Trusted Design

Looking Into a Cyber-Attack Facilitator in the Netherlands

概要

A small web hosting provider with servers in the Netherlands and Romania has been a hotbed of targeted attacks and advanced persistent threats (APT) since early 2015. Starting from May 2015 till today we counted over 100 serious cyber attacks that originated from servers of this small provider. Pawn Storm used the servers for at least 80 high profile attacks against various governments in the US, Europe, Asia, and the Middle East. Formally the Virtual Private Server (VPS) hosting company is registered in Dubai, United Arab Emirates (UAE). But from public postings on the Internet, it is apparent that the owner doesn’t really care about laws in UAE. In fact, Pawn Storm and another threat actor attacked the UAE government using servers of the VPS provider through highly targeted credential phishing. Other threat actors like DustySky (also known as the Gaza hackers) are also regularly using the VPS provider to host their command-and-control (C&C) servers and to send spear phishing e-mails.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 21.45
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1583.004 - Server
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1027.002 - Software Packing
MITREへのリンク →

Sea Turtle

Score: 7.05
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1583.003 - Virtual Private Server
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 7.05
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1583.003 - Virtual Private Server
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Indrik Spider

Score: 5.87
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1584.004 - Server
MITREへのリンク →

Agrius

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Contagious Interview

Score: 12.58
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1583.003 - Virtual Private Server
  • T1657 - Financial Theft
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Sandworm Team

Score: 18.64
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1583.004 - Server
  • T1584.005 - Botnet
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
MITREへのリンク →

Star Blizzard

Score: 5.01
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
MITREへのリンク →

HAFNIUM

Score: 9.99
Matched TTPs:
  • T1583.005 - Botnet
  • T1583.003 - Virtual Private Server
  • T1584.005 - Botnet
MITREへのリンク →

APT5

Score: 3.84
Matched TTPs:
  • T1583.005 - Botnet
MITREへのリンク →

Ke3chang

Score: 6.24
Matched TTPs:
  • T1583.005 - Botnet
  • T1569.002 - Service Execution
MITREへのリンク →

Volt Typhoon

Score: 19.36
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1217 - Browser Information Discovery
  • T1552.004 - Private Keys
  • T1584.005 - Botnet
  • T1027.002 - Software Packing
  • T1584.004 - Server
MITREへのリンク →

Turla

Score: 12.99
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1102.002 - Bidirectional Communication
  • T1555.004 - Windows Credential Manager
  • T1584.004 - Server
MITREへのリンク →

APT29

Score: 18.99
Matched TTPs:
  • T1586.003 - Cloud Accounts
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1090.004 - Domain Fronting
  • T1027.002 - Software Packing
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TA2541

Score: 9.92
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1573.002 - Asymmetric Cryptography
  • T1027.002 - Software Packing
  • T1027.015 - Compression
MITREへのリンク →

Earth Lusca

Score: 8.09
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.004 - Server
  • T1584.004 - Server
MITREへのリンク →

Mustang Panda

Score: 7.60
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Mustard Tempest

Score: 5.26
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.004 - Server
MITREへのリンク →

OilRig

Score: 12.36
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1555.004 - Windows Credential Manager
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TeamTNT

Score: 7.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1552.004 - Private Keys
  • T1027.002 - Software Packing
MITREへのリンク →

Gamaredon Group

Score: 10.05
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.003 - Virtual Private Server
  • T1102.002 - Bidirectional Communication
  • T1027.015 - Compression
MITREへのリンク →

Threat Group-3390

Score: 8.67
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
  • T1027.015 - Compression
MITREへのリンク →

TA505

Score: 4.03
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1027.002 - Software Packing
MITREへのリンク →

BlackByte

Score: 6.89
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.003 - Virtual Private Server
  • T1569.002 - Service Execution
MITREへのリンク →

BITTER

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT32

Score: 12.46
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1550.003 - Pass the Ticket
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1569.002 - Service Execution
MITREへのリンク →

HEXANE

Score: 4.37
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Saint Bear

Score: 5.52
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Moonstone Sleet

Score: 16.14
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1217 - Browser Information Discovery
  • T1583.003 - Virtual Private Server
  • T1598 - Phishing for Information
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN7

Score: 6.77
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1569.002 - Service Execution
MITREへのリンク →

EXOTIC LILY

Score: 5.99
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT42

Score: 7.24
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.003 - Virtual Private Server
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Fox Kitten

Score: 3.29
Matched TTPs:
  • T1217 - Browser Information Discovery
MITREへのリンク →

APT38

Score: 7.74
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1027.002 - Software Packing
  • T1569.002 - Service Execution
MITREへのリンク →

Scattered Spider

Score: 17.22
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1552.004 - Private Keys
  • T1657 - Financial Theft
  • T1598 - Phishing for Information
  • T1538 - Cloud Service Dashboard
MITREへのリンク →

Chimera

Score: 5.68
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1569.002 - Service Execution
MITREへのリンク →

Storm-0501

Score: 14.61
Matched TTPs:
  • T1552.004 - Private Keys
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1027.002 - Software Packing
MITREへのリンク →

Rocke

Score: 5.49
Matched TTPs:
  • T1552.004 - Private Keys
  • T1027.002 - Software Packing
MITREへのリンク →

GALLIUM

Score: 5.34
Matched TTPs:
  • T1583.004 - Server
  • T1027.002 - Software Packing
MITREへのリンク →

CURIUM

Score: 8.33
Matched TTPs:
  • T1583.004 - Server
  • T1583.003 - Virtual Private Server
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Winter Vivern

Score: 7.06
Matched TTPs:
  • T1056.003 - Web Portal Capture
  • T1583.003 - Virtual Private Server
MITREへのリンク →

APT28

Score: 14.39
Matched TTPs:
  • T1583.003 - Virtual Private Server
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1598 - Phishing for Information
  • T1498 - Network Denial of Service
MITREへのリンク →

Axiom

Score: 12.18
Matched TTPs:
  • T1583.003 - Virtual Private Server
  • T1584.005 - Botnet
  • T1203 - Exploitation for Client Execution
  • T1001.002 - Steganography
MITREへのリンク →

Dragonfly

Score: 6.85
Matched TTPs:
  • T1583.003 - Virtual Private Server
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
MITREへのリンク →

BRONZE BUTLER

Score: 5.34
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

INC Ransom

Score: 8.77
Matched TTPs:
  • T1657 - Financial Theft
  • T1537 - Transfer Data to Cloud Account
  • T1569.002 - Service Execution
MITREへのリンク →

Medusa Group

Score: 9.72
Matched TTPs:
  • T1657 - Financial Theft
  • T1573.002 - Asymmetric Cryptography
  • T1027.002 - Software Packing
  • T1569.002 - Service Execution
MITREへのリンク →

Cobalt Group

Score: 6.99
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Blue Mockingbird

Score: 5.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1569.002 - Service Execution
MITREへのリンク →

Leviathan

Score: 10.22
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
  • T1027.015 - Compression
MITREへのリンク →

Inception

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT37

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Lazarus Group

Score: 13.38
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT12

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT39

Score: 6.85
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1027.002 - Software Packing
  • T1569.002 - Service Execution
MITREへのリンク →

Magic Hound

Score: 4.92
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

MuddyWater

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

ZIRCONIUM

Score: 7.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1598 - Phishing for Information
  • T1027.002 - Software Packing
MITREへのリンク →

The White Company

Score: 3.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Patchwork

Score: 3.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Higaisa

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.015 - Compression
MITREへのリンク →

APT3

Score: 3.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Tropic Trooper

Score: 4.24
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Aoqin Dragon

Score: 3.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

APT41

Score: 5.94
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
  • T1569.002 - Service Execution
MITREへのリンク →

Elderwood

Score: 3.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Velvet Ant

Score: 5.14
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1569.002 - Service Execution
MITREへのリンク →

RedCurl

Score: 6.59
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

FIN6

Score: 7.67
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Wizard Spider

Score: 6.02
Matched TTPs:
  • T1555.004 - Windows Credential Manager
  • T1569.002 - Service Execution
MITREへのリンク →

Dark Caracal

Score: 4.58
Matched TTPs:
  • T1027.002 - Software Packing
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

Molerats

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1583.004 - Server
  • T1102.002 - Bidirectional Communication
  • T1027.002 - Software Packing
  • T1583 - Acquire Infrastructure
  • T1218.010 - Regsvr32
  • T1608.001 - Upload Malware
  • T1598 - Phishing for Information
MITREへのリンク →

Volt Typhoon

Score: 0.75
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1027.002 - Software Packing
  • T1584.005 - Botnet
  • T1584.003 - Virtual Private Server
  • T1584.004 - Server
  • T1552.004 - Private Keys
MITREへのリンク →

Sandworm Team

Score: 0.74
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1583.004 - Server
  • T1203 - Exploitation for Client Execution
  • T1584.005 - Botnet
  • T1583 - Acquire Infrastructure
  • T1584.004 - Server
  • T1608.001 - Upload Malware
MITREへのリンク →

APT29

Score: 0.74
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1027.002 - Software Packing
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1090.004 - Domain Fronting
  • T1586.003 - Cloud Accounts
MITREへのリンク →

Scattered Spider

Score: 0.66
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1657 - Financial Theft
  • T1538 - Cloud Service Dashboard
  • T1552.004 - Private Keys
  • T1598 - Phishing for Information
MITREへのリンク →

Moonstone Sleet

Score: 0.66
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1583.003 - Virtual Private Server
  • T1566.003 - Spearphishing via Service
  • T1569.002 - Service Execution
  • T1608.001 - Upload Malware
  • T1598 - Phishing for Information
MITREへのリンク →

Storm-0501

Score: 0.61
Matched TTPs:
  • T1537 - Transfer Data to Cloud Account
  • T1657 - Financial Theft
  • T1027.002 - Software Packing
  • T1218.010 - Regsvr32
  • T1552.004 - Private Keys
MITREへのリンク →

APT28

Score: 0.57
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1498 - Network Denial of Service
  • T1203 - Exploitation for Client Execution
  • T1583.003 - Virtual Private Server
  • T1598 - Phishing for Information
MITREへのリンク →

OilRig

Score: 0.55
Matched TTPs:
  • T1555.004 - Windows Credential Manager
  • T1573.002 - Asymmetric Cryptography
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1608.001 - Upload Malware
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る