Trusted Design

Operation Cloud Hopper (hashes)

概要

PwC’s cyber security practice has worked closely with BAE Systems and other members of the security community, along with the UK’s National Cyber Security Centre (NCSC), to uncover and disrupt what is thought to be one of the largest ever sustained global cyber espionage campaigns in an operation referred to as ‘Operation Cloud Hopper’. Since late 2016, PwC and BAE Systems have been collaborating to research the threat, brief the global security community and assist known victims. The threat actor behind the campaign is widely known within the security community as ‘APT10’, referred to within PwC UK as ‘Red Apollo’. The espionage campaign has targeted managed IT service providers (MSPs), allowing the APT10 group unprecedented potential access to the intellectual property and sensitive data of those MSPs and their clients globally.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 15.88
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1550.002 - Pass the Hash
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Sea Turtle

Score: 5.35
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Ember Bear

Score: 17.46
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1114 - Email Collection
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1550.002 - Pass the Hash
MITREへのリンク →

Indrik Spider

Score: 5.13
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
MITREへのリンク →

Agrius

Score: 4.50
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Contagious Interview

Score: 19.23
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1593.003 - Code Repositories
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Sandworm Team

Score: 17.54
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1591.002 - Business Relationships
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Star Blizzard

Score: 3.88
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1588.002 - Tool
MITREへのリンク →

Mustard Tempest

Score: 9.08
Matched TTPs:
  • T1583.008 - Malvertising
  • T1608.006 - SEO Poisoning
MITREへのリンク →

Silent Librarian

Score: 4.47
Matched TTPs:
  • T1114 - Email Collection
  • T1588.002 - Tool
MITREへのリンク →

Magic Hound

Score: 10.86
Matched TTPs:
  • T1114 - Email Collection
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Scattered Spider

Score: 11.53
Matched TTPs:
  • T1114 - Email Collection
  • T1588.002 - Tool
  • T1578.002 - Create Cloud Instance
  • T1078.004 - Cloud Accounts
MITREへのリンク →

FIN13

Score: 10.09
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1090.001 - Internal Proxy
MITREへのリンク →

Moonstone Sleet

Score: 4.62
Matched TTPs:
  • T1587.001 - Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Lazarus Group

Score: 21.29
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1090.001 - Internal Proxy
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

OilRig

Score: 14.80
Matched TTPs:
  • T1587.001 - Malware
  • T1195 - Supply Chain Compromise
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

UNC3886

Score: 7.70
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

Salt Typhoon

Score: 7.16
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT29

Score: 14.40
Matched TTPs:
  • T1587.001 - Malware
  • T1586.003 - Cloud Accounts
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1078.004 - Cloud Accounts
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Play

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

RedCurl

Score: 8.69
Matched TTPs:
  • T1587.001 - Malware
  • T1573.002 - Asymmetric Cryptography
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Turla

Score: 12.40
Matched TTPs:
  • T1587.001 - Malware
  • T1584.003 - Virtual Private Server
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1090.001 - Internal Proxy
MITREへのリンク →

Ke3chang

Score: 11.19
Matched TTPs:
  • T1587.001 - Malware
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1078.004 - Cloud Accounts
MITREへのリンク →

Mustang Panda

Score: 12.57
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1518 - Software Discovery
  • T1027.007 - Dynamic API Resolution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN7

Score: 9.56
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

HAFNIUM

Score: 12.09
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1593.003 - Code Repositories
  • T1078.004 - Cloud Accounts
MITREへのリンク →

APT5

Score: 8.24
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1078.004 - Cloud Accounts
MITREへのリンク →

Volt Typhoon

Score: 20.80
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1190 - Exploit Public-Facing Application
  • T1590.006 - Network Security Appliances
  • T1588.002 - Tool
  • T1518 - Software Discovery
  • T1596.005 - Scan Databases
  • T1090.001 - Internal Proxy
MITREへのリンク →

Rocke

Score: 4.76
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Threat Group-3390

Score: 5.07
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
MITREへのリンク →

APT28

Score: 26.35
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1557.004 - Evil Twin
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1550.002 - Pass the Hash
  • T1078.004 - Cloud Accounts
  • T1669 - Wi-Fi Networks
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Medusa Group

Score: 13.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1650 - Acquire Access
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Storm-0501

Score: 8.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1537 - Transfer Data to Cloud Account
  • T1078.004 - Cloud Accounts
MITREへのリンク →

Fox Kitten

Score: 4.22
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
MITREへのリンク →

menuPass

Score: 5.07
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

GALLIUM

Score: 5.07
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
MITREへのリンク →

Earth Lusca

Score: 5.07
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
MITREへのリンク →

INC Ransom

Score: 6.16
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Dragonfly

Score: 8.91
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1591.002 - Business Relationships
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
MITREへのリンク →

APT41

Score: 12.48
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1596.005 - Scan Databases
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

MuddyWater

Score: 10.21
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1518 - Software Discovery
MITREへのリンク →

APT39

Score: 7.65
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1090.001 - Internal Proxy
MITREへのリンク →

LAPSUS$

Score: 15.60
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1593.003 - Code Repositories
  • T1588.002 - Tool
  • T1578.002 - Create Cloud Instance
  • T1078.004 - Cloud Accounts
MITREへのリンク →

APT33

Score: 10.66
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1588.002 - Tool
  • T1078.004 - Cloud Accounts
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Wizard Spider

Score: 13.22
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

DarkVishnya

Score: 5.39
Matched TTPs:
  • T1588.002 - Tool
  • T1200 - Hardware Additions
MITREへのリンク →

Inception

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1518 - Software Discovery
MITREへのリンク →

Storm-1811

Score: 3.37
Matched TTPs:
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 6.88
Matched TTPs:
  • T1588.002 - Tool
  • T1518 - Software Discovery
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

FIN8

Score: 6.34
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

TA2541

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

FIN6

Score: 8.86
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Patchwork

Score: 4.13
Matched TTPs:
  • T1588.002 - Tool
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Cobalt Group

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Thrip

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

POLONIUM

Score: 3.25
Matched TTPs:
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

HEXANE

Score: 5.99
Matched TTPs:
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1518 - Software Discovery
MITREへのリンク →

Lotus Blossom

Score: 3.78
Matched TTPs:
  • T1588.002 - Tool
  • T1090.001 - Internal Proxy
MITREへのリンク →

Aquatic Panda

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
MITREへのリンク →

APT38

Score: 4.47
Matched TTPs:
  • T1588.002 - Tool
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT32

Score: 6.34
Matched TTPs:
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Gamaredon Group

Score: 3.25
Matched TTPs:
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Chimera

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
MITREへのリンク →

APT42

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

APT1

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
MITREへのリンク →

Carbanak

Score: 3.25
Matched TTPs:
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT37

Score: 6.02
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Velvet Ant

Score: 9.81
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1090.001 - Internal Proxy
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Tropic Trooper

Score: 5.49
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1518 - Software Discovery
MITREへのリンク →

Windshift

Score: 5.27
Matched TTPs:
  • T1518 - Software Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.84
Matched TTPs:
  • T1588.002 - Tool
  • T1210 - Exploitation of Remote Services
  • T1550.002 - Pass the Hash
  • T1669 - Wi-Fi Networks
  • T1102.002 - Bidirectional Communication
  • T1557.004 - Evil Twin
  • T1190 - Exploit Public-Facing Application
  • T1078.004 - Cloud Accounts
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Lazarus Group

Score: 0.72
Matched TTPs:
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
  • T1587.001 - Malware
  • T1102.002 - Bidirectional Communication
  • T1027.007 - Dynamic API Resolution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1529 - System Shutdown/Reboot
  • T1090.001 - Internal Proxy
MITREへのリンク →

Volt Typhoon

Score: 0.70
Matched TTPs:
  • T1588.002 - Tool
  • T1518 - Software Discovery
  • T1584.003 - Virtual Private Server
  • T1590.006 - Network Security Appliances
  • T1596.005 - Scan Databases
  • T1190 - Exploit Public-Facing Application
  • T1090.001 - Internal Proxy
MITREへのリンク →

Contagious Interview

Score: 0.62
Matched TTPs:
  • T1588.002 - Tool
  • T1583 - Acquire Infrastructure
  • T1566.003 - Spearphishing via Service
  • T1681 - Search Threat Vendor Data
  • T1587.001 - Malware
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1593.003 - Code Repositories
MITREへのリンク →

Sandworm Team

Score: 0.60
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1588.002 - Tool
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1102.002 - Bidirectional Communication
  • T1190 - Exploit Public-Facing Application
  • T1195 - Supply Chain Compromise
MITREへのリンク →

Ember Bear

Score: 0.58
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1550.002 - Pass the Hash
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1195 - Supply Chain Compromise
  • T1114 - Email Collection
MITREへのリンク →

Kimsuky

Score: 0.56
Matched TTPs:
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1102.002 - Bidirectional Communication
  • T1190 - Exploit Public-Facing Application
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る