Attack on French Diplomat Linked to Operation Lotus Blossom
概要
PaloAlto observed a targeted attack in November directed at an individual working for the French Ministry of Foreign Affairs. The attack involved a spear-phishing email sent to a single French diplomat based in Taipei, Taiwan and contained an invitation to a Science and Technology support group event.
The actors attempted to exploit CVE-2014-6332 using a slightly modified version of the proof-of-concept (POC) code to install a Trojan called Emissary, which is related to the Operation Lotus Blossom campaign. The TTPs used in this attack also match those detailed in the paper. The targeting of this individual suggests the actors are interested in breaching the French Ministry of Foreign Affairs itself or gaining insights into relations between France and Taiwan.
Created: 2026-02-23
Indicators
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 7.73
Matched TTPs:
- T1550.003 - Pass the Ticket
- T1204.001 - Malicious Link
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 7.95
Matched TTPs:
- T1550.003 - Pass the Ticket
- T1218.010 - Regsvr32
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1550.003 - Pass the Ticket
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1598.002 - Spearphishing Attachment
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1598.002 - Spearphishing Attachment
MITREへのリンク →
Score: 4.98
Matched TTPs:
- T1598.002 - Spearphishing Attachment
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 7.75
Matched TTPs:
- T1598.002 - Spearphishing Attachment
- T1614 - System Location Discovery
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1552.006 - Group Policy Preferences
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1552.006 - Group Policy Preferences
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 4.11
Matched TTPs:
- T1218.010 - Regsvr32
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 5.67
Matched TTPs:
- T1218.010 - Regsvr32
- T1219.002 - Remote Desktop Software
MITREへのリンク →
Score: 4.11
Matched TTPs:
- T1218.010 - Regsvr32
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 17.00
Matched TTPs:
- T1218.010 - Regsvr32
- T1102.002 - Bidirectional Communication
- T1598 - Phishing for Information
- T1219.002 - Remote Desktop Software
- T1204.001 - Malicious Link
- T1588.005 - Exploits
MITREへのリンク →
Score: 4.92
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 3.76
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 6.28
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1204.001 - Malicious Link
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 3.76
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 3.76
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 3.76
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 7.20
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1598 - Phishing for Information
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 3.76
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 7.20
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1598 - Phishing for Information
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 3.76
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1614 - System Location Discovery
MITREへのリンク →
Score: 10.91
Matched TTPs:
- T1598 - Phishing for Information
- T1219.002 - Remote Desktop Software
- T1538 - Cloud Service Dashboard
MITREへのリンク →
Score: 5.96
Matched TTPs:
- T1598 - Phishing for Information
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 6.81
Matched TTPs:
- T1219.002 - Remote Desktop Software
- T1204.001 - Malicious Link
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 4.29
Matched TTPs:
- T1219.002 - Remote Desktop Software
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 5.45
Matched TTPs:
- T1219.002 - Remote Desktop Software
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 4.29
Matched TTPs:
- T1219.002 - Remote Desktop Software
- T1204.001 - Malicious Link
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1001.002 - Steganography
MITREへのリンク →
Score: 3.88
Matched TTPs:
- T1204.001 - Malicious Link
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 3.88
Matched TTPs:
- T1204.001 - Malicious Link
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 3.88
Matched TTPs:
- T1204.001 - Malicious Link
- T1566.003 - Spearphishing via Service
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1056.004 - Credential API Hooking
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.80
Matched TTPs:
- T1102.002 - Bidirectional Communication
- T1588.005 - Exploits
- T1204.001 - Malicious Link
- T1598 - Phishing for Information
- T1218.010 - Regsvr32
- T1219.002 - Remote Desktop Software
MITREへのリンク →
Related CVEs
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る