Trusted Design

Spam Campaign Distributes AdWind RAT

概要

Dell SecureWorks Counter Threat Unit™ (CTU) researchers analyzed spam campaigns that distributed the AdWind remote access trojan (RAT). AdWind, also known as Frutas, UNRECOM, AlienSpy, and JSocket, is a Java-based RAT. It is typically distributed as a .jar (Java archive) attachment via spam emails (see Figure 1) and relies on social engineering to convince a victim to execute the attachment. In some samples analyzed by CTU researchers, the attachment was an obfuscated VBScript (.vbs) file that downloads and installs AdWind, or the email message just included a link to download and install the malware.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Cinnamon Tempest

Score: 8.87
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1591.003 - Identify Business Tempo
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Medusa Group

Score: 28.76
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1547.012 - Print Processors
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1218.003 - CMSTP
  • T1059.009 - Cloud API
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1553.004 - Install Root Certificate
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

menuPass

Score: 11.77
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1542.004 - ROMMONkit
  • T1622 - Debugger Evasion
MITREへのリンク →

INC Ransom

Score: 15.58
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1199 - Trusted Relationship
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1597 - Search Closed Sources
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Gamaredon Group

Score: 43.29
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1552.005 - Cloud Instance Metadata API
  • T1087.002 - Domain Account
  • T1591.003 - Identify Business Tempo
  • T1598.003 - Spearphishing Link
  • T1547.012 - Print Processors
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1059.009 - Cloud API
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1542.004 - ROMMONkit
  • T1570 - Lateral Tool Transfer
  • T1059.013 - Container CLI/API
  • T1553.004 - Install Root Certificate
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

APT32

Score: 30.70
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1110.001 - Password Guessing
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1553.004 - Install Root Certificate
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Mustang Panda

Score: 33.41
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1136.001 - Local Account
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1565.002 - Transmitted Data Manipulation
  • T1055.005 - Thread Local Storage
  • T1027.018 - Invisible Unicode
MITREへのリンク →

MuddyWater

Score: 31.93
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1547.012 - Print Processors
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1518.002 - Backup Software Discovery
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1059.013 - Container CLI/API
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Wizard Spider

Score: 17.97
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.009 - Cloud API
  • T1155 - AppleScript
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Leviathan

Score: 26.33
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
  • T1592.003 - Firmware
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

Velvet Ant

Score: 8.48
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN7

Score: 33.19
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1011.001 - Exfiltration Over Bluetooth
  • T1583.006 - Web Services
  • T1564.002 - Hidden Users
  • T1199 - Trusted Relationship
  • T1553.004 - Install Root Certificate
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

GALLIUM

Score: 3.86
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Volt Typhoon

Score: 20.13
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1070.006 - Timestomp
  • T1059.009 - Cloud API
  • T1049 - System Network Connections Discovery
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
MITREへのリンク →

Blue Mockingbird

Score: 12.48
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Naikon

Score: 3.21
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Lazarus Group

Score: 33.97
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1132.001 - Standard Encoding
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1070.006 - Timestomp
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1059.012 - Hypervisor CLI
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
MITREへのリンク →

Lotus Blossom

Score: 6.46
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Sandworm Team

Score: 31.82
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1049 - System Network Connections Discovery
  • T1199 - Trusted Relationship
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Earth Lusca

Score: 21.60
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.009 - Cloud API
  • T1136.002 - Domain Account
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1562.011 - Spoof Security Alerting
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Indrik Spider

Score: 11.94
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1059.009 - Cloud API
  • T1597 - Search Closed Sources
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
MITREへのリンク →

TA2541

Score: 18.99
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

Stealth Falcon

Score: 5.30
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1583.006 - Web Services
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Aquatic Panda

Score: 10.12
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1059.009 - Cloud API
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1622 - Debugger Evasion
MITREへのリンク →

APT29

Score: 22.83
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1138 - Application Shimming
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1555.004 - Windows Credential Manager
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

OilRig

Score: 41.09
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1552.005 - Cloud Instance Metadata API
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1586.002 - Email Accounts
  • T1059.009 - Cloud API
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1592.002 - Software
  • T1128 - Netsh Helper DLL
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Windshift

Score: 11.82
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN6

Score: 15.17
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

ToddyCat

Score: 9.45
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1553.004 - Install Root Certificate
  • T1547.008 - LSASS Driver
MITREへのリンク →

Deep Panda

Score: 8.20
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
  • T1553.004 - Install Root Certificate
MITREへのリンク →

Threat Group-3390

Score: 27.11
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1059.009 - Cloud API
  • T1155 - AppleScript
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1059.012 - Hypervisor CLI
  • T1546.017 - Udev Rules
MITREへのリンク →

APT42

Score: 10.39
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Ember Bear

Score: 14.44
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.009 - Cloud API
  • T1136.002 - Domain Account
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
MITREへのリンク →

Chimera

Score: 20.10
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1155 - AppleScript
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1542.004 - ROMMONkit
  • T1592.003 - Firmware
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BlackByte

Score: 19.05
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1059.009 - Cloud API
  • T1597 - Search Closed Sources
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN13

Score: 17.15
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1155 - AppleScript
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1686.001 - Cloud Firewall
MITREへのリンク →

Magic Hound

Score: 30.68
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.009 - Cloud API
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1187 - Forced Authentication
  • T1592.003 - Firmware
  • T1553.004 - Install Root Certificate
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT41

Score: 17.63
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1499.001 - OS Exhaustion Flood
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN8

Score: 17.62
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.009 - Cloud API
  • T1027.017 - SVG Smuggling
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TA577

Score: 6.65
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1543.003 - Windows Service
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Moonstone Sleet

Score: 18.52
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Scattered Spider

Score: 20.40
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
  • T1566.002 - Spearphishing Link
  • T1136.002 - Domain Account
  • T1619 - Cloud Storage Object Discovery
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN4

Score: 12.73
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1574.010 - Services File Permissions Weakness
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Winnti Group

Score: 4.80
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1583.006 - Web Services
MITREへのリンク →

Rocke

Score: 13.26
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
MITREへのリンク →

TeamTNT

Score: 14.83
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1586.002 - Email Accounts
  • T1583.006 - Web Services
  • T1597 - Search Closed Sources
MITREへのリンク →

APT28

Score: 34.46
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1552.005 - Cloud Instance Metadata API
  • T1087.002 - Domain Account
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1542.004 - ROMMONkit
  • T1592.003 - Firmware
  • T1218.010 - Regsvr32
  • T1553.004 - Install Root Certificate
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

UNC3886

Score: 14.12
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1583.006 - Web Services
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
MITREへのリンク →

Mustard Tempest

Score: 15.62
Matched TTPs:
  • T1682 - Query Public AI Services
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
  • T1543.002 - Systemd Service
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Turla

Score: 22.54
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1059.010 - AutoHotKey & AutoIT
  • T1059.009 - Cloud API
  • T1136.002 - Domain Account
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1570 - Lateral Tool Transfer
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Kimsuky

Score: 39.11
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.009 - Cloud API
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1597 - Search Closed Sources
  • T1027.014 - Polymorphic Code
  • T1570 - Lateral Tool Transfer
  • T1553.004 - Install Root Certificate
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Contagious Interview

Score: 18.85
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1565.002 - Transmitted Data Manipulation
  • T1221 - Template Injection
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

LuminousMoth

Score: 12.01
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1059.009 - Cloud API
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Salt Typhoon

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Play

Score: 7.73
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

Aoqin Dragon

Score: 5.23
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 19.92
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1087.002 - Domain Account
  • T1591.003 - Identify Business Tempo
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1574.010 - Services File Permissions Weakness
  • T1542.004 - ROMMONkit
  • T1128 - Netsh Helper DLL
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Ke3chang

Score: 9.90
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Malteiro

Score: 3.23
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
MITREへのリンク →

APT12

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

Machete

Score: 9.52
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Elderwood

Score: 7.73
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Transparent Tribe

Score: 7.73
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Dragonfly

Score: 19.03
Matched TTPs:
  • T1087.002 - Domain Account
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.009 - Cloud API
  • T1657 - Financial Theft
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

WIRTE

Score: 6.83
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

RTM

Score: 6.36
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1565.002 - Transmitted Data Manipulation
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

CURIUM

Score: 8.41
Matched TTPs:
  • T1087.002 - Domain Account
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Tropic Trooper

Score: 12.02
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1562.011 - Spoof Security Alerting
MITREへのリンク →

Dark Caracal

Score: 5.08
Matched TTPs:
  • T1087.002 - Domain Account
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

DarkHydrus

Score: 4.91
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1199 - Trusted Relationship
  • T1553.004 - Install Root Certificate
MITREへのリンク →

PLATINUM

Score: 7.97
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

TA551

Score: 7.44
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
  • T1562.011 - Spoof Security Alerting
MITREへのリンク →

HEXANE

Score: 10.62
Matched TTPs:
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1070.006 - Timestomp
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

BITTER

Score: 5.98
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

APT37

Score: 9.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

LazyScripter

Score: 8.90
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TA505

Score: 22.07
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1059.009 - Cloud API
  • T1136.002 - Domain Account
  • T1138 - Application Shimming
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT39

Score: 14.64
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Star Blizzard

Score: 10.57
Matched TTPs:
  • T1087.002 - Domain Account
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
  • T1199 - Trusted Relationship
MITREへのリンク →

Higaisa

Score: 11.79
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1553.004 - Install Root Certificate
  • T1546.017 - Udev Rules
MITREへのリンク →

Rancor

Score: 4.95
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
MITREへのリンク →

Cobalt Group

Score: 20.68
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1518.002 - Backup Software Discovery
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Storm-1811

Score: 14.64
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1486 - Data Encrypted for Impact
  • T1565.002 - Transmitted Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Inception

Score: 8.27
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
MITREへのリンク →

EXOTIC LILY

Score: 10.46
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Ajax Security Team

Score: 4.19
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1547.008 - LSASS Driver
MITREへのリンク →

Saint Bear

Score: 10.12
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1059.009 - Cloud API
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Patchwork

Score: 14.51
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TA459

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

Nomadic Octopus

Score: 4.06
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1553.004 - Install Root Certificate
MITREへのリンク →

Gorgon Group

Score: 10.10
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1553.004 - Install Root Certificate
MITREへのリンク →

APT19

Score: 12.82
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1553.004 - Install Root Certificate
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

SideCopy

Score: 7.26
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
MITREへのリンク →

Mofang

Score: 7.62
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

Tonto Team

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

Andariel

Score: 15.78
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1136.002 - Domain Account
  • T1583.006 - Web Services
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

BRONZE BUTLER

Score: 18.64
Matched TTPs:
  • T1087.002 - Domain Account
  • T1591.003 - Identify Business Tempo
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1542.004 - ROMMONkit
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT38

Score: 21.88
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.010 - AutoHotKey & AutoIT
  • T1059.009 - Cloud API
  • T1138 - Application Shimming
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Molerats

Score: 13.99
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1027.018 - Invisible Unicode
  • T1546.017 - Udev Rules
MITREへのリンク →

admin@338

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

Darkhotel

Score: 15.58
Matched TTPs:
  • T1087.002 - Domain Account
  • T1591.003 - Identify Business Tempo
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1564.002 - Hidden Users
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

The White Company

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

APT33

Score: 6.81
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Silence

Score: 8.39
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Sidewinder

Score: 13.56
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Confucius

Score: 5.96
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

BlackTech

Score: 8.28
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Evilnum

Score: 5.74
Matched TTPs:
  • T1543.003 - Windows Service
  • T1565.002 - Transmitted Data Manipulation
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT3

Score: 9.86
Matched TTPs:
  • T1543.003 - Windows Service
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1553.004 - Install Root Certificate
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT1

Score: 8.79
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1136.002 - Domain Account
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

ZIRCONIUM

Score: 12.35
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.010 - AutoHotKey & AutoIT
  • T1570 - Lateral Tool Transfer
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Silent Librarian

Score: 3.31
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1199 - Trusted Relationship
MITREへのリンク →

Winter Vivern

Score: 7.04
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Agrius

Score: 6.48
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1622 - Debugger Evasion
MITREへのリンク →

BackdoorDiplomacy

Score: 4.78
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

GOLD SOUTHFIELD

Score: 7.35
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Sea Turtle

Score: 10.72
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
MITREへのリンク →

Storm-0501

Score: 12.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1155 - AppleScript
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

Fox Kitten

Score: 8.39
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1542.004 - ROMMONkit
  • T1570 - Lateral Tool Transfer
  • T1622 - Debugger Evasion
MITREへのリンク →

Axiom

Score: 13.28
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1049 - System Network Connections Discovery
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

HAFNIUM

Score: 6.61
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1049 - System Network Connections Discovery
  • T1583.006 - Web Services
MITREへのリンク →

APT5

Score: 4.64
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
MITREへのリンク →

DarkVishnya

Score: 3.44
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1199 - Trusted Relationship
MITREへのリンク →

Carbanak

Score: 3.44
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1199 - Trusted Relationship
MITREへのリンク →

Akira

Score: 6.04
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1597 - Search Closed Sources
  • T1622 - Debugger Evasion
MITREへのリンク →

LAPSUS$

Score: 10.88
Matched TTPs:
  • T1136.002 - Domain Account
  • T1619 - Cloud Storage Object Discovery
  • T1199 - Trusted Relationship
  • T1592.003 - Firmware
MITREへのリンク →

Metador

Score: 3.31
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Thrip

Score: 3.78
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

CopyKittens

Score: 3.25
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1553.004 - Install Root Certificate
MITREへのリンク →

AppleJeus

Score: 3.29
Matched TTPs:
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1542.004 - ROMMONkit
MITREへのリンク →

Daggerfly

Score: 5.36
Matched TTPs:
  • T1570 - Lateral Tool Transfer
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Gamaredon Group

Score: 0.79
Matched TTPs:
  • T1542.004 - ROMMONkit
  • T1027.018 - Invisible Unicode
  • T1059.013 - Container CLI/API
  • T1552.005 - Cloud Instance Metadata API
  • T1591.003 - Identify Business Tempo
  • T1546.017 - Udev Rules
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1059.010 - AutoHotKey & AutoIT
  • T1570 - Lateral Tool Transfer
  • T1608 - Stage Capabilities
  • T1059.009 - Cloud API
  • T1547.012 - Print Processors
  • T1091 - Replication Through Removable Media
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
  • T1597 - Search Closed Sources
  • T1553.004 - Install Root Certificate
  • T1199 - Trusted Relationship
MITREへのリンク →

OilRig

Score: 0.76
Matched TTPs:
  • T1543.003 - Windows Service
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1552.005 - Cloud Instance Metadata API
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1583.006 - Web Services
  • T1606.002 - SAML Tokens
  • T1547.008 - LSASS Driver
  • T1128 - Netsh Helper DLL
  • T1059.010 - AutoHotKey & AutoIT
  • T1570 - Lateral Tool Transfer
  • T1059.009 - Cloud API
  • T1592.002 - Software
  • T1091 - Replication Through Removable Media
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
  • T1199 - Trusted Relationship
  • T1005 - Data from Local System
MITREへのリンク →

Kimsuky

Score: 0.72
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1606.002 - SAML Tokens
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1059.010 - AutoHotKey & AutoIT
  • T1570 - Lateral Tool Transfer
  • T1608 - Stage Capabilities
  • T1565.002 - Transmitted Data Manipulation
  • T1059.009 - Cloud API
  • T1027.014 - Polymorphic Code
  • T1091 - Replication Through Removable Media
  • T1087.002 - Domain Account
  • T1597 - Search Closed Sources
  • T1140 - Deobfuscate/Decode Files or Information
  • T1553.004 - Install Root Certificate
  • T1199 - Trusted Relationship
MITREへのリンク →

FIN7

Score: 0.68
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1027.007 - Dynamic API Resolution
  • T1586.002 - Email Accounts
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
  • T1011.001 - Exfiltration Over Bluetooth
  • T1199 - Trusted Relationship
  • T1564.002 - Hidden Users
  • T1553.004 - Install Root Certificate
  • T1027.018 - Invisible Unicode
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

APT28

Score: 0.66
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1592.003 - Firmware
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1199 - Trusted Relationship
  • T1553.004 - Install Root Certificate
  • T1542.004 - ROMMONkit
  • T1027.018 - Invisible Unicode
  • T1546.007 - Netsh Helper DLL
  • T1552.005 - Cloud Instance Metadata API
  • T1059.010 - AutoHotKey & AutoIT
  • T1499.001 - OS Exhaustion Flood
  • T1059.012 - Hypervisor CLI
  • T1087.002 - Domain Account
MITREへのリンク →

Lazarus Group

Score: 0.65
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1597 - Search Closed Sources
  • T1570 - Lateral Tool Transfer
  • T1583.006 - Web Services
  • T1132.001 - Standard Encoding
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1055.005 - Thread Local Storage
  • T1070.006 - Timestomp
  • T1606.002 - SAML Tokens
  • T1547.008 - LSASS Driver
  • T1199 - Trusted Relationship
  • T1059.010 - AutoHotKey & AutoIT
  • T1059.012 - Hypervisor CLI
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

Mustang Panda

Score: 0.64
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1136.001 - Local Account
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1565.002 - Transmitted Data Manipulation
  • T1199 - Trusted Relationship
  • T1055.005 - Thread Local Storage
  • T1027.018 - Invisible Unicode
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

Sandworm Team

Score: 0.63
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1140 - Deobfuscate/Decode Files or Information
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
  • T1187 - Forced Authentication
  • T1199 - Trusted Relationship
  • T1027.018 - Invisible Unicode
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
  • T1005 - Data from Local System
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

Magic Hound

Score: 0.62
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1597 - Search Closed Sources
  • T1140 - Deobfuscate/Decode Files or Information
  • T1592.003 - Firmware
  • T1583.006 - Web Services
  • T1187 - Forced Authentication
  • T1622 - Debugger Evasion
  • T1059.009 - Cloud API
  • T1553.004 - Install Root Certificate
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
  • T1199 - Trusted Relationship
  • T1059.012 - Hypervisor CLI
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

MuddyWater

Score: 0.61
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1597 - Search Closed Sources
  • T1586.002 - Email Accounts
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.011 - Spoof Security Alerting
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1547.012 - Print Processors
  • T1027.018 - Invisible Unicode
  • T1518.002 - Backup Software Discovery
  • T1059.013 - Container CLI/API
  • T1199 - Trusted Relationship
  • T1059.010 - AutoHotKey & AutoIT
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

APT32

Score: 0.61
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1570 - Lateral Tool Transfer
  • T1027.007 - Dynamic API Resolution
  • T1110.001 - Password Guessing
  • T1218.010 - Regsvr32
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1553.004 - Install Root Certificate
  • T1027.014 - Polymorphic Code
  • T1027.018 - Invisible Unicode
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

Medusa Group

Score: 0.60
Matched TTPs:
  • T1597 - Search Closed Sources
  • T1027.007 - Dynamic API Resolution
  • T1586.002 - Email Accounts
  • T1218.003 - CMSTP
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
  • T1059.009 - Cloud API
  • T1547.012 - Print Processors
  • T1553.004 - Install Root Certificate
  • T1128 - Netsh Helper DLL
  • T1199 - Trusted Relationship
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

Threat Group-3390

Score: 0.57
Matched TTPs:
  • T1546.017 - Udev Rules
  • T1570 - Lateral Tool Transfer
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1218.010 - Regsvr32
  • T1059.009 - Cloud API
  • T1199 - Trusted Relationship
  • T1155 - AppleScript
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
  • T1059.012 - Hypervisor CLI
  • T1087.002 - Domain Account
  • T1047 - Windows Management Instrumentation
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る