Trusted Design

SHELLDC.DLL (BACKDOOR)

概要

This malware is designed to be installed as a service. It provides file transfer, file copy, move, delete and setting of file attributes, command execution, interactive command shell, registry browsing, listing of RDP connected users and full remote desktop GUI interactivity via a custom protocol.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Gamaredon Group

Score: 21.26
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1552.005 - Cloud Instance Metadata API
  • T1547.012 - Print Processors
  • T1059.009 - Cloud API
  • T1608 - Stage Capabilities
  • T1542.004 - ROMMONkit
  • T1546.017 - Udev Rules
MITREへのリンク →

FIN7

Score: 17.71
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1586.002 - Email Accounts
  • T1011.001 - Exfiltration Over Bluetooth
  • T1622 - Debugger Evasion
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT19

Score: 8.45
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Kimsuky

Score: 22.99
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1608 - Stage Capabilities
  • T1027.014 - Polymorphic Code
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
  • T1665 - Hide Infrastructure
  • T1008 - Fallback Channels
MITREへのリンク →

UNC3886

Score: 6.07
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1556.002 - Password Filter DLL
MITREへのリンク →

Carbanak

Score: 6.46
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1586.002 - Email Accounts
MITREへのリンク →

APT3

Score: 8.80
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1177 - LSASS Driver
  • T1622 - Debugger Evasion
MITREへのリンク →

Magic Hound

Score: 5.41
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
MITREへのリンク →

TA551

Score: 4.68
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Blue Mockingbird

Score: 12.49
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Wizard Spider

Score: 25.40
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1155 - AppleScript
  • T1003.001 - LSASS Memory
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1204.001 - Malicious Link
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT32

Score: 19.54
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1027.014 - Polymorphic Code
  • T1174 - Password Filter DLL
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
  • T1556 - Modify Authentication Process
MITREへのリンク →

Lazarus Group

Score: 21.18
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1174 - Password Filter DLL
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1105 - Ingress Tool Transfer
  • T1665 - Hide Infrastructure
  • T1556 - Modify Authentication Process
MITREへのリンク →

TA505

Score: 7.05
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.009 - Cloud API
MITREへのリンク →

APT41

Score: 18.66
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1177 - LSASS Driver
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1008 - Fallback Channels
MITREへのリンク →

Sandworm Team

Score: 10.15
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1586.002 - Email Accounts
  • T1548.006 - TCC Manipulation
  • T1204.001 - Malicious Link
MITREへのリンク →

APT28

Score: 22.27
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1552.005 - Cloud Instance Metadata API
  • T1542.004 - ROMMONkit
  • T1105 - Ingress Tool Transfer
  • T1588.003 - Code Signing Certificates
  • T1548.006 - TCC Manipulation
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

HAFNIUM

Score: 11.07
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1105 - Ingress Tool Transfer
  • T1548.006 - TCC Manipulation
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

APT38

Score: 14.67
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.009 - Cloud API
  • T1174 - Password Filter DLL
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Daggerfly

Score: 5.22
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1174 - Password Filter DLL
MITREへのリンク →

RedCurl

Score: 7.64
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1542.004 - ROMMONkit
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Aquatic Panda

Score: 7.35
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
MITREへのリンク →

Storm-0501

Score: 14.33
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1155 - AppleScript
  • T1027.014 - Polymorphic Code
  • T1565.002 - Transmitted Data Manipulation
  • T1204.001 - Malicious Link
MITREへのリンク →

MuddyWater

Score: 12.50
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1547.012 - Print Processors
  • T1586.002 - Email Accounts
  • T1518.002 - Backup Software Discovery
MITREへのリンク →

OilRig

Score: 14.37
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1176.001 - Browser Extensions
  • T1586.002 - Email Accounts
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

Turla

Score: 9.30
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1059.009 - Cloud API
  • T1003.001 - LSASS Memory
MITREへのリンク →

Tropic Trooper

Score: 11.28
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1003.001 - LSASS Memory
  • T1105 - Ingress Tool Transfer
  • T1665 - Hide Infrastructure
MITREへのリンク →

Medusa Group

Score: 24.41
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1547.012 - Print Processors
  • T1586.002 - Email Accounts
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1204.001 - Malicious Link
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

DarkVishnya

Score: 4.53
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1586.002 - Email Accounts
MITREへのリンク →

Lotus Blossom

Score: 3.77
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
MITREへのリンク →

TeamTNT

Score: 7.36
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1586.002 - Email Accounts
  • T1665 - Hide Infrastructure
MITREへのリンク →

BlackByte

Score: 13.69
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1586.002 - Email Accounts
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1204.001 - Malicious Link
MITREへのリンク →

Threat Group-3390

Score: 10.36
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
  • T1155 - AppleScript
  • T1546.017 - Udev Rules
MITREへのリンク →

Ke3chang

Score: 6.67
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Agrius

Score: 3.58
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1622 - Debugger Evasion
MITREへのリンク →

Earth Lusca

Score: 3.77
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1059.009 - Cloud API
MITREへのリンク →

Cobalt Group

Score: 13.05
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1586.002 - Email Accounts
  • T1518.002 - Backup Software Discovery
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
MITREへのリンク →

Molerats

Score: 6.44
Matched TTPs:
  • T1685.002 - Disable or Modify Cloud Log
  • T1546.017 - Udev Rules
MITREへのリンク →

Rancor

Score: 3.29
Matched TTPs:
  • T1685.002 - Disable or Modify Cloud Log
MITREへのリンク →

ZIRCONIUM

Score: 3.29
Matched TTPs:
  • T1685.002 - Disable or Modify Cloud Log
MITREへのリンク →

Machete

Score: 3.29
Matched TTPs:
  • T1685.002 - Disable or Modify Cloud Log
MITREへのリンク →

Volt Typhoon

Score: 12.78
Matched TTPs:
  • T1556.002 - Password Filter DLL
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1665 - Hide Infrastructure
MITREへのリンク →

INC Ransom

Score: 6.64
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Akira

Score: 4.24
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1622 - Debugger Evasion
MITREへのリンク →

Patchwork

Score: 9.60
Matched TTPs:
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1665 - Hide Infrastructure
  • T1008 - Fallback Channels
MITREへのリンク →

Indrik Spider

Score: 3.48
Matched TTPs:
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
MITREへのリンク →

Silence

Score: 5.88
Matched TTPs:
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Dragonfly

Score: 5.82
Matched TTPs:
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

LuminousMoth

Score: 4.50
Matched TTPs:
  • T1059.009 - Cloud API
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN8

Score: 6.22
Matched TTPs:
  • T1059.009 - Cloud API
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN13

Score: 10.09
Matched TTPs:
  • T1155 - AppleScript
  • T1622 - Debugger Evasion
  • T1105 - Ingress Tool Transfer
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Chimera

Score: 15.69
Matched TTPs:
  • T1155 - AppleScript
  • T1542.004 - ROMMONkit
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1665 - Hide Infrastructure
MITREへのリンク →

Deep Panda

Score: 6.03
Matched TTPs:
  • T1177 - LSASS Driver
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Axiom

Score: 14.01
Matched TTPs:
  • T1177 - LSASS Driver
  • T1189 - Drive-by Compromise
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

Fox Kitten

Score: 10.31
Matched TTPs:
  • T1177 - LSASS Driver
  • T1542.004 - ROMMONkit
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT29

Score: 3.29
Matched TTPs:
  • T1177 - LSASS Driver
MITREへのリンク →

Mustang Panda

Score: 18.66
Matched TTPs:
  • T1608 - Stage Capabilities
  • T1565.002 - Transmitted Data Manipulation
  • T1055.005 - Thread Local Storage
  • T1105 - Ingress Tool Transfer
  • T1548.006 - TCC Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

BRONZE BUTLER

Score: 6.32
Matched TTPs:
  • T1542.004 - ROMMONkit
  • T1008 - Fallback Channels
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1542.004 - ROMMONkit
MITREへのリンク →

menuPass

Score: 10.31
Matched TTPs:
  • T1542.004 - ROMMONkit
  • T1174 - Password Filter DLL
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Leviathan

Score: 7.55
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
  • T1546.017 - Udev Rules
MITREへのリンク →

GALLIUM

Score: 3.29
Matched TTPs:
  • T1174 - Password Filter DLL
MITREへのリンク →

APT39

Score: 8.58
Matched TTPs:
  • T1564.007 - VBA Stomping
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Contagious Interview

Score: 5.67
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

Thrip

Score: 5.67
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

RTM

Score: 6.21
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1008 - Fallback Channels
MITREへのリンク →

Scattered Spider

Score: 10.20
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN6

Score: 9.13
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1556 - Modify Authentication Process
MITREへのリンク →

Rocke

Score: 5.95
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1008 - Fallback Channels
MITREへのリンク →

Higaisa

Score: 5.98
Matched TTPs:
  • T1665 - Hide Infrastructure
  • T1546.017 - Udev Rules
MITREへのリンク →

TA2541

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Wizard Spider

Score: 0.79
Matched TTPs:
  • T1059.009 - Cloud API
  • T1548.006 - TCC Manipulation
  • T1003.001 - LSASS Memory
  • T1027.007 - Dynamic API Resolution
  • T1583 - Acquire Infrastructure
  • T1622 - Debugger Evasion
  • T1204.001 - Malicious Link
  • T1155 - AppleScript
  • T1176.001 - Browser Extensions
  • T1556 - Modify Authentication Process
MITREへのリンク →

Medusa Group

Score: 0.77
Matched TTPs:
  • T1059.009 - Cloud API
  • T1586.002 - Email Accounts
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1622 - Debugger Evasion
  • T1547.012 - Print Processors
  • T1204.001 - Malicious Link
  • T1176.001 - Browser Extensions
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

Kimsuky

Score: 0.69
Matched TTPs:
  • T1059.009 - Cloud API
  • T1027.014 - Polymorphic Code
  • T1008 - Fallback Channels
  • T1583 - Acquire Infrastructure
  • T1608 - Stage Capabilities
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
  • T1665 - Hide Infrastructure
  • T1176.001 - Browser Extensions
MITREへのリンク →

APT28

Score: 0.69
Matched TTPs:
  • T1588.003 - Code Signing Certificates
  • T1548.006 - TCC Manipulation
  • T1542.004 - ROMMONkit
  • T1583 - Acquire Infrastructure
  • T1552.005 - Cloud Instance Metadata API
  • T1105 - Ingress Tool Transfer
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

Gamaredon Group

Score: 0.66
Matched TTPs:
  • T1059.009 - Cloud API
  • T1546.017 - Udev Rules
  • T1542.004 - ROMMONkit
  • T1583 - Acquire Infrastructure
  • T1608 - Stage Capabilities
  • T1547.012 - Print Processors
  • T1552.005 - Cloud Instance Metadata API
MITREへのリンク →

Lazarus Group

Score: 0.66
Matched TTPs:
  • T1174 - Password Filter DLL
  • T1583 - Acquire Infrastructure
  • T1665 - Hide Infrastructure
  • T1622 - Debugger Evasion
  • T1055.005 - Thread Local Storage
  • T1176.001 - Browser Extensions
  • T1105 - Ingress Tool Transfer
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT32

Score: 0.62
Matched TTPs:
  • T1059.009 - Cloud API
  • T1174 - Password Filter DLL
  • T1027.007 - Dynamic API Resolution
  • T1027.014 - Polymorphic Code
  • T1583 - Acquire Infrastructure
  • T1176.001 - Browser Extensions
  • T1105 - Ingress Tool Transfer
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN7

Score: 0.61
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1027.007 - Dynamic API Resolution
  • T1105 - Ingress Tool Transfer
  • T1583 - Acquire Infrastructure
  • T1622 - Debugger Evasion
  • T1176.001 - Browser Extensions
  • T1011.001 - Exfiltration Over Bluetooth
MITREへのリンク →

APT41

Score: 0.59
Matched TTPs:
  • T1059.009 - Cloud API
  • T1548.006 - TCC Manipulation
  • T1027.007 - Dynamic API Resolution
  • T1008 - Fallback Channels
  • T1583 - Acquire Infrastructure
  • T1622 - Debugger Evasion
  • T1176.001 - Browser Extensions
  • T1177 - LSASS Driver
MITREへのリンク →

Mustang Panda

Score: 0.56
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1565.002 - Transmitted Data Manipulation
  • T1608 - Stage Capabilities
  • T1055.005 - Thread Local Storage
  • T1105 - Ingress Tool Transfer
  • T1556 - Modify Authentication Process
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る