Trusted Design

LatentBot Piece by Piece | Malwarebytes Labs

概要

LatentBot is a multi-modular Trojan written in Delphi and known to have been around since 2013. Recently, we captured and dissected a sample distributed by RIG Exploit Kit. The main executable is a persistent botnet agent which downloads additional modules and reports about the performed activities to its Command and Control server. Depending on the modules that have been installed, LatentBot has various capabilities, including: - Act as a keylogger and form grabber - Steal cookies - Run a Socks Proxy from the victim system - Give remote access to the attacker (VNC / Remote Desktop)

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Contagious Interview

Score: 16.99
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1059.006 - Python
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Kimsuky

Score: 18.90
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1537 - Transfer Data to Cloud Account
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
  • T1126 - Network Share Connection Removal
  • T1003.003 - NTDS
MITREへのリンク →

FIN13

Score: 3.74
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1622 - Debugger Evasion
MITREへのリンク →

Moonstone Sleet

Score: 13.60
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1491 - Defacement
  • T1126 - Network Share Connection Removal
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Indrik Spider

Score: 3.74
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1622 - Debugger Evasion
MITREへのリンク →

Lazarus Group

Score: 15.92
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1587 - Develop Capabilities
  • T1216 - System Script Proxy Execution
MITREへのリンク →

OilRig

Score: 13.11
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
MITREへのリンク →

UNC3886

Score: 10.18
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1136.002 - Domain Account
  • T1547.015 - Login Items
  • T1218.010 - Regsvr32
MITREへのリンク →

LuminousMoth

Score: 6.53
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
MITREへのリンク →

Sandworm Team

Score: 9.18
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
MITREへのリンク →

APT29

Score: 10.18
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1218.010 - Regsvr32
  • T1546.018 - Python Startup Hooks
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Aoqin Dragon

Score: 5.64
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Turla

Score: 7.48
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1136.002 - Domain Account
  • T1587 - Develop Capabilities
MITREへのリンク →

Ke3chang

Score: 4.49
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Mustang Panda

Score: 12.85
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1526 - Cloud Service Discovery
  • T1055.005 - Thread Local Storage
MITREへのリンク →

TeamTNT

Score: 6.12
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

FIN7

Score: 16.78
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1011.001 - Exfiltration Over Bluetooth
  • T1564.002 - Hidden Users
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT39

Score: 14.48
Matched TTPs:
  • T1499.002 - Service Exhaustion Flood
  • T1599 - Network Boundary Bridging
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

TA2541

Score: 9.23
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1128 - Netsh Helper DLL
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Earth Lusca

Score: 4.43
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
MITREへのリンク →

LazyScripter

Score: 4.43
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
MITREへのリンク →

Threat Group-3390

Score: 12.80
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.003 - CMSTP
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1526 - Cloud Service Discovery
MITREへのリンク →

TA505

Score: 9.41
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1537 - Transfer Data to Cloud Account
  • T1587 - Develop Capabilities
MITREへのリンク →

BlackByte

Score: 6.02
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BITTER

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

APT32

Score: 5.86
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1622 - Debugger Evasion
MITREへのリンク →

Saint Bear

Score: 5.52
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

APT42

Score: 8.56
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1599 - Network Boundary Bridging
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Medusa Group

Score: 16.60
Matched TTPs:
  • T1218.003 - CMSTP
  • T1128 - Netsh Helper DLL
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Fox Kitten

Score: 4.93
Matched TTPs:
  • T1491 - Defacement
  • T1622 - Debugger Evasion
MITREへのリンク →

Volt Typhoon

Score: 10.61
Matched TTPs:
  • T1491 - Defacement
  • T1049 - System Network Connections Discovery
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

APT38

Score: 11.36
Matched TTPs:
  • T1491 - Defacement
  • T1537 - Transfer Data to Cloud Account
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Scattered Spider

Score: 11.52
Matched TTPs:
  • T1491 - Defacement
  • T1136.002 - Domain Account
  • T1090.004 - Domain Fronting
  • T1622 - Debugger Evasion
MITREへのリンク →

Chimera

Score: 7.33
Matched TTPs:
  • T1491 - Defacement
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Ember Bear

Score: 8.08
Matched TTPs:
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

APT1

Score: 4.11
Matched TTPs:
  • T1136.002 - Domain Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Aquatic Panda

Score: 4.11
Matched TTPs:
  • T1136.002 - Domain Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Andariel

Score: 3.95
Matched TTPs:
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
MITREへのリンク →

BackdoorDiplomacy

Score: 5.39
Matched TTPs:
  • T1136.002 - Domain Account
  • T1587 - Develop Capabilities
MITREへのリンク →

HAFNIUM

Score: 3.62
Matched TTPs:
  • T1049 - System Network Connections Discovery
MITREへのリンク →

Axiom

Score: 11.30
Matched TTPs:
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

PROMETHIUM

Score: 4.13
Matched TTPs:
  • T1547.015 - Login Items
MITREへのリンク →

Darkhotel

Score: 5.63
Matched TTPs:
  • T1564.002 - Hidden Users
  • T1218.010 - Regsvr32
MITREへのリンク →

Storm-1811

Score: 3.84
Matched TTPs:
  • T1599 - Network Boundary Bridging
MITREへのリンク →

APT28

Score: 6.03
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

Dragonfly

Score: 3.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

The White Company

Score: 3.55
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

BlackTech

Score: 4.65
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1526 - Cloud Service Discovery
MITREへのリンク →

Patchwork

Score: 5.19
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Cobalt Group

Score: 5.89
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
MITREへのリンク →

Leviathan

Score: 6.07
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1587 - Develop Capabilities
MITREへのリンク →

APT37

Score: 5.12
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT3

Score: 5.19
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Tropic Trooper

Score: 7.17
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1587 - Develop Capabilities
MITREへのリンク →

APT41

Score: 7.59
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Elderwood

Score: 3.55
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Velvet Ant

Score: 5.14
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN6

Score: 6.79
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN8

Score: 7.55
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
MITREへのリンク →

Storm-0501

Score: 6.19
Matched TTPs:
  • T1090.004 - Domain Fronting
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Wizard Spider

Score: 10.13
Matched TTPs:
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1587 - Develop Capabilities
MITREへのリンク →

INC Ransom

Score: 4.05
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Silence

Score: 4.05
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Blue Mockingbird

Score: 4.05
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.79
Matched TTPs:
  • T1003.003 - NTDS
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1126 - Network Share Connection Removal
  • T1526 - Cloud Service Discovery
  • T1091 - Replication Through Removable Media
  • T1606.002 - SAML Tokens
MITREへのリンク →

FIN7

Score: 0.74
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1091 - Replication Through Removable Media
  • T1564.002 - Hidden Users
  • T1027.007 - Dynamic API Resolution
  • T1011.001 - Exfiltration Over Bluetooth
  • T1606.002 - SAML Tokens
MITREへのリンク →

Medusa Group

Score: 0.72
Matched TTPs:
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1218.003 - CMSTP
  • T1216 - System Script Proxy Execution
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Contagious Interview

Score: 0.71
Matched TTPs:
  • T1059.006 - Python
  • T1044 - File System Permissions Weakness
  • T1126 - Network Share Connection Removal
  • T1091 - Replication Through Removable Media
  • T1606.002 - SAML Tokens
MITREへのリンク →

Lazarus Group

Score: 0.67
Matched TTPs:
  • T1587 - Develop Capabilities
  • T1622 - Debugger Evasion
  • T1218.010 - Regsvr32
  • T1216 - System Script Proxy Execution
  • T1055.005 - Thread Local Storage
  • T1606.002 - SAML Tokens
MITREへのリンク →

APT39

Score: 0.62
Matched TTPs:
  • T1537 - Transfer Data to Cloud Account
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1599 - Network Boundary Bridging
  • T1499.002 - Service Exhaustion Flood
MITREへのリンク →

Moonstone Sleet

Score: 0.61
Matched TTPs:
  • T1126 - Network Share Connection Removal
  • T1091 - Replication Through Removable Media
  • T1027.007 - Dynamic API Resolution
  • T1606.002 - SAML Tokens
  • T1491 - Defacement
MITREへのリンク →

Threat Group-3390

Score: 0.58
Matched TTPs:
  • T1537 - Transfer Data to Cloud Account
  • T1526 - Cloud Service Discovery
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1218.003 - CMSTP
MITREへのリンク →

Mustang Panda

Score: 0.56
Matched TTPs:
  • T1526 - Cloud Service Discovery
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1606.002 - SAML Tokens
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る