Trusted Design

Invitation to Trouble: The Rise of Calendar Phishing Attacks

概要

A new phishing tactic involving fake Microsoft and Google Calendar invites has been identified, aimed at stealing login credentials. These sophisticated attacks mimic designs from well-known platforms, exploiting routine business activities like scheduling meetings. Threat actors use email spoofing and create fake urgent calendar invitations to deceive employees. The phishing emails often contain buttons or links that redirect to fake login pages, closely resembling official Microsoft or Google login screens. The campaigns exploit the popularity of calendar invitations in corporate environments, allowing attackers to gather sensitive information if users are not vigilant. To prevent falling victim to these attacks, it is crucial to verify the authenticity of calendar invites, carefully check sender details, and avoid clicking suspicious links from unknown senders.

Created: 2026-03-21

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

Ember Bear

Score: 11.96
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1584.008 - Network Devices
  • T1102 - Web Service
  • T1597 - Search Closed Sources
MITREへのリンク →

Sandworm Team

Score: 32.88
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1484.002 - Trust Modification
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1562.012 - Disable or Modify Linux Audit System
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1027 - Obfuscated Files or Information
  • T1075 - Pass the Hash
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Andariel

Score: 5.61
Matched TTPs:
  • T1171 - LLMNR/NBT-NS Poisoning and Relay
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Magic Hound

Score: 50.66
Matched TTPs:
  • T1171 - LLMNR/NBT-NS Poisoning and Relay
  • T1587.003 - Digital Certificates
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1036.009 - Break Process Trees
  • T1024 - Custom Cryptographic Protocol
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1683 - Generate Content
  • T1592.003 - Firmware
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
  • T1053.002 - At
MITREへのリンク →

HAFNIUM

Score: 17.37
Matched TTPs:
  • T1171 - LLMNR/NBT-NS Poisoning and Relay
  • T1027.008 - Stripped Payloads
  • T1134.002 - Create Process with Token
  • T1218.008 - Odbcconf
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
MITREへのリンク →

Volt Typhoon

Score: 28.85
Matched TTPs:
  • T1685.001 - Disable or Modify Windows Event Log
  • T1562 - Impair Defenses
  • T1070.006 - Timestomp
  • T1547.005 - Security Support Provider
  • T1562.012 - Disable or Modify Linux Audit System
  • T1134.002 - Create Process with Token
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1102 - Web Service
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

APT28

Score: 22.06
Matched TTPs:
  • T1685.001 - Disable or Modify Windows Event Log
  • T1566.002 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1592.003 - Firmware
  • T1197 - BITS Jobs
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

ZIRCONIUM

Score: 16.39
Matched TTPs:
  • T1685.001 - Disable or Modify Windows Event Log
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1562.012 - Disable or Modify Linux Audit System
  • T1608.005 - Link Target
  • T1197 - BITS Jobs
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Leviathan

Score: 24.34
Matched TTPs:
  • T1685.001 - Disable or Modify Windows Event Log
  • T1484.002 - Trust Modification
  • T1543.003 - Windows Service
  • T1024 - Custom Cryptographic Protocol
  • T1183 - Image File Execution Options Injection
  • T1055.014 - VDSO Hijacking
  • T1592.003 - Firmware
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Mustard Tempest

Score: 14.37
Matched TTPs:
  • T1682 - Query Public AI Services
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1053.002 - At
MITREへのリンク →

Daggerfly

Score: 5.72
Matched TTPs:
  • T1584.008 - Network Devices
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT29

Score: 26.39
Matched TTPs:
  • T1584.008 - Network Devices
  • T1543.003 - Windows Service
  • T1024 - Custom Cryptographic Protocol
  • T1177 - LSASS Driver
  • T1568 - Dynamic Resolution
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1683 - Generate Content
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN13

Score: 13.48
Matched TTPs:
  • T1584.008 - Network Devices
  • T1547.005 - Security Support Provider
  • T1219.001 - IDE Tunneling
  • T1552.003 - Shell History
  • T1134.001 - Token Impersonation/Theft
MITREへのリンク →

Dragonfly

Score: 11.74
Matched TTPs:
  • T1584.008 - Network Devices
  • T1566.002 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1657 - Financial Theft
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Ke3chang

Score: 7.74
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.008 - Stripped Payloads
  • T1219.001 - IDE Tunneling
MITREへのリンク →

Agrius

Score: 4.39
Matched TTPs:
  • T1584.008 - Network Devices
  • T1597 - Search Closed Sources
MITREへのリンク →

APT41

Score: 35.85
Matched TTPs:
  • T1584.008 - Network Devices
  • T1562 - Impair Defenses
  • T1562.012 - Disable or Modify Linux Audit System
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1027 - Obfuscated Files or Information
  • T1002 - Data Compressed
  • T1030 - Data Transfer Size Limits
  • T1564.003 - Hidden Window
  • T1574.002 - DLL Side-Loading
  • T1037.001 - Logon Script (Windows)
MITREへのリンク →

APT5

Score: 11.18
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.008 - Stripped Payloads
  • T1219.001 - IDE Tunneling
  • T1102 - Web Service
MITREへのリンク →

menuPass

Score: 7.04
Matched TTPs:
  • T1584.008 - Network Devices
  • T1219.001 - IDE Tunneling
  • T1001 - Data Obfuscation
MITREへのリンク →

Threat Group-3390

Score: 9.48
Matched TTPs:
  • T1584.008 - Network Devices
  • T1091 - Replication Through Removable Media
  • T1001 - Data Obfuscation
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Wizard Spider

Score: 17.64
Matched TTPs:
  • T1584.008 - Network Devices
  • T1543.003 - Windows Service
  • T1038 - DLL Search Order Hijacking
  • T1183 - Image File Execution Options Injection
  • T1597 - Search Closed Sources
  • T1556.009 - Conditional Access Policies
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Silent Librarian

Score: 14.26
Matched TTPs:
  • T1596.001 - DNS/Passive DNS
  • T1566.002 - Spearphishing Link
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1584.005 - Botnet
MITREへのリンク →

Lazarus Group

Score: 28.84
Matched TTPs:
  • T1596.001 - DNS/Passive DNS
  • T1543.003 - Windows Service
  • T1070.006 - Timestomp
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1606.001 - Web Cookies
  • T1597 - Search Closed Sources
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Sea Turtle

Score: 20.81
Matched TTPs:
  • T1596.001 - DNS/Passive DNS
  • T1499.003 - Application Exhaustion Flood
  • T1587.003 - Digital Certificates
  • T1497.001 - System Checks
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1059.013 - Container CLI/API
MITREへのリンク →

Mustang Panda

Score: 27.36
Matched TTPs:
  • T1596.001 - DNS/Passive DNS
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1091 - Replication Through Removable Media
  • T1183 - Image File Execution Options Injection
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1102 - Web Service
  • T1608.005 - Link Target
  • T1565.002 - Transmitted Data Manipulation
  • T1027.018 - Invisible Unicode
MITREへのリンク →

UNC3886

Score: 6.25
Matched TTPs:
  • T1596.001 - DNS/Passive DNS
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
MITREへのリンク →

LuminousMoth

Score: 13.08
Matched TTPs:
  • T1596.001 - DNS/Passive DNS
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1219.001 - IDE Tunneling
  • T1584.005 - Botnet
  • T1027.018 - Invisible Unicode
MITREへのリンク →

BlackTech

Score: 5.96
Matched TTPs:
  • T1596.001 - DNS/Passive DNS
  • T1543.003 - Windows Service
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Axiom

Score: 12.18
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1177 - LSASS Driver
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

HEXANE

Score: 28.41
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1024 - Custom Cryptographic Protocol
  • T1091 - Replication Through Removable Media
  • T1562 - Impair Defenses
  • T1070.006 - Timestomp
  • T1547.005 - Security Support Provider
  • T1562.012 - Disable or Modify Linux Audit System
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1055.014 - VDSO Hijacking
MITREへのリンク →

RedCurl

Score: 9.44
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1543.003 - Windows Service
  • T1562.012 - Disable or Modify Linux Audit System
  • T1219.001 - IDE Tunneling
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT1

Score: 10.30
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1543.003 - Windows Service
  • T1183 - Image File Execution Options Injection
  • T1053.002 - At
MITREへのリンク →

Chimera

Score: 12.56
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1219.001 - IDE Tunneling
  • T1574 - Hijack Execution Flow
  • T1592.003 - Firmware
MITREへのリンク →

Winter Vivern

Score: 11.33
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1219.001 - IDE Tunneling
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

MuddyWater

Score: 22.73
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562 - Impair Defenses
  • T1518.002 - Backup Software Discovery
  • T1562.012 - Disable or Modify Linux Audit System
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Confucius

Score: 8.46
Matched TTPs:
  • T1543.003 - Windows Service
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Kimsuky

Score: 49.49
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1091 - Replication Through Removable Media
  • T1562.012 - Disable or Modify Linux Audit System
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1055.014 - VDSO Hijacking
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1597 - Search Closed Sources
  • T1001 - Data Obfuscation
  • T1030 - Data Transfer Size Limits
  • T1197 - BITS Jobs
  • T1565.002 - Transmitted Data Manipulation
  • T1027.018 - Invisible Unicode
  • T1053.002 - At
MITREへのリンク →

Sidewinder

Score: 12.53
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Elderwood

Score: 4.57
Matched TTPs:
  • T1543.003 - Windows Service
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Machete

Score: 4.57
Matched TTPs:
  • T1543.003 - Windows Service
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN7

Score: 15.32
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1584.005 - Botnet
  • T1608.005 - Link Target
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Transparent Tribe

Score: 7.86
Matched TTPs:
  • T1543.003 - Windows Service
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1053.002 - At
MITREへのリンク →

Evilnum

Score: 8.40
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562 - Impair Defenses
  • T1565.002 - Transmitted Data Manipulation
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN8

Score: 5.15
Matched TTPs:
  • T1543.003 - Windows Service
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT32

Score: 20.11
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1134.002 - Create Process with Token
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT3

Score: 9.44
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562.012 - Disable or Modify Linux Audit System
  • T1177 - LSASS Driver
  • T1219.001 - IDE Tunneling
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT33

Score: 7.53
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562 - Impair Defenses
  • T1562.012 - Disable or Modify Linux Audit System
  • T1027.018 - Invisible Unicode
MITREへのリンク →

EXOTIC LILY

Score: 12.11
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Molerats

Score: 4.86
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562.012 - Disable or Modify Linux Audit System
  • T1027.018 - Invisible Unicode
MITREへのリンク →

OilRig

Score: 26.98
Matched TTPs:
  • T1543.003 - Windows Service
  • T1574.014 - AppDomainManager
  • T1024 - Custom Cryptographic Protocol
  • T1091 - Replication Through Removable Media
  • T1562 - Impair Defenses
  • T1562.012 - Disable or Modify Linux Audit System
  • T1592.002 - Software
  • T1556.009 - Conditional Access Policies
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Windshift

Score: 7.10
Matched TTPs:
  • T1543.003 - Windows Service
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Cobalt Group

Score: 6.94
Matched TTPs:
  • T1543.003 - Windows Service
  • T1518.002 - Backup Software Discovery
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TA2541

Score: 14.08
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1001 - Data Obfuscation
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Earth Lusca

Score: 16.86
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1045 - Software Packing
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Storm-1811

Score: 21.35
Matched TTPs:
  • T1543.003 - Windows Service
  • T1027 - Obfuscated Files or Information
  • T1486 - Data Encrypted for Impact
  • T1567.003 - Exfiltration to Text Storage Sites
  • T1030 - Data Transfer Size Limits
  • T1565.002 - Transmitted Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Turla

Score: 19.26
Matched TTPs:
  • T1543.003 - Windows Service
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1218.001 - Compiled HTML File
  • T1556.009 - Conditional Access Policies
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TA577

Score: 5.47
Matched TTPs:
  • T1543.003 - Windows Service
  • T1024 - Custom Cryptographic Protocol
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Patchwork

Score: 13.53
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1562.012 - Disable or Modify Linux Audit System
  • T1219.001 - IDE Tunneling
  • T1001 - Data Obfuscation
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TA505

Score: 10.97
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1562.012 - Disable or Modify Linux Audit System
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1027.018 - Invisible Unicode
MITREへのリンク →

LazyScripter

Score: 9.13
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT42

Score: 14.93
Matched TTPs:
  • T1543.003 - Windows Service
  • T1091 - Replication Through Removable Media
  • T1583.001 - Domains
  • T1562.012 - Disable or Modify Linux Audit System
  • T1183 - Image File Execution Options Injection
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

APT39

Score: 6.77
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562 - Impair Defenses
  • T1219.001 - IDE Tunneling
  • T1027.018 - Invisible Unicode
MITREへのリンク →

TeamTNT

Score: 12.13
Matched TTPs:
  • T1497.001 - System Checks
  • T1036.009 - Break Process Trees
  • T1091 - Replication Through Removable Media
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
MITREへのリンク →

Salt Typhoon

Score: 12.00
Matched TTPs:
  • T1497.001 - System Checks
  • T1608.002 - Upload Tool
  • T1498 - Network Denial of Service
MITREへのリンク →

Rocke

Score: 12.48
Matched TTPs:
  • T1497.001 - System Checks
  • T1036.009 - Break Process Trees
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
MITREへのリンク →

Scattered Spider

Score: 49.71
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1583.001 - Domains
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1552.003 - Shell History
  • T1619 - Cloud Storage Object Discovery
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1030 - Data Transfer Size Limits
  • T1197 - BITS Jobs
  • T1564.003 - Hidden Window
  • T1565.002 - Transmitted Data Manipulation
  • T1498 - Network Denial of Service
  • T1027.002 - Software Packing
MITREへのリンク →

Star Blizzard

Score: 15.93
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1657 - Financial Theft
MITREへのリンク →

Moonstone Sleet

Score: 17.54
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1183 - Image File Execution Options Injection
  • T1134.002 - Create Process with Token
  • T1027 - Obfuscated Files or Information
  • T1197 - BITS Jobs
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 12.66
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1183 - Image File Execution Options Injection
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

INC Ransom

Score: 13.39
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1552.003 - Shell History
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Velvet Ant

Score: 6.54
Matched TTPs:
  • T1036.009 - Break Process Trees
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
MITREへのリンク →

Strider

Score: 8.26
Matched TTPs:
  • T1574.014 - AppDomainManager
  • T1130 - Install Root Certificate
MITREへのリンク →

LAPSUS$

Score: 34.94
Matched TTPs:
  • T1024 - Custom Cryptographic Protocol
  • T1547.005 - Security Support Provider
  • T1562.012 - Disable or Modify Linux Audit System
  • T1134.002 - Create Process with Token
  • T1019 - System Firmware
  • T1218.008 - Odbcconf
  • T1045 - Software Packing
  • T1619 - Cloud Storage Object Discovery
  • T1592.003 - Firmware
  • T1030 - Data Transfer Size Limits
  • T1564.003 - Hidden Window
MITREへのリンク →

IndigoZebra

Score: 4.68
Matched TTPs:
  • T1024 - Custom Cryptographic Protocol
  • T1608.005 - Link Target
MITREへのリンク →

Gamaredon Group

Score: 24.21
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1606.001 - Web Cookies
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
  • T1027.018 - Invisible Unicode
MITREへのリンク →

SideCopy

Score: 11.22
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
  • T1053.002 - At
MITREへのリンク →

BlackByte

Score: 17.24
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1606.001 - Web Cookies
  • T1134.001 - Token Impersonation/Theft
  • T1597 - Search Closed Sources
  • T1001 - Data Obfuscation
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

BITTER

Score: 5.59
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1683 - Generate Content
MITREへのリンク →

Saint Bear

Score: 12.70
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1134.002 - Create Process with Token
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1030 - Data Transfer Size Limits
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Contagious Interview

Score: 35.39
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1218.008 - Odbcconf
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1030 - Data Transfer Size Limits
  • T1565.002 - Transmitted Data Manipulation
  • T1221 - Template Injection
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Akira

Score: 11.20
Matched TTPs:
  • T1137.005 - Outlook Rules
  • T1552.003 - Shell History
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Leafminer

Score: 12.32
Matched TTPs:
  • T1562 - Impair Defenses
  • T1562.012 - Disable or Modify Linux Audit System
  • T1101 - Security Support Provider
  • T1219.001 - IDE Tunneling
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Stealth Falcon

Score: 8.34
Matched TTPs:
  • T1562 - Impair Defenses
  • T1562.012 - Disable or Modify Linux Audit System
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

FIN6

Score: 12.88
Matched TTPs:
  • T1562 - Impair Defenses
  • T1562.012 - Disable or Modify Linux Audit System
  • T1597 - Search Closed Sources
  • T1505 - Server Software Component
  • T1547.008 - LSASS Driver
MITREへのリンク →

Malteiro

Score: 7.24
Matched TTPs:
  • T1562 - Impair Defenses
  • T1562.012 - Disable or Modify Linux Audit System
  • T1552.003 - Shell History
MITREへのリンク →

APT37

Score: 3.82
Matched TTPs:
  • T1562.012 - Disable or Modify Linux Audit System
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Ajax Security Team

Score: 4.58
Matched TTPs:
  • T1562.012 - Disable or Modify Linux Audit System
  • T1547.008 - LSASS Driver
MITREへのリンク →

Inception

Score: 5.69
Matched TTPs:
  • T1562.012 - Disable or Modify Linux Audit System
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
MITREへのリンク →

Medusa Group

Score: 12.26
Matched TTPs:
  • T1183 - Image File Execution Options Injection
  • T1219.001 - IDE Tunneling
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Indrik Spider

Score: 10.27
Matched TTPs:
  • T1183 - Image File Execution Options Injection
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1498 - Network Denial of Service
MITREへのリンク →

TA551

Score: 4.86
Matched TTPs:
  • T1134.002 - Create Process with Token
  • T1218.012 - Verclsid
MITREへのリンク →

Deep Panda

Score: 3.29
Matched TTPs:
  • T1177 - LSASS Driver
MITREへのリンク →

Fox Kitten

Score: 6.93
Matched TTPs:
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
MITREへのリンク →

Blue Mockingbird

Score: 6.19
Matched TTPs:
  • T1045 - Software Packing
  • T1505 - Server Software Component
MITREへのリンク →

Cinnamon Tempest

Score: 4.86
Matched TTPs:
  • T1045 - Software Packing
  • T1552.003 - Shell History
MITREへのリンク →

Windigo

Score: 5.41
Matched TTPs:
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

POLONIUM

Score: 4.35
Matched TTPs:
  • T1045 - Software Packing
  • T1608.005 - Link Target
MITREへのリンク →

Equation

Score: 12.80
Matched TTPs:
  • T1589.003 - Employee Names
  • T1130 - Install Root Certificate
  • T1037.001 - Logon Script (Windows)
MITREへのリンク →

APT38

Score: 15.44
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1493 - Transmitted Data Manipulation
  • T1059.012 - Hypervisor CLI
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Tropic Trooper

Score: 4.92
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1683 - Generate Content
MITREへのリンク →

Dark Caracal

Score: 5.59
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Lotus Blossom

Score: 5.14
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1505 - Server Software Component
MITREへのリンク →

ToddyCat

Score: 3.82
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1547.008 - LSASS Driver
MITREへのリンク →

Darkhotel

Score: 3.06
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Play

Score: 5.62
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1552.003 - Shell History
  • T1597 - Search Closed Sources
MITREへのリンク →

BRONZE BUTLER

Score: 4.86
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Storm-0501

Score: 7.79
Matched TTPs:
  • T1552.003 - Shell History
  • T1027 - Obfuscated Files or Information
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1552.003 - Shell History
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Water Galura

Score: 4.86
Matched TTPs:
  • T1552.003 - Shell History
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Aquatic Panda

Score: 5.24
Matched TTPs:
  • T1102 - Web Service
  • T1597 - Search Closed Sources
MITREへのリンク →

TA578

Score: 3.37
Matched TTPs:
  • T1608.005 - Link Target
  • T1027.018 - Invisible Unicode
MITREへのリンク →

GOLD SOUTHFIELD

Score: 3.29
Matched TTPs:
  • T1562.013 - Disable or Modify Network Device Firewall
MITREへのリンク →

Gorgon Group

Score: 4.95
Matched TTPs:
  • T1597 - Search Closed Sources
  • T1001 - Data Obfuscation
MITREへのリンク →

Volatile Cedar

Score: 4.13
Matched TTPs:
  • T1002 - Data Compressed
MITREへのリンク →

RTM

Score: 4.69
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Magic Hound

Score: 0.70
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1053.002 - At
  • T1547.005 - Security Support Provider
  • T1045 - Software Packing
  • T1059.012 - Hypervisor CLI
  • T1608.005 - Link Target
  • T1027 - Obfuscated Files or Information
  • T1587.003 - Digital Certificates
  • T1547.008 - LSASS Driver
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
  • T1027.018 - Invisible Unicode
  • T1036.009 - Break Process Trees
  • T1171 - LLMNR/NBT-NS Poisoning and Relay
  • T1683 - Generate Content
  • T1543.003 - Windows Service
  • T1183 - Image File Execution Options Injection
  • T1592.003 - Firmware
  • T1024 - Custom Cryptographic Protocol
  • T1134.002 - Create Process with Token
MITREへのリンク →

Scattered Spider

Score: 0.69
Matched TTPs:
  • T1197 - BITS Jobs
  • T1547.005 - Security Support Provider
  • T1619 - Cloud Storage Object Discovery
  • T1027 - Obfuscated Files or Information
  • T1564.003 - Hidden Window
  • T1552.003 - Shell History
  • T1219.001 - IDE Tunneling
  • T1583.001 - Domains
  • T1566.002 - Spearphishing Link
  • T1019 - System Firmware
  • T1030 - Data Transfer Size Limits
  • T1045 - Software Packing
  • T1498 - Network Denial of Service
  • T1597 - Search Closed Sources
  • T1027.002 - Software Packing
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

Kimsuky

Score: 0.68
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1566.002 - Spearphishing Link
  • T1030 - Data Transfer Size Limits
  • T1053.002 - At
  • T1001 - Data Obfuscation
  • T1608.005 - Link Target
  • T1562.013 - Disable or Modify Network Device Firewall
  • T1552.003 - Shell History
  • T1219.001 - IDE Tunneling
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1027.018 - Invisible Unicode
  • T1218.012 - Verclsid
  • T1565.002 - Transmitted Data Manipulation
  • T1197 - BITS Jobs
  • T1562.012 - Disable or Modify Linux Audit System
  • T1543.003 - Windows Service
  • T1183 - Image File Execution Options Injection
  • T1024 - Custom Cryptographic Protocol
  • T1134.002 - Create Process with Token
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る