Trusted Design

An Update on Winnti

概要

The group continues to primarily use publicly available pentesting tools outside of the US. In the multiple incidents we have been involved in, the group has relied heavily on BeEF and Cobalt Strike. Cobalt Strike has been their primary toolset for command and control within the victim networks, while BeEF has been used to assist in the initial infection process. On the network traffic analysis end, post compromise activity results in some interesting but not unexpected activity. First, Winnti uses Cobalt Strike to collect credentials and move laterally. The stolen credentials may be used for remote access into the victim network if applicable. The group also continues to focus on theft of code signing certificates and internal documentation, including company files and internal communication history (chats/emails).

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Scattered Spider

Score: 17.91
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1578.002 - Create Cloud Instance
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1213.005 - Messaging Applications
MITREへのリンク →

FIN4

Score: 4.13
Matched TTPs:
  • T1564.008 - Email Hiding Rules
MITREへのリンク →

Magic Hound

Score: 8.26
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

HEXANE

Score: 6.02
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT29

Score: 7.04
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

Gamaredon Group

Score: 13.71
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

TA2541

Score: 10.27
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

Lotus Blossom

Score: 6.52
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1090.001 - Internal Proxy
MITREへのリンク →

FIN13

Score: 11.47
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1090.001 - Internal Proxy
MITREへのリンク →

HAFNIUM

Score: 6.19
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

Turla

Score: 18.66
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1555.004 - Windows Credential Manager
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1090.001 - Internal Proxy
  • T1078.003 - Local Accounts
MITREへのリンク →

Volt Typhoon

Score: 18.55
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1590.006 - Network Security Appliances
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1090.001 - Internal Proxy
MITREへのリンク →

FIN8

Score: 11.92
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Sandworm Team

Score: 12.32
Matched TTPs:
  • T1040 - Network Sniffing
  • T1219 - Remote Access Tools
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Kimsuky

Score: 17.39
Matched TTPs:
  • T1040 - Network Sniffing
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
  • T1078.003 - Local Accounts
MITREへのリンク →

Velvet Ant

Score: 16.01
Matched TTPs:
  • T1040 - Network Sniffing
  • T1573.002 - Asymmetric Cryptography
  • T1570 - Lateral Tool Transfer
  • T1569.002 - Service Execution
  • T1090.001 - Internal Proxy
  • T1078.003 - Local Accounts
MITREへのリンク →

Salt Typhoon

Score: 3.88
Matched TTPs:
  • T1040 - Network Sniffing
  • T1588.002 - Tool
MITREへのリンク →

APT33

Score: 8.79
Matched TTPs:
  • T1040 - Network Sniffing
  • T1552.006 - Group Policy Preferences
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

UNC3886

Score: 8.71
Matched TTPs:
  • T1040 - Network Sniffing
  • T1570 - Lateral Tool Transfer
  • T1008 - Fallback Channels
MITREへのリンク →

DarkVishnya

Score: 11.01
Matched TTPs:
  • T1040 - Network Sniffing
  • T1219 - Remote Access Tools
  • T1588.002 - Tool
  • T1200 - Hardware Additions
MITREへのリンク →

APT28

Score: 22.67
Matched TTPs:
  • T1040 - Network Sniffing
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
  • T1137.002 - Office Test
  • T1669 - Wi-Fi Networks
MITREへのリンク →

TeamTNT

Score: 3.37
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

OilRig

Score: 18.82
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1555.004 - Windows Credential Manager
  • T1105 - Ingress Tool Transfer
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
  • T1008 - Fallback Channels
MITREへのリンク →

FIN7

Score: 17.12
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1008 - Fallback Channels
  • T1078.003 - Local Accounts
MITREへのリンク →

INC Ransom

Score: 13.02
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Medusa Group

Score: 28.98
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1608.002 - Upload Tool
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1570 - Lateral Tool Transfer
  • T1650 - Acquire Access
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1218.014 - MMC
MITREへのリンク →

Carbanak

Score: 3.44
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1588.002 - Tool
MITREへのリンク →

MuddyWater

Score: 6.96
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Akira

Score: 6.76
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1657 - Financial Theft
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

BlackByte

Score: 9.65
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Cobalt Group

Score: 11.36
Matched TTPs:
  • T1219 - Remote Access Tools
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Threat Group-3390

Score: 14.81
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1588.003 - Code Signing Certificates
  • T1027.015 - Compression
MITREへのリンク →

Winter Vivern

Score: 5.31
Matched TTPs:
  • T1056.003 - Web Portal Capture
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

LAPSUS$

Score: 17.90
Matched TTPs:
  • T1213.001 - Confluence
  • T1552.008 - Chat Messages
  • T1588.002 - Tool
  • T1578.002 - Create Cloud Instance
  • T1213.005 - Messaging Applications
MITREへのリンク →

Contagious Interview

Score: 3.37
Matched TTPs:
  • T1657 - Financial Theft
  • T1588.002 - Tool
MITREへのリンク →

Cinnamon Tempest

Score: 4.15
Matched TTPs:
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Storm-0501

Score: 5.27
Matched TTPs:
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
MITREへのリンク →

Play

Score: 6.82
Matched TTPs:
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

Wizard Spider

Score: 21.56
Matched TTPs:
  • T1552.006 - Group Policy Preferences
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1555.004 - Windows Credential Manager
  • T1105 - Ingress Tool Transfer
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Fox Kitten

Score: 12.05
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1039 - Data from Network Shared Drive
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1213.005 - Messaging Applications
MITREへのリンク →

Earth Lusca

Score: 6.43
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1584.004 - Server
MITREへのリンク →

Ember Bear

Score: 4.98
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

Tonto Team

Score: 3.52
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

menuPass

Score: 9.05
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Dragonfly

Score: 12.00
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1221 - Template Injection
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Mustang Panda

Score: 9.32
Matched TTPs:
  • T1678 - Delay Execution
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Inception

Score: 6.75
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1221 - Template Injection
MITREへのリンク →

BlackTech

Score: 4.00
Matched TTPs:
  • T1588.002 - Tool
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Storm-1811

Score: 3.86
Matched TTPs:
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BRONZE BUTLER

Score: 4.66
Matched TTPs:
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT41

Score: 11.35
Matched TTPs:
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1008 - Fallback Channels
MITREへのリンク →

APT39

Score: 8.60
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1090.001 - Internal Proxy
MITREへのリンク →

GALLIUM

Score: 3.86
Matched TTPs:
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN6

Score: 7.64
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Patchwork

Score: 3.27
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Sea Turtle

Score: 3.52
Matched TTPs:
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
MITREへのリンク →

WIRTE

Score: 4.37
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Ke3chang

Score: 4.02
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Lazarus Group

Score: 12.47
Matched TTPs:
  • T1588.002 - Tool
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1008 - Fallback Channels
  • T1090.001 - Internal Proxy
MITREへのリンク →

FIN10

Score: 7.40
Matched TTPs:
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1078.003 - Local Accounts
MITREへのリンク →

Aquatic Panda

Score: 3.27
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Aoqin Dragon

Score: 3.08
Matched TTPs:
  • T1588.002 - Tool
  • T1570 - Lateral Tool Transfer
MITREへのリンク →

APT38

Score: 4.02
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

APT32

Score: 11.67
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Silence

Score: 5.67
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

Chimera

Score: 10.94
Matched TTPs:
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
MITREへのリンク →

APT19

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
MITREへのリンク →

APT42

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Blue Mockingbird

Score: 12.18
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1021.001 - Remote Desktop Protocol
  • T1569.002 - Service Execution
  • T1574.012 - COR_PROFILER
MITREへのリンク →

DarkHydrus

Score: 4.00
Matched TTPs:
  • T1588.002 - Tool
  • T1221 - Template Injection
MITREへのリンク →

RedCurl

Score: 5.78
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

TA551

Score: 3.52
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Leviathan

Score: 11.16
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
  • T1027.015 - Compression
MITREへのリンク →

Tropic Trooper

Score: 9.34
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

Agrius

Score: 3.88
Matched TTPs:
  • T1570 - Lateral Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Confucius

Score: 3.93
Matched TTPs:
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Daggerfly

Score: 3.61
Matched TTPs:
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Indrik Spider

Score: 5.26
Matched TTPs:
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

PLATINUM

Score: 5.31
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1056.004 - Credential API Hooking
MITREへのリンク →

Molerats

Score: 3.93
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

Moonstone Sleet

Score: 3.17
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Axiom

Score: 6.19
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1001.002 - Steganography
MITREへのリンク →

Higaisa

Score: 6.08
Matched TTPs:
  • T1090.001 - Internal Proxy
  • T1027.015 - Compression
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Medusa Group

Score: 0.83
Matched TTPs:
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1657 - Financial Theft
  • T1650 - Acquire Access
  • T1219 - Remote Access Tools
  • T1608.002 - Upload Tool
  • T1218.014 - MMC
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT28

Score: 0.63
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1669 - Wi-Fi Networks
  • T1221 - Template Injection
  • T1588.002 - Tool
  • T1137.002 - Office Test
  • T1040 - Network Sniffing
  • T1210 - Exploitation of Remote Services
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Wizard Spider

Score: 0.61
Matched TTPs:
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1552.006 - Group Policy Preferences
  • T1569.002 - Service Execution
  • T1588.002 - Tool
  • T1555.004 - Windows Credential Manager
  • T1210 - Exploitation of Remote Services
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Turla

Score: 0.57
Matched TTPs:
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1584.004 - Server
  • T1090.001 - Internal Proxy
  • T1588.002 - Tool
  • T1555.004 - Windows Credential Manager
  • T1016.001 - Internet Connection Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

Volt Typhoon

Score: 0.57
Matched TTPs:
  • T1570 - Lateral Tool Transfer
  • T1105 - Ingress Tool Transfer
  • T1584.004 - Server
  • T1090.001 - Internal Proxy
  • T1588.002 - Tool
  • T1590.006 - Network Security Appliances
  • T1016.001 - Internet Connection Discovery
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

LAPSUS$

Score: 0.56
Matched TTPs:
  • T1552.008 - Chat Messages
  • T1578.002 - Create Cloud Instance
  • T1588.002 - Tool
  • T1213.005 - Messaging Applications
  • T1213.001 - Confluence
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る