Trusted Design

Sandvine’s PacketLogic Devices Used to Deploy Government Spyware in Turkey

概要

A series of middleboxes on Türk Telekom’s network were being used to redirect hundreds of users attempting to download certain legitimate programs to versions of those programs bundled with spyware. The spyware we found bundled by operators was similar to that used in the StrongPity APT attacks. Before switching to the StrongPity spyware, the operators of the Turkey injection used the FinFisher “lawful intercept” spyware, which FinFisher asserts is sold only to government entities.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 20.42
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1588.005 - Exploits
MITREへのリンク →

Sea Turtle

Score: 6.85
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 16.43
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1588.005 - Exploits
MITREへのリンク →

Indrik Spider

Score: 5.13
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
MITREへのリンク →

Agrius

Score: 4.50
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Contagious Interview

Score: 18.35
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1204.005 - Malicious Library
  • T1480 - Execution Guardrails
  • T1583.006 - Web Services
  • T1588.002 - Tool
MITREへのリンク →

Sandworm Team

Score: 21.00
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Star Blizzard

Score: 5.86
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
MITREへのリンク →

FIN13

Score: 7.08
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Moonstone Sleet

Score: 4.07
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
MITREへのリンク →

Lazarus Group

Score: 18.29
Matched TTPs:
  • T1587.001 - Malware
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1001.003 - Protocol or Service Impersonation
  • T1564.001 - Hidden Files and Directories
  • T1055.001 - Dynamic-link Library Injection
MITREへのリンク →

OilRig

Score: 10.26
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

UNC3886

Score: 7.52
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

LuminousMoth

Score: 10.04
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Salt Typhoon

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

APT29

Score: 11.54
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1573 - Encrypted Channel
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Play

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Aoqin Dragon

Score: 4.44
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 4.76
Matched TTPs:
  • T1587.001 - Malware
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Turla

Score: 15.20
Matched TTPs:
  • T1587.001 - Malware
  • T1055 - Process Injection
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1055.001 - Dynamic-link Library Injection
MITREへのリンク →

Ke3chang

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Mustang Panda

Score: 17.68
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1001.003 - Protocol or Service Impersonation
  • T1518 - Software Discovery
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

TeamTNT

Score: 8.61
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1610 - Deploy Container
MITREへのリンク →

FIN7

Score: 22.13
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1674 - Input Injection
  • T1583.006 - Web Services
  • T1497.002 - User Activity Based Checks
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

TA2541

Score: 9.75
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1588.002 - Tool
MITREへのリンク →

Earth Lusca

Score: 8.76
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1583.006 - Web Services
  • T1588.002 - Tool
MITREへのリンク →

LazyScripter

Score: 6.44
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1583.006 - Web Services
MITREへのリンク →

Gamaredon Group

Score: 13.54
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1480 - Execution Guardrails
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Threat Group-3390

Score: 9.92
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

SideCopy

Score: 8.85
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1614 - System Location Discovery
  • T1518 - Software Discovery
MITREへのリンク →

TA505

Score: 8.21
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1055.001 - Dynamic-link Library Injection
MITREへのリンク →

BlackByte

Score: 9.75
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
  • T1480 - Execution Guardrails
MITREへのリンク →

BITTER

Score: 7.94
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1573 - Encrypted Channel
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT32

Score: 11.45
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

HEXANE

Score: 7.97
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1518 - Software Discovery
MITREへのリンク →

Saint Bear

Score: 5.48
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Rocke

Score: 4.14
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Volt Typhoon

Score: 9.20
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1614 - System Location Discovery
  • T1518 - Software Discovery
MITREへのリンク →

APT28

Score: 24.10
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1498 - Network Denial of Service
  • T1564.001 - Hidden Files and Directories
  • T1550.001 - Application Access Token
  • T1669 - Wi-Fi Networks
MITREへのリンク →

BackdoorDiplomacy

Score: 7.71
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1055.001 - Dynamic-link Library Injection
MITREへのリンク →

BlackTech

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Magic Hound

Score: 14.20
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1573 - Encrypted Channel
  • T1592.002 - Software
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Medusa Group

Score: 8.46
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1583.006 - Web Services
  • T1588.002 - Tool
MITREへのリンク →

Leviathan

Score: 5.89
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1055.001 - Dynamic-link Library Injection
MITREへのリンク →

Dragonfly

Score: 3.81
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Axiom

Score: 7.50
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1001.002 - Steganography
MITREへのリンク →

APT41

Score: 6.27
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

HAFNIUM

Score: 10.28
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1564.001 - Hidden Files and Directories
  • T1550.001 - Application Access Token
MITREへのリンク →

APT5

Score: 3.93
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
MITREへのリンク →

MuddyWater

Score: 10.97
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
MITREへのリンク →

APT39

Score: 4.72
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT38

Score: 3.31
Matched TTPs:
  • T1055 - Process Injection
  • T1588.002 - Tool
MITREへのリンク →

Silence

Score: 3.31
Matched TTPs:
  • T1055 - Process Injection
  • T1588.002 - Tool
MITREへのリンク →

Wizard Spider

Score: 6.24
Matched TTPs:
  • T1055 - Process Injection
  • T1588.002 - Tool
  • T1055.001 - Dynamic-link Library Injection
MITREへのリンク →

Cobalt Group

Score: 4.80
Matched TTPs:
  • T1055 - Process Injection
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT37

Score: 6.35
Matched TTPs:
  • T1055 - Process Injection
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Higaisa

Score: 9.88
Matched TTPs:
  • T1029 - Scheduled Transfer
  • T1203 - Exploitation for Client Execution
  • T1001.003 - Protocol or Service Impersonation
MITREへのリンク →

LAPSUS$

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Metador

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

APT1

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Aquatic Panda

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

Andariel

Score: 7.80
Matched TTPs:
  • T1588.001 - Malware
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Scattered Spider

Score: 3.31
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

ZIRCONIUM

Score: 4.41
Matched TTPs:
  • T1583.006 - Web Services
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Confucius

Score: 3.51
Matched TTPs:
  • T1583.006 - Web Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

POLONIUM

Score: 5.26
Matched TTPs:
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Darkhotel

Score: 5.63
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Inception

Score: 5.09
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
MITREへのリンク →

BRONZE BUTLER

Score: 5.09
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
MITREへのリンク →

Carbanak

Score: 3.25
Matched TTPs:
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

Tropic Trooper

Score: 13.46
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
  • T1564.001 - Hidden Files and Directories
  • T1055.001 - Dynamic-link Library Injection
MITREへのリンク →

APT12

Score: 3.89
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Sidewinder

Score: 4.24
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1518 - Software Discovery
MITREへのリンク →

Transparent Tribe

Score: 4.16
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.83
Matched TTPs:
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1203 - Exploitation for Client Execution
  • T1498 - Network Denial of Service
  • T1564.001 - Hidden Files and Directories
  • T1190 - Exploit Public-Facing Application
  • T1550.001 - Application Access Token
  • T1669 - Wi-Fi Networks
MITREへのリンク →

FIN7

Score: 0.80
Matched TTPs:
  • T1583.006 - Web Services
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1497.002 - User Activity Based Checks
  • T1102.002 - Bidirectional Communication
  • T1587.001 - Malware
  • T1564.001 - Hidden Files and Directories
  • T1674 - Input Injection
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Sandworm Team

Score: 0.76
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1587.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1592.002 - Software
  • T1190 - Exploit Public-Facing Application
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Kimsuky

Score: 0.68
Matched TTPs:
  • T1583.006 - Web Services
  • T1055 - Process Injection
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.005 - Exploits
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Mustang Panda

Score: 0.65
Matched TTPs:
  • T1583.006 - Web Services
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1587.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1564.001 - Hidden Files and Directories
  • T1518 - Software Discovery
  • T1001.003 - Protocol or Service Impersonation
MITREへのリンク →

Lazarus Group

Score: 0.62
Matched TTPs:
  • T1583.006 - Web Services
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1587.001 - Malware
  • T1055.001 - Dynamic-link Library Injection
  • T1203 - Exploitation for Client Execution
  • T1564.001 - Hidden Files and Directories
  • T1001.003 - Protocol or Service Impersonation
MITREへのリンク →

Contagious Interview

Score: 0.62
Matched TTPs:
  • T1583.006 - Web Services
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1587.001 - Malware
  • T1583 - Acquire Infrastructure
  • T1204.005 - Malicious Library
  • T1480 - Execution Guardrails
MITREへのリンク →

Turla

Score: 0.59
Matched TTPs:
  • T1583.006 - Web Services
  • T1055 - Process Injection
  • T1588.002 - Tool
  • T1102.002 - Bidirectional Communication
  • T1587.001 - Malware
  • T1055.001 - Dynamic-link Library Injection
  • T1588.001 - Malware
MITREへのリンク →

Ember Bear

Score: 0.56
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1190 - Exploit Public-Facing Application
  • T1588.005 - Exploits
  • T1583 - Acquire Infrastructure
  • T1588.001 - Malware
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る