Trusted Design

Operation Cloud Hopper (hashes)

概要

PwC’s cyber security practice has worked closely with BAE Systems and other members of the security community, along with the UK’s National Cyber Security Centre (NCSC), to uncover and disrupt what is thought to be one of the largest ever sustained global cyber espionage campaigns in an operation referred to as ‘Operation Cloud Hopper’. Since late 2016, PwC and BAE Systems have been collaborating to research the threat, brief the global security community and assist known victims. The threat actor behind the campaign is widely known within the security community as ‘APT10’, referred to within PwC UK as ‘Red Apollo’. The espionage campaign has targeted managed IT service providers (MSPs), allowing the APT10 group unprecedented potential access to the intellectual property and sensitive data of those MSPs and their clients globally.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 15.88
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1668 - Exclusive Control
  • T1008 - Fallback Channels
MITREへのリンク →

Sea Turtle

Score: 5.35
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Ember Bear

Score: 17.46
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1578 - Modify Cloud Compute Infrastructure
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1668 - Exclusive Control
MITREへのリンク →

Indrik Spider

Score: 5.13
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
MITREへのリンク →

Agrius

Score: 4.50
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Contagious Interview

Score: 19.23
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1021.006 - Windows Remote Management
  • T1218.008 - Odbcconf
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sandworm Team

Score: 17.54
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1193 - Spearphishing Attachment
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

Star Blizzard

Score: 3.88
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1199 - Trusted Relationship
MITREへのリンク →

Mustard Tempest

Score: 9.08
Matched TTPs:
  • T1682 - Query Public AI Services
  • T1543.002 - Systemd Service
MITREへのリンク →

Silent Librarian

Score: 4.47
Matched TTPs:
  • T1578 - Modify Cloud Compute Infrastructure
  • T1199 - Trusted Relationship
MITREへのリンク →

Magic Hound

Score: 10.86
Matched TTPs:
  • T1578 - Modify Cloud Compute Infrastructure
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1547.008 - LSASS Driver
MITREへのリンク →

Scattered Spider

Score: 11.53
Matched TTPs:
  • T1578 - Modify Cloud Compute Infrastructure
  • T1199 - Trusted Relationship
  • T1557.002 - ARP Cache Poisoning
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

FIN13

Score: 10.09
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
  • T1569.002 - Service Execution
MITREへのリンク →

Moonstone Sleet

Score: 4.62
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1547.008 - LSASS Driver
MITREへのリンク →

Lazarus Group

Score: 21.29
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1055.005 - Thread Local Storage
  • T1547.008 - LSASS Driver
  • T1569.002 - Service Execution
  • T1556 - Modify Authentication Process
  • T1216 - System Script Proxy Execution
MITREへのリンク →

OilRig

Score: 14.80
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

UNC3886

Score: 7.70
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
MITREへのリンク →

Salt Typhoon

Score: 7.16
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT29

Score: 14.40
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1202 - Indirect Command Execution
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1021.001 - Remote Desktop Protocol
  • T1547.008 - LSASS Driver
MITREへのリンク →

Play

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

RedCurl

Score: 8.69
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1128 - Netsh Helper DLL
  • T1055.009 - Proc Memory
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Turla

Score: 12.40
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1176 - Software Extensions
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1569.002 - Service Execution
MITREへのリンク →

Ke3chang

Score: 11.19
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1027.008 - Stripped Payloads
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Mustang Panda

Score: 12.57
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1159 - Launch Agent
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN7

Score: 9.56
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

HAFNIUM

Score: 12.09
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.008 - Odbcconf
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT5

Score: 8.24
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Volt Typhoon

Score: 20.80
Matched TTPs:
  • T1176 - Software Extensions
  • T1140 - Deobfuscate/Decode Files or Information
  • T1164 - Re-opened Applications
  • T1199 - Trusted Relationship
  • T1159 - Launch Agent
  • T1574.002 - DLL Side-Loading
  • T1569.002 - Service Execution
MITREへのリンク →

Rocke

Score: 4.76
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1008 - Fallback Channels
MITREへのリンク →

Threat Group-3390

Score: 5.07
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
MITREへのリンク →

APT28

Score: 26.35
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1139 - Bash History
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1668 - Exclusive Control
  • T1021.001 - Remote Desktop Protocol
  • T1546.007 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Medusa Group

Score: 13.22
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1598 - Phishing for Information
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Storm-0501

Score: 8.24
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.009 - Proc Memory
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Fox Kitten

Score: 4.22
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
MITREへのリンク →

menuPass

Score: 5.07
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

GALLIUM

Score: 5.07
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
MITREへのリンク →

Earth Lusca

Score: 5.07
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
MITREへのリンク →

INC Ransom

Score: 6.16
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1055.009 - Proc Memory
MITREへのリンク →

Dragonfly

Score: 8.91
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1193 - Spearphishing Attachment
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
MITREへのリンク →

APT41

Score: 12.48
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
  • T1574.002 - DLL Side-Loading
  • T1008 - Fallback Channels
MITREへのリンク →

MuddyWater

Score: 10.21
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1159 - Launch Agent
MITREへのリンク →

APT39

Score: 7.65
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1569.002 - Service Execution
MITREへのリンク →

LAPSUS$

Score: 15.60
Matched TTPs:
  • T1193 - Spearphishing Attachment
  • T1218.008 - Odbcconf
  • T1199 - Trusted Relationship
  • T1557.002 - ARP Cache Poisoning
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT33

Score: 10.66
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1199 - Trusted Relationship
  • T1021.001 - Remote Desktop Protocol
  • T1556 - Modify Authentication Process
MITREへのリンク →

Wizard Spider

Score: 13.22
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1059.001 - PowerShell
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
  • T1556 - Modify Authentication Process
MITREへのリンク →

DarkVishnya

Score: 5.39
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1213.003 - Code Repositories
MITREへのリンク →

Inception

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1159 - Launch Agent
MITREへのリンク →

Storm-1811

Score: 3.37
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

BRONZE BUTLER

Score: 6.88
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1159 - Launch Agent
  • T1008 - Fallback Channels
MITREへのリンク →

FIN8

Score: 6.34
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

TA2541

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

FIN6

Score: 8.86
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Patchwork

Score: 4.13
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1008 - Fallback Channels
MITREへのリンク →

Cobalt Group

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Thrip

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

POLONIUM

Score: 3.25
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

HEXANE

Score: 5.99
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1159 - Launch Agent
MITREへのリンク →

Lotus Blossom

Score: 3.78
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1569.002 - Service Execution
MITREへのリンク →

Aquatic Panda

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
MITREへのリンク →

APT38

Score: 4.47
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT32

Score: 6.34
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
  • T1556 - Modify Authentication Process
MITREへのリンク →

Gamaredon Group

Score: 3.25
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

Chimera

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
MITREへのリンク →

APT42

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

APT1

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
MITREへのリンク →

Carbanak

Score: 3.25
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

APT37

Score: 6.02
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Velvet Ant

Score: 9.81
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Tropic Trooper

Score: 5.49
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1159 - Launch Agent
MITREへのリンク →

Windshift

Score: 5.27
Matched TTPs:
  • T1159 - Launch Agent
  • T1547.008 - LSASS Driver
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1008 - Fallback Channels
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.84
Matched TTPs:
  • T1059.001 - PowerShell
  • T1547.002 - Authentication Package
  • T1021.001 - Remote Desktop Protocol
  • T1668 - Exclusive Control
  • T1199 - Trusted Relationship
  • T1139 - Bash History
  • T1566.003 - Spearphishing via Service
  • T1140 - Deobfuscate/Decode Files or Information
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

Lazarus Group

Score: 0.72
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
  • T1569.002 - Service Execution
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
  • T1055.005 - Thread Local Storage
  • T1216 - System Script Proxy Execution
  • T1606.002 - SAML Tokens
MITREへのリンク →

Volt Typhoon

Score: 0.70
Matched TTPs:
  • T1164 - Re-opened Applications
  • T1199 - Trusted Relationship
  • T1176 - Software Extensions
  • T1159 - Launch Agent
  • T1569.002 - Service Execution
  • T1140 - Deobfuscate/Decode Files or Information
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

Contagious Interview

Score: 0.62
Matched TTPs:
  • T1021.006 - Windows Remote Management
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1033 - System Owner/User Discovery
  • T1556 - Modify Authentication Process
  • T1218.008 - Odbcconf
  • T1606.002 - SAML Tokens
MITREへのリンク →

Sandworm Team

Score: 0.60
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
  • T1033 - System Owner/User Discovery
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1606.002 - SAML Tokens
  • T1193 - Spearphishing Attachment
MITREへのリンク →

Ember Bear

Score: 0.58
Matched TTPs:
  • T1059.001 - PowerShell
  • T1578 - Modify Cloud Compute Infrastructure
  • T1668 - Exclusive Control
  • T1033 - System Owner/User Discovery
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Kimsuky

Score: 0.56
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1668 - Exclusive Control
  • T1199 - Trusted Relationship
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1606.002 - SAML Tokens
  • T1008 - Fallback Channels
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る