TrickBot Is Hand-Picking Private Banks
概要
IBM X-Force research follows organized cybercrime and continually monitors the criminals’ targets and modus operandi. In a recent analysis of TrickBot campaigns in the U.K., Australia and Germany, I found that the operators of the infamous Trojan have been adding new redirection attacks focused on a list of brands that I had never seen in the past.
Curious about this addition to the TrickBot prime target roster, I went on to examine each URL, only to find out that the operators have been doing a lot of homework. The current configuration files are replete with private banks, private wealth management firms, investment banking, and even a retirement insurance and annuity company. One of the new targets is among the oldest banks in the world, located in the U.K.
Created: 2026-02-23
Indicators
Indicatorsは見つかっていない。
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 4.13
Matched TTPs:
- T1564.008 - Email Hiding Rules
MITREへのリンク →
Score: 7.42
Matched TTPs:
- T1564.008 - Email Hiding Rules
- T1102.003 - One-Way Communication
MITREへのリンク →
Score: 12.84
Matched TTPs:
- T1491 - Defacement
- T1535 - Unused/Unsupported Cloud Regions
- T1102.003 - One-Way Communication
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 9.25
Matched TTPs:
- T1491 - Defacement
- T1535 - Unused/Unsupported Cloud Regions
- T1552.003 - Shell History
MITREへのリンク →
Score: 5.81
Matched TTPs:
- T1491 - Defacement
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 6.12
Matched TTPs:
- T1491 - Defacement
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 6.27
Matched TTPs:
- T1535 - Unused/Unsupported Cloud Regions
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 5.96
Matched TTPs:
- T1535 - Unused/Unsupported Cloud Regions
- T1552.003 - Shell History
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1535 - Unused/Unsupported Cloud Regions
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1011.001 - Exfiltration Over Bluetooth
MITREへのリンク →
Score: 12.18
Matched TTPs:
- T1552.003 - Shell History
- T1562.010 - Downgrade Attack
- T1102.003 - One-Way Communication
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 8.64
Matched TTPs:
- T1552.003 - Shell History
- T1102.003 - One-Way Communication
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 7.06
Matched TTPs:
- T1552.003 - Shell History
- T1094 - Custom Command and Control Protocol
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1562.010 - Downgrade Attack
MITREへのリンク →
Score: 7.00
Matched TTPs:
- T1562.010 - Downgrade Attack
- T1546.017 - Udev Rules
MITREへのリンク →
Score: 7.82
Matched TTPs:
- T1102.003 - One-Way Communication
- T1169 - Sudo
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1102.003 - One-Way Communication
MITREへのリンク →
Score: 7.06
Matched TTPs:
- T1592.002 - Software
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1146 - Clear Command History
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1543.002 - Systemd Service
MITREへのリンク →
Score: 5.36
Matched TTPs:
- T1665 - Hide Infrastructure
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 5.98
Matched TTPs:
- T1665 - Hide Infrastructure
- T1546.017 - Udev Rules
MITREへのリンク →
Score: 5.36
Matched TTPs:
- T1665 - Hide Infrastructure
- T1547.008 - LSASS Driver
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.78
Matched TTPs:
- T1491 - Defacement
- T1665 - Hide Infrastructure
- T1535 - Unused/Unsupported Cloud Regions
- T1102.003 - One-Way Communication
MITREへのリンク →
Score: 0.74
Matched TTPs:
- T1562.010 - Downgrade Attack
- T1102.003 - One-Way Communication
- T1547.008 - LSASS Driver
- T1552.003 - Shell History
MITREへのリンク →
Score: 0.62
Matched TTPs:
- T1491 - Defacement
- T1535 - Unused/Unsupported Cloud Regions
- T1552.003 - Shell History
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1102.003 - One-Way Communication
- T1665 - Hide Infrastructure
- T1552.003 - Shell History
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る