Trusted Design

Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries

概要

Israel-based “Cyber Warfare” vendor NSO Group produces and sells a mobile phone spyware suite called Pegasus. To monitor a target, a government operator of Pegasus must convince the target to click on a specially crafted exploit link, which, when clicked, delivers a chain of zero-day exploits to penetrate security features on the phone and installs Pegasus without the user’s knowledge or permission. Once the phone is exploited and Pegasus is installed, it begins contacting the operator’s command and control (C&C) servers to receive and execute operators’ commands, and send back the target’s private data, including passwords, contact lists, calendar events, text messages, and live voice calls from popular mobile messaging apps. The operator can even turn on the phone’s camera and microphone to capture activity in the phone’s vicinity.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 36.36
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1003.007 - Proc Filesystem
  • T1583.005 - Botnet
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1131 - Authentication Package
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
  • T1565.002 - Transmitted Data Manipulation
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1665 - Hide Infrastructure
  • T1003.003 - NTDS
  • T1008 - Fallback Channels
MITREへのリンク →

Sea Turtle

Score: 5.69
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Ember Bear

Score: 18.15
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1584.003 - Virtual Private Server
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1209 - Time Providers
  • T1003.003 - NTDS
MITREへのリンク →

Indrik Spider

Score: 8.39
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1003.007 - Proc Filesystem
  • T1546.016 - Installer Packages
MITREへのリンク →

Agrius

Score: 7.72
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1209 - Time Providers
MITREへのリンク →

Contagious Interview

Score: 20.01
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1131 - Authentication Package
  • T1021.006 - Windows Remote Management
  • T1565.002 - Transmitted Data Manipulation
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sandworm Team

Score: 24.45
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1583.005 - Botnet
  • T1584.003 - Virtual Private Server
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1187 - Forced Authentication
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1546.016 - Installer Packages
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Star Blizzard

Score: 3.03
Matched TTPs:
  • T1033 - System Owner/User Discovery
MITREへのリンク →

APT28

Score: 30.02
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1583.005 - Botnet
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1131 - Authentication Package
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1055.008 - Ptrace System Calls
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 23.63
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1584.003 - Virtual Private Server
  • T1202 - Indirect Command Execution
  • T1140 - Deobfuscate/Decode Files or Information
  • T1683 - Generate Content
  • T1555.004 - Windows Credential Manager
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

LAPSUS$

Score: 16.42
Matched TTPs:
  • T1216.001 - PubPrn
  • T1584.003 - Virtual Private Server
  • T1019 - System Firmware
  • T1136.002 - Domain Account
  • T1588.005 - Exploits
MITREへのリンク →

APT41

Score: 14.84
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.007 - Dynamic API Resolution
  • T1008 - Fallback Channels
MITREへのリンク →

Scattered Spider

Score: 23.53
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1535 - Unused/Unsupported Cloud Regions
  • T1019 - System Firmware
  • T1136.002 - Domain Account
  • T1197 - BITS Jobs
  • T1565.002 - Transmitted Data Manipulation
  • T1588.005 - Exploits
MITREへのリンク →

TA505

Score: 8.29
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1136.002 - Domain Account
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Volt Typhoon

Score: 24.13
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1535 - Unused/Unsupported Cloud Regions
  • T1164 - Re-opened Applications
  • T1546.016 - Installer Packages
  • T1209 - Time Providers
  • T1665 - Hide Infrastructure
MITREへのリンク →

APT3

Score: 6.09
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1584.003 - Virtual Private Server
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN13

Score: 9.16
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
MITREへのリンク →

HAFNIUM

Score: 16.62
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059 - Command and Scripting Interpreter
  • T1556.005 - Reversible Encryption
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

APT5

Score: 5.31
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Ke3chang

Score: 12.87
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BRONZE BUTLER

Score: 8.44
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1556.005 - Reversible Encryption
  • T1008 - Fallback Channels
MITREへのリンク →

TeamTNT

Score: 21.84
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1036.009 - Break Process Trees
  • T1535 - Unused/Unsupported Cloud Regions
  • T1612 - Build Image on Host
  • T1142 - Keychain
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1665 - Hide Infrastructure
MITREへのリンク →

OilRig

Score: 21.94
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1005 - Data from Local System
  • T1592.002 - Software
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Turla

Score: 20.02
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1131 - Authentication Package
  • T1136.002 - Domain Account
  • T1612 - Build Image on Host
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1546.016 - Installer Packages
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Aquatic Panda

Score: 6.43
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1136.002 - Domain Account
MITREへのリンク →

Chimera

Score: 10.71
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.007 - Dynamic API Resolution
  • T1665 - Hide Infrastructure
MITREへのリンク →

Earth Lusca

Score: 10.64
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1546.016 - Installer Packages
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT1

Score: 6.43
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1136.002 - Domain Account
MITREへのリンク →

Velvet Ant

Score: 13.00
Matched TTPs:
  • T1583.005 - Botnet
  • T1036.009 - Break Process Trees
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Salt Typhoon

Score: 11.79
Matched TTPs:
  • T1583.005 - Botnet
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.002 - Upload Tool
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT33

Score: 12.46
Matched TTPs:
  • T1583.005 - Botnet
  • T1567.001 - Exfiltration to Code Repository
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

UNC3886

Score: 15.63
Matched TTPs:
  • T1583.005 - Botnet
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
  • T1585.002 - Email Accounts
  • T1136.002 - Domain Account
MITREへのリンク →

DarkVishnya

Score: 9.34
Matched TTPs:
  • T1583.005 - Botnet
  • T1213.003 - Code Repositories
  • T1209 - Time Providers
MITREへのリンク →

Magic Hound

Score: 23.06
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1683 - Generate Content
  • T1187 - Forced Authentication
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Rocke

Score: 17.11
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1140 - Deobfuscate/Decode Files or Information
  • T1535 - Unused/Unsupported Cloud Regions
  • T1612 - Build Image on Host
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1008 - Fallback Channels
MITREへのリンク →

INC Ransom

Score: 9.07
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1140 - Deobfuscate/Decode Files or Information
  • T1209 - Time Providers
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT39

Score: 15.87
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1599 - Network Boundary Bridging
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Axiom

Score: 7.45
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1160 - Launch Daemon
MITREへのリンク →

ToddyCat

Score: 8.27
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1665 - Hide Infrastructure
  • T1547.008 - LSASS Driver
MITREへのリンク →

Fox Kitten

Score: 11.05
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1612 - Build Image on Host
  • T1209 - Time Providers
  • T1588.005 - Exploits
MITREへのリンク →

Andariel

Score: 7.75
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1136.002 - Domain Account
  • T1187 - Forced Authentication
MITREへのリンク →

RedCurl

Score: 8.28
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1612 - Build Image on Host
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Lazarus Group

Score: 17.73
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1546.016 - Installer Packages
  • T1209 - Time Providers
  • T1665 - Hide Infrastructure
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Gamaredon Group

Score: 13.05
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1612 - Build Image on Host
  • T1554 - Compromise Host Software Binary
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN6

Score: 13.40
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1612 - Build Image on Host
  • T1209 - Time Providers
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

LuminousMoth

Score: 6.45
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1136.002 - Domain Account
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT37

Score: 5.03
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Dragonfly

Score: 5.75
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1546.016 - Installer Packages
MITREへのリンク →

CURIUM

Score: 3.97
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1547.008 - LSASS Driver
MITREへのリンク →

Inception

Score: 5.16
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1612 - Build Image on Host
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Patchwork

Score: 8.93
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1027.018 - Invisible Unicode
  • T1665 - Hide Infrastructure
  • T1008 - Fallback Channels
MITREへのリンク →

Threat Group-3390

Score: 5.87
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
MITREへのリンク →

FIN7

Score: 13.61
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1011.001 - Exfiltration Over Bluetooth
  • T1547.002 - Authentication Package
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT38

Score: 6.39
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

menuPass

Score: 4.68
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1140 - Deobfuscate/Decode Files or Information
  • T1209 - Time Providers
MITREへのリンク →

Wizard Spider

Score: 13.27
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1567.001 - Exfiltration to Code Repository
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
  • T1556 - Modify Authentication Process
MITREへのリンク →

Dark Caracal

Score: 5.16
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1556.005 - Reversible Encryption
  • T1547.008 - LSASS Driver
MITREへのリンク →

BackdoorDiplomacy

Score: 5.69
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1209 - Time Providers
MITREへのリンク →

BlackTech

Score: 4.60
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Medusa Group

Score: 6.82
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Storm-0501

Score: 7.84
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1535 - Unused/Unsupported Cloud Regions
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

BlackByte

Score: 6.82
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Blue Mockingbird

Score: 3.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Winter Vivern

Score: 4.02
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Leviathan

Score: 9.80
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1554 - Compromise Host Software Binary
  • T1546.016 - Installer Packages
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Play

Score: 5.60
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1142 - Keychain
MITREへのリンク →

MuddyWater

Score: 6.42
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.002 - Authentication Package
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
MITREへのリンク →

SilverTerrier

Score: 4.47
Matched TTPs:
  • T1131 - Authentication Package
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT32

Score: 15.27
Matched TTPs:
  • T1131 - Authentication Package
  • T1612 - Build Image on Host
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
  • T1027.007 - Dynamic API Resolution
  • T1556 - Modify Authentication Process
MITREへのリンク →

TA2541

Score: 3.82
Matched TTPs:
  • T1136.002 - Domain Account
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Metador

Score: 3.65
Matched TTPs:
  • T1136.002 - Domain Account
  • T1556.005 - Reversible Encryption
MITREへのリンク →

LazyScripter

Score: 6.34
Matched TTPs:
  • T1136.002 - Domain Account
  • T1612 - Build Image on Host
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN8

Score: 7.82
Matched TTPs:
  • T1612 - Build Image on Host
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

EXOTIC LILY

Score: 6.41
Matched TTPs:
  • T1612 - Build Image on Host
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT42

Score: 7.56
Matched TTPs:
  • T1612 - Build Image on Host
  • T1599 - Network Boundary Bridging
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Mustang Panda

Score: 12.51
Matched TTPs:
  • T1612 - Build Image on Host
  • T1565.002 - Transmitted Data Manipulation
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
  • T1556 - Modify Authentication Process
MITREへのリンク →

Tropic Trooper

Score: 9.41
Matched TTPs:
  • T1683 - Generate Content
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1665 - Hide Infrastructure
MITREへのリンク →

BITTER

Score: 4.81
Matched TTPs:
  • T1683 - Generate Content
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Storm-1811

Score: 13.83
Matched TTPs:
  • T1599 - Network Boundary Bridging
  • T1486 - Data Encrypted for Impact
  • T1565.002 - Transmitted Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

ZIRCONIUM

Score: 7.20
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Moonstone Sleet

Score: 9.55
Matched TTPs:
  • T1197 - BITS Jobs
  • T1556.005 - Reversible Encryption
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Evilnum

Score: 4.29
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Thrip

Score: 5.67
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

RTM

Score: 6.21
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1008 - Fallback Channels
MITREへのリンク →

Daggerfly

Score: 5.38
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1546.016 - Installer Packages
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Higaisa

Score: 4.02
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1665 - Hide Infrastructure
MITREへのリンク →

Confucius

Score: 5.38
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1665 - Hide Infrastructure
MITREへのリンク →

Windshift

Score: 5.07
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Cobalt Group

Score: 4.31
Matched TTPs:
  • T1556.005 - Reversible Encryption
  • T1209 - Time Providers
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.80
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1583.005 - Botnet
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
  • T1131 - Authentication Package
  • T1665 - Hide Infrastructure
  • T1033 - System Owner/User Discovery
  • T1003.003 - NTDS
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1008 - Fallback Channels
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

APT28

Score: 0.67
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1222.002 - Linux and Mac Permissions
  • T1583.005 - Botnet
  • T1547.002 - Authentication Package
  • T1197 - BITS Jobs
  • T1131 - Authentication Package
  • T1566.003 - Spearphishing via Service
  • T1055.008 - Ptrace System Calls
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Volt Typhoon

Score: 0.57
Matched TTPs:
  • T1209 - Time Providers
  • T1003.007 - Proc Filesystem
  • T1584.003 - Virtual Private Server
  • T1164 - Re-opened Applications
  • T1560.003 - Archive via Custom Method
  • T1665 - Hide Infrastructure
  • T1546.016 - Installer Packages
  • T1140 - Deobfuscate/Decode Files or Information
  • T1535 - Unused/Unsupported Cloud Regions
MITREへのリンク →

Sandworm Team

Score: 0.57
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1583.005 - Botnet
  • T1005 - Data from Local System
  • T1547.002 - Authentication Package
  • T1546.016 - Installer Packages
  • T1187 - Forced Authentication
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Scattered Spider

Score: 0.57
Matched TTPs:
  • T1136.002 - Domain Account
  • T1197 - BITS Jobs
  • T1588.005 - Exploits
  • T1560.003 - Archive via Custom Method
  • T1535 - Unused/Unsupported Cloud Regions
  • T1565.002 - Transmitted Data Manipulation
  • T1019 - System Firmware
MITREへのリンク →

Magic Hound

Score: 0.56
Matched TTPs:
  • T1209 - Time Providers
  • T1584.003 - Virtual Private Server
  • T1036.009 - Break Process Trees
  • T1547.002 - Authentication Package
  • T1187 - Forced Authentication
  • T1683 - Generate Content
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る