Trusted Design

Attack on French Diplomat Linked to Operation Lotus Blossom

概要

PaloAlto observed a targeted attack in November directed at an individual working for the French Ministry of Foreign Affairs. The attack involved a spear-phishing email sent to a single French diplomat based in Taipei, Taiwan and contained an invitation to a Science and Technology support group event. The actors attempted to exploit CVE-2014-6332 using a slightly modified version of the proof-of-concept (POC) code to install a Trojan called Emissary, which is related to the Operation Lotus Blossom campaign. The TTPs used in this attack also match those detailed in the paper. The targeting of this individual suggests the actors are interested in breaching the French Ministry of Foreign Affairs itself or gaining insights into relations between France and Taiwan.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT29

Score: 7.73
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT32

Score: 7.95
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1218.010 - Regsvr32
  • T1204.001 - Malicious Link
MITREへのリンク →

BRONZE BUTLER

Score: 3.84
Matched TTPs:
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Dragonfly

Score: 3.62
Matched TTPs:
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

Star Blizzard

Score: 3.62
Matched TTPs:
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

Sidewinder

Score: 4.98
Matched TTPs:
  • T1598.002 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

SideCopy

Score: 7.75
Matched TTPs:
  • T1598.002 - Spearphishing Attachment
  • T1614 - System Location Discovery
MITREへのリンク →

APT33

Score: 5.49
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1204.001 - Malicious Link
MITREへのリンク →

Wizard Spider

Score: 5.49
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1204.001 - Malicious Link
MITREへのリンク →

Cobalt Group

Score: 4.11
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1204.001 - Malicious Link
MITREへのリンク →

Storm-0501

Score: 5.67
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1219.002 - Remote Desktop Software
MITREへのリンク →

Leviathan

Score: 4.11
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1204.001 - Malicious Link
MITREへのリンク →

Kimsuky

Score: 17.00
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
  • T1588.005 - Exploits
MITREへのリンク →

Lazarus Group

Score: 4.92
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT39

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Magic Hound

Score: 6.28
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Turla

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

FIN7

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Sandworm Team

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

APT28

Score: 7.20
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1204.001 - Malicious Link
MITREへのリンク →

MuddyWater

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

ZIRCONIUM

Score: 7.20
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1204.001 - Malicious Link
MITREへのリンク →

Gamaredon Group

Score: 3.76
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1204.001 - Malicious Link
MITREへのリンク →

Volt Typhoon

Score: 4.13
Matched TTPs:
  • T1614 - System Location Discovery
MITREへのリンク →

Scattered Spider

Score: 10.91
Matched TTPs:
  • T1598 - Phishing for Information
  • T1219.002 - Remote Desktop Software
  • T1538 - Cloud Service Dashboard
MITREへのリンク →

Moonstone Sleet

Score: 5.96
Matched TTPs:
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 6.81
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Evilnum

Score: 4.29
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
MITREへのリンク →

Storm-1811

Score: 5.45
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Mustang Panda

Score: 4.29
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1204.001 - Malicious Link
MITREへのリンク →

Axiom

Score: 4.54
Matched TTPs:
  • T1001.002 - Steganography
MITREへのリンク →

Windshift

Score: 3.88
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 3.88
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

EXOTIC LILY

Score: 3.88
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ember Bear

Score: 4.13
Matched TTPs:
  • T1588.005 - Exploits
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.80
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1588.005 - Exploits
  • T1204.001 - Malicious Link
  • T1598 - Phishing for Information
  • T1218.010 - Regsvr32
  • T1219.002 - Remote Desktop Software
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る