Trusted Design

Angler EK installs bedep, vawtrak and POS malware

概要

On October 26, 2015, Cyphort Labs discovered that psychcentral[.]com has been compromised and is currently infecting visitors via drive-by-download malwares. We immediately contacted psychcentral about this infection as early as we have discovered it. As of October 29, their technical team identified the problem and addressed the issue. The site was infected with an iframe injector that redirects to Angler EK. It uses a flash exploit that targets the recent vulnerability in Adobe flash. We found it to be installing bedep and vawtrak. Bedep was known to be the notorious ad fraud malware and vawtrak is a banking trojan following the success of Zeus. We have seen Angler to be using bedep as its payload but adding vawtrak in its arsenal is something we haven’t seen in the past until recently. Moroever, the vawtrak sample we got downloads a new memory scraping malware that scans for credit card data in memory.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT41

Score: 7.21
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1140 - Deobfuscate/Decode Files or Information
  • T1684 - Social Engineering
MITREへのリンク →

Scattered Spider

Score: 11.37
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1566.002 - Spearphishing Link
  • T1491 - Defacement
  • T1565 - Data Manipulation
MITREへのリンク →

TA505

Score: 3.29
Matched TTPs:
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

Volt Typhoon

Score: 14.72
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1546.016 - Installer Packages
MITREへのリンク →

APT3

Score: 3.29
Matched TTPs:
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

FIN13

Score: 4.76
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Sandworm Team

Score: 15.35
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
MITREへのリンク →

Storm-0501

Score: 5.31
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Mustang Panda

Score: 9.34
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

ZIRCONIUM

Score: 4.86
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1547.002 - Authentication Package
MITREへのリンク →

APT32

Score: 13.85
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1684 - Social Engineering
  • T1592.004 - Client Configurations
  • T1565 - Data Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

Kimsuky

Score: 18.88
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1684 - Social Engineering
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1132.002 - Non-Standard Encoding
  • T1003.003 - NTDS
MITREへのリンク →

Magic Hound

Score: 11.19
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT28

Score: 10.86
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.002 - Authentication Package
  • T1146 - Clear Command History
MITREへのリンク →

Star Blizzard

Score: 4.80
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1565 - Data Manipulation
MITREへのリンク →

Moonstone Sleet

Score: 10.61
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1491 - Defacement
  • T1565 - Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 7.32
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1565 - Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dragonfly

Score: 6.76
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1546.016 - Installer Packages
MITREへのリンク →

FIN7

Score: 8.41
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1011.001 - Exfiltration Over Bluetooth
  • T1547.002 - Authentication Package
MITREへのリンク →

Ember Bear

Score: 5.60
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1003.003 - NTDS
MITREへのリンク →

Medusa Group

Score: 6.56
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1565 - Data Manipulation
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Fox Kitten

Score: 7.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1565 - Data Manipulation
MITREへのリンク →

BlackByte

Score: 3.93
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1684 - Social Engineering
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Earth Lusca

Score: 4.30
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1546.016 - Installer Packages
MITREへのリンク →

APT29

Score: 12.38
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1181 - Extra Window Memory Injection
  • T1592.004 - Client Configurations
  • T1547.008 - LSASS Driver
MITREへのリンク →

Leviathan

Score: 6.64
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1565 - Data Manipulation
  • T1546.016 - Installer Packages
MITREへのリンク →

APT5

Score: 3.93
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1684 - Social Engineering
MITREへのリンク →

MuddyWater

Score: 3.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.002 - Authentication Package
MITREへのリンク →

Salt Typhoon

Score: 4.22
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT39

Score: 3.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.002 - Authentication Package
MITREへのリンク →

APT38

Score: 5.74
Matched TTPs:
  • T1684 - Social Engineering
  • T1491 - Defacement
MITREへのリンク →

Wizard Spider

Score: 5.20
Matched TTPs:
  • T1684 - Social Engineering
  • T1556 - Modify Authentication Process
MITREへのリンク →

TA2541

Score: 5.20
Matched TTPs:
  • T1684 - Social Engineering
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Cobalt Group

Score: 5.20
Matched TTPs:
  • T1684 - Social Engineering
  • T1128 - Netsh Helper DLL
MITREへのリンク →

APT37

Score: 4.86
Matched TTPs:
  • T1684 - Social Engineering
  • T1547.002 - Authentication Package
MITREへのリンク →

Velvet Ant

Score: 5.20
Matched TTPs:
  • T1684 - Social Engineering
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Gamaredon Group

Score: 4.86
Matched TTPs:
  • T1684 - Social Engineering
  • T1547.002 - Authentication Package
MITREへのリンク →

Turla

Score: 7.69
Matched TTPs:
  • T1684 - Social Engineering
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
MITREへのリンク →

Chimera

Score: 6.91
Matched TTPs:
  • T1491 - Defacement
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

BRONZE BUTLER

Score: 3.84
Matched TTPs:
  • T1592.004 - Client Configurations
MITREへのリンク →

EXOTIC LILY

Score: 4.86
Matched TTPs:
  • T1565 - Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

HEXANE

Score: 4.74
Matched TTPs:
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
MITREへのリンク →

Lazarus Group

Score: 16.97
Matched TTPs:
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
  • T1055.005 - Thread Local Storage
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Contagious Interview

Score: 7.61
Matched TTPs:
  • T1565 - Data Manipulation
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

OilRig

Score: 8.02
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT42

Score: 6.37
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

FIN6

Score: 8.02
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN8

Score: 5.49
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

LAPSUS$

Score: 3.62
Matched TTPs:
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.77
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1565 - Data Manipulation
  • T1003.003 - NTDS
  • T1547.002 - Authentication Package
  • T1140 - Deobfuscate/Decode Files or Information
  • T1132.002 - Non-Standard Encoding
  • T1684 - Social Engineering
MITREへのリンク →

Lazarus Group

Score: 0.73
Matched TTPs:
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
  • T1556 - Modify Authentication Process
  • T1055.005 - Thread Local Storage
  • T1547.008 - LSASS Driver
MITREへのリンク →

Sandworm Team

Score: 0.70
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1565 - Data Manipulation
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
MITREへのリンク →

Volt Typhoon

Score: 0.64
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1546.016 - Installer Packages
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

APT32

Score: 0.63
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1592.004 - Client Configurations
  • T1565 - Data Manipulation
  • T1556 - Modify Authentication Process
  • T1684 - Social Engineering
MITREへのリンク →

APT29

Score: 0.56
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1547.008 - LSASS Driver
  • T1140 - Deobfuscate/Decode Files or Information
  • T1181 - Extra Window Memory Injection
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る