Trusted Design

KingKong.dll - Recent PoisonIvy and PlugX variants targeting South East Asia

概要

(Description updated in 2018) The Vietnamese government published a brief analysis of spearphishes it had encountered in 2017, such as APEC-SMEWG Strategic Plan 2017-2020.doc. This pulse includes indicators from this analysis, and indicators from other campaigns that employ related malware. The attackers deliver malware through topically titled spearphises, for example Energy_Data_Meeting_fall_2016. Many documents call out to tetrasecured[.]com/word/webstat/image.php?id= (sinkholed by AlienVault) to track when when they are opened. This domain also contains pages to phish credentials for popular online mail providers such as Gmail and Yahoo. It is likely these spearphishes are generated via a builder - so attribution to an exact group of attackers may be incorrect. Recent variants drop distinctively named malware such as KingKong.dll.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

BlackTech

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

MuddyWater

Score: 5.83
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Confucius

Score: 8.98
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Kimsuky

Score: 33.29
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1534 - Internal Spearphishing
  • T1566 - Phishing
  • T1218.010 - Regsvr32
  • T1593.001 - Social Media
  • T1598 - Phishing for Information
  • T1584.001 - Domains
  • T1078.003 - Local Accounts
MITREへのリンク →

Sidewinder

Score: 12.49
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Elderwood

Score: 5.58
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Machete

Score: 4.09
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1189 - Drive-by Compromise
MITREへのリンク →

FIN7

Score: 15.60
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1571 - Non-Standard Port
  • T1124 - System Time Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

Mustard Tempest

Score: 6.50
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1189 - Drive-by Compromise
  • T1584.001 - Domains
MITREへのリンク →

Sandworm Team

Score: 10.19
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1571 - Non-Standard Port
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Transparent Tribe

Score: 10.38
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1584.001 - Domains
MITREへのリンク →

Mustang Panda

Score: 24.84
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1070 - Indicator Removal
  • T1583.006 - Web Services
  • T1678 - Delay Execution
  • T1203 - Exploitation for Client Execution
  • T1027.007 - Dynamic API Resolution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN8

Score: 5.07
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT32

Score: 24.22
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1571 - Non-Standard Port
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1078.003 - Local Accounts
MITREへのリンク →

APT3

Score: 6.56
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
MITREへのリンク →

APT1

Score: 7.12
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1584.001 - Domains
MITREへのリンク →

Lazarus Group

Score: 29.22
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1070 - Indicator Removal
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1571 - Non-Standard Port
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1027.007 - Dynamic API Resolution
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Leviathan

Score: 13.47
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1534 - Internal Spearphishing
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

APT33

Score: 13.09
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1552.006 - Group Policy Preferences
  • T1571 - Non-Standard Port
  • T1203 - Exploitation for Client Execution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

ZIRCONIUM

Score: 15.56
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1598 - Phishing for Information
  • T1124 - System Time Discovery
MITREへのリンク →

EXOTIC LILY

Score: 11.70
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1593.001 - Social Media
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Magic Hound

Score: 26.75
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1583.006 - Web Services
  • T1571 - Non-Standard Port
  • T1573 - Encrypted Channel
  • T1036.010 - Masquerade Account Name
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
  • T1584.001 - Domains
MITREへのリンク →

OilRig

Score: 18.76
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1137.004 - Outlook Home Page
  • T1555.004 - Windows Credential Manager
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Windshift

Score: 6.61
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Cobalt Group

Score: 6.56
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT29

Score: 14.64
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1573 - Encrypted Channel
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
  • T1078.003 - Local Accounts
MITREへのリンク →

TA2541

Score: 5.85
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1583.006 - Web Services
MITREへのリンク →

Earth Lusca

Score: 10.36
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

RedCurl

Score: 6.17
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Storm-1811

Score: 18.19
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1583.001 - Domains
  • T1566.004 - Spearphishing Voice
  • T1667 - Email Bombing
  • T1036.010 - Masquerade Account Name
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Turla

Score: 17.73
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1583.006 - Web Services
  • T1584.006 - Web Services
  • T1555.004 - Windows Credential Manager
  • T1189 - Drive-by Compromise
  • T1124 - System Time Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

Wizard Spider

Score: 14.92
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1036.004 - Masquerade Task or Service
  • T1552.006 - Group Policy Preferences
  • T1555.004 - Windows Credential Manager
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Patchwork

Score: 8.04
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

TA505

Score: 3.84
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
MITREへのリンク →

LazyScripter

Score: 5.85
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1583.006 - Web Services
MITREへのリンク →

APT42

Score: 6.59
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1583.001 - Domains
  • T1070 - Indicator Removal
MITREへのリンク →

Scattered Spider

Score: 11.55
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
  • T1598.004 - Spearphishing Voice
  • T1598 - Phishing for Information
MITREへのリンク →

Silent Librarian

Score: 3.98
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.001 - Domains
MITREへのリンク →

APT28

Score: 16.71
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1598 - Phishing for Information
  • T1189 - Drive-by Compromise
  • T1221 - Template Injection
MITREへのリンク →

Star Blizzard

Score: 8.47
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

Moonstone Sleet

Score: 10.81
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

CURIUM

Score: 15.35
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 18.50
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1598.002 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
  • T1189 - Drive-by Compromise
  • T1221 - Template Injection
MITREへのリンク →

Saint Bear

Score: 4.38
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Tropic Trooper

Score: 11.81
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1573 - Encrypted Channel
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN6

Score: 8.24
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036.004 - Masquerade Task or Service
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

BRONZE BUTLER

Score: 6.73
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1124 - System Time Discovery
MITREへのリンク →

WIRTE

Score: 6.02
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1571 - Non-Standard Port
  • T1218.010 - Regsvr32
MITREへのリンク →

Threat Group-3390

Score: 5.65
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Gamaredon Group

Score: 13.58
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1534 - Internal Spearphishing
  • T1571 - Non-Standard Port
  • T1221 - Template Injection
MITREへのリンク →

Darkhotel

Score: 6.73
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1124 - System Time Discovery
MITREへのリンク →

BITTER

Score: 9.60
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1573 - Encrypted Channel
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Inception

Score: 8.27
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TA551

Score: 3.62
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
MITREへのリンク →

APT41

Score: 4.46
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Winter Vivern

Score: 9.87
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1036.004 - Masquerade Task or Service
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

Higaisa

Score: 7.06
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

APT19

Score: 5.39
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
MITREへのリンク →

SideCopy

Score: 7.78
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1584.001 - Domains
MITREへのリンク →

Andariel

Score: 4.13
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

APT37

Score: 4.13
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Silence

Score: 3.27
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1571 - Non-Standard Port
MITREへのリンク →

IndigoZebra

Score: 4.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1583.006 - Web Services
MITREへのリンク →

APT38

Score: 4.16
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.001 - Domains
  • T1189 - Drive-by Compromise
MITREへのリンク →

DarkHydrus

Score: 4.03
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1221 - Template Injection
MITREへのリンク →

The White Company

Score: 4.96
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

APT-C-36

Score: 5.37
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036.004 - Masquerade Task or Service
  • T1571 - Non-Standard Port
MITREへのリンク →

HEXANE

Score: 5.14
Matched TTPs:
  • T1583.001 - Domains
  • T1534 - Internal Spearphishing
MITREへのリンク →

Contagious Interview

Score: 19.17
Matched TTPs:
  • T1583.001 - Domains
  • T1681 - Search Threat Vendor Data
  • T1583.006 - Web Services
  • T1571 - Non-Standard Port
  • T1593.001 - Social Media
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

RedEcho

Score: 3.92
Matched TTPs:
  • T1583.001 - Domains
  • T1571 - Non-Standard Port
MITREへのリンク →

Sea Turtle

Score: 8.96
Matched TTPs:
  • T1583.001 - Domains
  • T1566 - Phishing
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1659 - Content Injection
MITREへのリンク →

UNC3886

Score: 14.45
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

LAPSUS$

Score: 4.13
Matched TTPs:
  • T1598.004 - Spearphishing Voice
MITREへのリンク →

APT5

Score: 3.62
Matched TTPs:
  • T1070 - Indicator Removal
MITREへのリンク →

PROMETHIUM

Score: 10.66
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
  • T1189 - Drive-by Compromise
  • T1078.003 - Local Accounts
MITREへのリンク →

Storm-0501

Score: 8.69
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

HAFNIUM

Score: 4.68
Matched TTPs:
  • T1583.006 - Web Services
  • T1078.003 - Local Accounts
MITREへのリンク →

INC Ransom

Score: 7.13
Matched TTPs:
  • T1566 - Phishing
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Axiom

Score: 6.54
Matched TTPs:
  • T1566 - Phishing
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

AppleJeus

Score: 3.29
Matched TTPs:
  • T1566 - Phishing
MITREへのリンク →

GOLD SOUTHFIELD

Score: 3.29
Matched TTPs:
  • T1566 - Phishing
MITREへのリンク →

Ember Bear

Score: 3.89
Matched TTPs:
  • T1571 - Non-Standard Port
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Velvet Ant

Score: 5.06
Matched TTPs:
  • T1571 - Non-Standard Port
  • T1078.003 - Local Accounts
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Dark Caracal

Score: 4.29
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.83
Matched TTPs:
  • T1598 - Phishing for Information
  • T1036.004 - Masquerade Task or Service
  • T1598.003 - Spearphishing Link
  • T1566 - Phishing
  • T1584.001 - Domains
  • T1593.001 - Social Media
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1566.002 - Spearphishing Link
  • T1534 - Internal Spearphishing
  • T1078.003 - Local Accounts
  • T1218.010 - Regsvr32
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Lazarus Group

Score: 0.76
Matched TTPs:
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1036.004 - Masquerade Task or Service
  • T1124 - System Time Discovery
  • T1571 - Non-Standard Port
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1070 - Indicator Removal
  • T1566.003 - Spearphishing via Service
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1566.002 - Spearphishing Link
  • T1027.007 - Dynamic API Resolution
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Magic Hound

Score: 0.69
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1584.001 - Domains
  • T1571 - Non-Standard Port
  • T1189 - Drive-by Compromise
  • T1573 - Encrypted Channel
  • T1566.003 - Spearphishing via Service
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1036.010 - Masquerade Account Name
MITREへのリンク →

APT32

Score: 0.68
Matched TTPs:
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1036.004 - Masquerade Task or Service
  • T1598.003 - Spearphishing Link
  • T1571 - Non-Standard Port
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1566.002 - Spearphishing Link
  • T1078.003 - Local Accounts
  • T1218.010 - Regsvr32
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Mustang Panda

Score: 0.66
Matched TTPs:
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1598.003 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1070 - Indicator Removal
  • T1583.001 - Domains
  • T1583.006 - Web Services
  • T1566.002 - Spearphishing Link
  • T1027.007 - Dynamic API Resolution
  • T1678 - Delay Execution
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Storm-1811

Score: 0.55
Matched TTPs:
  • T1566.004 - Spearphishing Voice
  • T1667 - Email Bombing
  • T1566.003 - Spearphishing via Service
  • T1583.001 - Domains
  • T1566.002 - Spearphishing Link
  • T1036.010 - Masquerade Account Name
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る