Trusted Design

Privileges and Credentials: Phished at the Request of Counsel

概要

In May and June 2017, FireEye observed a phishing campaign targeting at least seven global law and investment firms. We have associated this campaign with APT19, a group that we assess is composed of freelancers, with some degree of sponsorship by the Chinese government. APT19 used three different techniques to attempt to compromise targets. In early May, the phishing lures leveraged RTF attachments that exploited the Microsoft Windows vulnerability described in CVE 2017-0199. Toward the end of May, APT19 switched to using macro-enabled Microsoft Excel (XLSM) documents. In the most recent versions, APT19 added an application whitelisting bypass to the macro-enabled Microsoft Excel (XLSM) documents. At least one observed phishing lure delivered a Cobalt Strike payload.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

LAPSUS$

Score: 20.43
Matched TTPs:
  • T1597.002 - Purchase Technical Data
  • T1598.004 - Spearphishing Voice
  • T1591.002 - Business Relationships
  • T1588.002 - Tool
  • T1589.001 - Credentials
  • T1591.004 - Identify Roles
MITREへのリンク →

Contagious Interview

Score: 14.05
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1587.001 - Malware
  • T1583.001 - Domains
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ember Bear

Score: 9.76
Matched TTPs:
  • T1491.002 - External Defacement
  • T1203 - Exploitation for Client Execution
  • T1588.005 - Exploits
MITREへのリンク →

Sandworm Team

Score: 23.94
Matched TTPs:
  • T1491.002 - External Defacement
  • T1587.001 - Malware
  • T1588.006 - Vulnerabilities
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1591.002 - Business Relationships
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
MITREへのリンク →

Volt Typhoon

Score: 25.02
Matched TTPs:
  • T1584.008 - Network Devices
  • T1588.006 - Vulnerabilities
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1614 - System Location Discovery
  • T1591.004 - Identify Roles
  • T1584.004 - Server
  • T1680 - Local Storage Discovery
MITREへのリンク →

APT28

Score: 28.26
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1589.001 - Credentials
  • T1203 - Exploitation for Client Execution
  • T1598 - Phishing for Information
  • T1221 - Template Injection
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

ZIRCONIUM

Score: 11.04
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1598 - Phishing for Information
MITREへのリンク →

Leviathan

Score: 17.40
Matched TTPs:
  • T1584.008 - Network Devices
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1534 - Internal Spearphishing
  • T1589.001 - Credentials
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
MITREへのリンク →

Kimsuky

Score: 36.87
Matched TTPs:
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1657 - Financial Theft
  • T1591 - Gather Victim Org Information
  • T1534 - Internal Spearphishing
  • T1588.002 - Tool
  • T1566 - Phishing
  • T1598 - Phishing for Information
  • T1680 - Local Storage Discovery
  • T1588.005 - Exploits
  • T1584.001 - Domains
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN13

Score: 5.47
Matched TTPs:
  • T1587.001 - Malware
  • T1657 - Financial Theft
  • T1588.002 - Tool
MITREへのリンク →

Moonstone Sleet

Score: 16.19
Matched TTPs:
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1591 - Gather Victim Org Information
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Indrik Spider

Score: 4.93
Matched TTPs:
  • T1587.001 - Malware
  • T1584.004 - Server
MITREへのリンク →

Lazarus Group

Score: 18.30
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1584.004 - Server
  • T1680 - Local Storage Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 12.97
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1555.004 - Windows Credential Manager
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 3.59
Matched TTPs:
  • T1587.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT29

Score: 14.35
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1550.003 - Pass the Ticket
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1078.003 - Local Accounts
MITREへのリンク →

Play

Score: 8.13
Matched TTPs:
  • T1587.001 - Malware
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
MITREへのリンク →

Aoqin Dragon

Score: 4.44
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Turla

Score: 12.07
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1555.004 - Windows Credential Manager
  • T1584.004 - Server
  • T1078.003 - Local Accounts
MITREへのリンク →

Mustang Panda

Score: 13.83
Matched TTPs:
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1608 - Stage Capabilities
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

TeamTNT

Score: 6.45
Matched TTPs:
  • T1587.001 - Malware
  • T1583.001 - Domains
  • T1680 - Local Storage Discovery
MITREへのリンク →

FIN7

Score: 14.91
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1591.004 - Identify Roles
  • T1078.003 - Local Accounts
MITREへのリンク →

Storm-0501

Score: 6.37
Matched TTPs:
  • T1588.006 - Vulnerabilities
  • T1657 - Financial Theft
MITREへのリンク →

Sidewinder

Score: 8.45
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Scattered Spider

Score: 19.46
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1598.004 - Spearphishing Voice
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1556.006 - Multi-Factor Authentication
  • T1598 - Phishing for Information
MITREへのリンク →

Silent Librarian

Score: 4.83
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1588.002 - Tool
MITREへのリンク →

APT32

Score: 13.70
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1550.003 - Pass the Ticket
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Magic Hound

Score: 14.07
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1589.001 - Credentials
  • T1566.003 - Spearphishing via Service
  • T1584.001 - Domains
MITREへのリンク →

Star Blizzard

Score: 9.32
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1598.002 - Spearphishing Attachment
  • T1588.002 - Tool
MITREへのリンク →

CURIUM

Score: 7.37
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 20.64
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1591.002 - Business Relationships
  • T1598.002 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1584.004 - Server
MITREへのリンク →

Patchwork

Score: 8.51
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1680 - Local Storage Discovery
MITREへのリンク →

Cobalt Group

Score: 3.22
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Tropic Trooper

Score: 11.02
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1680 - Local Storage Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN6

Score: 4.25
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Windshift

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 7.06
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1550.003 - Pass the Ticket
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

MuddyWater

Score: 11.38
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1137.001 - Office Template Macros
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1027.004 - Compile After Delivery
MITREへのリンク →

menuPass

Score: 3.24
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
MITREへのリンク →

Threat Group-3390

Score: 4.73
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Gamaredon Group

Score: 13.64
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1534 - Internal Spearphishing
  • T1588.002 - Tool
  • T1027.004 - Compile After Delivery
  • T1221 - Template Injection
MITREへのリンク →

BITTER

Score: 4.73
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Inception

Score: 6.37
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

EXOTIC LILY

Score: 6.41
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT33

Score: 7.35
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1552.006 - Group Policy Preferences
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT41

Score: 3.22
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Higaisa

Score: 5.20
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1680 - Local Storage Discovery
MITREへのリンク →

Confucius

Score: 8.35
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1680 - Local Storage Discovery
MITREへのリンク →

BlackTech

Score: 3.22
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ferocious Kitten

Score: 3.24
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
MITREへのリンク →

Malteiro

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1657 - Financial Theft
MITREへのリンク →

SideCopy

Score: 11.91
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1614 - System Location Discovery
  • T1584.001 - Domains
MITREへのリンク →

Transparent Tribe

Score: 7.17
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1584.001 - Domains
MITREへのリンク →

Wizard Spider

Score: 9.48
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1552.006 - Group Policy Preferences
  • T1588.002 - Tool
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

TA2541

Score: 3.24
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
MITREへのリンク →

TA505

Score: 3.24
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
MITREへのリンク →

IndigoZebra

Score: 3.24
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
MITREへのリンク →

APT1

Score: 6.53
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1584.001 - Domains
MITREへのリンク →

APT38

Score: 3.24
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1588.002 - Tool
MITREへのリンク →

DarkHydrus

Score: 4.88
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1221 - Template Injection
MITREへのリンク →

Storm-1811

Score: 4.89
Matched TTPs:
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

HEXANE

Score: 9.61
Matched TTPs:
  • T1583.001 - Domains
  • T1534 - Internal Spearphishing
  • T1588.002 - Tool
  • T1591.004 - Identify Roles
MITREへのリンク →

Earth Lusca

Score: 5.20
Matched TTPs:
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1584.004 - Server
MITREへのリンク →

Sea Turtle

Score: 13.43
Matched TTPs:
  • T1583.001 - Domains
  • T1588.002 - Tool
  • T1566 - Phishing
  • T1203 - Exploitation for Client Execution
  • T1027.004 - Compile After Delivery
  • T1078.003 - Local Accounts
MITREへのリンク →

INC Ransom

Score: 6.66
Matched TTPs:
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1566 - Phishing
MITREへのリンク →

Cinnamon Tempest

Score: 3.37
Matched TTPs:
  • T1657 - Financial Theft
  • T1588.002 - Tool
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

Medusa Group

Score: 3.37
Matched TTPs:
  • T1657 - Financial Theft
  • T1588.002 - Tool
MITREへのリンク →

FIN10

Score: 3.52
Matched TTPs:
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
MITREへのリンク →

Chimera

Score: 7.12
Matched TTPs:
  • T1588.002 - Tool
  • T1589.001 - Credentials
  • T1680 - Local Storage Discovery
MITREへのリンク →

Axiom

Score: 9.32
Matched TTPs:
  • T1566 - Phishing
  • T1203 - Exploitation for Client Execution
  • T1001.002 - Steganography
MITREへのリンク →

GOLD SOUTHFIELD

Score: 3.29
Matched TTPs:
  • T1566 - Phishing
MITREへのリンク →

Rocke

Score: 3.62
Matched TTPs:
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

ToddyCat

Score: 5.36
Matched TTPs:
  • T1680 - Local Storage Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Mustard Tempest

Score: 3.29
Matched TTPs:
  • T1584.001 - Domains
MITREへのリンク →

Velvet Ant

Score: 6.80
Matched TTPs:
  • T1078.003 - Local Accounts
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.79
Matched TTPs:
  • T1566 - Phishing
  • T1566.001 - Spearphishing Attachment
  • T1591 - Gather Victim Org Information
  • T1588.005 - Exploits
  • T1657 - Financial Theft
  • T1598.003 - Spearphishing Link
  • T1534 - Internal Spearphishing
  • T1588.002 - Tool
  • T1587.001 - Malware
  • T1078.003 - Local Accounts
  • T1583.001 - Domains
  • T1584.001 - Domains
  • T1598 - Phishing for Information
  • T1680 - Local Storage Discovery
MITREへのリンク →

APT28

Score: 0.69
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1566.001 - Spearphishing Attachment
  • T1221 - Template Injection
  • T1591 - Gather Victim Org Information
  • T1589.001 - Credentials
  • T1211 - Exploitation for Defense Evasion
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1588.002 - Tool
  • T1583.001 - Domains
  • T1598 - Phishing for Information
MITREへのリンク →

Volt Typhoon

Score: 0.60
Matched TTPs:
  • T1584.004 - Server
  • T1591 - Gather Victim Org Information
  • T1591.004 - Identify Roles
  • T1584.008 - Network Devices
  • T1588.002 - Tool
  • T1680 - Local Storage Discovery
  • T1588.006 - Vulnerabilities
  • T1614 - System Location Discovery
MITREへのリンク →

Sandworm Team

Score: 0.58
Matched TTPs:
  • T1584.004 - Server
  • T1203 - Exploitation for Client Execution
  • T1566.001 - Spearphishing Attachment
  • T1591.002 - Business Relationships
  • T1491.002 - External Defacement
  • T1598.003 - Spearphishing Link
  • T1588.002 - Tool
  • T1587.001 - Malware
  • T1583.001 - Domains
  • T1588.006 - Vulnerabilities
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る