Trusted Design

CryptoWall sent by Angler and Neutrino exploit kits

概要

Since August 2015, actors using Angler exploit kit (EK) to send ransomware have occasionally switched back and forth between Angler EK and Neutrino EK. Sometime in mid-August 2015, actors using Angler EK to send ransomware switched to Neutrino EK [1]. The next week, those actors were back to using Angler EK [2, 3] and we've seen the occasional switching back and forth since then. I hadn't seen much Neutrino EK at all in November and December of 2015, but these actors switched back to Neutrino EK by the first week of January [4]. This occasional switch between the two EKs can be confusing. I've seen this EK switch initially confuse more than one security professional [5]. As of Tuesday 2016-01-12, these actors are back to Angler EK. And as always, we continue to see malicious spam (malspam) as another vector for ransomware. Source : https://isc.sans.edu/forums/diary/CryptoWall+sent+by+Angler+and+Neutrino+exploit+kits+or+through+malicious+spam/20611/

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

UNC3886

Score: 8.22
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Contagious Interview

Score: 6.66
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 12.40
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1090.004 - Domain Fronting
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT32

Score: 5.34
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

BRONZE BUTLER

Score: 7.93
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Gamaredon Group

Score: 6.94
Matched TTPs:
  • T1001 - Data Obfuscation
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Gorgon Group

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

Threat Group-3390

Score: 4.65
Matched TTPs:
  • T1055.012 - Process Hollowing
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Patchwork

Score: 4.65
Matched TTPs:
  • T1055.012 - Process Hollowing
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

BlackByte

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

TA2541

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

menuPass

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

Kimsuky

Score: 9.68
Matched TTPs:
  • T1055.012 - Process Hollowing
  • T1102.002 - Bidirectional Communication
  • T1588.005 - Exploits
MITREへのリンク →

APT37

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Lazarus Group

Score: 13.14
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT12

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Magic Hound

Score: 4.92
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Turla

Score: 4.99
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1124 - System Time Discovery
MITREへのリンク →

FIN7

Score: 4.99
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1124 - System Time Discovery
MITREへのリンク →

Sandworm Team

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT28

Score: 8.02
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

MuddyWater

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

ZIRCONIUM

Score: 4.99
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1124 - System Time Discovery
MITREへのリンク →

Sidewinder

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

The White Company

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Higaisa

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Mustang Panda

Score: 5.63
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Ember Bear

Score: 5.63
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1588.005 - Exploits
MITREへのリンク →

Darkhotel

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

OilRig

Score: 4.02
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

CURIUM

Score: 5.12
Matched TTPs:
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Medusa Group

Score: 4.54
Matched TTPs:
  • T1218.014 - MMC
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.83
Matched TTPs:
  • T1027.007 - Dynamic API Resolution
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 0.77
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1090.004 - Domain Fronting
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Kimsuky

Score: 0.64
Matched TTPs:
  • T1588.005 - Exploits
  • T1055.012 - Process Hollowing
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

UNC3886

Score: 0.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る