Trusted Design

Gootkit banking Trojan jumps the Channel

概要

First documented in mid-2014, the Gootkit banking Trojan appeared to focus solely on customers from several French banks. This JavaScript-based malware combines web-injects (a la Zeus) and a clever persistence technique to create a robust tool for stealing online banking logins and other credentials from users of infected systems. In 2015, Gootkit integrated certain fileless features previously noted in Poweliks, and it has also been observed being dropped directly by Angler EK or indirectly via Bedep.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT32

Score: 24.37
Matched TTPs:
  • T1027.011 - Fileless Storage
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
  • T1564.001 - Hidden Files and Directories
  • T1078.003 - Local Accounts
MITREへのリンク →

Turla

Score: 22.25
Matched TTPs:
  • T1027.011 - Fileless Storage
  • T1059.007 - JavaScript
  • T1055 - Process Injection
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1555.004 - Windows Credential Manager
  • T1189 - Drive-by Compromise
  • T1078.003 - Local Accounts
MITREへのリンク →

Saint Bear

Score: 5.96
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
MITREへのリンク →

MoustachedBouncer

Score: 6.51
Matched TTPs:
  • T1059.007 - JavaScript
  • T1659 - Content Injection
MITREへのリンク →

MuddyWater

Score: 5.96
Matched TTPs:
  • T1059.007 - JavaScript
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Earth Lusca

Score: 11.35
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

Winter Vivern

Score: 13.87
Matched TTPs:
  • T1059.007 - JavaScript
  • T1056.003 - Web Portal Capture
  • T1041 - Exfiltration Over C2 Channel
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

Silence

Score: 4.43
Matched TTPs:
  • T1059.007 - JavaScript
  • T1055 - Process Injection
MITREへのリンク →

Contagious Interview

Score: 14.99
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

LazyScripter

Score: 5.96
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
MITREへのリンク →

TA505

Score: 3.95
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
MITREへのリンク →

FIN7

Score: 15.83
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1674 - Input Injection
  • T1583.006 - Web Services
  • T1564.001 - Hidden Files and Directories
  • T1078.003 - Local Accounts
MITREへのリンク →

Cobalt Group

Score: 7.18
Matched TTPs:
  • T1059.007 - JavaScript
  • T1055 - Process Injection
  • T1218.010 - Regsvr32
MITREへのリンク →

Higaisa

Score: 11.64
Matched TTPs:
  • T1059.007 - JavaScript
  • T1029 - Scheduled Transfer
  • T1041 - Exfiltration Over C2 Channel
  • T1027.015 - Compression
MITREへのリンク →

Kimsuky

Score: 21.48
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
  • T1218.010 - Regsvr32
  • T1588.003 - Code Signing Certificates
  • T1078.003 - Local Accounts
MITREへのリンク →

Indrik Spider

Score: 5.82
Matched TTPs:
  • T1059.007 - JavaScript
  • T1136 - Create Account
MITREへのリンク →

Molerats

Score: 5.12
Matched TTPs:
  • T1059.007 - JavaScript
  • T1027.015 - Compression
MITREへのリンク →

Leafminer

Score: 3.74
Matched TTPs:
  • T1059.007 - JavaScript
  • T1189 - Drive-by Compromise
MITREへのリンク →

Mustang Panda

Score: 17.88
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

TA578

Score: 3.99
Matched TTPs:
  • T1059.007 - JavaScript
  • T1583.006 - Web Services
MITREへのリンク →

Star Blizzard

Score: 3.95
Matched TTPs:
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
MITREへのリンク →

Sandworm Team

Score: 3.95
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

TA2541

Score: 9.60
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1583.006 - Web Services
  • T1027.015 - Compression
MITREへのリンク →

LuminousMoth

Score: 6.61
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1041 - Exfiltration Over C2 Channel
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Mustard Tempest

Score: 3.74
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1189 - Drive-by Compromise
MITREへのリンク →

OilRig

Score: 13.28
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1137.004 - Outlook Home Page
  • T1555.004 - Windows Credential Manager
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Gamaredon Group

Score: 14.72
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
  • T1221 - Template Injection
  • T1027.015 - Compression
MITREへのリンク →

Threat Group-3390

Score: 14.17
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1608.002 - Upload Tool
  • T1189 - Drive-by Compromise
  • T1588.003 - Code Signing Certificates
  • T1027.015 - Compression
MITREへのリンク →

BlackByte

Score: 6.40
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

APT38

Score: 7.85
Matched TTPs:
  • T1055 - Process Injection
  • T1189 - Drive-by Compromise
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Wizard Spider

Score: 11.20
Matched TTPs:
  • T1055 - Process Injection
  • T1041 - Exfiltration Over C2 Channel
  • T1555.004 - Windows Credential Manager
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

APT37

Score: 7.85
Matched TTPs:
  • T1055 - Process Injection
  • T1189 - Drive-by Compromise
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Velvet Ant

Score: 5.12
Matched TTPs:
  • T1055 - Process Injection
  • T1078.003 - Local Accounts
MITREへのリンク →

PLATINUM

Score: 4.22
Matched TTPs:
  • T1055 - Process Injection
  • T1189 - Drive-by Compromise
MITREへのリンク →

Medusa Group

Score: 12.29
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

FIN13

Score: 5.19
Matched TTPs:
  • T1657 - Financial Theft
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Storm-0501

Score: 5.27
Matched TTPs:
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
MITREへのリンク →

Scattered Spider

Score: 8.34
Matched TTPs:
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1136 - Create Account
MITREへのリンク →

Play

Score: 5.19
Matched TTPs:
  • T1657 - Financial Theft
  • T1078.003 - Local Accounts
MITREへのリンク →

HAFNIUM

Score: 11.48
Matched TTPs:
  • T1583.006 - Web Services
  • T1564.001 - Hidden Files and Directories
  • T1550.001 - Application Access Token
  • T1078.003 - Local Accounts
MITREへのリンク →

ZIRCONIUM

Score: 3.99
Matched TTPs:
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

APT28

Score: 13.73
Matched TTPs:
  • T1583.006 - Web Services
  • T1189 - Drive-by Compromise
  • T1221 - Template Injection
  • T1564.001 - Hidden Files and Directories
  • T1550.001 - Application Access Token
MITREへのリンク →

APT29

Score: 4.68
Matched TTPs:
  • T1583.006 - Web Services
  • T1078.003 - Local Accounts
MITREへのリンク →

Lazarus Group

Score: 16.17
Matched TTPs:
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
  • T1189 - Drive-by Compromise
  • T1027.007 - Dynamic API Resolution
  • T1564.001 - Hidden Files and Directories
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Confucius

Score: 7.14
Matched TTPs:
  • T1583.006 - Web Services
  • T1041 - Exfiltration Over C2 Channel
  • T1221 - Template Injection
MITREへのリンク →

Magic Hound

Score: 3.78
Matched TTPs:
  • T1583.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

Leviathan

Score: 9.64
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
  • T1027.015 - Compression
MITREへのリンク →

Stealth Falcon

Score: 5.59
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

CURIUM

Score: 7.36
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

Inception

Score: 5.90
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1221 - Template Injection
MITREへのリンク →

APT19

Score: 4.51
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
MITREへのリンク →

Transparent Tribe

Score: 4.43
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Dragonfly

Score: 4.92
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1221 - Template Injection
MITREへのリンク →

PROMETHIUM

Score: 4.43
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1078.003 - Local Accounts
MITREへのリンク →

Tropic Trooper

Score: 8.48
Matched TTPs:
  • T1221 - Template Injection
  • T1564.001 - Hidden Files and Directories
  • T1078.003 - Local Accounts
MITREへのリンク →

DarkHydrus

Score: 3.15
Matched TTPs:
  • T1221 - Template Injection
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Salt Typhoon

Score: 3.84
Matched TTPs:
  • T1136 - Create Account
MITREへのリンク →

BlackTech

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

FIN8

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT32

Score: 0.80
Matched TTPs:
  • T1583.006 - Web Services
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1564.001 - Hidden Files and Directories
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
  • T1027.011 - Fileless Storage
  • T1041 - Exfiltration Over C2 Channel
  • T1078.003 - Local Accounts
MITREへのリンク →

Turla

Score: 0.77
Matched TTPs:
  • T1584.006 - Web Services
  • T1583.006 - Web Services
  • T1059.007 - JavaScript
  • T1055 - Process Injection
  • T1189 - Drive-by Compromise
  • T1027.011 - Fileless Storage
  • T1555.004 - Windows Credential Manager
  • T1078.003 - Local Accounts
MITREへのリンク →

Kimsuky

Score: 0.70
Matched TTPs:
  • T1583.006 - Web Services
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1588.003 - Code Signing Certificates
  • T1218.010 - Regsvr32
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1078.003 - Local Accounts
MITREへのリンク →

Mustang Panda

Score: 0.63
Matched TTPs:
  • T1583.006 - Web Services
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1564.001 - Hidden Files and Directories
  • T1588.003 - Code Signing Certificates
  • T1041 - Exfiltration Over C2 Channel
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN7

Score: 0.62
Matched TTPs:
  • T1583.006 - Web Services
  • T1059.007 - JavaScript
  • T1608.001 - Upload Malware
  • T1564.001 - Hidden Files and Directories
  • T1674 - Input Injection
  • T1078.003 - Local Accounts
MITREへのリンク →

Lazarus Group

Score: 0.56
Matched TTPs:
  • T1583.006 - Web Services
  • T1529 - System Shutdown/Reboot
  • T1564.001 - Hidden Files and Directories
  • T1189 - Drive-by Compromise
  • T1041 - Exfiltration Over C2 Channel
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る