Trusted Design

Campaign on the Government of Thailand Delivers Bookworm Trojan

概要

Threat actors have delivered Bookworm as a payload in attacks on targets in Thailand. Readers who are interested in this campaign should start with our first blog that lays out the overall functionality of the malware and introduces its many components. Unit 42 does not have detailed targeting information for all known Bookworm samples, but we are aware of attempted attacks on at least two branches of government in Thailand. We speculate that other attacks delivering Bookworm were also targeting organizations in Thailand based on the contents of the associated decoys documents, as well as several of the dynamic DNS domain names used to host C2 servers that contain the words “Thai” or “Thailand”. Analysis of compromised systems seen communicating with Bookworm C2 servers also confirms our speculation on targeting with a majority of systems existing within Thailand.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Volt Typhoon

Score: 30.23
Matched TTPs:
  • T1592 - Gather Victim Host Information
  • T1590.004 - Network Topology
  • T1584.005 - Botnet
  • T1590 - Gather Victim Network Information
  • T1593 - Search Open Websites/Domains
  • T1614 - System Location Discovery
  • T1584.004 - Server
  • T1596.005 - Scan Databases
MITREへのリンク →

Ember Bear

Score: 9.47
Matched TTPs:
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Sandworm Team

Score: 40.07
Matched TTPs:
  • T1491.002 - External Defacement
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1583.001 - Domains
  • T1591.002 - Business Relationships
  • T1584.005 - Botnet
  • T1199 - Trusted Relationship
  • T1593 - Search Open Websites/Domains
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
  • T1590.001 - Domain Properties
MITREへのリンク →

Andariel

Score: 10.95
Matched TTPs:
  • T1590.005 - IP Addresses
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Magic Hound

Score: 31.04
Matched TTPs:
  • T1590.005 - IP Addresses
  • T1562 - Impair Defenses
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
  • T1036.010 - Masquerade Account Name
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
  • T1584.001 - Domains
MITREへのリンク →

HAFNIUM

Score: 20.61
Matched TTPs:
  • T1590.005 - IP Addresses
  • T1592.004 - Client Configurations
  • T1584.005 - Botnet
  • T1583.006 - Web Services
  • T1590 - Gather Victim Network Information
  • T1199 - Trusted Relationship
MITREへのリンク →

APT41

Score: 19.27
Matched TTPs:
  • T1568.002 - Domain Generation Algorithms
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1595.003 - Wordlist Scanning
  • T1596.005 - Scan Databases
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

TA551

Score: 6.88
Matched TTPs:
  • T1568.002 - Domain Generation Algorithms
  • T1218.010 - Regsvr32
MITREへのリンク →

Sea Turtle

Score: 9.60
Matched TTPs:
  • T1583.002 - DNS Server
  • T1583.001 - Domains
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Axiom

Score: 15.26
Matched TTPs:
  • T1583.002 - DNS Server
  • T1584.005 - Botnet
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1001.002 - Steganography
MITREへのリンク →

HEXANE

Score: 9.73
Matched TTPs:
  • T1583.002 - DNS Server
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Salt Typhoon

Score: 3.84
Matched TTPs:
  • T1590.004 - Network Topology
MITREへのリンク →

FIN13

Score: 5.94
Matched TTPs:
  • T1590.004 - Network Topology
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

BlackByte

Score: 9.73
Matched TTPs:
  • T1562 - Impair Defenses
  • T1608.001 - Upload Malware
  • T1614.001 - System Language Discovery
MITREへのリンク →

TA2541

Score: 8.25
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Earth Lusca

Score: 13.72
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
MITREへのリンク →

Mustang Panda

Score: 18.95
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1593 - Search Open Websites/Domains
  • T1678 - Delay Execution
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Kimsuky

Score: 22.60
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1593 - Search Open Websites/Domains
  • T1218.010 - Regsvr32
  • T1102.002 - Bidirectional Communication
  • T1102.001 - Dead Drop Resolver
  • T1584.001 - Domains
MITREへのリンク →

Mustard Tempest

Score: 7.02
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1189 - Drive-by Compromise
  • T1584.001 - Domains
MITREへのリンク →

OilRig

Score: 14.10
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TeamTNT

Score: 3.49
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
MITREへのリンク →

LazyScripter

Score: 5.50
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1583.006 - Web Services
MITREへのリンク →

Gamaredon Group

Score: 15.18
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1102.003 - One-Way Communication
  • T1102.002 - Bidirectional Communication
  • T1221 - Template Injection
MITREへのリンク →

Star Blizzard

Score: 6.78
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1593 - Search Open Websites/Domains
MITREへのリンク →

Threat Group-3390

Score: 9.50
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

SideCopy

Score: 9.39
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1614 - System Location Discovery
  • T1584.001 - Domains
MITREへのリンク →

TA505

Score: 3.49
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
MITREへのリンク →

BITTER

Score: 7.08
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT32

Score: 13.60
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Saint Bear

Score: 5.48
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Moonstone Sleet

Score: 6.01
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 15.44
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1681 - Search Threat Vendor Data
  • T1583.006 - Web Services
  • T1593 - Search Open Websites/Domains
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN7

Score: 10.00
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

EXOTIC LILY

Score: 7.51
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT42

Score: 6.24
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.001 - Domains
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

APT28

Score: 24.16
Matched TTPs:
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1546.015 - Component Object Model Hijacking
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1498 - Network Denial of Service
  • T1221 - Template Injection
MITREへのリンク →

Storm-1811

Score: 12.20
Matched TTPs:
  • T1583.001 - Domains
  • T1667 - Email Bombing
  • T1036.010 - Masquerade Account Name
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT1

Score: 4.80
Matched TTPs:
  • T1583.001 - Domains
  • T1584.001 - Domains
MITREへのリンク →

IndigoZebra

Score: 3.53
Matched TTPs:
  • T1583.001 - Domains
  • T1583.006 - Web Services
MITREへのリンク →

Leviathan

Score: 14.49
Matched TTPs:
  • T1583.001 - Domains
  • T1102.003 - One-Way Communication
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
MITREへのリンク →

Scattered Spider

Score: 5.65
Matched TTPs:
  • T1583.001 - Domains
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Dragonfly

Score: 18.23
Matched TTPs:
  • T1583.001 - Domains
  • T1591.002 - Business Relationships
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
  • T1189 - Drive-by Compromise
  • T1221 - Template Injection
  • T1584.004 - Server
MITREへのリンク →

Transparent Tribe

Score: 8.06
Matched TTPs:
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1584.001 - Domains
MITREへのリンク →

ZIRCONIUM

Score: 8.02
Matched TTPs:
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

RedEcho

Score: 4.26
Matched TTPs:
  • T1583.001 - Domains
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Lazarus Group

Score: 28.93
Matched TTPs:
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1574.013 - KernelCallbackTable
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT38

Score: 6.90
Matched TTPs:
  • T1583.001 - Domains
  • T1189 - Drive-by Compromise
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Winter Vivern

Score: 9.00
Matched TTPs:
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

CURIUM

Score: 9.43
Matched TTPs:
  • T1583.001 - Domains
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

menuPass

Score: 4.26
Matched TTPs:
  • T1583.001 - Domains
  • T1199 - Trusted Relationship
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1659 - Content Injection
MITREへのリンク →

UNC3886

Score: 7.72
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

LAPSUS$

Score: 10.72
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1199 - Trusted Relationship
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Carbanak

Score: 4.49
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

FIN6

Score: 7.36
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

PROMETHIUM

Score: 3.86
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1189 - Drive-by Compromise
MITREへのリンク →

Higaisa

Score: 3.59
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Storm-0501

Score: 8.46
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1614.001 - System Language Discovery
MITREへのリンク →

Medusa Group

Score: 8.38
Matched TTPs:
  • T1583.006 - Web Services
  • T1573.002 - Asymmetric Cryptography
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Turla

Score: 12.63
Matched TTPs:
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
MITREへのリンク →

MuddyWater

Score: 5.90
Matched TTPs:
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT29

Score: 13.31
Matched TTPs:
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
  • T1090.004 - Domain Fronting
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Confucius

Score: 6.66
Matched TTPs:
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

POLONIUM

Score: 7.16
Matched TTPs:
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Indrik Spider

Score: 6.68
Matched TTPs:
  • T1590 - Gather Victim Network Information
  • T1584.004 - Server
MITREへのリンク →

RedCurl

Score: 5.49
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Cobalt Group

Score: 6.99
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Inception

Score: 7.39
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

APT19

Score: 4.51
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
MITREへのリンク →

APT37

Score: 9.28
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT12

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Patchwork

Score: 6.54
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

APT3

Score: 5.12
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
MITREへのリンク →

BRONZE BUTLER

Score: 6.54
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Tropic Trooper

Score: 7.39
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1221 - Template Injection
MITREへのリンク →

Elderwood

Score: 3.26
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Darkhotel

Score: 3.26
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Volatile Cedar

Score: 4.13
Matched TTPs:
  • T1595.003 - Wordlist Scanning
MITREへのリンク →

Ke3chang

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

Malteiro

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

DarkVishnya

Score: 4.54
Matched TTPs:
  • T1200 - Hardware Additions
MITREへのリンク →

RTM

Score: 5.05
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Windshift

Score: 4.29
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dark Caracal

Score: 4.29
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Daggerfly

Score: 4.60
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
MITREへのリンク →

DarkHydrus

Score: 3.15
Matched TTPs:
  • T1221 - Template Injection
MITREへのリンク →

Rocke

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.83
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1584.005 - Botnet
  • T1590.001 - Domain Properties
  • T1203 - Exploitation for Client Execution
  • T1593 - Search Open Websites/Domains
  • T1584.004 - Server
  • T1591.002 - Business Relationships
  • T1199 - Trusted Relationship
  • T1592.002 - Software
  • T1583.001 - Domains
  • T1102.002 - Bidirectional Communication
  • T1195 - Supply Chain Compromise
  • T1491.002 - External Defacement
MITREへのリンク →

Magic Hound

Score: 0.66
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1583.006 - Web Services
  • T1590.005 - IP Addresses
  • T1189 - Drive-by Compromise
  • T1036.010 - Masquerade Account Name
  • T1036.004 - Masquerade Task or Service
  • T1592.002 - Software
  • T1562 - Impair Defenses
  • T1583.001 - Domains
  • T1102.002 - Bidirectional Communication
  • T1584.001 - Domains
MITREへのリンク →

Volt Typhoon

Score: 0.65
Matched TTPs:
  • T1596.005 - Scan Databases
  • T1584.005 - Botnet
  • T1590.004 - Network Topology
  • T1592 - Gather Victim Host Information
  • T1593 - Search Open Websites/Domains
  • T1590 - Gather Victim Network Information
  • T1614 - System Location Discovery
  • T1584.004 - Server
MITREへのリンク →

Lazarus Group

Score: 0.62
Matched TTPs:
  • T1574.013 - KernelCallbackTable
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1583.006 - Web Services
  • T1529 - System Shutdown/Reboot
  • T1189 - Drive-by Compromise
  • T1584.004 - Server
  • T1036.004 - Masquerade Task or Service
  • T1027.007 - Dynamic API Resolution
  • T1583.001 - Domains
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る