Trusted Design

Untangling the Patchwork Cyberespionage Group

概要

Patchwork (also known as Dropping Elephant) is a cyberespionage group known for targeting diplomatic and government agencies that has since added businesses to their list of targets. Patchwork’s moniker is from its notoriety for rehashing off-the-rack tools and malware for its own campaigns. The attack vectors they use may not be groundbreaking—what with other groups exploiting zero-days or adjusting their tactics—but the group’s repertoire of infection vectors and payloads makes them a credible threat. We trailed Patchwork’s activities over the course of its campaigns in 2017. The diversity of their methods is notable—from the social engineering hooks, attack chains, and backdoors they deployed. They’ve also joined the Dynamic Data Exchange (DDE) and Windows Script Component (SCT) abuse bandwagons and started exploiting recently reported vulnerabilities. These imply they’re at least keeping an eye on other threats and security flaws that they can repurpose for their own ends. Also of note are its attem

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 37.72
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1114.002 - Remote Email Collection
  • T1218.010 - Regsvr32
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
  • T1588.005 - Exploits
  • T1078.003 - Local Accounts
MITREへのリンク →

Sea Turtle

Score: 13.13
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1027.004 - Compile After Delivery
  • T1078.003 - Local Accounts
MITREへのリンク →

Ember Bear

Score: 30.18
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1491.002 - External Defacement
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1595.002 - Vulnerability Scanning
  • T1210 - Exploitation of Remote Services
  • T1562.001 - Disable or Modify Tools
  • T1203 - Exploitation for Client Execution
  • T1550.002 - Pass the Hash
  • T1588.005 - Exploits
MITREへのリンク →

Indrik Spider

Score: 10.23
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Agrius

Score: 8.49
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Contagious Interview

Score: 38.10
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1588.007 - Artificial Intelligence
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1681 - Search Threat Vendor Data
  • T1593.003 - Code Repositories
  • T1497 - Virtualization/Sandbox Evasion
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Sandworm Team

Score: 37.33
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1491.002 - External Defacement
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1595.002 - Vulnerability Scanning
  • T1591.002 - Business Relationships
  • T1584.005 - Botnet
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1499 - Endpoint Denial of Service
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Star Blizzard

Score: 13.02
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
MITREへのリンク →

FIN13

Score: 12.65
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Moonstone Sleet

Score: 8.24
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1105 - Ingress Tool Transfer
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Lazarus Group

Score: 22.13
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
  • T1680 - Local Storage Discovery
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

OilRig

Score: 31.22
Matched TTPs:
  • T1587.001 - Malware
  • T1497.001 - System Checks
  • T1566.001 - Spearphishing Attachment
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1036 - Masquerading
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

UNC3886

Score: 14.83
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1681 - Search Threat Vendor Data
  • T1562.001 - Disable or Modify Tools
  • T1587.004 - Exploits
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

LuminousMoth

Score: 5.69
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Salt Typhoon

Score: 7.16
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT29

Score: 24.56
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
  • T1203 - Exploitation for Client Execution
  • T1562.008 - Disable or Modify Cloud Logs
  • T1105 - Ingress Tool Transfer
  • T1566.003 - Spearphishing via Service
  • T1078.003 - Local Accounts
MITREへのリンク →

Play

Score: 12.18
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

Aoqin Dragon

Score: 6.62
Matched TTPs:
  • T1587.001 - Malware
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 5.72
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Moses Staff

Score: 5.19
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Turla

Score: 15.87
Matched TTPs:
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1583.006 - Web Services
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

Ke3chang

Score: 14.23
Matched TTPs:
  • T1587.001 - Malware
  • T1583.005 - Botnet
  • T1007 - System Service Discovery
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Mustang Panda

Score: 37.85
Matched TTPs:
  • T1587.001 - Malware
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1176.002 - IDE Extensions
  • T1219.001 - IDE Tunneling
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1678 - Delay Execution
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

TeamTNT

Score: 21.32
Matched TTPs:
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1595.002 - Vulnerability Scanning
  • T1610 - Deploy Container
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

FIN7

Score: 22.75
Matched TTPs:
  • T1587.001 - Malware
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1674 - Input Injection
  • T1583.006 - Web Services
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

Cobalt Group

Score: 12.23
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

MuddyWater

Score: 21.13
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1203 - Exploitation for Client Execution
  • T1027.004 - Compile After Delivery
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Sidewinder

Score: 12.26
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT28

Score: 35.27
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1595.002 - Vulnerability Scanning
  • T1583.006 - Web Services
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
  • T1546.015 - Component Object Model Hijacking
  • T1589.001 - Credentials
  • T1203 - Exploitation for Client Execution
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

APT37

Score: 5.89
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Gallmaker

Score: 3.62
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Leviathan

Score: 19.98
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1218.010 - Regsvr32
  • T1587.004 - Exploits
  • T1589.001 - Credentials
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BITTER

Score: 8.71
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TA505

Score: 9.02
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Patchwork

Score: 9.57
Matched TTPs:
  • T1559.002 - Dynamic Data Exchange
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

Evilnum

Score: 4.22
Matched TTPs:
  • T1497.001 - System Checks
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Volt Typhoon

Score: 29.39
Matched TTPs:
  • T1497.001 - System Checks
  • T1007 - System Service Discovery
  • T1190 - Exploit Public-Facing Application
  • T1584.005 - Botnet
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1587.004 - Exploits
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
  • T1596.005 - Scan Databases
  • T1680 - Local Storage Discovery
MITREへのリンク →

Darkhotel

Score: 10.43
Matched TTPs:
  • T1497.001 - System Checks
  • T1566.001 - Spearphishing Attachment
  • T1497 - Virtualization/Sandbox Evasion
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Gamaredon Group

Score: 19.88
Matched TTPs:
  • T1497.001 - System Checks
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1001 - Data Obfuscation
  • T1027.004 - Compile After Delivery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Saint Bear

Score: 12.00
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1497 - Virtualization/Sandbox Evasion
  • T1583.006 - Web Services
  • T1562.001 - Disable or Modify Tools
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Tropic Trooper

Score: 14.14
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN6

Score: 11.54
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

admin@338

Score: 8.04
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1007 - System Service Discovery
  • T1069.001 - Local Groups
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Windshift

Score: 9.11
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036 - Masquerading
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 13.25
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1007 - System Service Discovery
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

WIRTE

Score: 5.25
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

menuPass

Score: 8.90
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Threat Group-3390

Score: 14.32
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT32

Score: 21.07
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1078.003 - Local Accounts
MITREへのリンク →

Inception

Score: 8.71
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
MITREへのリンク →

EXOTIC LILY

Score: 6.86
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Ajax Security Team

Score: 4.17
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1105 - Ingress Tool Transfer
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 20.93
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1591.002 - Business Relationships
  • T1598.002 - Spearphishing Attachment
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Elderwood

Score: 3.14
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT33

Score: 10.87
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1552.006 - Group Policy Preferences
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

TA551

Score: 6.58
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036 - Masquerading
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT41

Score: 22.91
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1595.003 - Wordlist Scanning
  • T1213.003 - Code Repositories
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1596.005 - Scan Databases
MITREへのリンク →

Winter Vivern

Score: 7.90
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1595.002 - Vulnerability Scanning
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Higaisa

Score: 5.20
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1680 - Local Storage Discovery
MITREへのリンク →

Confucius

Score: 7.99
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

BlackTech

Score: 4.69
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Gorgon Group

Score: 4.30
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT19

Score: 4.47
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
MITREへのリンク →

Malteiro

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1657 - Financial Theft
MITREへのリンク →

SideCopy

Score: 9.99
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN8

Score: 7.99
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Nomadic Octopus

Score: 3.84
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036 - Masquerading
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

LazyScripter

Score: 7.82
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1583.006 - Web Services
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN4

Score: 3.54
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1114.002 - Remote Email Collection
MITREへのリンク →

Wizard Spider

Score: 16.67
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1552.006 - Group Policy Preferences
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Andariel

Score: 3.14
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TA2541

Score: 11.03
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Tonto Team

Score: 9.04
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1210 - Exploitation of Remote Services
  • T1069.001 - Local Groups
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

CURIUM

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

IndigoZebra

Score: 4.51
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT1

Score: 9.66
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1007 - System Service Discovery
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
  • T1550.002 - Pass the Hash
MITREへのリンク →

APT38

Score: 4.30
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

PLATINUM

Score: 3.84
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1036 - Masquerading
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT39

Score: 3.97
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

HAFNIUM

Score: 20.90
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1593.003 - Code Repositories
  • T1584.005 - Botnet
  • T1583.006 - Web Services
  • T1114.002 - Remote Email Collection
  • T1105 - Ingress Tool Transfer
  • T1078.003 - Local Accounts
MITREへのリンク →

APT5

Score: 5.31
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Aquatic Panda

Score: 11.28
Matched TTPs:
  • T1007 - System Service Discovery
  • T1595.002 - Vulnerability Scanning
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Chimera

Score: 18.99
Matched TTPs:
  • T1007 - System Service Discovery
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
  • T1589.001 - Credentials
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

Earth Lusca

Score: 14.17
Matched TTPs:
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1583.006 - Web Services
  • T1210 - Exploitation of Remote Services
  • T1588.002 - Tool
MITREへのリンク →

BlackByte

Score: 6.02
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

HEXANE

Score: 9.50
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1069.001 - Local Groups
  • T1588.002 - Tool
  • T1518 - Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT42

Score: 5.57
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Rocke

Score: 7.67
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1027.004 - Compile After Delivery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BackdoorDiplomacy

Score: 3.10
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Magic Hound

Score: 18.13
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1114.002 - Remote Email Collection
  • T1589.001 - Credentials
  • T1105 - Ingress Tool Transfer
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Medusa Group

Score: 20.84
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
  • T1650 - Acquire Access
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Storm-0501

Score: 6.74
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
MITREへのリンク →

Fox Kitten

Score: 8.84
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1105 - Ingress Tool Transfer
  • T1213.005 - Messaging Applications
MITREへのリンク →

Cinnamon Tempest

Score: 5.62
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

ToddyCat

Score: 6.83
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1680 - Local Storage Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Blue Mockingbird

Score: 5.07
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
MITREへのリンク →

GALLIUM

Score: 5.84
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Volatile Cedar

Score: 8.97
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1595.003 - Wordlist Scanning
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

INC Ransom

Score: 7.42
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Axiom

Score: 6.59
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1584.005 - Botnet
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

ZIRCONIUM

Score: 4.98
Matched TTPs:
  • T1036 - Masquerading
  • T1583.006 - Web Services
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Storm-1811

Score: 6.34
Matched TTPs:
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

LAPSUS$

Score: 19.67
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1593.003 - Code Repositories
  • T1588.002 - Tool
  • T1589.001 - Credentials
  • T1213.003 - Code Repositories
  • T1213.005 - Messaging Applications
MITREへのリンク →

Akira

Score: 4.32
Matched TTPs:
  • T1657 - Financial Theft
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Scattered Spider

Score: 13.64
Matched TTPs:
  • T1657 - Financial Theft
  • T1588.002 - Tool
  • T1562.001 - Disable or Modify Tools
  • T1213.003 - Code Repositories
  • T1105 - Ingress Tool Transfer
  • T1213.005 - Messaging Applications
MITREへのリンク →

DarkVishnya

Score: 5.39
Matched TTPs:
  • T1588.002 - Tool
  • T1200 - Hardware Additions
MITREへのリンク →

Leafminer

Score: 3.52
Matched TTPs:
  • T1588.002 - Tool
  • T1114.002 - Remote Email Collection
MITREへのリンク →

Thrip

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN10

Score: 3.52
Matched TTPs:
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
MITREへのリンク →

Velvet Ant

Score: 11.34
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1573.002 - Asymmetric Cryptography
  • T1078.003 - Local Accounts
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.84
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
  • T1584.005 - Botnet
  • T1588.002 - Tool
  • T1595.002 - Vulnerability Scanning
  • T1608.001 - Upload Malware
  • T1566.001 - Spearphishing Attachment
  • T1591.002 - Business Relationships
  • T1491.002 - External Defacement
  • T1499 - Endpoint Denial of Service
  • T1036 - Masquerading
MITREへのリンク →

Kimsuky

Score: 0.83
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1078.003 - Local Accounts
  • T1657 - Financial Theft
  • T1114.002 - Remote Email Collection
  • T1608.001 - Upload Malware
  • T1007 - System Service Discovery
  • T1566.001 - Spearphishing Attachment
  • T1562.001 - Disable or Modify Tools
  • T1680 - Local Storage Discovery
  • T1550.002 - Pass the Hash
  • T1218.010 - Regsvr32
  • T1588.005 - Exploits
MITREへのリンク →

Mustang Panda

Score: 0.83
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1219.001 - IDE Tunneling
  • T1518 - Software Discovery
  • T1203 - Exploitation for Client Execution
  • T1583.006 - Web Services
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1027.007 - Dynamic API Resolution
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1608 - Stage Capabilities
  • T1608.001 - Upload Malware
  • T1566.001 - Spearphishing Attachment
  • T1176.002 - IDE Extensions
  • T1678 - Delay Execution
MITREへのリンク →

Contagious Interview

Score: 0.82
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1583 - Acquire Infrastructure
  • T1583.006 - Web Services
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
  • T1657 - Financial Theft
  • T1593.003 - Code Repositories
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1608.001 - Upload Malware
  • T1562.001 - Disable or Modify Tools
  • T1681 - Search Threat Vendor Data
  • T1497 - Virtualization/Sandbox Evasion
  • T1036 - Masquerading
MITREへのリンク →

APT28

Score: 0.80
Matched TTPs:
  • T1589.001 - Credentials
  • T1105 - Ingress Tool Transfer
  • T1203 - Exploitation for Client Execution
  • T1583.006 - Web Services
  • T1190 - Exploit Public-Facing Application
  • T1211 - Exploitation for Defense Evasion
  • T1588.002 - Tool
  • T1559.002 - Dynamic Data Exchange
  • T1546.015 - Component Object Model Hijacking
  • T1595.002 - Vulnerability Scanning
  • T1114.002 - Remote Email Collection
  • T1566.001 - Spearphishing Attachment
  • T1550.002 - Pass the Hash
  • T1210 - Exploitation of Remote Services
  • T1036 - Masquerading
MITREへのリンク →

OilRig

Score: 0.72
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1608.001 - Upload Malware
  • T1566.001 - Spearphishing Attachment
  • T1007 - System Service Discovery
  • T1573.002 - Asymmetric Cryptography
  • T1497.001 - System Checks
  • T1036 - Masquerading
  • T1069.001 - Local Groups
MITREへのリンク →

Volt Typhoon

Score: 0.69
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1518 - Software Discovery
  • T1190 - Exploit Public-Facing Application
  • T1587.004 - Exploits
  • T1584.005 - Botnet
  • T1596.005 - Scan Databases
  • T1588.002 - Tool
  • T1007 - System Service Discovery
  • T1680 - Local Storage Discovery
  • T1497.001 - System Checks
  • T1069.001 - Local Groups
MITREへのリンク →

Ember Bear

Score: 0.68
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1595.002 - Vulnerability Scanning
  • T1491.002 - External Defacement
  • T1562.001 - Disable or Modify Tools
  • T1550.002 - Pass the Hash
  • T1210 - Exploitation of Remote Services
  • T1036 - Masquerading
  • T1588.005 - Exploits
MITREへのリンク →

APT29

Score: 0.61
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1203 - Exploitation for Client Execution
  • T1583.006 - Web Services
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1566.003 - Spearphishing via Service
  • T1562.008 - Disable or Modify Cloud Logs
  • T1595.002 - Vulnerability Scanning
  • T1114.002 - Remote Email Collection
  • T1566.001 - Spearphishing Attachment
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN7

Score: 0.58
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1674 - Input Injection
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1559.002 - Dynamic Data Exchange
  • T1608.001 - Upload Malware
  • T1566.001 - Spearphishing Attachment
  • T1078.003 - Local Accounts
  • T1210 - Exploitation of Remote Services
MITREへのリンク →

APT41

Score: 0.58
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1595.003 - Wordlist Scanning
  • T1203 - Exploitation for Client Execution
  • T1213.003 - Code Repositories
  • T1190 - Exploit Public-Facing Application
  • T1596.005 - Scan Databases
  • T1588.002 - Tool
  • T1595.002 - Vulnerability Scanning
  • T1566.001 - Spearphishing Attachment
  • T1550.002 - Pass the Hash
MITREへのリンク →

Lazarus Group

Score: 0.57
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1203 - Exploitation for Client Execution
  • T1583.006 - Web Services
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1566.001 - Spearphishing Attachment
  • T1562.001 - Disable or Modify Tools
  • T1680 - Local Storage Discovery
MITREへのリンク →

TeamTNT

Score: 0.56
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1587.001 - Malware
  • T1610 - Deploy Container
  • T1595.002 - Vulnerability Scanning
  • T1608.001 - Upload Malware
  • T1007 - System Service Discovery
  • T1562.001 - Disable or Modify Tools
  • T1680 - Local Storage Discovery
  • T1036 - Masquerading
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る