Trusted Design

Tofsee – modular spambot

概要

Tofsee, also known as Gheg, is another botnet analyzed by CERT Polska. Its main job is to send spam, but it is able to do other tasks as well. It is possible thanks to the modular design of this malware – it consists of the main binary (the one user downloads and infects with), which later downloads several additional modules from the C2 server – they modify code by overwriting some of the called functions with their own. An example of some actions these modules perform is spreading by posting click-bait messages on Facebook and VKontakte (Russian social network). Bot communicates with the botmaster using non-standard protocol built on top of TCP. The first message after establishing the connection is always sent by the server – the most important thing it contains is a random 128-byte key used for encrypting further communication. It is therefore impossible to decode the communication if one wasn’t listening right from its beginning.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Sandworm Team

Score: 16.78
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1049 - System Network Connections Discovery
  • T1562.001 - Disable or Modify Tools
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Patchwork

Score: 9.80
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1566.002 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1665 - Hide Infrastructure
MITREへのリンク →

APT42

Score: 12.28
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1091 - Replication Through Removable Media
  • T1677 - Poisoned Pipeline Execution
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

BRONZE BUTLER

Score: 12.98
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1591.003 - Identify Business Tempo
  • T1592.004 - Client Configurations
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

TA551

Score: 6.68
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1027.014 - Polymorphic Code
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Lazarus Group

Score: 45.43
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1016.001 - Internet Connection Discovery
  • T1677 - Poisoned Pipeline Execution
  • T1588.001 - Malware
  • T1069.001 - Local Groups
  • T1562.001 - Disable or Modify Tools
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1055.005 - Thread Local Storage
  • T1055.015 - ListPlanting
  • T1665 - Hide Infrastructure
  • T1587 - Develop Capabilities
  • T1547.008 - LSASS Driver
  • T1569.002 - Service Execution
  • T1556 - Modify Authentication Process
MITREへのリンク →

Tropic Trooper

Score: 12.44
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
  • T1665 - Hide Infrastructure
  • T1587 - Develop Capabilities
MITREへのリンク →

MuddyWater

Score: 6.33
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT19

Score: 8.45
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1027.014 - Polymorphic Code
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT33

Score: 9.08
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1562.001 - Disable or Modify Tools
  • T1556.005 - Reversible Encryption
  • T1556 - Modify Authentication Process
MITREへのリンク →

HAFNIUM

Score: 15.53
Matched TTPs:
  • T1161 - LC_LOAD_DYLIB Addition
  • T1027.008 - Stripped Payloads
  • T1049 - System Network Connections Discovery
  • T1556.005 - Reversible Encryption
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

FIN6

Score: 13.26
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.001 - Malware
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

CopyKittens

Score: 3.15
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
MITREへのリンク →

Mustang Panda

Score: 23.81
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1136.001 - Local Account
  • T1677 - Poisoned Pipeline Execution
  • T1556.005 - Reversible Encryption
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

Kimsuky

Score: 29.19
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1131 - Authentication Package
  • T1588.001 - Malware
  • T1041 - Exfiltration Over C2 Channel
  • T1027.014 - Polymorphic Code
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
  • T1556.005 - Reversible Encryption
  • T1665 - Hide Infrastructure
MITREへのリンク →

UNC3886

Score: 8.69
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.001 - Malware
  • T1055.015 - ListPlanting
MITREへのリンク →

Lotus Blossom

Score: 6.08
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1569.002 - Service Execution
MITREへのリンク →

Darkhotel

Score: 5.20
Matched TTPs:
  • T1591.003 - Identify Business Tempo
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

RedCurl

Score: 7.37
Matched TTPs:
  • T1591.003 - Identify Business Tempo
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Gamaredon Group

Score: 20.07
Matched TTPs:
  • T1591.003 - Identify Business Tempo
  • T1091 - Replication Through Removable Media
  • T1554 - Compromise Host Software Binary
  • T1061 - Graphical User Interface
  • T1562.001 - Disable or Modify Tools
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Cinnamon Tempest

Score: 3.44
Matched TTPs:
  • T1591.003 - Identify Business Tempo
MITREへのリンク →

Sidewinder

Score: 7.27
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Scattered Spider

Score: 10.03
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1197 - BITS Jobs
  • T1090.004 - Domain Fronting
MITREへのリンク →

ZIRCONIUM

Score: 10.39
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1588.001 - Malware
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
MITREへのリンク →

APT32

Score: 24.50
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1131 - Authentication Package
  • T1592.004 - Client Configurations
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1556 - Modify Authentication Process
MITREへのリンク →

Magic Hound

Score: 18.27
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1036.009 - Break Process Trees
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT28

Score: 27.74
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1131 - Authentication Package
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1055.008 - Ptrace System Calls
  • T1564.004 - NTFS File Attributes
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

Star Blizzard

Score: 8.05
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
MITREへのリンク →

Moonstone Sleet

Score: 11.58
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1197 - BITS Jobs
  • T1556.005 - Reversible Encryption
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 6.75
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dragonfly

Score: 11.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT5

Score: 7.47
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1677 - Poisoned Pipeline Execution
MITREへのリンク →

Ke3chang

Score: 5.03
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Rocke

Score: 7.03
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1562.001 - Disable or Modify Tools
  • T1556.005 - Reversible Encryption
MITREへのリンク →

INC Ransom

Score: 3.44
Matched TTPs:
  • T1036.009 - Break Process Trees
MITREへのリンク →

Velvet Ant

Score: 11.51
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
  • T1569.002 - Service Execution
MITREへのリンク →

TeamTNT

Score: 9.43
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
  • T1665 - Hide Infrastructure
MITREへのリンク →

TA2541

Score: 4.72
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Earth Lusca

Score: 3.74
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

LuminousMoth

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Mustard Tempest

Score: 3.74
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

OilRig

Score: 14.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
  • T1055.015 - ListPlanting
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Threat Group-3390

Score: 4.93
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

SideCopy

Score: 5.59
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
MITREへのリンク →

TA505

Score: 6.09
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
  • T1587 - Develop Capabilities
MITREへのリンク →

BlackByte

Score: 3.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1556.005 - Reversible Encryption
MITREへのリンク →

BITTER

Score: 5.26
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
  • T1556.005 - Reversible Encryption
MITREへのリンク →

HEXANE

Score: 4.37
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1547.002 - Authentication Package
MITREへのリンク →

Contagious Interview

Score: 17.46
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1131 - Authentication Package
  • T1562.001 - Disable or Modify Tools
  • T1221 - Template Injection
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN7

Score: 12.30
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
  • T1547.002 - Authentication Package
  • T1055.015 - ListPlanting
MITREへのリンク →

EXOTIC LILY

Score: 4.50
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1547.008 - LSASS Driver
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1055.003 - Thread Execution Hijacking
MITREへのリンク →

Turla

Score: 14.49
Matched TTPs:
  • T1131 - Authentication Package
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1587 - Develop Capabilities
  • T1569.002 - Service Execution
MITREへのリンク →

SilverTerrier

Score: 8.09
Matched TTPs:
  • T1131 - Authentication Package
  • T1041 - Exfiltration Over C2 Channel
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT29

Score: 6.37
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1547.008 - LSASS Driver
MITREへのリンク →

Carbanak

Score: 4.49
Matched TTPs:
  • T1588.001 - Malware
  • T1547.002 - Authentication Package
MITREへのリンク →

FIN13

Score: 6.21
Matched TTPs:
  • T1588.001 - Malware
  • T1556.005 - Reversible Encryption
  • T1569.002 - Service Execution
MITREへのリンク →

APT-C-36

Score: 4.49
Matched TTPs:
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Winter Vivern

Score: 5.05
Matched TTPs:
  • T1588.001 - Malware
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Wizard Spider

Score: 8.96
Matched TTPs:
  • T1588.001 - Malware
  • T1556.005 - Reversible Encryption
  • T1587 - Develop Capabilities
  • T1556 - Modify Authentication Process
MITREへのリンク →

PROMETHIUM

Score: 3.86
Matched TTPs:
  • T1588.001 - Malware
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Higaisa

Score: 9.05
Matched TTPs:
  • T1588.001 - Malware
  • T1556.005 - Reversible Encryption
  • T1665 - Hide Infrastructure
  • T1569.002 - Service Execution
MITREへのリンク →

Storm-0501

Score: 8.97
Matched TTPs:
  • T1588.001 - Malware
  • T1027.014 - Polymorphic Code
  • T1090.004 - Domain Fronting
MITREへのリンク →

BackdoorDiplomacy

Score: 5.02
Matched TTPs:
  • T1588.001 - Malware
  • T1587 - Develop Capabilities
MITREへのリンク →

APT41

Score: 10.34
Matched TTPs:
  • T1588.001 - Malware
  • T1041 - Exfiltration Over C2 Channel
  • T1556.005 - Reversible Encryption
  • T1055.015 - ListPlanting
MITREへのリンク →

Axiom

Score: 9.93
Matched TTPs:
  • T1049 - System Network Connections Discovery
  • T1059.012 - Hypervisor CLI
  • T1160 - Launch Daemon
MITREへのリンク →

Volt Typhoon

Score: 9.38
Matched TTPs:
  • T1049 - System Network Connections Discovery
  • T1665 - Hide Infrastructure
  • T1569.002 - Service Execution
MITREへのリンク →

Leviathan

Score: 11.57
Matched TTPs:
  • T1554 - Compromise Host Software Binary
  • T1027.014 - Polymorphic Code
  • T1059.012 - Hypervisor CLI
  • T1587 - Develop Capabilities
MITREへのリンク →

WIRTE

Score: 6.33
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
  • T1556.005 - Reversible Encryption
MITREへのリンク →

RedEcho

Score: 6.33
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Cobalt Group

Score: 6.68
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Inception

Score: 3.93
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT37

Score: 5.35
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT39

Score: 6.51
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1569.002 - Service Execution
MITREへのリンク →

Medusa Group

Score: 3.93
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

FIN8

Score: 6.68
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
  • T1556 - Modify Authentication Process
MITREへのリンク →

PLATINUM

Score: 6.30
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

Windshift

Score: 5.48
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dark Caracal

Score: 5.48
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1547.008 - LSASS Driver
MITREへのリンク →

Chimera

Score: 4.02
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1665 - Hide Infrastructure
MITREへのリンク →

Confucius

Score: 4.02
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1665 - Hide Infrastructure
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 7.06
Matched TTPs:
  • T1130 - Install Root Certificate
  • T1569.002 - Service Execution
MITREへのリンク →

ToddyCat

Score: 5.36
Matched TTPs:
  • T1665 - Hide Infrastructure
  • T1547.008 - LSASS Driver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.77
Matched TTPs:
  • T1569.002 - Service Execution
  • T1547.002 - Authentication Package
  • T1055.005 - Thread Local Storage
  • T1587 - Develop Capabilities
  • T1556 - Modify Authentication Process
  • T1665 - Hide Infrastructure
  • T1562.001 - Disable or Modify Tools
  • T1016.001 - Internet Connection Discovery
  • T1556.005 - Reversible Encryption
  • T1069.001 - Local Groups
  • T1161 - LC_LOAD_DYLIB Addition
  • T1588.001 - Malware
  • T1059.012 - Hypervisor CLI
  • T1677 - Poisoned Pipeline Execution
  • T1055.015 - ListPlanting
  • T1547.008 - LSASS Driver
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る