Trusted Design

20160203: BE2 extraordinary plugins, Siemens targeting

概要

It examines several additional plugins more closely, targeting details around BE2 Siemens exploitation, and some of their unusual coding failures.We previously introduced an unknown set of plugins and functionality for the linux platform, six in total. For the windows platform, we collected 17 plugins. The incident explained about attacks made through Plugins.The plugins mostly used were related to Windows and Linux functionality .These plugins gave access to the attacker into the system , through this attacker was able to control the systems.The plugin in connection with Windows systems are User mode functionality plugin, plugin which controls Driver and kernel mode functionality,communication plugin and so on.Some of the plugins installed were failed to do the purpose.This incident source also gives details of timing cycle to their visits.This incident might be helpful in analyzing behavior of the attacker and attack vectors used by them.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 19.37
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027.014 - Polymorphic Code
  • T1570 - Lateral Tool Transfer
  • T1003.003 - NTDS
MITREへのリンク →

FIN13

Score: 10.69
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1686.001 - Cloud Firewall
MITREへのリンク →

Moonstone Sleet

Score: 10.30
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1491 - Defacement
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Indrik Spider

Score: 8.65
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1597 - Search Closed Sources
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Lazarus Group

Score: 34.57
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1070.006 - Timestomp
  • T1550 - Use Alternate Authentication Material
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1069.001 - Local Groups
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1055.015 - ListPlanting
  • T1547.008 - LSASS Driver
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Contagious Interview

Score: 16.34
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1016 - System Network Configuration Discovery
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1221 - Template Injection
  • T1547.008 - LSASS Driver
MITREへのリンク →

OilRig

Score: 25.86
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1005 - Data from Local System
  • T1586.002 - Email Accounts
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1570 - Lateral Tool Transfer
  • T1055.015 - ListPlanting
  • T1547.008 - LSASS Driver
MITREへのリンク →

UNC3886

Score: 16.35
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1606 - Forge Web Credentials
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1055.015 - ListPlanting
MITREへのリンク →

LuminousMoth

Score: 7.27
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1089 - Disabling Security Tools
  • T1550 - Use Alternate Authentication Material
  • T1199 - Trusted Relationship
MITREへのリンク →

Sandworm Team

Score: 19.17
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1590.003 - Network Trust Dependencies
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1075 - Pass the Hash
MITREへのリンク →

Salt Typhoon

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

APT29

Score: 8.43
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Play

Score: 7.73
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

Aoqin Dragon

Score: 4.44
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Turla

Score: 21.28
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1590.003 - Network Trust Dependencies
  • T1021 - Remote Services
  • T1003.001 - LSASS Memory
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Ke3chang

Score: 13.45
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Mustang Panda

Score: 14.51
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1136.001 - Local Account
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

TeamTNT

Score: 10.53
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1586.002 - Email Accounts
  • T1583.006 - Web Services
  • T1597 - Search Closed Sources
MITREへのリンク →

FIN7

Score: 17.11
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
  • T1055.015 - ListPlanting
MITREへのリンク →

Medusa Group

Score: 31.79
Matched TTPs:
  • T1036.008 - Masquerade File Type
  • T1547.012 - Print Processors
  • T1590.003 - Network Trust Dependencies
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1218.003 - CMSTP
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

MuddyWater

Score: 25.80
Matched TTPs:
  • T1547.012 - Print Processors
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1518.002 - Backup Software Discovery
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
MITREへのリンク →

Gamaredon Group

Score: 20.69
Matched TTPs:
  • T1547.012 - Print Processors
  • T1590.003 - Network Trust Dependencies
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1061 - Graphical User Interface
  • T1570 - Lateral Tool Transfer
  • T1059.013 - Container CLI/API
MITREへのリンク →

Chimera

Score: 16.83
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1003.007 - Proc Filesystem
  • T1590.003 - Network Trust Dependencies
  • T1491 - Defacement
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Cinnamon Tempest

Score: 4.05
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Velvet Ant

Score: 12.81
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Tonto Team

Score: 5.97
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
MITREへのリンク →

Patchwork

Score: 6.67
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1550 - Use Alternate Authentication Material
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Aquatic Panda

Score: 6.90
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1003.007 - Proc Filesystem
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

GALLIUM

Score: 4.05
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Higaisa

Score: 7.03
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
MITREへのリンク →

APT32

Score: 14.05
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1550 - Use Alternate Authentication Material
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Storm-1811

Score: 5.11
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

Tropic Trooper

Score: 13.62
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1003.001 - LSASS Memory
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Earth Lusca

Score: 10.84
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
MITREへのリンク →

BRONZE BUTLER

Score: 8.40
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1003.007 - Proc Filesystem
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
MITREへのリンク →

APT3

Score: 4.75
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
MITREへのリンク →

BlackTech

Score: 7.83
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

SideCopy

Score: 4.02
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
MITREへのリンク →

Daggerfly

Score: 3.97
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Threat Group-3390

Score: 14.66
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

BackdoorDiplomacy

Score: 4.05
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

APT19

Score: 5.33
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Sidewinder

Score: 4.75
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
MITREへのリンク →

APT41

Score: 17.75
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1578.003 - Delete Cloud Instance
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1027.007 - Dynamic API Resolution
  • T1055.015 - ListPlanting
MITREへのリンク →

menuPass

Score: 11.68
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
MITREへのリンク →

Poseidon Group

Score: 4.04
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1583.006 - Web Services
MITREへのリンク →

Volt Typhoon

Score: 15.72
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1070.006 - Timestomp
  • T1491 - Defacement
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

admin@338

Score: 4.02
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1218.010 - Regsvr32
MITREへのリンク →

APT1

Score: 4.89
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
MITREへのリンク →

Gorgon Group

Score: 4.93
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

ToddyCat

Score: 7.80
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT37

Score: 8.92
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT38

Score: 15.76
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1491 - Defacement
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

TA505

Score: 4.93
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

Silence

Score: 5.53
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BlackByte

Score: 17.22
Matched TTPs:
  • T1070.003 - Clear Command History
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1550 - Use Alternate Authentication Material
  • T1597 - Search Closed Sources
  • T1570 - Lateral Tool Transfer
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Magic Hound

Score: 12.29
Matched TTPs:
  • T1070.003 - Clear Command History
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1547.008 - LSASS Driver
MITREへのリンク →

Ember Bear

Score: 18.08
Matched TTPs:
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1059.001 - PowerShell
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

Rocke

Score: 8.41
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
MITREへのリンク →

APT28

Score: 32.55
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1548.004 - Elevated Execution with Prompt
  • T1218.010 - Regsvr32
  • T1146 - Clear Command History
  • T1055.008 - Ptrace System Calls
  • T1546.007 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

GOLD SOUTHFIELD

Score: 4.06
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
MITREへのリンク →

Sea Turtle

Score: 7.43
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
MITREへのリンク →

Storm-0501

Score: 9.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
  • T1090.004 - Domain Fronting
MITREへのリンク →

Fox Kitten

Score: 9.74
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1059.001 - PowerShell
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Agrius

Score: 3.27
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
MITREへのリンク →

Blue Mockingbird

Score: 7.46
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Leviathan

Score: 8.30
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
MITREへのリンク →

INC Ransom

Score: 9.11
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1586.002 - Email Accounts
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Dragonfly

Score: 11.39
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Axiom

Score: 10.09
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1218.010 - Regsvr32
  • T1160 - Launch Daemon
MITREへのリンク →

HAFNIUM

Score: 7.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1583.006 - Web Services
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

APT5

Score: 7.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1578.003 - Delete Cloud Instance
  • T1583.006 - Web Services
MITREへのリンク →

APT39

Score: 11.08
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021 - Remote Services
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

DarkVishnya

Score: 7.98
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1199 - Trusted Relationship
  • T1213.003 - Code Repositories
MITREへのリンク →

Carbanak

Score: 3.44
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1199 - Trusted Relationship
MITREへのリンク →

Akira

Score: 8.52
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1597 - Search Closed Sources
  • T1601 - Modify System Image
MITREへのリンク →

Cobalt Group

Score: 14.56
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1518.002 - Backup Software Discovery
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
MITREへのリンク →

HEXANE

Score: 6.21
Matched TTPs:
  • T1070.006 - Timestomp
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
MITREへのリンク →

FIN6

Score: 12.91
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Scattered Spider

Score: 10.06
Matched TTPs:
  • T1491 - Defacement
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1090.004 - Domain Fronting
MITREへのリンク →

Wizard Spider

Score: 11.64
Matched TTPs:
  • T1003.001 - LSASS Memory
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Windshift

Score: 4.04
Matched TTPs:
  • T1583.006 - Web Services
  • T1547.008 - LSASS Driver
MITREへのリンク →

Deep Panda

Score: 4.26
Matched TTPs:
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Darkhotel

Score: 3.01
Matched TTPs:
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
MITREへのリンク →

Stealth Falcon

Score: 3.75
Matched TTPs:
  • T1583.006 - Web Services
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Andariel

Score: 3.01
Matched TTPs:
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
MITREへのリンク →

Inception

Score: 6.61
Matched TTPs:
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
MITREへのリンク →

LAPSUS$

Score: 4.98
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1601 - Modify System Image
MITREへのリンク →

FIN8

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

TA2541

Score: 5.39
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
MITREへのリンク →

WIRTE

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Lotus Blossom

Score: 3.08
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

APT42

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Saint Bear

Score: 3.29
Matched TTPs:
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.81
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1070.006 - Timestomp
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1055.015 - ListPlanting
  • T1606.002 - SAML Tokens
  • T1547.008 - LSASS Driver
  • T1570 - Lateral Tool Transfer
  • T1550 - Use Alternate Authentication Material
  • T1590.003 - Network Trust Dependencies
  • T1069.001 - Local Groups
  • T1216 - System Script Proxy Execution
  • T1218.010 - Regsvr32
  • T1597 - Search Closed Sources
MITREへのリンク →

APT28

Score: 0.76
Matched TTPs:
  • T1583.006 - Web Services
  • T1146 - Clear Command History
  • T1199 - Trusted Relationship
  • T1140 - Deobfuscate/Decode Files or Information
  • T1550 - Use Alternate Authentication Material
  • T1055.008 - Ptrace System Calls
  • T1566.003 - Spearphishing via Service
  • T1548.004 - Elevated Execution with Prompt
  • T1546.007 - Netsh Helper DLL
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
MITREへのリンク →

Medusa Group

Score: 0.76
Matched TTPs:
  • T1036.008 - Masquerade File Type
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.012 - Print Processors
  • T1590.003 - Network Trust Dependencies
  • T1216 - System Script Proxy Execution
  • T1128 - Netsh Helper DLL
  • T1597 - Search Closed Sources
  • T1586.002 - Email Accounts
  • T1218.003 - CMSTP
MITREへのリンク →

OilRig

Score: 0.62
Matched TTPs:
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1055.015 - ListPlanting
  • T1606.002 - SAML Tokens
  • T1547.008 - LSASS Driver
  • T1570 - Lateral Tool Transfer
  • T1586.002 - Email Accounts
  • T1003.007 - Proc Filesystem
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1005 - Data from Local System
MITREへのリンク →

MuddyWater

Score: 0.62
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.013 - Container CLI/API
  • T1547.012 - Print Processors
  • T1059.001 - PowerShell
  • T1518.002 - Backup Software Discovery
  • T1218.010 - Regsvr32
  • T1597 - Search Closed Sources
  • T1586.002 - Email Accounts
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る