Trusted Design

PROOFPOINT 2016-03-01: Operation Transparent Tribe

概要

Proofpoint researchers recently uncovered evidence of an advanced persistent threat (APT) against Indian diplomatic and military resources. Our investigation began with malicious emails sent to Indian embassies in Saudi Arabia and Kazakstan but turned up connections to watering hole sites focused on Indian military personnel and designed to drop a remote access Trojan (RAT) with a variety of data extration functions. Our analysis shows that many of the campaigns and attacks appear related by common IOCs, vectors, payloads, and language, but the exact nature and attribution associated with this APT remain under investigation.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Volt Typhoon

Score: 45.25
Matched TTPs:
  • T1148 - HISTCONTROL
  • T1114 - Email Collection
  • T1553.002 - Code Signing
  • T1140 - Deobfuscate/Decode Files or Information
  • T1164 - Re-opened Applications
  • T1049 - System Network Connections Discovery
  • T1057 - Process Discovery
  • T1552.008 - Chat Messages
  • T1102.003 - One-Way Communication
  • T1584.002 - DNS Server
  • T1065 - Uncommonly Used Port
  • T1622 - Debugger Evasion
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

LAPSUS$

Score: 19.69
Matched TTPs:
  • T1216.001 - PubPrn
  • T1193 - Spearphishing Attachment
  • T1218.008 - Odbcconf
  • T1065 - Uncommonly Used Port
  • T1588.005 - Exploits
MITREへのリンク →

Contagious Interview

Score: 31.00
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1021.006 - Windows Remote Management
  • T1218.008 - Odbcconf
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1102.003 - One-Way Communication
  • T1690 - Prevent Command History Logging
  • T1556 - Modify Authentication Process
MITREへのリンク →

Scattered Spider

Score: 22.77
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
  • T1578 - Modify Cloud Compute Infrastructure
  • T1566.002 - Spearphishing Link
  • T1552.003 - Shell History
  • T1027.002 - Software Packing
  • T1622 - Debugger Evasion
  • T1588.005 - Exploits
MITREへのリンク →

FIN4

Score: 4.13
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
MITREへのリンク →

Ember Bear

Score: 18.69
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1578 - Modify Cloud Compute Infrastructure
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1519 - Emond
MITREへのリンク →

Sandworm Team

Score: 42.92
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1114 - Email Collection
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1583.005 - Botnet
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1193 - Spearphishing Attachment
  • T1049 - System Network Connections Discovery
  • T1102.003 - One-Way Communication
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
  • T1075 - Pass the Hash
MITREへのリンク →

Andariel

Score: 9.18
Matched TTPs:
  • T1171 - LLMNR/NBT-NS Poisoning and Relay
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
MITREへのリンク →

Magic Hound

Score: 23.44
Matched TTPs:
  • T1171 - LLMNR/NBT-NS Poisoning and Relay
  • T1578 - Modify Cloud Compute Infrastructure
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1187 - Forced Authentication
  • T1622 - Debugger Evasion
  • T1098.002 - Additional Email Delegate Permissions
MITREへのリンク →

HAFNIUM

Score: 23.18
Matched TTPs:
  • T1171 - LLMNR/NBT-NS Poisoning and Relay
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.008 - Odbcconf
  • T1059 - Command and Scripting Interpreter
  • T1049 - System Network Connections Discovery
  • T1608.005 - Link Target
  • T1552.008 - Chat Messages
MITREへのリンク →

Silent Librarian

Score: 9.37
Matched TTPs:
  • T1578 - Modify Cloud Compute Infrastructure
  • T1114 - Email Collection
  • T1566.002 - Spearphishing Link
MITREへのリンク →

Kimsuky

Score: 39.58
Matched TTPs:
  • T1114 - Email Collection
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1583.005 - Botnet
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1152 - Launchctl
  • T1683.001 - Written Content
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1102.003 - One-Way Communication
  • T1690 - Prevent Command History Logging
  • T1622 - Debugger Evasion
MITREへのリンク →

EXOTIC LILY

Score: 15.13
Matched TTPs:
  • T1114 - Email Collection
  • T1091 - Replication Through Removable Media
  • T1149 - LC_MAIN Hijacking
  • T1690 - Prevent Command History Logging
  • T1218.010 - Regsvr32
MITREへのリンク →

TA578

Score: 5.30
Matched TTPs:
  • T1114 - Email Collection
  • T1608.005 - Link Target
MITREへのリンク →

FIN13

Score: 11.58
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1553.002 - Code Signing
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1622 - Debugger Evasion
MITREへのリンク →

Moonstone Sleet

Score: 9.81
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1057 - Process Discovery
MITREへのリンク →

Indrik Spider

Score: 7.59
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1552.008 - Chat Messages
  • T1622 - Debugger Evasion
MITREへのリンク →

Lazarus Group

Score: 21.44
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1677 - Poisoned Pipeline Execution
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1069.001 - Local Groups
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

OilRig

Score: 13.80
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

UNC3886

Score: 12.23
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1583.005 - Botnet
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
  • T1218.010 - Regsvr32
MITREへのリンク →

LuminousMoth

Score: 4.07
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Salt Typhoon

Score: 13.19
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1583.005 - Botnet
  • T1553.002 - Code Signing
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT29

Score: 7.07
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

Play

Score: 6.09
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
MITREへのリンク →

Aoqin Dragon

Score: 3.59
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 5.13
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1542.004 - ROMMONkit
MITREへのリンク →

Moses Staff

Score: 3.57
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Turla

Score: 7.73
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1608.005 - Link Target
  • T1218.001 - Compiled HTML File
MITREへのリンク →

Ke3chang

Score: 7.19
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Mustang Panda

Score: 24.22
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1677 - Poisoned Pipeline Execution
  • T1608.005 - Link Target
  • T1102.003 - One-Way Communication
  • T1169 - Sudo
  • T1218.010 - Regsvr32
  • T1556 - Modify Authentication Process
MITREへのリンク →

TeamTNT

Score: 8.20
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1519 - Emond
MITREへのリンク →

FIN7

Score: 16.11
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1065 - Uncommonly Used Port
  • T1622 - Debugger Evasion
MITREへのリンク →

Sidewinder

Score: 7.57
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
MITREへのリンク →

ZIRCONIUM

Score: 4.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.005 - Link Target
MITREへのリンク →

APT32

Score: 10.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT28

Score: 30.00
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1583.005 - Botnet
  • T1140 - Deobfuscate/Decode Files or Information
  • T1152 - Launchctl
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1542.004 - ROMMONkit
  • T1218.010 - Regsvr32
  • T1146 - Clear Command History
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

Star Blizzard

Score: 11.34
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
  • T1102.003 - One-Way Communication
MITREへのリンク →

CURIUM

Score: 6.08
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1218.001 - Compiled HTML File
MITREへのリンク →

Dragonfly

Score: 14.54
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1193 - Spearphishing Attachment
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Patchwork

Score: 5.60
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Velvet Ant

Score: 3.03
Matched TTPs:
  • T1583.005 - Botnet
MITREへのリンク →

APT33

Score: 7.27
Matched TTPs:
  • T1583.005 - Botnet
  • T1218.010 - Regsvr32
  • T1556 - Modify Authentication Process
MITREへのリンク →

DarkVishnya

Score: 3.03
Matched TTPs:
  • T1583.005 - Botnet
MITREへのリンク →

TA2541

Score: 3.99
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
MITREへのリンク →

Earth Lusca

Score: 9.08
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1218.001 - Compiled HTML File
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1543.002 - Systemd Service
MITREへのリンク →

LazyScripter

Score: 3.99
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
MITREへのリンク →

Gamaredon Group

Score: 7.02
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1542.004 - ROMMONkit
MITREへのリンク →

Threat Group-3390

Score: 9.07
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1218.010 - Regsvr32
MITREへのリンク →

SideCopy

Score: 9.73
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
  • T1584.002 - DNS Server
MITREへのリンク →

BlackByte

Score: 8.71
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1102.002 - Bidirectional Communication
  • T1622 - Debugger Evasion
MITREへのリンク →

BITTER

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

HEXANE

Score: 7.24
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1065 - Uncommonly Used Port
  • T1622 - Debugger Evasion
MITREへのリンク →

Saint Bear

Score: 5.48
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

APT42

Score: 5.59
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1677 - Poisoned Pipeline Execution
MITREへのリンク →

Medusa Group

Score: 16.32
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1622 - Debugger Evasion
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

Storm-0501

Score: 7.61
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Fox Kitten

Score: 10.00
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1542.004 - ROMMONkit
  • T1622 - Debugger Evasion
  • T1588.005 - Exploits
MITREへのリンク →

Cinnamon Tempest

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
MITREへのリンク →

Agrius

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

menuPass

Score: 6.15
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1542.004 - ROMMONkit
  • T1622 - Debugger Evasion
MITREへのリンク →

Blue Mockingbird

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

Winter Vivern

Score: 5.09
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.001 - Compiled HTML File
MITREへのリンク →

Leviathan

Score: 4.61
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Volatile Cedar

Score: 5.60
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1002 - Data Compressed
MITREへのリンク →

INC Ransom

Score: 5.64
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1622 - Debugger Evasion
MITREへのリンク →

Axiom

Score: 12.77
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

APT41

Score: 12.88
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1002 - Data Compressed
  • T1622 - Debugger Evasion
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

APT5

Score: 6.74
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1677 - Poisoned Pipeline Execution
  • T1622 - Debugger Evasion
MITREへのリンク →

MuddyWater

Score: 4.98
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

APT39

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1055.003 - Thread Execution Hijacking
MITREへのリンク →

Malteiro

Score: 6.14
Matched TTPs:
  • T1552.003 - Shell History
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Akira

Score: 4.17
Matched TTPs:
  • T1552.003 - Shell History
  • T1622 - Debugger Evasion
MITREへのリンク →

Confucius

Score: 3.51
Matched TTPs:
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

BRONZE BUTLER

Score: 4.53
Matched TTPs:
  • T1542.004 - ROMMONkit
  • T1218.010 - Regsvr32
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1542.004 - ROMMONkit
MITREへのリンク →

Chimera

Score: 4.68
Matched TTPs:
  • T1542.004 - ROMMONkit
  • T1622 - Debugger Evasion
MITREへのリンク →

Cobalt Group

Score: 3.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

APT3

Score: 3.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN8

Score: 4.39
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

Wizard Spider

Score: 4.39
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN6

Score: 4.39
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Volt Typhoon

Score: 0.84
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1553.002 - Code Signing
  • T1622 - Debugger Evasion
  • T1065 - Uncommonly Used Port
  • T1552.008 - Chat Messages
  • T1584.002 - DNS Server
  • T1574.002 - DLL Side-Loading
  • T1114 - Email Collection
  • T1057 - Process Discovery
  • T1148 - HISTCONTROL
  • T1049 - System Network Connections Discovery
  • T1102.003 - One-Way Communication
  • T1164 - Re-opened Applications
MITREへのリンク →

Sandworm Team

Score: 0.82
Matched TTPs:
  • T1583.005 - Botnet
  • T1140 - Deobfuscate/Decode Files or Information
  • T1075 - Pass the Hash
  • T1187 - Forced Authentication
  • T1606.002 - SAML Tokens
  • T1005 - Data from Local System
  • T1114 - Email Collection
  • T1566.002 - Spearphishing Link
  • T1193 - Spearphishing Attachment
  • T1218.010 - Regsvr32
  • T1049 - System Network Connections Discovery
  • T1091 - Replication Through Removable Media
  • T1102.003 - One-Way Communication
  • T1564.008 - Email Hiding Rules
MITREへのリンク →

Kimsuky

Score: 0.73
Matched TTPs:
  • T1583.005 - Botnet
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
  • T1606.002 - SAML Tokens
  • T1608.005 - Link Target
  • T1114 - Email Collection
  • T1566.002 - Spearphishing Link
  • T1057 - Process Discovery
  • T1690 - Prevent Command History Logging
  • T1552.003 - Shell History
  • T1152 - Launchctl
  • T1091 - Replication Through Removable Media
  • T1102.003 - One-Way Communication
  • T1683.001 - Written Content
MITREへのリンク →

APT28

Score: 0.62
Matched TTPs:
  • T1583.005 - Botnet
  • T1140 - Deobfuscate/Decode Files or Information
  • T1542.004 - ROMMONkit
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1566.002 - Spearphishing Link
  • T1057 - Process Discovery
  • T1546.007 - Netsh Helper DLL
  • T1152 - Launchctl
  • T1146 - Clear Command History
MITREへのリンク →

Contagious Interview

Score: 0.59
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1606.002 - SAML Tokens
  • T1608.005 - Link Target
  • T1690 - Prevent Command History Logging
  • T1556 - Modify Authentication Process
  • T1021.006 - Windows Remote Management
  • T1552.003 - Shell History
  • T1091 - Replication Through Removable Media
  • T1102.003 - One-Way Communication
  • T1218.008 - Odbcconf
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る