Trusted Design

HDRoot Bootkit

概要

(Kaspersky) Some time ago while tracking Winnti group activity we came across a suspicious 64-bit sample. It was a standalone utility with the name HDD Rootkit for planting a bootkit on a computer. Once installed the bootkit infects the operating system with a backdoor at the early booting stage. The principles of this bootkit’s work, named HDRoot, have been described in the first part of our article. During our investigation we found several backdoors that the HDRoot bootkit used for infecting operating systems. These backdoors are described in this part of the article.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT38

Score: 12.00
Matched TTPs:
  • T1602 - Data from Configuration Repository
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1597 - Search Closed Sources
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Sandworm Team

Score: 7.88
Matched TTPs:
  • T1602 - Data from Configuration Repository
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Lazarus Group

Score: 25.78
Matched TTPs:
  • T1602 - Data from Configuration Repository
  • T1071.004 - DNS
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1578.001 - Create Snapshot
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Ember Bear

Score: 6.37
Matched TTPs:
  • T1602 - Data from Configuration Repository
  • T1218.013 - Mavinject
  • T1597 - Search Closed Sources
MITREへのリンク →

APT37

Score: 8.27
Matched TTPs:
  • T1602 - Data from Configuration Repository
  • T1120 - Peripheral Device Discovery
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Winnti Group

Score: 3.29
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
MITREへのリンク →

APT41

Score: 16.79
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1071.004 - DNS
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1177 - LSASS Driver
  • T1588.001 - Malware
MITREへのリンク →

Rocke

Score: 7.42
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1218.013 - Mavinject
  • T1120 - Peripheral Device Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

TeamTNT

Score: 13.98
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1176.001 - Browser Extensions
  • T1003.007 - Proc Filesystem
  • T1120 - Peripheral Device Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

APT28

Score: 13.31
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1071.004 - DNS
  • T1218.013 - Mavinject
  • T1058 - Service Registry Permissions Weakness
  • T1608.005 - Link Target
MITREへのリンク →

UNC3886

Score: 11.87
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1606.002 - SAML Tokens
  • T1588.001 - Malware
  • T1597 - Search Closed Sources
  • T1578.001 - Create Snapshot
MITREへのリンク →

Gamaredon Group

Score: 9.19
Matched TTPs:
  • T1218.013 - Mavinject
  • T1120 - Peripheral Device Discovery
  • T1058 - Service Registry Permissions Weakness
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

Volt Typhoon

Score: 9.87
Matched TTPs:
  • T1218.013 - Mavinject
  • T1003.007 - Proc Filesystem
  • T1083 - File and Directory Discovery
  • T1578.001 - Create Snapshot
MITREへのリンク →

BRONZE BUTLER

Score: 8.05
Matched TTPs:
  • T1218.013 - Mavinject
  • T1003.007 - Proc Filesystem
  • T1597 - Search Closed Sources
  • T1578.001 - Create Snapshot
MITREへのリンク →

TA2541

Score: 6.15
Matched TTPs:
  • T1218.013 - Mavinject
  • T1120 - Peripheral Device Discovery
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

Indrik Spider

Score: 7.55
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1597 - Search Closed Sources
MITREへのリンク →

FIN7

Score: 16.11
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1058 - Service Registry Permissions Weakness
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1578.001 - Create Snapshot
MITREへのリンク →

MuddyWater

Score: 6.15
Matched TTPs:
  • T1218.013 - Mavinject
  • T1120 - Peripheral Device Discovery
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

admin@338

Score: 4.87
Matched TTPs:
  • T1218.013 - Mavinject
  • T1003.007 - Proc Filesystem
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Earth Lusca

Score: 7.61
Matched TTPs:
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1003.007 - Proc Filesystem
  • T1608.005 - Link Target
MITREへのリンク →

BackdoorDiplomacy

Score: 3.23
Matched TTPs:
  • T1218.013 - Mavinject
  • T1588.001 - Malware
MITREへのリンク →

RedCurl

Score: 4.44
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

APT29

Score: 8.53
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1177 - LSASS Driver
  • T1608.005 - Link Target
MITREへのリンク →

Naikon

Score: 3.23
Matched TTPs:
  • T1218.013 - Mavinject
  • T1588.001 - Malware
MITREへのリンク →

Chimera

Score: 6.25
Matched TTPs:
  • T1218.013 - Mavinject
  • T1003.007 - Proc Filesystem
  • T1578.001 - Create Snapshot
MITREへのリンク →

Aquatic Panda

Score: 10.69
Matched TTPs:
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1003.007 - Proc Filesystem
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1597 - Search Closed Sources
MITREへのリンク →

APT32

Score: 8.39
Matched TTPs:
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1608.005 - Link Target
MITREへのリンク →

Ke3chang

Score: 8.90
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1176.001 - Browser Extensions
  • T1003.007 - Proc Filesystem
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Tropic Trooper

Score: 7.31
Matched TTPs:
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1058 - Service Registry Permissions Weakness
MITREへのリンク →

Magic Hound

Score: 8.25
Matched TTPs:
  • T1218.013 - Mavinject
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

PROMETHIUM

Score: 5.17
Matched TTPs:
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1588.001 - Malware
MITREへのリンク →

INC Ransom

Score: 6.56
Matched TTPs:
  • T1218.013 - Mavinject
  • T1083 - File and Directory Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

LuminousMoth

Score: 6.27
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1058 - Service Registry Permissions Weakness
MITREへのリンク →

OilRig

Score: 8.90
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1176.001 - Browser Extensions
  • T1003.007 - Proc Filesystem
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Carbanak

Score: 5.17
Matched TTPs:
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1588.001 - Malware
MITREへのリンク →

Darkhotel

Score: 7.97
Matched TTPs:
  • T1218.013 - Mavinject
  • T1120 - Peripheral Device Discovery
  • T1058 - Service Registry Permissions Weakness
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT1

Score: 3.66
Matched TTPs:
  • T1218.013 - Mavinject
  • T1003.007 - Proc Filesystem
MITREへのリンク →

Blue Mockingbird

Score: 4.28
Matched TTPs:
  • T1218.013 - Mavinject
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Sidewinder

Score: 4.93
Matched TTPs:
  • T1218.013 - Mavinject
  • T1120 - Peripheral Device Discovery
  • T1578.001 - Create Snapshot
MITREへのリンク →

Kimsuky

Score: 14.80
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1176.001 - Browser Extensions
  • T1003.007 - Proc Filesystem
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

Poseidon Group

Score: 3.66
Matched TTPs:
  • T1218.013 - Mavinject
  • T1003.007 - Proc Filesystem
MITREへのリンク →

Fox Kitten

Score: 6.52
Matched TTPs:
  • T1218.013 - Mavinject
  • T1177 - LSASS Driver
  • T1588.001 - Malware
MITREへのリンク →

Turla

Score: 13.36
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1120 - Peripheral Device Discovery
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1578.001 - Create Snapshot
MITREへのリンク →

Mustang Panda

Score: 9.48
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1058 - Service Registry Permissions Weakness
  • T1608.005 - Link Target
MITREへのリンク →

FIN13

Score: 6.53
Matched TTPs:
  • T1218.013 - Mavinject
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
MITREへのリンク →

Moonstone Sleet

Score: 3.30
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Contagious Interview

Score: 7.11
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

Play

Score: 5.10
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

Aoqin Dragon

Score: 5.13
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1058 - Service Registry Permissions Weakness
MITREへのリンク →

Moses Staff

Score: 3.30
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Medusa Group

Score: 15.11
Matched TTPs:
  • T1036.008 - Masquerade File Type
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Wizard Spider

Score: 14.79
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1083 - File and Directory Discovery
  • T1567.001 - Exfiltration to Code Repository
  • T1597 - Search Closed Sources
MITREへのリンク →

BlackByte

Score: 4.94
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

APT19

Score: 3.14
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

APT3

Score: 6.43
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1120 - Peripheral Device Discovery
  • T1177 - LSASS Driver
MITREへのリンク →

Agrius

Score: 3.73
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1597 - Search Closed Sources
MITREへのリンク →

ZIRCONIUM

Score: 7.91
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1578.001 - Create Snapshot
MITREへのリンク →

Higaisa

Score: 5.89
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1578.001 - Create Snapshot
MITREへのリンク →

CURIUM

Score: 3.80
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1578.001 - Create Snapshot
MITREへのリンク →

Scattered Spider

Score: 6.62
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1083 - File and Directory Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

Storm-0501

Score: 3.30
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
MITREへのリンク →

Winter Vivern

Score: 3.30
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
MITREへのリンク →

Deep Panda

Score: 3.29
Matched TTPs:
  • T1177 - LSASS Driver
MITREへのリンク →

Axiom

Score: 7.82
Matched TTPs:
  • T1177 - LSASS Driver
  • T1160 - Launch Daemon
MITREへのリンク →

Equation

Score: 8.67
Matched TTPs:
  • T1589.003 - Employee Names
  • T1130 - Install Root Certificate
MITREへのリンク →

FIN6

Score: 3.89
Matched TTPs:
  • T1588.001 - Malware
  • T1597 - Search Closed Sources
MITREへのリンク →

Saint Bear

Score: 3.81
Matched TTPs:
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

APT33

Score: 4.13
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.78
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1606.002 - SAML Tokens
  • T1216 - System Script Proxy Execution
  • T1608.005 - Link Target
  • T1176.001 - Browser Extensions
  • T1218.013 - Mavinject
  • T1578.001 - Create Snapshot
  • T1602 - Data from Configuration Repository
  • T1597 - Search Closed Sources
  • T1071.004 - DNS
MITREへのリンク →

FIN7

Score: 0.57
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1606.002 - SAML Tokens
  • T1608.005 - Link Target
  • T1058 - Service Registry Permissions Weakness
  • T1176.001 - Browser Extensions
  • T1218.013 - Mavinject
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT41

Score: 0.56
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1177 - LSASS Driver
  • T1176.001 - Browser Extensions
  • T1499.001 - OS Exhaustion Flood
  • T1218.013 - Mavinject
  • T1071.004 - DNS
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る