Trusted Design

Angler EK installs bedep, vawtrak and POS malware

概要

On October 26, 2015, Cyphort Labs discovered that psychcentral[.]com has been compromised and is currently infecting visitors via drive-by-download malwares. We immediately contacted psychcentral about this infection as early as we have discovered it. As of October 29, their technical team identified the problem and addressed the issue. The site was infected with an iframe injector that redirects to Angler EK. It uses a flash exploit that targets the recent vulnerability in Adobe flash. We found it to be installing bedep and vawtrak. Bedep was known to be the notorious ad fraud malware and vawtrak is a banking trojan following the success of Zeus. We have seen Angler to be using bedep as its payload but adding vawtrak in its arsenal is something we haven’t seen in the past until recently. Moroever, the vawtrak sample we got downloads a new memory scraping malware that scans for credit card data in memory.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT41

Score: 7.21
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
MITREへのリンク →

Scattered Spider

Score: 11.37
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1598.003 - Spearphishing Link
  • T1217 - Browser Information Discovery
  • T1585.001 - Social Media Accounts
MITREへのリンク →

TA505

Score: 3.29
Matched TTPs:
  • T1069 - Permission Groups Discovery
MITREへのリンク →

Volt Typhoon

Score: 14.72
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1588.006 - Vulnerabilities
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1584.004 - Server
MITREへのリンク →

APT3

Score: 3.29
Matched TTPs:
  • T1069 - Permission Groups Discovery
MITREへのリンク →

FIN13

Score: 4.76
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Sandworm Team

Score: 15.35
Matched TTPs:
  • T1588.006 - Vulnerabilities
  • T1598.003 - Spearphishing Link
  • T1190 - Exploit Public-Facing Application
  • T1585.001 - Social Media Accounts
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
MITREへのリンク →

Storm-0501

Score: 5.31
Matched TTPs:
  • T1588.006 - Vulnerabilities
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Mustang Panda

Score: 9.34
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.007 - Dynamic API Resolution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

ZIRCONIUM

Score: 4.86
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT32

Score: 13.85
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1055 - Process Injection
  • T1550.003 - Pass the Ticket
  • T1585.001 - Social Media Accounts
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Kimsuky

Score: 18.88
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
  • T1585.001 - Social Media Accounts
  • T1102.002 - Bidirectional Communication
  • T1111 - Multi-Factor Authentication Interception
  • T1588.005 - Exploits
MITREへのリンク →

Magic Hound

Score: 11.19
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1190 - Exploit Public-Facing Application
  • T1585.001 - Social Media Accounts
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT28

Score: 10.86
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1190 - Exploit Public-Facing Application
  • T1102.002 - Bidirectional Communication
  • T1498 - Network Denial of Service
MITREへのリンク →

Star Blizzard

Score: 4.80
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1585.001 - Social Media Accounts
MITREへのリンク →

Moonstone Sleet

Score: 10.61
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1217 - Browser Information Discovery
  • T1585.001 - Social Media Accounts
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

CURIUM

Score: 7.32
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1585.001 - Social Media Accounts
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 6.76
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1190 - Exploit Public-Facing Application
  • T1584.004 - Server
MITREへのリンク →

FIN7

Score: 8.41
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1674 - Input Injection
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Ember Bear

Score: 5.60
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.005 - Exploits
MITREへのリンク →

Medusa Group

Score: 6.56
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1585.001 - Social Media Accounts
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Fox Kitten

Score: 7.10
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1585.001 - Social Media Accounts
MITREへのリンク →

BlackByte

Score: 3.93
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Earth Lusca

Score: 4.30
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1584.004 - Server
MITREへのリンク →

APT29

Score: 12.38
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1556.007 - Hybrid Identity
  • T1550.003 - Pass the Ticket
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Leviathan

Score: 6.64
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1585.001 - Social Media Accounts
  • T1584.004 - Server
MITREへのリンク →

APT5

Score: 3.93
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
MITREへのリンク →

MuddyWater

Score: 3.87
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Salt Typhoon

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT39

Score: 3.87
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT38

Score: 5.74
Matched TTPs:
  • T1055 - Process Injection
  • T1217 - Browser Information Discovery
MITREへのリンク →

Wizard Spider

Score: 5.20
Matched TTPs:
  • T1055 - Process Injection
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

TA2541

Score: 5.20
Matched TTPs:
  • T1055 - Process Injection
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Cobalt Group

Score: 5.20
Matched TTPs:
  • T1055 - Process Injection
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

APT37

Score: 4.86
Matched TTPs:
  • T1055 - Process Injection
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Velvet Ant

Score: 5.20
Matched TTPs:
  • T1055 - Process Injection
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Gamaredon Group

Score: 4.86
Matched TTPs:
  • T1055 - Process Injection
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Turla

Score: 7.69
Matched TTPs:
  • T1055 - Process Injection
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
MITREへのリンク →

Chimera

Score: 6.91
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1111 - Multi-Factor Authentication Interception
MITREへのリンク →

BRONZE BUTLER

Score: 3.84
Matched TTPs:
  • T1550.003 - Pass the Ticket
MITREへのリンク →

EXOTIC LILY

Score: 4.86
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

HEXANE

Score: 4.74
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Lazarus Group

Score: 16.97
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Contagious Interview

Score: 7.61
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

OilRig

Score: 8.02
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT42

Score: 6.37
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1111 - Multi-Factor Authentication Interception
MITREへのリンク →

FIN6

Score: 8.02
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN8

Score: 5.49
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

LAPSUS$

Score: 3.62
Matched TTPs:
  • T1111 - Multi-Factor Authentication Interception
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.77
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1585.001 - Social Media Accounts
  • T1055 - Process Injection
  • T1588.005 - Exploits
  • T1111 - Multi-Factor Authentication Interception
  • T1598.003 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Lazarus Group

Score: 0.73
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1584.004 - Server
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Sandworm Team

Score: 0.70
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1585.001 - Social Media Accounts
  • T1588.006 - Vulnerabilities
  • T1584.004 - Server
  • T1598.003 - Spearphishing Link
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Volt Typhoon

Score: 0.64
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1069 - Permission Groups Discovery
  • T1588.006 - Vulnerabilities
  • T1584.004 - Server
  • T1217 - Browser Information Discovery
MITREへのリンク →

APT32

Score: 0.63
Matched TTPs:
  • T1585.001 - Social Media Accounts
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1550.003 - Pass the Ticket
  • T1598.003 - Spearphishing Link
  • T1055 - Process Injection
MITREへのリンク →

APT29

Score: 0.56
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1566.003 - Spearphishing via Service
  • T1550.003 - Pass the Ticket
  • T1556.007 - Hybrid Identity
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る