8.21
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
  • T1569.002 - Service Execution
MITREへのリンク →

FIN13

Score: 4.86
Matched TTPs:
  • T1657 - Financial Theft
  • T1003.003 - NTDS
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

Medusa Group

Score: 7.26
Matched TTPs:
  • T1657 - Financial Theft
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

BlackByte

Score: 6.24
Matched TTPs:
  • T1480 - Execution Guardrails
  • T1569.002 - Service Execution
MITREへのリンク →

Gamaredon Group

Score: 3.84
Matched TTPs:
  • T1480 - Execution Guardrails
MITREへのリンク →

SideCopy

Score: 3.62
Matched TTPs:
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

APT33

Score: 4.13
Matched TTPs:
  • T1552.006 - Group Policy Preferences
MITREへのリンク →

Wizard Spider

Score: 12.02
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1588.003 - Code Signing Certificates
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

Lazarus Group

Score: 5.81
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN7

Score: 9.30
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1591.004 - Identify Roles
  • T1569.002 - Service Execution
MITREへのリンク →

Indrik Spider

Score: 3.84
Matched TTPs:
  • T1590 - Gather Victim Network Information
MITREへのリンク →

HAFNIUM

Score: 8.93
Matched TTPs:
  • T1590 - Gather Victim Network Information
  • T1199 - Trusted Relationship
  • T1003.003 - NTDS
MITREへのリンク →

GOLD SOUTHFIELD

Score: 6.03
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1566 - Phishing
MITREへのリンク →

Threat Group-3390

Score: 5.90
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

menuPass

Score: 5.09
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1003.003 - NTDS
MITREへのリンク →

Sea Turtle

Score: 6.03
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1566 - Phishing
MITREへのリンク →

Axiom

Score: 3.29
Matched TTPs:
  • T1566 - Phishing
MITREへのリンク →

Chimera

Score: 8.58
Matched TTPs:
  • T1201 - Password Policy Discovery
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

Storm-1811

Score: 5.56
Matched TTPs:
  • T1656 - Impersonation
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Saint Bear

Score: 3.03
Matched TTPs:
  • T1656 - Impersonation
MITREへのリンク →

APT42

Score: 3.03
Matched TTPs:
  • T1656 - Impersonation
MITREへのリンク →

APT41

Score: 11.91
Matched TTPs:
  • T1656 - Impersonation
  • T1596.005 - Scan Databases
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1591.004 - Identify Roles
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

BlackTech

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

FIN8

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

FIN6

Score: 7.26
Matched TTPs:
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ke3chang

Score: 4.74
Matched TTPs:
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.85
Matched TTPs:
  • T1593.001 - Social Media
  • T1598 - Phishing for Information
  • T1589.003 - Employee Names
  • T1593 - Search Open Websites/Domains
  • T1594 - Search Victim-Owned Websites
  • T1587 - Develop Capabilities
  • T1656 - Impersonation
  • T1657 - Financial Theft
  • T1591 - Gather Victim Org Information
  • T1566 - Phishing
  • T1598.003 - Spearphishing Link
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Sandworm Team

Score: 0.68
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1589.003 - Employee Names
  • T1593 - Search Open Websites/Domains
  • T1594 - Search Victim-Owned Websites
  • T1199 - Trusted Relationship
  • T1598.003 - Spearphishing Link
  • T1003.003 - NTDS
MITREへのリンク →

Contagious Interview

Score: 0.67
Matched TTPs:
  • T1593.001 - Social Media
  • T1681 - Search Threat Vendor Data
  • T1588.007 - Artificial Intelligence
  • T1593 - Search Open Websites/Domains
  • T1480 - Execution Guardrails
  • T1587 - Develop Capabilities
  • T1656 - Impersonation
  • T1657 - Financial Theft
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Volt Typhoon

Score: 0.57
Matched TTPs:
  • T1593 - Search Open Websites/Domains
  • T1594 - Search Victim-Owned Websites
  • T1591.004 - Identify Roles
  • T1590 - Gather Victim Network Information
  • T1596.005 - Scan Databases
  • T1591 - Gather Victim Org Information
  • T1003.003 - NTDS
MITREへのリンク →

APT28

Score: 0.55
Matched TTPs:
  • T1598 - Phishing for Information
  • T1137.002 - Office Test
  • T1498 - Network Denial of Service
  • T1199 - Trusted Relationship
  • T1591 - Gather Victim Org Information
  • T1598.003 - Spearphishing Link
  • T1003.003 - NTDS
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る