Trusted Design

Mokes: New Family of Cross-Platform Desktop Backdoors Discovered

概要

Recently [Kaspersky] came across a new family of cross-platform backdoors for desktop environments. First we got the Linux variant, and with information extracted from its binary, we were able to find the variant for Windows desktops, too. Not only that, but the Windows version was additionally equipped with a valid code signing signature. Let´s have a look at both of them.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Winnti Group

Score: 5.22
Matched TTPs:
  • T1014 - Rootkit
  • T1553.002 - Code Signing
MITREへのリンク →

APT41

Score: 14.58
Matched TTPs:
  • T1014 - Rootkit
  • T1069 - Permission Groups Discovery
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1546.008 - Accessibility Features
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Rocke

Score: 7.86
Matched TTPs:
  • T1014 - Rootkit
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1552.004 - Private Keys
MITREへのリンク →

TeamTNT

Score: 7.86
Matched TTPs:
  • T1014 - Rootkit
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1552.004 - Private Keys
MITREへのリンク →

APT28

Score: 4.42
Matched TTPs:
  • T1014 - Rootkit
  • T1036.005 - Match Legitimate Resource Name or Location
MITREへのリンク →

UNC3886

Score: 3.29
Matched TTPs:
  • T1014 - Rootkit
MITREへのリンク →

Scattered Spider

Score: 14.44
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1553.002 - Code Signing
  • T1552.004 - Private Keys
  • T1556.009 - Conditional Access Policies
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

TA505

Score: 5.22
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1553.002 - Code Signing
MITREへのリンク →

Volt Typhoon

Score: 13.64
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1218 - System Binary Proxy Execution
  • T1552.004 - Private Keys
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT3

Score: 8.22
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1546.008 - Accessibility Features
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

FIN13

Score: 6.07
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Gamaredon Group

Score: 4.98
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1480 - Execution Guardrails
MITREへのリンク →

FIN7

Score: 9.26
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1674 - Input Injection
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Patchwork

Score: 8.56
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1587.002 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT29

Score: 4.42
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1546.008 - Accessibility Features
MITREへのリンク →

PROMETHIUM

Score: 6.92
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1587.002 - Code Signing Certificates
MITREへのリンク →

LuminousMoth

Score: 3.07
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
MITREへのリンク →

OilRig

Score: 7.87
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Lazarus Group

Score: 8.85
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1218 - System Binary Proxy Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Darkhotel

Score: 3.07
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
MITREへのリンク →

Blue Mockingbird

Score: 7.32
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1021.001 - Remote Desktop Protocol
  • T1574.012 - COR_PROFILER
MITREへのリンク →

menuPass

Score: 4.72
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT39

Score: 6.92
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.006 - Code Signing Policy Modification
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Kimsuky

Score: 7.87
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Silence

Score: 4.72
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Fox Kitten

Score: 6.07
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1546.008 - Accessibility Features
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Turla

Score: 5.27
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.006 - Code Signing Policy Modification
MITREへのリンク →

Mustang Panda

Score: 10.76
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1553.002 - Code Signing
  • T1678 - Delay Execution
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Wizard Spider

Score: 6.73
Matched TTPs:
  • T1553.002 - Code Signing
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Leviathan

Score: 3.58
Matched TTPs:
  • T1553.002 - Code Signing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

FIN6

Score: 3.58
Matched TTPs:
  • T1553.002 - Code Signing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Medusa Group

Score: 3.58
Matched TTPs:
  • T1553.002 - Code Signing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Daggerfly

Score: 5.78
Matched TTPs:
  • T1553.002 - Code Signing
  • T1587.002 - Code Signing Certificates
MITREへのリンク →

Storm-0501

Score: 7.57
Matched TTPs:
  • T1552.004 - Private Keys
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

Deep Panda

Score: 3.29
Matched TTPs:
  • T1546.008 - Accessibility Features
MITREへのリンク →

Axiom

Score: 4.93
Matched TTPs:
  • T1546.008 - Accessibility Features
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Contagious Interview

Score: 3.84
Matched TTPs:
  • T1480 - Execution Guardrails
MITREへのリンク →

BlackByte

Score: 5.49
Matched TTPs:
  • T1480 - Execution Guardrails
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT37

Score: 4.13
Matched TTPs:
  • T1036.001 - Invalid Code Signature
MITREへのリンク →

Windshift

Score: 4.13
Matched TTPs:
  • T1036.001 - Invalid Code Signature
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

BlackTech

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

FIN8

Score: 4.80
Matched TTPs:
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Threat Group-3390

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT41

Score: 0.79
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1546.008 - Accessibility Features
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1021.001 - Remote Desktop Protocol
  • T1014 - Rootkit
  • T1553.002 - Code Signing
MITREへのリンク →

Scattered Spider

Score: 0.77
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1552.004 - Private Keys
  • T1021.001 - Remote Desktop Protocol
  • T1553.002 - Code Signing
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

Volt Typhoon

Score: 0.73
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1552.004 - Private Keys
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1021.001 - Remote Desktop Protocol
  • T1218 - System Binary Proxy Execution
MITREへのリンク →

Mustang Panda

Score: 0.59
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1588.003 - Code Signing Certificates
  • T1678 - Delay Execution
  • T1553.002 - Code Signing
MITREへのリンク →

FIN7

Score: 0.56
Matched TTPs:
  • T1674 - Input Injection
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1021.001 - Remote Desktop Protocol
  • T1553.002 - Code Signing
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る