Trusted Design

Sakula Reloaded

概要

Sakula is a well known malware variant linked to several significant targeted intrusion campaigns over the past 2-3 years. This remote access toolkit has been publicly examined multiple times by the threat intelligence community. CrowdStrike has released two blog posts detailing Sakula campaigns and continues to investigate its usage. In the past two years, two campaigns of Sakula activity stand out as being particularly significant – the “French Aerospace” Campaign and the “Ironman” Campaign. In recent months, CrowdStrike has observed limited use of what appears to be a third Sakula variant.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Contagious Interview

Score: 16.88
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT41

Score: 8.66
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Scattered Spider

Score: 12.09
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1021.001 - Remote Desktop Protocol
  • T1213.005 - Messaging Applications
MITREへのリンク →

TA505

Score: 7.95
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1204.001 - Malicious Link
MITREへのリンク →

Volt Typhoon

Score: 9.75
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

APT3

Score: 9.17
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN13

Score: 7.88
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Kimsuky

Score: 10.08
Matched TTPs:
  • T1587.001 - Malware
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

Moonstone Sleet

Score: 4.62
Matched TTPs:
  • T1587.001 - Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Indrik Spider

Score: 3.74
Matched TTPs:
  • T1587.001 - Malware
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Lazarus Group

Score: 19.46
Matched TTPs:
  • T1587.001 - Malware
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1027.007 - Dynamic API Resolution
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 18.63
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1137.004 - Outlook Home Page
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 16.90
Matched TTPs:
  • T1587.001 - Malware
  • T1070.006 - Timestomp
  • T1681 - Search Threat Vendor Data
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

LuminousMoth

Score: 6.76
Matched TTPs:
  • T1587.001 - Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1204.001 - Malicious Link
MITREへのリンク →

Sandworm Team

Score: 7.18
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
MITREへのリンク →

APT29

Score: 12.45
Matched TTPs:
  • T1587.001 - Malware
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Play

Score: 4.33
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1070.004 - File Deletion
MITREへのリンク →

Aoqin Dragon

Score: 4.44
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 7.58
Matched TTPs:
  • T1587.001 - Malware
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
MITREへのリンク →

Turla

Score: 9.36
Matched TTPs:
  • T1587.001 - Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1204.001 - Malicious Link
  • T1124 - System Time Discovery
MITREへのリンク →

Mustang Panda

Score: 14.06
Matched TTPs:
  • T1587.001 - Malware
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1027.007 - Dynamic API Resolution
  • T1204.001 - Malicious Link
MITREへのリンク →

TeamTNT

Score: 3.48
Matched TTPs:
  • T1587.001 - Malware
  • T1070.004 - File Deletion
MITREへのリンク →

FIN7

Score: 8.54
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
  • T1124 - System Time Discovery
MITREへのリンク →

APT28

Score: 16.50
Matched TTPs:
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
  • T1669 - Wi-Fi Networks
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

APT5

Score: 5.77
Matched TTPs:
  • T1070.006 - Timestomp
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT38

Score: 6.34
Matched TTPs:
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
MITREへのリンク →

APT32

Score: 7.83
Matched TTPs:
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
MITREへのリンク →

Chimera

Score: 9.22
Matched TTPs:
  • T1070.006 - Timestomp
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

Rocke

Score: 4.13
Matched TTPs:
  • T1070.006 - Timestomp
  • T1070.004 - File Deletion
MITREへのリンク →

Medusa Group

Score: 10.76
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Threat Group-3390

Score: 7.86
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

TA2541

Score: 7.41
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1204.001 - Malicious Link
MITREへのリンク →

Ember Bear

Score: 5.33
Matched TTPs:
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
MITREへのリンク →

LAPSUS$

Score: 7.15
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1213.005 - Messaging Applications
MITREへのリンク →

Metador

Score: 4.69
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1070.004 - File Deletion
MITREへのリンク →

APT1

Score: 4.96
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Aquatic Panda

Score: 6.34
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

LazyScripter

Score: 3.82
Matched TTPs:
  • T1588.001 - Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

Andariel

Score: 3.95
Matched TTPs:
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Earth Lusca

Score: 4.67
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1204.001 - Malicious Link
MITREへのリンク →

BackdoorDiplomacy

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Magic Hound

Score: 7.76
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BlackTech

Score: 3.70
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

MuddyWater

Score: 3.70
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

Wizard Spider

Score: 5.24
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

Storm-1811

Score: 3.37
Matched TTPs:
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 6.32
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

menuPass

Score: 3.88
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

FIN8

Score: 7.98
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

APT39

Score: 5.24
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN6

Score: 9.15
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Patchwork

Score: 6.73
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

Cobalt Group

Score: 9.48
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN10

Score: 3.88
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

INC Ransom

Score: 3.88
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Dragonfly

Score: 5.37
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT33

Score: 3.70
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
MITREへのリンク →

Silence

Score: 3.88
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Gamaredon Group

Score: 3.59
Matched TTPs:
  • T1588.002 - Tool
  • T1070.004 - File Deletion
  • T1204.001 - Malicious Link
MITREへのリンク →

APT42

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Sidewinder

Score: 5.45
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
  • T1124 - System Time Discovery
MITREへのリンク →

The White Company

Score: 5.47
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

EXOTIC LILY

Score: 5.38
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Axiom

Score: 3.14
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Higaisa

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Leviathan

Score: 4.50
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
  • T1204.001 - Malicious Link
MITREへのリンク →

Tropic Trooper

Score: 5.62
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
MITREへのリンク →

Darkhotel

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

BlackByte

Score: 3.03
Matched TTPs:
  • T1070.004 - File Deletion
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Fox Kitten

Score: 5.49
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1213.005 - Messaging Applications
MITREへのリンク →

Windshift

Score: 3.88
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

ZIRCONIUM

Score: 3.95
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1124 - System Time Discovery
MITREへのリンク →

CURIUM

Score: 5.12
Matched TTPs:
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.84
Matched TTPs:
  • T1070.006 - Timestomp
  • T1587.001 - Malware
  • T1566.003 - Spearphishing via Service
  • T1027.007 - Dynamic API Resolution
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
  • T1070.004 - File Deletion
  • T1203 - Exploitation for Client Execution
  • T1588.002 - Tool
MITREへのリンク →

OilRig

Score: 0.77
Matched TTPs:
  • T1587.001 - Malware
  • T1566.003 - Spearphishing via Service
  • T1137.004 - Outlook Home Page
  • T1021.001 - Remote Desktop Protocol
  • T1573.002 - Asymmetric Cryptography
  • T1070.004 - File Deletion
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
  • T1588.002 - Tool
MITREへのリンク →

APT28

Score: 0.74
Matched TTPs:
  • T1070.006 - Timestomp
  • T1669 - Wi-Fi Networks
  • T1211 - Exploitation for Defense Evasion
  • T1070.004 - File Deletion
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
  • T1588.002 - Tool
MITREへのリンク →

UNC3886

Score: 0.72
Matched TTPs:
  • T1070.006 - Timestomp
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1124 - System Time Discovery
  • T1070.004 - File Deletion
  • T1203 - Exploitation for Client Execution
  • T1588.001 - Malware
MITREへのリンク →

Contagious Interview

Score: 0.69
Matched TTPs:
  • T1587.001 - Malware
  • T1566.003 - Spearphishing via Service
  • T1681 - Search Threat Vendor Data
  • T1070.004 - File Deletion
  • T1588.007 - Artificial Intelligence
  • T1204.001 - Malicious Link
  • T1588.002 - Tool
MITREへのリンク →

Mustang Panda

Score: 0.63
Matched TTPs:
  • T1070.006 - Timestomp
  • T1587.001 - Malware
  • T1027.007 - Dynamic API Resolution
  • T1070.004 - File Deletion
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
  • T1588.002 - Tool
MITREへのリンク →

APT29

Score: 0.58
Matched TTPs:
  • T1070.006 - Timestomp
  • T1587.001 - Malware
  • T1566.003 - Spearphishing via Service
  • T1070.004 - File Deletion
  • T1203 - Exploitation for Client Execution
  • T1204.001 - Malicious Link
  • T1588.002 - Tool
MITREへのリンク →

Scattered Spider

Score: 0.56
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1021.001 - Remote Desktop Protocol
  • T1213.005 - Messaging Applications
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る