Trusted Design

Down the H-W0rm Hole with Houdinis RAT

概要

Commodity Remote Access Trojans (RATs) -- which are designed, productized and sold to the casual and experienced hacker alike -- put powerful remote access capabilities into the hands of criminals. RATs, such as H-W0rm, njRAT, KilerRAT, DarkComet, Netwire, XtremeRAT, JSocket/AlienSpy/Adwind and others, hold special interest for the Threat Research Team at Fidelis Cybersecurity. We're constantly following, detecting and monitoring the lifecycle of these RATs as they appear, disappear and often reappear under a new moniker. There have been recent reports 1, 2 about a new version of one such commodity RAT, H-W0rm (Hworm), and the various campaigns it is being used in. Our telemetry shows that H-W0rm is one of the most active RATs we've seen, with infections observed across virtually all enterprise verticals and geographies in which Fidelis Cybersecurity products are deployed.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Sandworm Team

Score: 14.97
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
MITREへのリンク →

TA2541

Score: 4.03
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Earth Lusca

Score: 3.44
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Mustang Panda

Score: 9.94
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Kimsuky

Score: 10.99
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1543.002 - Systemd Service
MITREへのリンク →

OilRig

Score: 8.96
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

TeamTNT

Score: 8.56
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1071.003 - Mail Protocols
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Threat Group-3390

Score: 6.99
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

TA505

Score: 4.03
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

BlackByte

Score: 5.09
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

BITTER

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

APT32

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1622 - Debugger Evasion
MITREへのリンク →

Saint Bear

Score: 5.52
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Moonstone Sleet

Score: 9.10
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1491 - Defacement
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Contagious Interview

Score: 9.95
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1021.006 - Windows Remote Management
  • T1126 - Network Share Connection Removal
MITREへのリンク →

FIN7

Score: 7.68
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

Ember Bear

Score: 6.81
Matched TTPs:
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
MITREへのリンク →

Rocke

Score: 3.52
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Volt Typhoon

Score: 13.39
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT28

Score: 13.97
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
  • T1546.007 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN13

Score: 5.46
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Magic Hound

Score: 6.96
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1187 - Forced Authentication
  • T1622 - Debugger Evasion
MITREへのリンク →

Medusa Group

Score: 12.05
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1598 - Phishing for Information
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Storm-0501

Score: 3.52
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Fox Kitten

Score: 8.74
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Ke3chang

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Agrius

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

menuPass

Score: 5.46
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Blue Mockingbird

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

GALLIUM

Score: 3.52
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

APT29

Score: 5.02
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Leviathan

Score: 4.61
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

INC Ransom

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

UNC3886

Score: 13.82
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
  • T1547.015 - Login Items
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

Dragonfly

Score: 6.95
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Axiom

Score: 9.15
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

APT41

Score: 9.00
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

HAFNIUM

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT5

Score: 3.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1622 - Debugger Evasion
MITREへのリンク →

APT39

Score: 5.17
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

APT38

Score: 5.34
Matched TTPs:
  • T1491 - Defacement
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Scattered Spider

Score: 7.27
Matched TTPs:
  • T1491 - Defacement
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Chimera

Score: 9.87
Matched TTPs:
  • T1491 - Defacement
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1578.001 - Create Snapshot
MITREへのリンク →

PROMETHIUM

Score: 4.13
Matched TTPs:
  • T1547.015 - Login Items
MITREへのリンク →

Andariel

Score: 5.34
Matched TTPs:
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
MITREへのリンク →

Sidewinder

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

The White Company

Score: 6.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1578.001 - Create Snapshot
MITREへのリンク →

Lazarus Group

Score: 9.87
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

Patchwork

Score: 5.19
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Higaisa

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

Cobalt Group

Score: 3.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

APT3

Score: 5.19
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

BRONZE BUTLER

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

Aoqin Dragon

Score: 3.55
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Elderwood

Score: 3.55
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Darkhotel

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

ZIRCONIUM

Score: 4.65
Matched TTPs:
  • T1537 - Transfer Data to Cloud Account
  • T1578.001 - Create Snapshot
MITREへのリンク →

Wizard Spider

Score: 3.99
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

FIN6

Score: 3.99
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.84
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
MITREへのリンク →

APT28

Score: 0.78
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1566.003 - Spearphishing via Service
  • T1140 - Deobfuscate/Decode Files or Information
  • T1546.007 - Netsh Helper DLL
  • T1218.010 - Regsvr32
MITREへのリンク →

UNC3886

Score: 0.76
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1021.006 - Windows Remote Management
  • T1547.015 - Login Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
MITREへのリンク →

Volt Typhoon

Score: 0.73
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1578.001 - Create Snapshot
  • T1491 - Defacement
  • T1622 - Debugger Evasion
  • T1537 - Transfer Data to Cloud Account
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Medusa Group

Score: 0.70
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1622 - Debugger Evasion
  • T1537 - Transfer Data to Cloud Account
  • T1140 - Deobfuscate/Decode Files or Information
  • T1598 - Phishing for Information
MITREへのリンク →

Kimsuky

Score: 0.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1622 - Debugger Evasion
  • T1126 - Network Share Connection Removal
  • T1537 - Transfer Data to Cloud Account
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Contagious Interview

Score: 0.61
Matched TTPs:
  • T1126 - Network Share Connection Removal
  • T1091 - Replication Through Removable Media
  • T1021.006 - Windows Remote Management
MITREへのリンク →

Mustang Panda

Score: 0.59
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Chimera

Score: 0.58
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1491 - Defacement
  • T1578.001 - Create Snapshot
MITREへのリンク →

Lazarus Group

Score: 0.57
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT41

Score: 0.56
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1622 - Debugger Evasion
  • T1537 - Transfer Data to Cloud Account
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る