Trusted Design

EPS Processing Zero-Days Exploited by Multiple Threat Actors

概要

Recently, FireEye identified three new zero-day vulnerabilities in Microsoft Office products that are being exploited in the wild. At the end of March 2017, we detected another malicious document leveraging an unknown vulnerability in EPS and a recently patched vulnerability in Windows Graphics Device Interface (GDI) to drop malware. Following the April 2017 Patch Tuesday, in which Microsoft disabled EPS, FireEye detected a second unknown vulnerability in EPS. FireEye believes that two actors – Turla and an unknown financially motivated actor – were using the first EPS zero-day (CVE-2017-0261), and APT28 was using the second EPS zero-day (CVE-2017-0262) along with a new Escalation of Privilege (EOP) zero-day (CVE-2017-0263). Turla and APT28 are Russian cyber espionage groups that have used these zero-days against European diplomatic and military entities. The unidentified financial group targeted regional and global banks with offices in the Middle East.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Turla

Score: 22.54
Matched TTPs:
  • T1564.012 - File/Path Exclusions
  • T1587.001 - Malware
  • T1112 - Modify Registry
  • T1588.001 - Malware
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1027.005 - Indicator Removal from Tools
  • T1078.003 - Local Accounts
MITREへのリンク →

Ember Bear

Score: 19.67
Matched TTPs:
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
  • T1588.005 - Exploits
MITREへのリンク →

Sandworm Team

Score: 19.52
Matched TTPs:
  • T1491.002 - External Defacement
  • T1587.001 - Malware
  • T1588.006 - Vulnerabilities
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Kimsuky

Score: 20.80
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1027.016 - Junk Code Insertion
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1588.005 - Exploits
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN13

Score: 6.94
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1588.002 - Tool
MITREへのリンク →

Moonstone Sleet

Score: 4.62
Matched TTPs:
  • T1587.001 - Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Indrik Spider

Score: 5.72
Matched TTPs:
  • T1587.001 - Malware
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Lazarus Group

Score: 14.68
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1036.003 - Rename Legitimate Utilities
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 13.92
Matched TTPs:
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 23.63
Matched TTPs:
  • T1587.001 - Malware
  • T1497.001 - System Checks
  • T1195 - Supply Chain Compromise
  • T1112 - Modify Registry
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1027.005 - Indicator Removal from Tools
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 15.11
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1681 - Search Threat Vendor Data
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

LuminousMoth

Score: 7.23
Matched TTPs:
  • T1587.001 - Malware
  • T1112 - Modify Registry
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Salt Typhoon

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

APT29

Score: 21.83
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1550.003 - Pass the Ticket
  • T1553.005 - Mark-of-the-Web Bypass
  • T1588.002 - Tool
  • T1562.008 - Disable or Modify Cloud Logs
  • T1566.003 - Spearphishing via Service
  • T1078.003 - Local Accounts
MITREへのリンク →

Play

Score: 11.40
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1078.003 - Local Accounts
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1587.001 - Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Ke3chang

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Mustang Panda

Score: 17.80
Matched TTPs:
  • T1587.001 - Malware
  • T1176.002 - IDE Extensions
  • T1027.016 - Junk Code Insertion
  • T1588.002 - Tool
  • T1518 - Software Discovery
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

TeamTNT

Score: 3.89
Matched TTPs:
  • T1587.001 - Malware
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

FIN7

Score: 15.06
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1674 - Input Injection
  • T1027.016 - Junk Code Insertion
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
MITREへのリンク →

Evilnum

Score: 3.44
Matched TTPs:
  • T1497.001 - System Checks
MITREへのリンク →

Volt Typhoon

Score: 21.46
Matched TTPs:
  • T1497.001 - System Checks
  • T1588.006 - Vulnerabilities
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1614 - System Location Discovery
  • T1518 - Software Discovery
MITREへのリンク →

Darkhotel

Score: 3.44
Matched TTPs:
  • T1497.001 - System Checks
MITREへのリンク →

Gamaredon Group

Score: 14.51
Matched TTPs:
  • T1497.001 - System Checks
  • T1112 - Modify Registry
  • T1027.016 - Junk Code Insertion
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1221 - Template Injection
MITREへのリンク →

Storm-0501

Score: 11.12
Matched TTPs:
  • T1588.006 - Vulnerabilities
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1490 - Inhibit System Recovery
MITREへのリンク →

APT38

Score: 16.14
Matched TTPs:
  • T1565.003 - Runtime Data Manipulation
  • T1112 - Modify Registry
  • T1553.005 - Mark-of-the-Web Bypass
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1036.003 - Rename Legitimate Utilities
MITREへのリンク →

BlackByte

Score: 12.51
Matched TTPs:
  • T1562 - Impair Defenses
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Magic Hound

Score: 12.60
Matched TTPs:
  • T1562 - Impair Defenses
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Rocke

Score: 3.27
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Threat Group-3390

Score: 8.28
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1112 - Modify Registry
  • T1588.002 - Tool
MITREへのリンク →

APT28

Score: 14.14
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1221 - Template Injection
  • T1137.002 - Office Test
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

BackdoorDiplomacy

Score: 4.78
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Medusa Group

Score: 23.17
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1112 - Modify Registry
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
  • T1490 - Inhibit System Recovery
  • T1218.014 - MMC
MITREへのリンク →

Sea Turtle

Score: 4.99
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
MITREへのリンク →

Cinnamon Tempest

Score: 4.84
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1588.002 - Tool
MITREへのリンク →

Agrius

Score: 3.27
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

menuPass

Score: 5.60
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1036.003 - Rename Legitimate Utilities
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Blue Mockingbird

Score: 8.69
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1588.002 - Tool
  • T1574.012 - COR_PROFILER
MITREへのリンク →

GALLIUM

Score: 8.76
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1027.005 - Indicator Removal from Tools
  • T1036.003 - Rename Legitimate Utilities
MITREへのリンク →

Earth Lusca

Score: 9.64
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1027.003 - Steganography
MITREへのリンク →

Leviathan

Score: 4.50
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1027.003 - Steganography
MITREへのリンク →

INC Ransom

Score: 6.64
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Dragonfly

Score: 7.30
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1588.002 - Tool
  • T1221 - Template Injection
MITREへのリンク →

Axiom

Score: 6.01
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1001.002 - Steganography
MITREへのリンク →

APT41

Score: 4.15
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1112 - Modify Registry
  • T1588.002 - Tool
MITREへのリンク →

HAFNIUM

Score: 4.14
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1078.003 - Local Accounts
MITREへのリンク →

MuddyWater

Score: 9.90
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1027.003 - Steganography
  • T1518 - Software Discovery
MITREへのリンク →

Patchwork

Score: 5.83
Matched TTPs:
  • T1112 - Modify Registry
  • T1588.002 - Tool
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

TA505

Score: 10.78
Matched TTPs:
  • T1112 - Modify Registry
  • T1588.001 - Malware
  • T1553.005 - Mark-of-the-Web Bypass
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Wizard Spider

Score: 11.89
Matched TTPs:
  • T1112 - Modify Registry
  • T1552.006 - Group Policy Preferences
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1490 - Inhibit System Recovery
MITREへのリンク →

APT32

Score: 15.91
Matched TTPs:
  • T1112 - Modify Registry
  • T1027.016 - Junk Code Insertion
  • T1550.003 - Pass the Ticket
  • T1588.002 - Tool
  • T1036.003 - Rename Legitimate Utilities
  • T1078.003 - Local Accounts
MITREへのリンク →

Aquatic Panda

Score: 6.93
Matched TTPs:
  • T1112 - Modify Registry
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Gorgon Group

Score: 4.48
Matched TTPs:
  • T1112 - Modify Registry
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

APT42

Score: 5.43
Matched TTPs:
  • T1112 - Modify Registry
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Saint Bear

Score: 3.63
Matched TTPs:
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

FIN8

Score: 5.43
Matched TTPs:
  • T1112 - Modify Registry
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

TA2541

Score: 7.85
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

LAPSUS$

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Metador

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

APT1

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Andariel

Score: 5.49
Matched TTPs:
  • T1588.001 - Malware
  • T1027.003 - Steganography
MITREへのリンク →

Scattered Spider

Score: 15.45
Matched TTPs:
  • T1588.001 - Malware
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1538 - Cloud Service Dashboard
  • T1490 - Inhibit System Recovery
MITREへのリンク →

BRONZE BUTLER

Score: 12.27
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1027.003 - Steganography
  • T1518 - Software Discovery
MITREへのリンク →

Akira

Score: 4.32
Matched TTPs:
  • T1657 - Financial Theft
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

APT33

Score: 4.98
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1588.002 - Tool
MITREへのリンク →

Tonto Team

Score: 3.15
Matched TTPs:
  • T1069.001 - Local Groups
MITREへのリンク →

HEXANE

Score: 6.75
Matched TTPs:
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1518 - Software Discovery
MITREへのリンク →

admin@338

Score: 3.15
Matched TTPs:
  • T1069.001 - Local Groups
MITREへのリンク →

Chimera

Score: 4.00
Matched TTPs:
  • T1069.001 - Local Groups
  • T1588.002 - Tool
MITREへのリンク →

Inception

Score: 6.75
Matched TTPs:
  • T1588.002 - Tool
  • T1221 - Template Injection
  • T1518 - Software Discovery
MITREへのリンク →

Storm-1811

Score: 3.37
Matched TTPs:
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN6

Score: 7.92
Matched TTPs:
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Cobalt Group

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

FIN10

Score: 3.52
Matched TTPs:
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
MITREへのリンク →

DarkHydrus

Score: 4.00
Matched TTPs:
  • T1588.002 - Tool
  • T1221 - Template Injection
MITREへのリンク →

Velvet Ant

Score: 11.34
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
  • T1078.003 - Local Accounts
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Deep Panda

Score: 3.15
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

APT3

Score: 3.15
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
MITREへのリンク →

Daggerfly

Score: 3.29
Matched TTPs:
  • T1036.003 - Rename Legitimate Utilities
MITREへのリンク →

Tropic Trooper

Score: 14.34
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1027.003 - Steganography
  • T1221 - Template Injection
  • T1518 - Software Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

APT37

Score: 3.03
Matched TTPs:
  • T1027.003 - Steganography
MITREへのリンク →

TA551

Score: 3.03
Matched TTPs:
  • T1027.003 - Steganography
MITREへのリンク →

SideCopy

Score: 6.88
Matched TTPs:
  • T1614 - System Location Discovery
  • T1518 - Software Discovery
MITREへのリンク →

Confucius

Score: 3.15
Matched TTPs:
  • T1221 - Template Injection
MITREへのリンク →

Windshift

Score: 5.27
Matched TTPs:
  • T1518 - Software Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

OilRig

Score: 0.83
Matched TTPs:
  • T1069.001 - Local Groups
  • T1027.005 - Indicator Removal from Tools
  • T1566.003 - Spearphishing via Service
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1497.001 - System Checks
  • T1112 - Modify Registry
  • T1195 - Supply Chain Compromise
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Turla

Score: 0.83
Matched TTPs:
  • T1564.012 - File/Path Exclusions
  • T1069.001 - Local Groups
  • T1027.005 - Indicator Removal from Tools
  • T1587.001 - Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1078.003 - Local Accounts
  • T1112 - Modify Registry
MITREへのリンク →

Medusa Group

Score: 0.83
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1657 - Financial Theft
  • T1562.001 - Disable or Modify Tools
  • T1490 - Inhibit System Recovery
  • T1608.002 - Upload Tool
  • T1218.014 - MMC
  • T1112 - Modify Registry
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

APT29

Score: 0.81
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1562.008 - Disable or Modify Cloud Logs
  • T1588.002 - Tool
  • T1553.005 - Mark-of-the-Web Bypass
  • T1078.003 - Local Accounts
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Volt Typhoon

Score: 0.75
Matched TTPs:
  • T1069.001 - Local Groups
  • T1190 - Exploit Public-Facing Application
  • T1518 - Software Discovery
  • T1588.006 - Vulnerabilities
  • T1588.002 - Tool
  • T1614 - System Location Discovery
  • T1497.001 - System Checks
  • T1112 - Modify Registry
MITREへのリンク →

Kimsuky

Score: 0.75
Matched TTPs:
  • T1027.016 - Junk Code Insertion
  • T1588.005 - Exploits
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1657 - Financial Theft
  • T1562.001 - Disable or Modify Tools
  • T1078.003 - Local Accounts
  • T1112 - Modify Registry
MITREへのリンク →

Sandworm Team

Score: 0.73
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.006 - Vulnerabilities
  • T1491.002 - External Defacement
  • T1588.002 - Tool
  • T1490 - Inhibit System Recovery
  • T1195 - Supply Chain Compromise
MITREへのリンク →

Ember Bear

Score: 0.70
Matched TTPs:
  • T1588.005 - Exploits
  • T1588.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1491.002 - External Defacement
  • T1562.001 - Disable or Modify Tools
  • T1112 - Modify Registry
  • T1195 - Supply Chain Compromise
MITREへのリンク →

APT32

Score: 0.65
Matched TTPs:
  • T1027.016 - Junk Code Insertion
  • T1036.003 - Rename Legitimate Utilities
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
  • T1550.003 - Pass the Ticket
  • T1112 - Modify Registry
MITREへのリンク →

Mustang Panda

Score: 0.64
Matched TTPs:
  • T1027.016 - Junk Code Insertion
  • T1587.001 - Malware
  • T1027.007 - Dynamic API Resolution
  • T1518 - Software Discovery
  • T1588.002 - Tool
  • T1176.002 - IDE Extensions
MITREへのリンク →

APT38

Score: 0.62
Matched TTPs:
  • T1565.003 - Runtime Data Manipulation
  • T1036.003 - Rename Legitimate Utilities
  • T1588.002 - Tool
  • T1553.005 - Mark-of-the-Web Bypass
  • T1562.001 - Disable or Modify Tools
  • T1112 - Modify Registry
MITREへのリンク →

UNC3886

Score: 0.62
Matched TTPs:
  • T1027.005 - Indicator Removal from Tools
  • T1587.001 - Malware
  • T1588.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

APT28

Score: 0.61
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1137.002 - Office Test
  • T1221 - Template Injection
MITREへのリンク →

FIN7

Score: 0.61
Matched TTPs:
  • T1027.016 - Junk Code Insertion
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
  • T1674 - Input Injection
MITREへのリンク →

Gamaredon Group

Score: 0.59
Matched TTPs:
  • T1027.016 - Junk Code Insertion
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1497.001 - System Checks
  • T1112 - Modify Registry
  • T1221 - Template Injection
MITREへのリンク →

Lazarus Group

Score: 0.59
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1587.001 - Malware
  • T1027.007 - Dynamic API Resolution
  • T1036.003 - Rename Legitimate Utilities
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Scattered Spider

Score: 0.58
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1657 - Financial Theft
  • T1562.001 - Disable or Modify Tools
  • T1490 - Inhibit System Recovery
  • T1538 - Cloud Service Dashboard
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る