Trusted Design

Down the H-W0rm Hole with Houdinis RAT

概要

Commodity Remote Access Trojans (RATs) -- which are designed, productized and sold to the casual and experienced hacker alike -- put powerful remote access capabilities into the hands of criminals. RATs, such as H-W0rm, njRAT, KilerRAT, DarkComet, Netwire, XtremeRAT, JSocket/AlienSpy/Adwind and others, hold special interest for the Threat Research Team at Fidelis Cybersecurity. We're constantly following, detecting and monitoring the lifecycle of these RATs as they appear, disappear and often reappear under a new moniker. There have been recent reports 1, 2 about a new version of one such commodity RAT, H-W0rm (Hworm), and the various campaigns it is being used in. Our telemetry shows that H-W0rm is one of the most active RATs we've seen, with infections observed across virtually all enterprise verticals and geographies in which Fidelis Cybersecurity products are deployed.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Sandworm Team

Score: 14.97
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
MITREへのリンク →

TA2541

Score: 4.03
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1027.002 - Software Packing
MITREへのリンク →

Earth Lusca

Score: 3.44
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Mustang Panda

Score: 9.94
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1003.003 - NTDS
MITREへのリンク →

Kimsuky

Score: 10.99
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1027.002 - Software Packing
  • T1021.001 - Remote Desktop Protocol
  • T1587 - Develop Capabilities
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1608.006 - SEO Poisoning
MITREへのリンク →

OilRig

Score: 8.96
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

TeamTNT

Score: 8.56
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1610 - Deploy Container
  • T1027.002 - Software Packing
MITREへのリンク →

Threat Group-3390

Score: 6.99
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

TA505

Score: 4.03
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1027.002 - Software Packing
MITREへのリンク →

BlackByte

Score: 5.09
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

BITTER

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT32

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Saint Bear

Score: 5.52
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Moonstone Sleet

Score: 9.10
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1217 - Browser Information Discovery
  • T1587 - Develop Capabilities
MITREへのリンク →

Contagious Interview

Score: 9.95
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1681 - Search Threat Vendor Data
  • T1587 - Develop Capabilities
MITREへのリンク →

FIN7

Score: 7.68
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 6.81
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Rocke

Score: 3.52
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1027.002 - Software Packing
MITREへのリンク →

Volt Typhoon

Score: 13.39
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1027.002 - Software Packing
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
  • T1124 - System Time Discovery
MITREへのリンク →

APT28

Score: 13.97
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
  • T1669 - Wi-Fi Networks
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

FIN13

Score: 5.46
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Magic Hound

Score: 6.96
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1592.002 - Software
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Medusa Group

Score: 12.05
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1650 - Acquire Access
  • T1027.002 - Software Packing
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Storm-0501

Score: 3.52
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1027.002 - Software Packing
MITREへのリンク →

Fox Kitten

Score: 8.74
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Ke3chang

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

Agrius

Score: 3.12
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

menuPass

Score: 5.46
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Blue Mockingbird

Score: 3.12
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

GALLIUM

Score: 3.52
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1027.002 - Software Packing
MITREへのリンク →

APT29

Score: 5.02
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Leviathan

Score: 4.61
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

INC Ransom

Score: 3.12
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

UNC3886

Score: 13.82
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1681 - Search Threat Vendor Data
  • T1205.001 - Port Knocking
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Dragonfly

Score: 6.95
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Axiom

Score: 9.15
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
  • T1001.002 - Steganography
MITREへのリンク →

APT41

Score: 9.00
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

HAFNIUM

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

APT5

Score: 3.12
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT39

Score: 5.17
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1027.002 - Software Packing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT38

Score: 5.34
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1027.002 - Software Packing
MITREへのリンク →

Scattered Spider

Score: 7.27
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Chimera

Score: 9.87
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
  • T1124 - System Time Discovery
MITREへのリンク →

PROMETHIUM

Score: 4.13
Matched TTPs:
  • T1205.001 - Port Knocking
MITREへのリンク →

Andariel

Score: 5.34
Matched TTPs:
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Sidewinder

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

The White Company

Score: 6.14
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
  • T1124 - System Time Discovery
MITREへのリンク →

Lazarus Group

Score: 9.87
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

Patchwork

Score: 5.19
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Higaisa

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Cobalt Group

Score: 3.14
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT3

Score: 5.19
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

BRONZE BUTLER

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Aoqin Dragon

Score: 3.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Elderwood

Score: 3.55
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.002 - Software Packing
MITREへのリンク →

Darkhotel

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

ZIRCONIUM

Score: 4.65
Matched TTPs:
  • T1027.002 - Software Packing
  • T1124 - System Time Discovery
MITREへのリンク →

Wizard Spider

Score: 3.99
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

FIN6

Score: 3.99
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.84
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1608.001 - Upload Malware
  • T1592.002 - Software
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

APT28

Score: 0.78
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1669 - Wi-Fi Networks
  • T1203 - Exploitation for Client Execution
  • T1190 - Exploit Public-Facing Application
  • T1003.003 - NTDS
MITREへのリンク →

UNC3886

Score: 0.76
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1124 - System Time Discovery
  • T1203 - Exploitation for Client Execution
  • T1190 - Exploit Public-Facing Application
  • T1205.001 - Port Knocking
MITREへのリンク →

Volt Typhoon

Score: 0.73
Matched TTPs:
  • T1124 - System Time Discovery
  • T1217 - Browser Information Discovery
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
  • T1027.002 - Software Packing
  • T1003.003 - NTDS
MITREへのリンク →

Medusa Group

Score: 0.70
Matched TTPs:
  • T1650 - Acquire Access
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
  • T1027.002 - Software Packing
  • T1003.003 - NTDS
MITREへのリンク →

Kimsuky

Score: 0.62
Matched TTPs:
  • T1587 - Develop Capabilities
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
  • T1027.002 - Software Packing
MITREへのリンク →

Contagious Interview

Score: 0.61
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1587 - Develop Capabilities
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

Mustang Panda

Score: 0.59
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Chimera

Score: 0.58
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1217 - Browser Information Discovery
  • T1124 - System Time Discovery
  • T1003.003 - NTDS
MITREへのリンク →

Lazarus Group

Score: 0.57
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT41

Score: 0.56
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1190 - Exploit Public-Facing Application
  • T1021.001 - Remote Desktop Protocol
  • T1027.002 - Software Packing
  • T1003.003 - NTDS
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る