Trusted Design

PROJECT CAMERASHY: CLOSING THE APERTURE ON CHINA’S UNIT 78020

概要

China is aggressively claiming territory deeper into the South China Sea, threatening economic and political stability in the Southeast Asia and beyond. The territorial activity is accompanied by high-tempo cyber espionage and malware attacks, malicious attachments and spear phishing, directed at Southeast Asian military, diplomatic, and economic targets. ThreatConnect, in partnership with Defense Group Inc., has attributed the targeted cyber espionage infrastructure activity associated with the “Naikon” Advanced Persistent Threat (APT) group to a specific unit of the Chinese People’s Liberation Army (PLA). Our assessment is based on technical analysis of Naikon threat activity and native language research on a PLA officer within Unit 78020. Project CameraShy takes readers through our intelligence analysis, pivot by pivot, as we connect the dots using the Diamond Model of Intrusion Analysis.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Contagious Interview

Score: 12.57
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1681 - Search Threat Vendor Data
  • T1070.004 - File Deletion
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Medusa Group

Score: 8.21
Matched TTPs:
  • T1106 - Native API
  • T1070.004 - File Deletion
  • T1218.014 - MMC
MITREへのリンク →

Higaisa

Score: 3.78
Matched TTPs:
  • T1106 - Native API
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Lazarus Group

Score: 15.10
Matched TTPs:
  • T1106 - Native API
  • T1591 - Gather Victim Org Information
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Chimera

Score: 3.67
Matched TTPs:
  • T1106 - Native API
  • T1070.004 - File Deletion
MITREへのリンク →

BlackTech

Score: 3.78
Matched TTPs:
  • T1106 - Native API
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Sandworm Team

Score: 11.93
Matched TTPs:
  • T1106 - Native API
  • T1591.002 - Business Relationships
  • T1195.002 - Compromise Software Supply Chain
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

Tropic Trooper

Score: 5.16
Matched TTPs:
  • T1106 - Native API
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

ToddyCat

Score: 4.81
Matched TTPs:
  • T1106 - Native API
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

menuPass

Score: 3.67
Matched TTPs:
  • T1106 - Native API
  • T1070.004 - File Deletion
MITREへのリンク →

APT37

Score: 3.78
Matched TTPs:
  • T1106 - Native API
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Gamaredon Group

Score: 3.67
Matched TTPs:
  • T1106 - Native API
  • T1070.004 - File Deletion
MITREへのリンク →

Mustang Panda

Score: 13.83
Matched TTPs:
  • T1106 - Native API
  • T1678 - Delay Execution
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT38

Score: 3.67
Matched TTPs:
  • T1106 - Native API
  • T1070.004 - File Deletion
MITREへのリンク →

Silence

Score: 3.67
Matched TTPs:
  • T1106 - Native API
  • T1070.004 - File Deletion
MITREへのリンク →

UNC3886

Score: 7.01
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

Dragonfly

Score: 9.65
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1195.002 - Compromise Software Supply Chain
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

LAPSUS$

Score: 11.60
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1591.004 - Identify Roles
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

APT29

Score: 9.24
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT32

Score: 6.72
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

BRONZE BUTLER

Score: 10.00
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

APT33

Score: 5.63
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Wizard Spider

Score: 5.51
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1070.004 - File Deletion
MITREへのリンク →

APT28

Score: 18.67
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1203 - Exploitation for Client Execution
  • T1598 - Phishing for Information
  • T1070.004 - File Deletion
  • T1498 - Network Denial of Service
  • T1137.002 - Office Test
MITREへのリンク →

Moonstone Sleet

Score: 12.18
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1195.002 - Compromise Software Supply Chain
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN7

Score: 9.84
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1195.002 - Compromise Software Supply Chain
  • T1591.004 - Identify Roles
MITREへのリンク →

Kimsuky

Score: 11.39
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1598 - Phishing for Information
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Volt Typhoon

Score: 16.27
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1590 - Gather Victim Network Information
  • T1591.004 - Identify Roles
  • T1070.004 - File Deletion
  • T1596.005 - Scan Databases
MITREへのリンク →

Indrik Spider

Score: 3.84
Matched TTPs:
  • T1590 - Gather Victim Network Information
MITREへのリンク →

HAFNIUM

Score: 3.84
Matched TTPs:
  • T1590 - Gather Victim Network Information
MITREへのリンク →

APT41

Score: 13.22
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1596.005 - Scan Databases
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Cobalt Group

Score: 5.80
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

Threat Group-3390

Score: 5.80
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Patchwork

Score: 6.16
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

OilRig

Score: 5.40
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ke3chang

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

BlackByte

Score: 5.00
Matched TTPs:
  • T1614.001 - System Language Discovery
  • T1070.004 - File Deletion
MITREへのリンク →

Storm-0501

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

Malteiro

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1591.004 - Identify Roles
MITREへのリンク →

Scattered Spider

Score: 7.57
Matched TTPs:
  • T1598 - Phishing for Information
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

ZIRCONIUM

Score: 3.44
Matched TTPs:
  • T1598 - Phishing for Information
MITREへのリンク →

FIN6

Score: 3.90
Matched TTPs:
  • T1070.004 - File Deletion
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Magic Hound

Score: 3.90
Matched TTPs:
  • T1070.004 - File Deletion
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Rocke

Score: 4.67
Matched TTPs:
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Mustard Tempest

Score: 4.54
Matched TTPs:
  • T1608.006 - SEO Poisoning
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.85
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1137.002 - Office Test
  • T1498 - Network Denial of Service
  • T1598 - Phishing for Information
  • T1070.004 - File Deletion
  • T1591 - Gather Victim Org Information
MITREへのリンク →

Volt Typhoon

Score: 0.78
Matched TTPs:
  • T1596.005 - Scan Databases
  • T1590 - Gather Victim Network Information
  • T1591.004 - Identify Roles
  • T1070.004 - File Deletion
  • T1591 - Gather Victim Org Information
MITREへのリンク →

Lazarus Group

Score: 0.73
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1070.004 - File Deletion
  • T1106 - Native API
  • T1591 - Gather Victim Org Information
MITREへのリンク →

Mustang Panda

Score: 0.67
Matched TTPs:
  • T1678 - Delay Execution
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1070.004 - File Deletion
  • T1106 - Native API
MITREへのリンク →

APT41

Score: 0.67
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1195.002 - Compromise Software Supply Chain
  • T1596.005 - Scan Databases
  • T1070.004 - File Deletion
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Sandworm Team

Score: 0.62
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1195.002 - Compromise Software Supply Chain
  • T1591.002 - Business Relationships
  • T1070.004 - File Deletion
  • T1106 - Native API
MITREへのリンク →

Moonstone Sleet

Score: 0.60
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1591 - Gather Victim Org Information
  • T1195.002 - Compromise Software Supply Chain
  • T1598 - Phishing for Information
MITREへのリンク →

Kimsuky

Score: 0.59
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1102.001 - Dead Drop Resolver
  • T1598 - Phishing for Information
  • T1070.004 - File Deletion
MITREへのリンク →

Contagious Interview

Score: 0.58
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1681 - Search Threat Vendor Data
  • T1588.007 - Artificial Intelligence
  • T1070.004 - File Deletion
MITREへのリンク →

LAPSUS$

Score: 0.56
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1578.002 - Create Cloud Instance
  • T1591.004 - Identify Roles
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る