Trusted Design

Microsoft OLE URL Moniker improperly handles remotely-linked HTA data

概要

Microsoft OLE uses the URL Moniker to processes remotely-linked content in a vulnerable manner. The remote content is opened based on the application associated with the server-provided MIME type. Some MIME types are dangerous, as they can result in code execution. For example, the application/hta mime type is associated with mshta.exe. Opening arbitrary HTA content is equivalent to executing arbitrary code. This vulnerability is reportedly being exploited in the wild. The exploits used in the wild have the following characteristics.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Gamaredon Group

Score: 28.91
Matched TTPs:
  • T1021.005 - VNC
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1547.012 - Print Processors
  • T1218.012 - Verclsid
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1562.001 - Disable or Modify Tools
  • T1059.013 - Container CLI/API
  • T1200 - Hardware Additions
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN7

Score: 23.03
Matched TTPs:
  • T1021.005 - VNC
  • T1047 - Windows Management Instrumentation
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1562.001 - Disable or Modify Tools
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

GCMAN

Score: 3.62
Matched TTPs:
  • T1021.005 - VNC
MITREへのリンク →

Fox Kitten

Score: 8.02
Matched TTPs:
  • T1021.005 - VNC
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
MITREへのリンク →

Cinnamon Tempest

Score: 3.28
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1089 - Disabling Security Tools
MITREへのリンク →

Medusa Group

Score: 8.55
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1547.012 - Print Processors
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
MITREへのリンク →

menuPass

Score: 9.33
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
MITREへのリンク →

INC Ransom

Score: 3.19
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1622 - Debugger Evasion
MITREへのリンク →

APT32

Score: 21.24
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1218.012 - Verclsid
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

Mustang Panda

Score: 28.36
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1053.007 - Container Orchestration Job
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1136.001 - Local Account
  • T1218.012 - Verclsid
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

MuddyWater

Score: 26.06
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1547.012 - Print Processors
  • T1089 - Disabling Security Tools
  • T1218.012 - Verclsid
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Wizard Spider

Score: 13.15
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

Leviathan

Score: 16.41
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Velvet Ant

Score: 5.67
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1089 - Disabling Security Tools
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

GALLIUM

Score: 3.28
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1089 - Disabling Security Tools
MITREへのリンク →

Volt Typhoon

Score: 12.40
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1686.003 - Windows Host Firewall
  • T1070.006 - Timestomp
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
MITREへのリンク →

Blue Mockingbird

Score: 10.47
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
  • T1001.001 - Junk Data
MITREへのリンク →

Naikon

Score: 4.94
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
MITREへのリンク →

Lazarus Group

Score: 24.14
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1070.006 - Timestomp
  • T1218.012 - Verclsid
  • T1583.006 - Web Services
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sandworm Team

Score: 13.75
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1686.003 - Windows Host Firewall
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Earth Lusca

Score: 15.24
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1089 - Disabling Security Tools
  • T1218.012 - Verclsid
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Indrik Spider

Score: 3.98
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1622 - Debugger Evasion
MITREへのリンク →

TA2541

Score: 8.35
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Stealth Falcon

Score: 3.06
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1583.006 - Web Services
MITREへのリンク →

Aquatic Panda

Score: 4.92
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1089 - Disabling Security Tools
  • T1622 - Debugger Evasion
MITREへのリンク →

APT29

Score: 13.69
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1138 - Application Shimming
  • T1218.012 - Verclsid
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

OilRig

Score: 16.86
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1048 - Exfiltration Over Alternative Protocol
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

Windshift

Score: 9.29
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN6

Score: 7.60
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1622 - Debugger Evasion
  • T1556 - Modify Authentication Process
MITREへのリンク →

ToddyCat

Score: 3.06
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1583.006 - Web Services
MITREへのリンク →

Deep Panda

Score: 5.81
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Threat Group-3390

Score: 10.94
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Ember Bear

Score: 12.31
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1059.001 - PowerShell
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

Chimera

Score: 6.44
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1089 - Disabling Security Tools
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
MITREへのリンク →

BlackByte

Score: 3.19
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN13

Score: 4.92
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1089 - Disabling Security Tools
  • T1622 - Debugger Evasion
MITREへのリンク →

Magic Hound

Score: 12.47
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1583.006 - Web Services
  • T1562.001 - Disable or Modify Tools
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT41

Score: 10.73
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1048 - Exfiltration Over Alternative Protocol
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN8

Score: 10.41
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

Kimsuky

Score: 29.37
Matched TTPs:
  • T1053.007 - Container Orchestration Job
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1496.004 - Cloud Service Hijacking
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1003.003 - NTDS
MITREへのリンク →

Cobalt Group

Score: 21.77
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1598.004 - Spearphishing Voice
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1052 - Exfiltration Over Physical Medium
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Sidewinder

Score: 14.30
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1218.012 - Verclsid
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT28

Score: 16.44
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1200 - Hardware Additions
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT37

Score: 9.19
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Gallmaker

Score: 4.41
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
MITREへのリンク →

BITTER

Score: 5.90
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

TA505

Score: 14.35
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1138 - Application Shimming
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Patchwork

Score: 13.86
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT12

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

Machete

Score: 9.52
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Elderwood

Score: 7.73
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Transparent Tribe

Score: 7.73
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Dragonfly

Score: 12.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1200 - Hardware Additions
  • T1622 - Debugger Evasion
MITREへのリンク →

WIRTE

Score: 6.81
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Contagious Interview

Score: 11.83
Matched TTPs:
  • T1087.002 - Domain Account
  • T1562.001 - Disable or Modify Tools
  • T1221 - Template Injection
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

RTM

Score: 5.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT-C-36

Score: 4.06
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

CURIUM

Score: 3.43
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Tropic Trooper

Score: 9.56
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Dark Caracal

Score: 5.99
Matched TTPs:
  • T1087.002 - Domain Account
  • T1048 - Exfiltration Over Alternative Protocol
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

RedCurl

Score: 4.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1027.018 - Invisible Unicode
MITREへのリンク →

DarkHydrus

Score: 4.81
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1200 - Hardware Additions
MITREへのリンク →

PLATINUM

Score: 7.97
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

TA551

Score: 6.75
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1027.014 - Polymorphic Code
MITREへのリンク →

HEXANE

Score: 7.80
Matched TTPs:
  • T1087.002 - Domain Account
  • T1070.006 - Timestomp
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
MITREへのリンク →

Ferocious Kitten

Score: 5.10
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1685.005 - Clear Windows Event Logs
MITREへのリンク →

LazyScripter

Score: 6.81
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1027.018 - Invisible Unicode
MITREへのリンク →

PROMETHIUM

Score: 6.69
Matched TTPs:
  • T1087.002 - Domain Account
  • T1547.015 - Login Items
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT39

Score: 6.12
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Higaisa

Score: 10.54
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1052 - Exfiltration Over Physical Medium
MITREへのリンク →

Rancor

Score: 4.95
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
MITREへのリンク →

FIN4

Score: 4.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Storm-1811

Score: 3.97
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1089 - Disabling Security Tools
MITREへのリンク →

Inception

Score: 12.91
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

EXOTIC LILY

Score: 5.96
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Saint Bear

Score: 4.52
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TA459

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

APT19

Score: 7.91
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1027.014 - Polymorphic Code
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

SideCopy

Score: 5.74
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1218.012 - Verclsid
MITREへのリンク →

Mofang

Score: 4.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Tonto Team

Score: 7.64
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
MITREへのリンク →

Andariel

Score: 6.44
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

BRONZE BUTLER

Score: 10.10
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1685.005 - Clear Windows Event Logs
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT38

Score: 19.22
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1138 - Application Shimming
  • T1218.012 - Verclsid
  • T1583.006 - Web Services
  • T1048 - Exfiltration Over Alternative Protocol
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Molerats

Score: 9.27
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1685.002 - Disable or Modify Cloud Log
  • T1583.006 - Web Services
  • T1027.018 - Invisible Unicode
MITREへのリンク →

admin@338

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

Darkhotel

Score: 6.44
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

The White Company

Score: 3.16
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

APT33

Score: 11.11
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

Silence

Score: 9.15
Matched TTPs:
  • T1087.002 - Domain Account
  • T1598.003 - Spearphishing Link
  • T1048 - Exfiltration Over Alternative Protocol
  • T1562.001 - Disable or Modify Tools
  • T1622 - Debugger Evasion
MITREへのリンク →

Confucius

Score: 11.46
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1027.018 - Invisible Unicode
MITREへのリンク →

BlackTech

Score: 11.14
Matched TTPs:
  • T1087.002 - Domain Account
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1089 - Disabling Security Tools
  • T1685.005 - Clear Windows Event Logs
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Storm-0501

Score: 8.11
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
MITREへのリンク →

LuminousMoth

Score: 4.54
Matched TTPs:
  • T1543.003 - Windows Service
  • T1089 - Disabling Security Tools
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Mustard Tempest

Score: 4.57
Matched TTPs:
  • T1543.003 - Windows Service
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Evilnum

Score: 4.54
Matched TTPs:
  • T1543.003 - Windows Service
  • T1089 - Disabling Security Tools
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT3

Score: 9.20
Matched TTPs:
  • T1543.003 - Windows Service
  • T1089 - Disabling Security Tools
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT1

Score: 5.49
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
MITREへのリンク →

ZIRCONIUM

Score: 6.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1685.002 - Disable or Modify Cloud Log
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Turla

Score: 6.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Winter Vivern

Score: 4.00
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Daggerfly

Score: 4.86
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Ke3chang

Score: 4.96
Matched TTPs:
  • T1685.005 - Clear Windows Event Logs
  • T1583.006 - Web Services
MITREへのリンク →

Scarlet Mimic

Score: 3.44
Matched TTPs:
  • T1685.005 - Clear Windows Event Logs
MITREへのリンク →

UNC3886

Score: 7.14
Matched TTPs:
  • T1547.015 - Login Items
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
MITREへのリンク →

Scattered Spider

Score: 5.78
Matched TTPs:
  • T1619 - Cloud Storage Object Discovery
  • T1622 - Debugger Evasion
MITREへのリンク →

LAPSUS$

Score: 4.13
Matched TTPs:
  • T1619 - Cloud Storage Object Discovery
MITREへのリンク →

APT5

Score: 3.17
Matched TTPs:
  • T1583.006 - Web Services
  • T1622 - Debugger Evasion
MITREへのリンク →

Rocke

Score: 7.54
Matched TTPs:
  • T1583.006 - Web Services
  • T1562.001 - Disable or Modify Tools
  • T1059.013 - Container CLI/API
MITREへのリンク →

Axiom

Score: 9.44
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

Sea Turtle

Score: 5.12
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Gamaredon Group

Score: 0.74
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1598.003 - Spearphishing Link
  • T1200 - Hardware Additions
  • T1027.018 - Invisible Unicode
  • T1218.012 - Verclsid
  • T1547.012 - Print Processors
  • T1059.013 - Container CLI/API
  • T1021.005 - VNC
  • T1583.006 - Web Services
  • T1608 - Stage Capabilities
  • T1562.001 - Disable or Modify Tools
  • T1087.002 - Domain Account
MITREへのリンク →

Kimsuky

Score: 0.74
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1598.003 - Spearphishing Link
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1218.012 - Verclsid
  • T1003.003 - NTDS
  • T1543.003 - Windows Service
  • T1496.004 - Cloud Service Hijacking
  • T1583.006 - Web Services
  • T1608 - Stage Capabilities
  • T1053.007 - Container Orchestration Job
  • T1087.002 - Domain Account
MITREへのリンク →

Mustang Panda

Score: 0.74
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1089 - Disabling Security Tools
  • T1027.018 - Invisible Unicode
  • T1136.001 - Local Account
  • T1218.012 - Verclsid
  • T1543.003 - Windows Service
  • T1556 - Modify Authentication Process
  • T1583.006 - Web Services
  • T1608 - Stage Capabilities
  • T1053.007 - Container Orchestration Job
  • T1087.002 - Domain Account
MITREへのリンク →

MuddyWater

Score: 0.69
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1089 - Disabling Security Tools
  • T1027.018 - Invisible Unicode
  • T1218.012 - Verclsid
  • T1547.012 - Print Processors
  • T1059.013 - Container CLI/API
  • T1543.003 - Windows Service
  • T1206 - Sudo Caching
  • T1583.006 - Web Services
  • T1059.001 - PowerShell
  • T1087.002 - Domain Account
MITREへのリンク →

FIN7

Score: 0.65
Matched TTPs:
  • T1047 - Windows Management Instrumentation
  • T1598.003 - Spearphishing Link
  • T1622 - Debugger Evasion
  • T1027.018 - Invisible Unicode
  • T1218.012 - Verclsid
  • T1021.005 - VNC
  • T1543.003 - Windows Service
  • T1206 - Sudo Caching
  • T1583.006 - Web Services
  • T1562.001 - Disable or Modify Tools
  • T1059.001 - PowerShell
  • T1087.002 - Domain Account
MITREへのリンク →

Lazarus Group

Score: 0.63
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1047 - Windows Management Instrumentation
  • T1598.003 - Spearphishing Link
  • T1622 - Debugger Evasion
  • T1218.010 - Regsvr32
  • T1089 - Disabling Security Tools
  • T1070.006 - Timestomp
  • T1218.012 - Verclsid
  • T1543.003 - Windows Service
  • T1556 - Modify Authentication Process
  • T1583.006 - Web Services
  • T1562.001 - Disable or Modify Tools
  • T1087.002 - Domain Account
MITREへのリンク →

APT32

Score: 0.58
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1047 - Windows Management Instrumentation
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1218.010 - Regsvr32
  • T1089 - Disabling Security Tools
  • T1027.018 - Invisible Unicode
  • T1218.012 - Verclsid
  • T1543.003 - Windows Service
  • T1556 - Modify Authentication Process
  • T1562.001 - Disable or Modify Tools
  • T1087.002 - Domain Account
MITREへのリンク →

Cobalt Group

Score: 0.58
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1598.003 - Spearphishing Link
  • T1622 - Debugger Evasion
  • T1218.010 - Regsvr32
  • T1027.018 - Invisible Unicode
  • T1598.004 - Spearphishing Voice
  • T1543.003 - Windows Service
  • T1052 - Exfiltration Over Physical Medium
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る