Trusted Design

CRYPTOWALL 4 - THE EVOLUTION CONTINUES

概要

Over the past year, Talos has devoted a significant amount of time to better understanding how ransomware operates, its relation to other malware, and its economic impact. This research has proven valuable for Talos and led the development of better detection methods within the products we support along with the disruption of adversarial operations. CryptoWall is one ransomware variant that has shown gradual evolution over the past year with CryptoWall 2 and Cryptowall 3. Despite global efforts to detect and disrupt the distribution of CryptoWall, adversaries have continued to innovate and evolve their craft, leading to the release of CryptoWall 4. In order to ensure we have the most effective detection possible, Talos reverse engineered CryptoWall 4 to better understand its execution, behavior, deltas from previous versions and share our research and findings with the community.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 20.89
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1565.002 - Transmitted Data Manipulation
  • T1126 - Network Share Connection Removal
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Sea Turtle

Score: 3.88
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1199 - Trusted Relationship
MITREへのリンク →

Ember Bear

Score: 9.34
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1005 - Data from Local System
  • T1136.002 - Domain Account
MITREへのリンク →

Indrik Spider

Score: 7.47
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Agrius

Score: 3.03
Matched TTPs:
  • T1033 - System Owner/User Discovery
MITREへのリンク →

Contagious Interview

Score: 18.61
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1565.002 - Transmitted Data Manipulation
  • T1126 - Network Share Connection Removal
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Sandworm Team

Score: 21.41
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1049 - System Network Connections Discovery
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Star Blizzard

Score: 5.86
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
MITREへのリンク →

FIN13

Score: 10.01
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1053.006 - Systemd Timers
MITREへのリンク →

Moonstone Sleet

Score: 12.54
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1059.011 - Lua
  • T1027 - Obfuscated Files or Information
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Lazarus Group

Score: 9.67
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1055.005 - Thread Local Storage
  • T1578.001 - Create Snapshot
MITREへのリンク →

OilRig

Score: 10.12
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1027.018 - Invisible Unicode
MITREへのリンク →

UNC3886

Score: 7.15
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1136.002 - Domain Account
  • T1578.001 - Create Snapshot
MITREへのリンク →

LuminousMoth

Score: 8.74
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT29

Score: 7.93
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1683 - Generate Content
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Play

Score: 5.47
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

RedCurl

Score: 5.74
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.011 - Lua
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Turla

Score: 9.36
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1027.018 - Invisible Unicode
  • T1578.001 - Create Snapshot
MITREへのリンク →

Ke3chang

Score: 5.23
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
MITREへのリンク →

Mustang Panda

Score: 20.16
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1169 - Sudo
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1565.002 - Transmitted Data Manipulation
  • T1055.005 - Thread Local Storage
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TeamTNT

Score: 4.07
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
MITREへのリンク →

FIN7

Score: 11.21
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
  • T1578.001 - Create Snapshot
MITREへのリンク →

TA2541

Score: 9.79
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

Earth Lusca

Score: 11.96
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1562.011 - Spoof Security Alerting
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Mustard Tempest

Score: 7.87
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1543.002 - Systemd Service
  • T1027.018 - Invisible Unicode
MITREへのリンク →

LazyScripter

Score: 5.79
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Gamaredon Group

Score: 9.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

Threat Group-3390

Score: 5.97
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1546.017 - Udev Rules
MITREへのリンク →

TA505

Score: 8.98
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
MITREへのリンク →

BlackByte

Score: 4.31
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

BITTER

Score: 6.44
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1683 - Generate Content
MITREへのリンク →

APT32

Score: 4.18
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Saint Bear

Score: 3.33
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1027.018 - Invisible Unicode
MITREへのリンク →

EXOTIC LILY

Score: 3.33
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1027.018 - Invisible Unicode
MITREへのリンク →

LAPSUS$

Score: 7.44
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1557.002 - ARP Cache Poisoning
MITREへのリンク →

Metador

Score: 3.31
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

APT1

Score: 3.31
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Aquatic Panda

Score: 3.31
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Andariel

Score: 5.49
Matched TTPs:
  • T1136.002 - Domain Account
  • T1562.011 - Spoof Security Alerting
MITREへのリンク →

BackdoorDiplomacy

Score: 5.59
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
MITREへのリンク →

Scattered Spider

Score: 15.23
Matched TTPs:
  • T1136.002 - Domain Account
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1557.002 - ARP Cache Poisoning
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

HAFNIUM

Score: 3.62
Matched TTPs:
  • T1049 - System Network Connections Discovery
MITREへのリンク →

Axiom

Score: 3.62
Matched TTPs:
  • T1049 - System Network Connections Discovery
MITREへのリンク →

Volt Typhoon

Score: 7.06
Matched TTPs:
  • T1049 - System Network Connections Discovery
  • T1199 - Trusted Relationship
  • T1578.001 - Create Snapshot
MITREへのリンク →

INC Ransom

Score: 5.71
Matched TTPs:
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Cinnamon Tempest

Score: 3.37
Matched TTPs:
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

Storm-0501

Score: 7.79
Matched TTPs:
  • T1552.003 - Shell History
  • T1027 - Obfuscated Files or Information
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

Akira

Score: 4.86
Matched TTPs:
  • T1552.003 - Shell History
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Medusa Group

Score: 10.25
Matched TTPs:
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1598 - Phishing for Information
MITREへのリンク →

Water Galura

Score: 4.86
Matched TTPs:
  • T1552.003 - Shell History
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Magic Hound

Score: 8.17
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1683 - Generate Content
  • T1027.018 - Invisible Unicode
MITREへのリンク →

MuddyWater

Score: 5.24
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1562.011 - Spoof Security Alerting
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Storm-1811

Score: 6.12
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

BRONZE BUTLER

Score: 6.48
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1562.011 - Spoof Security Alerting
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT41

Score: 5.48
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

FIN8

Score: 4.55
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
MITREへのリンク →

GALLIUM

Score: 3.14
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
MITREへのリンク →

APT-C-36

Score: 3.14
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
MITREへのリンク →

Thrip

Score: 3.78
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

APT38

Score: 4.55
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Chimera

Score: 3.44
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT3

Score: 3.65
Matched TTPs:
  • T1059.011 - Lua
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Windshift

Score: 3.65
Matched TTPs:
  • T1059.011 - Lua
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT37

Score: 5.32
Matched TTPs:
  • T1059.011 - Lua
  • T1562.011 - Spoof Security Alerting
MITREへのリンク →

Tropic Trooper

Score: 6.66
Matched TTPs:
  • T1683 - Generate Content
  • T1562.011 - Spoof Security Alerting
MITREへのリンク →

TA551

Score: 3.03
Matched TTPs:
  • T1562.011 - Spoof Security Alerting
MITREへのリンク →

Leviathan

Score: 7.55
Matched TTPs:
  • T1562.011 - Spoof Security Alerting
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

Evilnum

Score: 4.29
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Molerats

Score: 4.51
Matched TTPs:
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

Mofang

Score: 4.51
Matched TTPs:
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

ZIRCONIUM

Score: 3.95
Matched TTPs:
  • T1027.018 - Invisible Unicode
  • T1578.001 - Create Snapshot
MITREへのリンク →

Sidewinder

Score: 3.95
Matched TTPs:
  • T1027.018 - Invisible Unicode
  • T1578.001 - Create Snapshot
MITREへのリンク →

Higaisa

Score: 5.74
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1546.017 - Udev Rules
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.81
Matched TTPs:
  • T1059.011 - Lua
  • T1091 - Replication Through Removable Media
  • T1606.002 - SAML Tokens
  • T1027 - Obfuscated Files or Information
  • T1033 - System Owner/User Discovery
  • T1049 - System Network Connections Discovery
  • T1027.018 - Invisible Unicode
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
MITREへのリンク →

Kimsuky

Score: 0.76
Matched TTPs:
  • T1059.011 - Lua
  • T1552.003 - Shell History
  • T1091 - Replication Through Removable Media
  • T1606.002 - SAML Tokens
  • T1126 - Network Share Connection Removal
  • T1565.002 - Transmitted Data Manipulation
  • T1033 - System Owner/User Discovery
  • T1027.018 - Invisible Unicode
  • T1199 - Trusted Relationship
MITREへのリンク →

Mustang Panda

Score: 0.75
Matched TTPs:
  • T1059.011 - Lua
  • T1091 - Replication Through Removable Media
  • T1606.002 - SAML Tokens
  • T1565.002 - Transmitted Data Manipulation
  • T1169 - Sudo
  • T1055.005 - Thread Local Storage
  • T1027.018 - Invisible Unicode
  • T1199 - Trusted Relationship
MITREへのリンク →

Contagious Interview

Score: 0.72
Matched TTPs:
  • T1552.003 - Shell History
  • T1091 - Replication Through Removable Media
  • T1606.002 - SAML Tokens
  • T1126 - Network Share Connection Removal
  • T1565.002 - Transmitted Data Manipulation
  • T1033 - System Owner/User Discovery
  • T1027.018 - Invisible Unicode
  • T1199 - Trusted Relationship
MITREへのリンク →

Scattered Spider

Score: 0.61
Matched TTPs:
  • T1552.003 - Shell History
  • T1557.002 - ARP Cache Poisoning
  • T1565.002 - Transmitted Data Manipulation
  • T1027 - Obfuscated Files or Information
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る