Trusted Design

LATENTBOT: Trace Me If You Can

概要

FireEye Labs recently uncovered LATENTBOT, a new, highly obfuscated BOT that has been in the wild since mid-2013. It has managed to leave hardly any traces on the Internet, is capable of watching its victims without ever being noticed, and can even corrupt a hard disk, thus making a PC useless. Through our Dynamic Threat Intelligence (DTI), we have observed multiple campaigns targeting multiple industries in the United States, United Kingdom, South Korea, Brazil, United Arab Emirates, Singapore, Canada, Peru and Poland – primarily in the financial services and insurance sectors. Although the infection strategy is not new, the final payload dropped – which we named LATENTBOT – caught our attention since it implements several layers of obfuscation, a unique exfiltration mechanism, and has been very successful at infecting multiple organizations. Source : https://www.fireeye.com/blog/threat-research/2015/12/latentbot_trace_me.html

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Lazarus Group

Score: 21.48
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1587.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1591 - Gather Victim Org Information
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1561.001 - Disk Content Wipe
MITREへのリンク →

TA577

Score: 3.84
Matched TTPs:
  • T1027.009 - Embedded Payloads
MITREへのリンク →

Moonstone Sleet

Score: 13.72
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1591 - Gather Victim Org Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

LAPSUS$

Score: 21.05
Matched TTPs:
  • T1597.002 - Purchase Technical Data
  • T1591.002 - Business Relationships
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1591.004 - Identify Roles
  • T1213.005 - Messaging Applications
MITREへのリンク →

Contagious Interview

Score: 28.79
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1681 - Search Threat Vendor Data
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1593 - Search Open Websites/Domains
  • T1593.001 - Social Media
  • T1027.010 - Command Obfuscation
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ember Bear

Score: 11.93
Matched TTPs:
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Sandworm Team

Score: 36.03
Matched TTPs:
  • T1491.002 - External Defacement
  • T1594 - Search Victim-Owned Websites
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1591.002 - Business Relationships
  • T1584.005 - Botnet
  • T1199 - Trusted Relationship
  • T1593 - Search Open Websites/Domains
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Mustard Tempest

Score: 11.05
Matched TTPs:
  • T1583.008 - Malvertising
  • T1608.001 - Upload Malware
  • T1608.006 - SEO Poisoning
MITREへのリンク →

Silent Librarian

Score: 3.29
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
MITREへのリンク →

Kimsuky

Score: 34.09
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1593.002 - Search Engines
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1591 - Gather Victim Org Information
  • T1593 - Search Open Websites/Domains
  • T1593.001 - Social Media
  • T1027.010 - Command Obfuscation
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Volt Typhoon

Score: 25.77
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1590.006 - Network Security Appliances
  • T1584.005 - Botnet
  • T1591 - Gather Victim Org Information
  • T1593 - Search Open Websites/Domains
  • T1591.004 - Identify Roles
  • T1596.005 - Scan Databases
MITREへのリンク →

EXOTIC LILY

Score: 17.66
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1608.001 - Upload Malware
  • T1597 - Search Closed Sources
  • T1593.001 - Social Media
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TA578

Score: 5.30
Matched TTPs:
  • T1594 - Search Victim-Owned Websites
  • T1583.006 - Web Services
MITREへのリンク →

FIN13

Score: 6.71
Matched TTPs:
  • T1587.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
MITREへのリンク →

OilRig

Score: 11.93
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 12.28
Matched TTPs:
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

LuminousMoth

Score: 6.53
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
MITREへのリンク →

APT29

Score: 19.95
Matched TTPs:
  • T1587.001 - Malware
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
  • T1090.004 - Domain Fronting
  • T1027.006 - HTML Smuggling
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Play

Score: 6.48
Matched TTPs:
  • T1587.001 - Malware
  • T1657 - Financial Theft
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Aoqin Dragon

Score: 3.59
Matched TTPs:
  • T1587.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1587.001 - Malware
  • T1199 - Trusted Relationship
MITREへのリンク →

Turla

Score: 12.05
Matched TTPs:
  • T1587.001 - Malware
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Mustang Panda

Score: 10.86
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1593 - Search Open Websites/Domains
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

TeamTNT

Score: 4.07
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
MITREへのリンク →

FIN7

Score: 21.49
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1674 - Input Injection
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1591 - Gather Victim Org Information
  • T1591.004 - Identify Roles
  • T1027.010 - Command Obfuscation
MITREへのリンク →

TA2541

Score: 6.44
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1583.006 - Web Services
MITREへのリンク →

Earth Lusca

Score: 10.07
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1584.006 - Web Services
MITREへのリンク →

LazyScripter

Score: 8.31
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Gamaredon Group

Score: 9.98
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1027.010 - Command Obfuscation
  • T1561.001 - Disk Content Wipe
MITREへのリンク →

Star Blizzard

Score: 5.26
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1593 - Search Open Websites/Domains
MITREへのリンク →

Threat Group-3390

Score: 10.35
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1608.002 - Upload Tool
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

TA505

Score: 6.30
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1027.010 - Command Obfuscation
MITREへのリンク →

BITTER

Score: 5.56
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT32

Score: 9.44
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

HEXANE

Score: 7.46
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1591.004 - Identify Roles
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Saint Bear

Score: 5.48
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1659 - Content Injection
MITREへのリンク →

Medusa Group

Score: 10.53
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Dragonfly

Score: 5.34
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Aquatic Panda

Score: 6.42
Matched TTPs:
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Andariel

Score: 7.80
Matched TTPs:
  • T1588.001 - Malware
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

BackdoorDiplomacy

Score: 4.55
Matched TTPs:
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Scattered Spider

Score: 8.83
Matched TTPs:
  • T1588.001 - Malware
  • T1657 - Financial Theft
  • T1213.005 - Messaging Applications
MITREへのリンク →

Winter Vivern

Score: 5.72
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1584.006 - Web Services
MITREへのリンク →

Wizard Spider

Score: 3.96
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1027.010 - Command Obfuscation
MITREへのリンク →

FIN6

Score: 6.48
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1027.010 - Command Obfuscation
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Fox Kitten

Score: 7.80
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1027.010 - Command Obfuscation
  • T1213.005 - Messaging Applications
MITREへのリンク →

ZIRCONIUM

Score: 4.11
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
MITREへのリンク →

Magic Hound

Score: 16.88
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1592.002 - Software
  • T1027.010 - Command Obfuscation
  • T1591.001 - Determine Physical Locations
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Higaisa

Score: 3.59
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Storm-0501

Score: 4.62
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
MITREへのリンク →

APT41

Score: 11.01
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1596.005 - Scan Databases
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

HAFNIUM

Score: 8.38
Matched TTPs:
  • T1584.005 - Botnet
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
MITREへのリンク →

Axiom

Score: 5.12
Matched TTPs:
  • T1584.005 - Botnet
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

MuddyWater

Score: 5.37
Matched TTPs:
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

APT28

Score: 9.54
Matched TTPs:
  • T1583.006 - Web Services
  • T1591 - Gather Victim Org Information
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Confucius

Score: 3.51
Matched TTPs:
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

POLONIUM

Score: 4.76
Matched TTPs:
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
MITREへのリンク →

GOLD SOUTHFIELD

Score: 4.61
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Sea Turtle

Score: 4.24
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

CURIUM

Score: 6.14
Matched TTPs:
  • T1584.006 - Web Services
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Sidewinder

Score: 3.36
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Patchwork

Score: 6.64
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Cobalt Group

Score: 3.36
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
MITREへのリンク →

BRONZE BUTLER

Score: 4.78
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Rocke

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.86
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1491.002 - External Defacement
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1592.002 - Software
  • T1593 - Search Open Websites/Domains
  • T1584.005 - Botnet
  • T1027.010 - Command Obfuscation
  • T1591.002 - Business Relationships
  • T1587.001 - Malware
  • T1199 - Trusted Relationship
  • T1594 - Search Victim-Owned Websites
MITREへのリンク →

Kimsuky

Score: 0.78
Matched TTPs:
  • T1593.002 - Search Engines
  • T1593.001 - Social Media
  • T1608.001 - Upload Malware
  • T1593 - Search Open Websites/Domains
  • T1657 - Financial Theft
  • T1036.004 - Masquerade Task or Service
  • T1591 - Gather Victim Org Information
  • T1027.010 - Command Obfuscation
  • T1587.001 - Malware
  • T1583.006 - Web Services
  • T1594 - Search Victim-Owned Websites
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Contagious Interview

Score: 0.68
Matched TTPs:
  • T1593.001 - Social Media
  • T1608.001 - Upload Malware
  • T1588.007 - Artificial Intelligence
  • T1566.003 - Spearphishing via Service
  • T1593 - Search Open Websites/Domains
  • T1681 - Search Threat Vendor Data
  • T1657 - Financial Theft
  • T1027.010 - Command Obfuscation
  • T1587.001 - Malware
  • T1583.006 - Web Services
MITREへのリンク →

Volt Typhoon

Score: 0.63
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1591.004 - Identify Roles
  • T1594 - Search Victim-Owned Websites
  • T1593 - Search Open Websites/Domains
  • T1591 - Gather Victim Org Information
  • T1596.005 - Scan Databases
  • T1584.005 - Botnet
MITREへのリンク →

FIN7

Score: 0.58
Matched TTPs:
  • T1591.004 - Identify Roles
  • T1608.001 - Upload Malware
  • T1674 - Input Injection
  • T1036.004 - Masquerade Task or Service
  • T1591 - Gather Victim Org Information
  • T1027.010 - Command Obfuscation
  • T1587.001 - Malware
  • T1583.006 - Web Services
MITREへのリンク →

Lazarus Group

Score: 0.56
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1561.001 - Disk Content Wipe
  • T1036.004 - Masquerade Task or Service
  • T1591 - Gather Victim Org Information
  • T1587.001 - Malware
  • T1583.006 - Web Services
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る