Trusted Design

Duuzer back door Trojan targets South Korea

概要

Symantec has found that South Korea is being impacted by an active back door Trojan, detected as Backdoor.Duuzer. While the malware attack has not been exclusively targeting the region, it has been focusing on the South Korean manufacturing industry. Duuzer is a well-designed threat that gives attackers remote access to the compromised computer, downloads additional files, and steals data. It’s clearly the work of skilled attackers looking to obtain valuable information There is also evidence to suggest that the actors behind Duuzer are spreading two other threats, detected as W32.Brambul and Backdoor.Joanap, to target more organizations in South Korea. Brambul and Joanap appear to be used to download extra payloads and carry out reconnaissance on infected computers.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Ember Bear

Score: 9.45
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Sandworm Team

Score: 24.68
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
  • T1548.006 - TCC Manipulation
MITREへのリンク →

OilRig

Score: 25.60
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Gamaredon Group

Score: 16.53
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1061 - Graphical User Interface
  • T1547.002 - Authentication Package
  • T1546.017 - Udev Rules
MITREへのリンク →

APT28

Score: 17.96
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1548.006 - TCC Manipulation
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

Turla

Score: 14.95
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
MITREへのリンク →

Kimsuky

Score: 16.33
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1547.002 - Authentication Package
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN13

Score: 12.94
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1053.006 - Systemd Timers
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Moonstone Sleet

Score: 6.59
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1547.008 - LSASS Driver
MITREへのリンク →

Indrik Spider

Score: 6.58
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
MITREへのリンク →

Lazarus Group

Score: 19.23
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Contagious Interview

Score: 10.19
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

UNC3886

Score: 6.72
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.004 - Unix Shell
MITREへのリンク →

LuminousMoth

Score: 4.92
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
MITREへのリンク →

Salt Typhoon

Score: 7.16
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT29

Score: 13.53
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1592.004 - Client Configurations
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

Play

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Ke3chang

Score: 6.76
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Mustang Panda

Score: 17.29
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1526 - Cloud Service Discovery
  • T1055.005 - Thread Local Storage
  • T1548.006 - TCC Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

TeamTNT

Score: 4.07
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
MITREへのリンク →

FIN7

Score: 10.43
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1622 - Debugger Evasion
MITREへのリンク →

TA2541

Score: 5.97
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1546.017 - Udev Rules
MITREへのリンク →

Earth Lusca

Score: 7.13
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1546.016 - Installer Packages
MITREへのリンク →

Threat Group-3390

Score: 13.34
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1526 - Cloud Service Discovery
  • T1546.017 - Udev Rules
MITREへのリンク →

BlackByte

Score: 5.09
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

APT32

Score: 12.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1592.004 - Client Configurations
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1556 - Modify Authentication Process
MITREへのリンク →

HEXANE

Score: 6.87
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1622 - Debugger Evasion
MITREへのリンク →

EXOTIC LILY

Score: 4.50
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1547.008 - LSASS Driver
MITREへのリンク →

Volt Typhoon

Score: 9.14
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

GOLD SOUTHFIELD

Score: 4.22
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

BlackTech

Score: 5.47
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1526 - Cloud Service Discovery
MITREへのリンク →

Magic Hound

Score: 8.89
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
MITREへのリンク →

Medusa Group

Score: 10.85
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

Sea Turtle

Score: 5.07
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
MITREへのリンク →

Storm-0501

Score: 8.35
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
  • T1090.004 - Domain Fronting
MITREへのリンク →

Fox Kitten

Score: 5.46
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Agrius

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

menuPass

Score: 9.05
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Blue Mockingbird

Score: 6.71
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
MITREへのリンク →

GALLIUM

Score: 5.47
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
MITREへのリンク →

Leviathan

Score: 11.85
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
  • T1546.017 - Udev Rules
MITREへのリンク →

INC Ransom

Score: 3.97
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Dragonfly

Score: 9.14
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Axiom

Score: 7.66
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

APT41

Score: 6.31
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

HAFNIUM

Score: 6.56
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT5

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

MuddyWater

Score: 4.72
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

APT39

Score: 6.36
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1622 - Debugger Evasion
MITREへのリンク →

BRONZE BUTLER

Score: 4.69
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1199 - Trusted Relationship
MITREへのリンク →

POLONIUM

Score: 5.99
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

LAPSUS$

Score: 5.94
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Inception

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Wizard Spider

Score: 10.74
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

Storm-1811

Score: 3.37
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

Scattered Spider

Score: 8.97
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1090.004 - Domain Fronting
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

FIN8

Score: 8.39
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN6

Score: 10.11
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Patchwork

Score: 5.65
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
  • T1622 - Debugger Evasion
MITREへのリンク →

WIRTE

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Cobalt Group

Score: 5.24
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
MITREへのリンク →

Thrip

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT33

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

Chimera

Score: 4.84
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT19

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Carbanak

Score: 3.25
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

Deep Panda

Score: 5.90
Matched TTPs:
  • T1059.004 - Unix Shell
  • T1027.014 - Polymorphic Code
MITREへのリンク →

APT3

Score: 4.80
Matched TTPs:
  • T1059.004 - Unix Shell
  • T1622 - Debugger Evasion
MITREへのリンク →

Molerats

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

Higaisa

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

OilRig

Score: 0.79
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1552.005 - Cloud Instance Metadata API
  • T1622 - Debugger Evasion
  • T1091 - Replication Through Removable Media
  • T1547.008 - LSASS Driver
  • T1005 - Data from Local System
  • T1556 - Modify Authentication Process
  • T1526 - Cloud Service Discovery
  • T1059.004 - Unix Shell
  • T1606.002 - SAML Tokens
MITREへのリンク →

Sandworm Team

Score: 0.78
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
  • T1122 - Component Object Model Hijacking
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1548.006 - TCC Manipulation
  • T1606.002 - SAML Tokens
  • T1546.016 - Installer Packages
  • T1564.008 - Email Hiding Rules
MITREへのリンク →

Lazarus Group

Score: 0.66
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
  • T1055.005 - Thread Local Storage
  • T1606.002 - SAML Tokens
  • T1546.016 - Installer Packages
MITREへのリンク →

APT28

Score: 0.61
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1552.005 - Cloud Instance Metadata API
  • T1122 - Component Object Model Hijacking
  • T1546.007 - Netsh Helper DLL
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Kimsuky

Score: 0.58
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.002 - Authentication Package
  • T1027.014 - Polymorphic Code
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1091 - Replication Through Removable Media
  • T1526 - Cloud Service Discovery
  • T1606.002 - SAML Tokens
MITREへのリンク →

Mustang Panda

Score: 0.57
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1091 - Replication Through Removable Media
  • T1556 - Modify Authentication Process
  • T1526 - Cloud Service Discovery
  • T1055.005 - Thread Local Storage
  • T1548.006 - TCC Manipulation
  • T1606.002 - SAML Tokens
MITREへのリンク →

Turla

Score: 0.56
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
  • T1552.005 - Cloud Instance Metadata API
  • T1059.004 - Unix Shell
  • T1606.002 - SAML Tokens
  • T1546.016 - Installer Packages
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る