Trusted Design

KingKong.dll - Recent PoisonIvy and PlugX variants targeting South East Asia

概要

(Description updated in 2018) The Vietnamese government published a brief analysis of spearphishes it had encountered in 2017, such as APEC-SMEWG Strategic Plan 2017-2020.doc. This pulse includes indicators from this analysis, and indicators from other campaigns that employ related malware. The attackers deliver malware through topically titled spearphises, for example Energy_Data_Meeting_fall_2016. Many documents call out to tetrasecured[.]com/word/webstat/image.php?id= (sinkholed by AlienVault) to track when when they are opened. This domain also contains pages to phish credentials for popular online mail providers such as Gmail and Yahoo. It is likely these spearphishes are generated via a builder - so attribution to an exact group of attackers may be incorrect. Recent variants drop distinctively named malware such as KingKong.dll.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

BlackTech

Score: 3.81
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
MITREへのリンク →

MuddyWater

Score: 5.83
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

Confucius

Score: 8.98
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Kimsuky

Score: 33.29
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1055.014 - VDSO Hijacking
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1027.014 - Polymorphic Code
  • T1690 - Prevent Command History Logging
  • T1197 - BITS Jobs
  • T1053.002 - At
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Sidewinder

Score: 12.49
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

Elderwood

Score: 5.58
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Machete

Score: 4.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

FIN7

Score: 15.60
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1562.001 - Disable or Modify Tools
  • T1578.001 - Create Snapshot
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Mustard Tempest

Score: 6.50
Matched TTPs:
  • T1543.003 - Windows Service
  • T1059.012 - Hypervisor CLI
  • T1053.002 - At
MITREへのリンク →

Sandworm Team

Score: 10.19
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
MITREへのリンク →

Transparent Tribe

Score: 10.38
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1053.002 - At
MITREへのリンク →

Mustang Panda

Score: 24.84
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1677 - Poisoned Pipeline Execution
  • T1608.005 - Link Target
  • T1169 - Sudo
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN8

Score: 5.07
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT32

Score: 24.22
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1556 - Modify Authentication Process
  • T1490 - Inhibit System Recovery
MITREへのリンク →

APT3

Score: 6.56
Matched TTPs:
  • T1543.003 - Windows Service
  • T1218.010 - Regsvr32
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

APT1

Score: 7.12
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1053.002 - At
MITREへのリンク →

Lazarus Group

Score: 29.22
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1677 - Poisoned Pipeline Execution
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1055.005 - Thread Local Storage
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Leviathan

Score: 13.47
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1055.014 - VDSO Hijacking
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT33

Score: 13.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1567.001 - Exfiltration to Code Repository
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
  • T1556 - Modify Authentication Process
MITREへのリンク →

ZIRCONIUM

Score: 15.56
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1197 - BITS Jobs
  • T1578.001 - Create Snapshot
MITREへのリンク →

EXOTIC LILY

Score: 11.70
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1690 - Prevent Command History Logging
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Magic Hound

Score: 26.75
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1562.001 - Disable or Modify Tools
  • T1683 - Generate Content
  • T1578.002 - Create Cloud Instance
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
  • T1053.002 - At
MITREへのリンク →

OilRig

Score: 18.76
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1218.010 - Regsvr32
  • T1592.002 - Software
  • T1556.009 - Conditional Access Policies
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Windshift

Score: 6.61
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Cobalt Group

Score: 6.56
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
MITREへのリンク →

APT29

Score: 14.64
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1608.005 - Link Target
  • T1683 - Generate Content
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
  • T1490 - Inhibit System Recovery
MITREへのリンク →

TA2541

Score: 5.85
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
MITREへのリンク →

Earth Lusca

Score: 10.36
Matched TTPs:
  • T1543.003 - Windows Service
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

RedCurl

Score: 6.17
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1055.009 - Proc Memory
MITREへのリンク →

Storm-1811

Score: 18.19
Matched TTPs:
  • T1543.003 - Windows Service
  • T1098.007 - Additional Local or Domain Groups
  • T1486 - Data Encrypted for Impact
  • T1567.003 - Exfiltration to Text Storage Sites
  • T1578.002 - Create Cloud Instance
  • T1547.008 - LSASS Driver
MITREへのリンク →

Turla

Score: 17.73
Matched TTPs:
  • T1543.003 - Windows Service
  • T1608.005 - Link Target
  • T1218.001 - Compiled HTML File
  • T1556.009 - Conditional Access Policies
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Wizard Spider

Score: 14.92
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1588.001 - Malware
  • T1567.001 - Exfiltration to Code Repository
  • T1556.009 - Conditional Access Policies
  • T1556 - Modify Authentication Process
MITREへのリンク →

Patchwork

Score: 8.04
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

TA505

Score: 3.84
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
MITREへのリンク →

LazyScripter

Score: 5.85
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
MITREへのリンク →

APT42

Score: 6.59
Matched TTPs:
  • T1543.003 - Windows Service
  • T1098.007 - Additional Local or Domain Groups
  • T1677 - Poisoned Pipeline Execution
MITREへのリンク →

Scattered Spider

Score: 11.55
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1019 - System Firmware
  • T1197 - BITS Jobs
MITREへのリンク →

Silent Librarian

Score: 3.98
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
MITREへのリンク →

APT28

Score: 16.71
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1197 - BITS Jobs
  • T1059.012 - Hypervisor CLI
  • T1200 - Hardware Additions
MITREへのリンク →

Star Blizzard

Score: 8.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1657 - Financial Theft
MITREへのリンク →

Moonstone Sleet

Score: 10.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1197 - BITS Jobs
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 15.35
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dragonfly

Score: 18.50
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1578.002 - Create Cloud Instance
  • T1059.012 - Hypervisor CLI
  • T1200 - Hardware Additions
MITREへのリンク →

Saint Bear

Score: 4.38
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

Tropic Trooper

Score: 11.81
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1683 - Generate Content
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1490 - Inhibit System Recovery
MITREへのリンク →

FIN6

Score: 8.24
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1588.001 - Malware
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

BRONZE BUTLER

Score: 6.73
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

WIRTE

Score: 6.02
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Threat Group-3390

Score: 5.65
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Gamaredon Group

Score: 13.58
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1055.014 - VDSO Hijacking
  • T1562.001 - Disable or Modify Tools
  • T1200 - Hardware Additions
MITREへのリンク →

Darkhotel

Score: 6.73
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

BITTER

Score: 9.60
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1683 - Generate Content
  • T1218.010 - Regsvr32
MITREへのリンク →

Inception

Score: 8.27
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1547.008 - LSASS Driver
MITREへのリンク →

TA551

Score: 3.62
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
MITREへのリンク →

APT41

Score: 4.46
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
MITREへのリンク →

Winter Vivern

Score: 9.87
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Higaisa

Score: 7.06
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT19

Score: 5.39
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

SideCopy

Score: 7.78
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
  • T1053.002 - At
MITREへのリンク →

Andariel

Score: 4.13
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT37

Score: 4.13
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Silence

Score: 3.27
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

IndigoZebra

Score: 4.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
MITREへのリンク →

APT38

Score: 4.16
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

DarkHydrus

Score: 4.03
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1200 - Hardware Additions
MITREへのリンク →

The White Company

Score: 4.96
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT-C-36

Score: 5.37
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

HEXANE

Score: 5.14
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1055.014 - VDSO Hijacking
MITREへのリンク →

Contagious Interview

Score: 19.17
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1021.006 - Windows Remote Management
  • T1608.005 - Link Target
  • T1562.001 - Disable or Modify Tools
  • T1690 - Prevent Command History Logging
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

RedEcho

Score: 3.92
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Sea Turtle

Score: 8.96
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1218.010 - Regsvr32
  • T1490 - Inhibit System Recovery
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1055.003 - Thread Execution Hijacking
MITREへのリンク →

UNC3886

Score: 14.45
Matched TTPs:
  • T1021.006 - Windows Remote Management
  • T1588.001 - Malware
  • T1547.015 - Login Items
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

LAPSUS$

Score: 4.13
Matched TTPs:
  • T1019 - System Firmware
MITREへのリンク →

APT5

Score: 3.62
Matched TTPs:
  • T1677 - Poisoned Pipeline Execution
MITREへのリンク →

PROMETHIUM

Score: 10.66
Matched TTPs:
  • T1588.001 - Malware
  • T1547.015 - Login Items
  • T1059.012 - Hypervisor CLI
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Storm-0501

Score: 8.69
Matched TTPs:
  • T1588.001 - Malware
  • T1027.014 - Polymorphic Code
  • T1055.009 - Proc Memory
MITREへのリンク →

HAFNIUM

Score: 4.68
Matched TTPs:
  • T1608.005 - Link Target
  • T1490 - Inhibit System Recovery
MITREへのリンク →

INC Ransom

Score: 7.13
Matched TTPs:
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1055.009 - Proc Memory
MITREへのリンク →

Axiom

Score: 6.54
Matched TTPs:
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

AppleJeus

Score: 3.29
Matched TTPs:
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

GOLD SOUTHFIELD

Score: 3.29
Matched TTPs:
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Ember Bear

Score: 3.89
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
MITREへのリンク →

Velvet Ant

Score: 5.06
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

Dark Caracal

Score: 4.29
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.83
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1490 - Inhibit System Recovery
  • T1053.002 - At
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1197 - BITS Jobs
  • T1608.005 - Link Target
  • T1690 - Prevent Command History Logging
  • T1055.014 - VDSO Hijacking
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Lazarus Group

Score: 0.76
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1677 - Poisoned Pipeline Execution
  • T1055.005 - Thread Local Storage
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
  • T1598.003 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
  • T1608.005 - Link Target
MITREへのリンク →

Magic Hound

Score: 0.69
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
  • T1053.002 - At
  • T1566.002 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1683 - Generate Content
  • T1578.002 - Create Cloud Instance
  • T1608.005 - Link Target
MITREへのリンク →

APT32

Score: 0.68
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
  • T1556 - Modify Authentication Process
  • T1490 - Inhibit System Recovery
  • T1059.012 - Hypervisor CLI
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1218.010 - Regsvr32
  • T1608.005 - Link Target
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Mustang Panda

Score: 0.66
Matched TTPs:
  • T1169 - Sudo
  • T1098.007 - Additional Local or Domain Groups
  • T1677 - Poisoned Pipeline Execution
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1543.003 - Windows Service
  • T1218.010 - Regsvr32
  • T1608.005 - Link Target
MITREへのリンク →

Storm-1811

Score: 0.55
Matched TTPs:
  • T1567.003 - Exfiltration to Text Storage Sites
  • T1098.007 - Additional Local or Domain Groups
  • T1547.008 - LSASS Driver
  • T1486 - Data Encrypted for Impact
  • T1543.003 - Windows Service
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る