Trusted Design

Henry IV, Hotspur, Hal, and hallucinations

概要

This article draws parallels between Shakespeare's Henry IV and modern cybersecurity challenges, particularly focusing on the adoption of AI. It emphasizes the importance of taking calculated risks, learning from failures, and surrounding oneself with knowledgeable peers. The piece also highlights a new campaign by UAT-10027 using the 'Dohdoor' backdoor, which leverages DNS-over-HTTPS for stealthy communications and targets education and healthcare sectors in the US. The author encourages security teams to stay vigilant, update detection tools, and monitor for unusual activities to combat sophisticated threats.

Created: 2026-02-27

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

APT28

Score: 25.39
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1071.004 - DNS
  • T1566.002 - Spearphishing Link
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT29

Score: 33.99
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1584.008 - Network Devices
  • T1177 - LSASS Driver
  • T1592.004 - Client Configurations
  • T1218.012 - Verclsid
  • T1218.005 - Mshta
  • T1608.005 - Link Target
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1223 - Compiled HTML File
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

LAPSUS$

Score: 39.05
Matched TTPs:
  • T1216.001 - PubPrn
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1045 - Software Packing
  • T1175 - Component Object Model and Distributed COM
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1137.004 - Outlook Home Page
  • T1065 - Uncommonly Used Port
  • T1564.003 - Hidden Window
  • T1132.002 - Non-Standard Encoding
  • T1588.005 - Exploits
MITREへのリンク →

Contagious Interview

Score: 31.22
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1021.006 - Windows Remote Management
  • T1045 - Software Packing
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Daggerfly

Score: 3.95
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.018 - Invisible Unicode
MITREへのリンク →

GALLIUM

Score: 4.97
Matched TTPs:
  • T1584.008 - Network Devices
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
MITREへのリンク →

FIN13

Score: 10.30
Matched TTPs:
  • T1584.008 - Network Devices
  • T1547.005 - Security Support Provider
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1591.004 - Identify Roles
MITREへのリンク →

Dragonfly

Score: 20.84
Matched TTPs:
  • T1584.008 - Network Devices
  • T1566.002 - Spearphishing Link
  • T1009 - Binary Padding
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
MITREへのリンク →

Ke3chang

Score: 10.12
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.008 - Stripped Payloads
  • T1219.001 - IDE Tunneling
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
MITREへのリンク →

Agrius

Score: 5.34
Matched TTPs:
  • T1584.008 - Network Devices
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

APT41

Score: 40.78
Matched TTPs:
  • T1584.008 - Network Devices
  • T1071.004 - DNS
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1041 - Exfiltration Over C2 Channel
  • T1686.002 - Network Device Firewall
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1002 - Data Compressed
  • T1564.003 - Hidden Window
  • T1591.004 - Identify Roles
  • T1574.002 - DLL Side-Loading
  • T1037.001 - Logon Script (Windows)
MITREへのリンク →

APT5

Score: 8.69
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.008 - Stripped Payloads
  • T1219.001 - IDE Tunneling
  • T1591.004 - Identify Roles
MITREへのリンク →

menuPass

Score: 6.27
Matched TTPs:
  • T1584.008 - Network Devices
  • T1219.001 - IDE Tunneling
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
MITREへのリンク →

Threat Group-3390

Score: 9.04
Matched TTPs:
  • T1584.008 - Network Devices
  • T1091 - Replication Through Removable Media
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
MITREへのリンク →

Wizard Spider

Score: 12.67
Matched TTPs:
  • T1584.008 - Network Devices
  • T1038 - DLL Search Order Hijacking
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Ember Bear

Score: 9.44
Matched TTPs:
  • T1584.008 - Network Devices
  • T1175 - Component Object Model and Distributed COM
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
MITREへのリンク →

Sea Turtle

Score: 14.76
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1175 - Component Object Model and Distributed COM
  • T1686.002 - Network Device Firewall
  • T1157 - Dylib Hijacking
  • T1137.004 - Outlook Home Page
MITREへのリンク →

Axiom

Score: 14.70
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1177 - LSASS Driver
  • T1175 - Component Object Model and Distributed COM
  • T1049 - System Network Connections Discovery
  • T1157 - Dylib Hijacking
MITREへのリンク →

HEXANE

Score: 18.74
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1055.014 - VDSO Hijacking
  • T1065 - Uncommonly Used Port
  • T1159 - Launch Agent
MITREへのリンク →

Lazarus Group

Score: 21.82
Matched TTPs:
  • T1071.004 - DNS
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

Medusa Group

Score: 16.71
Matched TTPs:
  • T1036.008 - Masquerade File Type
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

Scattered Spider

Score: 41.84
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1566.002 - Spearphishing Link
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1218.005 - Mshta
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1564.003 - Hidden Window
  • T1588.005 - Exploits
MITREへのリンク →

Storm-0501

Score: 13.06
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1218.005 - Mshta
  • T1027 - Obfuscated Files or Information
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Sidewinder

Score: 13.83
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
  • T1159 - Launch Agent
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Mustang Panda

Score: 15.14
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1591.004 - Identify Roles
  • T1159 - Launch Agent
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Sandworm Team

Score: 25.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1049 - System Network Connections Discovery
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1187 - Forced Authentication
  • T1075 - Pass the Hash
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Silent Librarian

Score: 7.73
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1584.005 - Botnet
  • T1157 - Dylib Hijacking
MITREへのリンク →

ZIRCONIUM

Score: 8.88
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.005 - Link Target
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT32

Score: 24.01
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1592.004 - Client Configurations
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1039 - Data from Network Shared Drive
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Kimsuky

Score: 35.96
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
  • T1132.002 - Non-Standard Encoding
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Magic Hound

Score: 26.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1547.005 - Security Support Provider
  • T1009 - Binary Padding
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1187 - Forced Authentication
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Star Blizzard

Score: 12.41
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1657 - Financial Theft
  • T1157 - Dylib Hijacking
MITREへのリンク →

Moonstone Sleet

Score: 15.10
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1175 - Component Object Model and Distributed COM
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 11.13
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1175 - Component Object Model and Distributed COM
  • T1218.001 - Compiled HTML File
  • T1547.008 - LSASS Driver
MITREへのリンク →

Patchwork

Score: 6.07
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

HAFNIUM

Score: 16.35
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1049 - System Network Connections Discovery
  • T1608.005 - Link Target
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
MITREへのリンク →

TA2541

Score: 9.48
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Earth Lusca

Score: 13.65
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1045 - Software Packing
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1218.001 - Compiled HTML File
  • T1027.018 - Invisible Unicode
MITREへのリンク →

LuminousMoth

Score: 8.48
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1219.001 - IDE Tunneling
  • T1584.005 - Botnet
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Mustard Tempest

Score: 3.33
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1027.018 - Invisible Unicode
MITREへのリンク →

OilRig

Score: 15.19
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1051 - Shared Webroot
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

TeamTNT

Score: 13.72
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

LazyScripter

Score: 8.64
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Gamaredon Group

Score: 20.22
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1045 - Software Packing
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

SideCopy

Score: 10.68
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
  • T1159 - Launch Agent
MITREへのリンク →

TA505

Score: 10.95
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

BlackByte

Score: 15.45
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1175 - Component Object Model and Distributed COM
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

BITTER

Score: 4.07
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Saint Bear

Score: 8.10
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

FIN7

Score: 25.50
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1218.012 - Verclsid
  • T1584.005 - Botnet
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1065 - Uncommonly Used Port
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

EXOTIC LILY

Score: 5.86
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT42

Score: 8.12
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1175 - Component Object Model and Distributed COM
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

Akira

Score: 10.10
Matched TTPs:
  • T1137.005 - Outlook Rules
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

MuddyWater

Score: 19.17
Matched TTPs:
  • T1518.002 - Backup Software Discovery
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1159 - Launch Agent
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Cobalt Group

Score: 11.29
Matched TTPs:
  • T1518.002 - Backup Software Discovery
  • T1039 - Data from Network Shared Drive
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Salt Typhoon

Score: 6.88
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1009 - Binary Padding
MITREへのリンク →

Volt Typhoon

Score: 35.13
Matched TTPs:
  • T1547.005 - Security Support Provider
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1049 - System Network Connections Discovery
  • T1057 - Process Discovery
  • T1686.002 - Network Device Firewall
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1488 - Disk Content Wipe
  • T1065 - Uncommonly Used Port
  • T1591.004 - Identify Roles
  • T1159 - Launch Agent
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

Carbanak

Score: 3.77
Matched TTPs:
  • T1009 - Binary Padding
  • T1157 - Dylib Hijacking
MITREへのリンク →

Rocke

Score: 6.97
Matched TTPs:
  • T1009 - Binary Padding
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
MITREへのリンク →

ToddyCat

Score: 7.12
Matched TTPs:
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

UNC3886

Score: 20.72
Matched TTPs:
  • T1009 - Binary Padding
  • T1021.006 - Windows Remote Management
  • T1219.001 - IDE Tunneling
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1488 - Disk Content Wipe
  • T1591.004 - Identify Roles
MITREへのリンク →

APT38

Score: 16.97
Matched TTPs:
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1493 - Transmitted Data Manipulation
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Velvet Ant

Score: 8.27
Matched TTPs:
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
MITREへのリンク →

APT3

Score: 9.42
Matched TTPs:
  • T1177 - LSASS Driver
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Deep Panda

Score: 6.03
Matched TTPs:
  • T1177 - LSASS Driver
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Fox Kitten

Score: 15.67
Matched TTPs:
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
  • T1588.005 - Exploits
MITREへのリンク →

Turla

Score: 15.48
Matched TTPs:
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1218.001 - Compiled HTML File
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Blue Mockingbird

Score: 6.04
Matched TTPs:
  • T1045 - Software Packing
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
MITREへのリンク →

Cinnamon Tempest

Score: 4.72
Matched TTPs:
  • T1045 - Software Packing
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
MITREへのリンク →

MoustachedBouncer

Score: 4.44
Matched TTPs:
  • T1045 - Software Packing
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Windigo

Score: 6.39
Matched TTPs:
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1159 - Launch Agent
MITREへのリンク →

POLONIUM

Score: 5.78
Matched TTPs:
  • T1045 - Software Packing
  • T1608.005 - Link Target
  • T1157 - Dylib Hijacking
MITREへのリンク →

Winter Vivern

Score: 9.76
Matched TTPs:
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1218.001 - Compiled HTML File
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

BRONZE BUTLER

Score: 10.64
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1159 - Launch Agent
MITREへのリンク →

Inception

Score: 9.13
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1027.014 - Polymorphic Code
  • T1159 - Launch Agent
MITREへのリンク →

RedCurl

Score: 6.14
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Chimera

Score: 11.84
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1157 - Dylib Hijacking
  • T1574 - Hijack Execution Flow
  • T1591.004 - Identify Roles
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

Tropic Trooper

Score: 5.00
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1591.004 - Identify Roles
  • T1159 - Launch Agent
MITREへのリンク →

Dark Caracal

Score: 4.78
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT39

Score: 4.08
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1157 - Dylib Hijacking
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Play

Score: 5.48
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
MITREへのリンク →

Confucius

Score: 7.01
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT18

Score: 3.68
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1157 - Dylib Hijacking
  • T1591.004 - Identify Roles
MITREへのリンク →

Leafminer

Score: 3.82
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1051 - Shared Webroot
MITREへのリンク →

APT33

Score: 7.40
Matched TTPs:
  • T1051 - Shared Webroot
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Indrik Spider

Score: 9.04
Matched TTPs:
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

TA551

Score: 6.04
Matched TTPs:
  • T1218.012 - Verclsid
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
MITREへのリンク →

TA578

Score: 3.37
Matched TTPs:
  • T1608.005 - Link Target
  • T1027.018 - Invisible Unicode
MITREへのリンク →

SilverTerrier

Score: 3.62
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Leviathan

Score: 13.00
Matched TTPs:
  • T1055.014 - VDSO Hijacking
  • T1157 - Dylib Hijacking
  • T1027.014 - Polymorphic Code
  • T1488 - Disk Content Wipe
  • T1027.018 - Invisible Unicode
MITREへのリンク →

Aquatic Panda

Score: 5.58
Matched TTPs:
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

INC Ransom

Score: 6.52
Matched TTPs:
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

FIN6

Score: 8.79
Matched TTPs:
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN8

Score: 8.18
Matched TTPs:
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1027.018 - Invisible Unicode
MITREへのリンク →

APT37

Score: 5.09
Matched TTPs:
  • T1078 - Valid Accounts
  • T1591.004 - Identify Roles
MITREへのリンク →

Windshift

Score: 10.76
Matched TTPs:
  • T1078 - Valid Accounts
  • T1159 - Launch Agent
  • T1027.018 - Invisible Unicode
  • T1547.008 - LSASS Driver
MITREへのリンク →

Storm-1811

Score: 10.36
Matched TTPs:
  • T1027 - Obfuscated Files or Information
  • T1567.003 - Exfiltration to Text Storage Sites
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

Andariel

Score: 3.84
Matched TTPs:
  • T1187 - Forced Authentication
MITREへのリンク →

Volatile Cedar

Score: 4.13
Matched TTPs:
  • T1002 - Data Compressed
MITREへのリンク →

Equation

Score: 8.26
Matched TTPs:
  • T1130 - Install Root Certificate
  • T1037.001 - Logon Script (Windows)
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Scattered Spider

Score: 0.70
Matched TTPs:
  • T1157 - Dylib Hijacking
  • T1219.001 - IDE Tunneling
  • T1027 - Obfuscated Files or Information
  • T1051 - Shared Webroot
  • T1547.005 - Security Support Provider
  • T1588.005 - Exploits
  • T1566.002 - Spearphishing Link
  • T1045 - Software Packing
  • T1564.003 - Hidden Window
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1686.002 - Network Device Firewall
  • T1597 - Search Closed Sources
  • T1039 - Data from Network Shared Drive
  • T1218.005 - Mshta
  • T1019 - System Firmware
MITREへのリンク →

APT41

Score: 0.68
Matched TTPs:
  • T1037.001 - Logon Script (Windows)
  • T1071.004 - DNS
  • T1219.001 - IDE Tunneling
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1574.002 - DLL Side-Loading
  • T1584.008 - Network Devices
  • T1045 - Software Packing
  • T1041 - Exfiltration Over C2 Channel
  • T1564.003 - Hidden Window
  • T1177 - LSASS Driver
  • T1591.004 - Identify Roles
  • T1686.002 - Network Device Firewall
  • T1002 - Data Compressed
MITREへのリンク →

LAPSUS$

Score: 0.65
Matched TTPs:
  • T1137.004 - Outlook Home Page
  • T1175 - Component Object Model and Distributed COM
  • T1157 - Dylib Hijacking
  • T1588.005 - Exploits
  • T1547.005 - Security Support Provider
  • T1216.001 - PubPrn
  • T1065 - Uncommonly Used Port
  • T1045 - Software Packing
  • T1564.003 - Hidden Window
  • T1132.002 - Non-Standard Encoding
  • T1039 - Data from Network Shared Drive
  • T1019 - System Firmware
MITREへのリンク →

Kimsuky

Score: 0.60
Matched TTPs:
  • T1027.018 - Invisible Unicode
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1051 - Shared Webroot
  • T1057 - Process Discovery
  • T1566.002 - Spearphishing Link
  • T1055.014 - VDSO Hijacking
  • T1027.014 - Polymorphic Code
  • T1041 - Exfiltration Over C2 Channel
  • T1591.004 - Identify Roles
  • T1132.002 - Non-Standard Encoding
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
MITREへのリンク →

Volt Typhoon

Score: 0.59
Matched TTPs:
  • T1488 - Disk Content Wipe
  • T1049 - System Network Connections Discovery
  • T1157 - Dylib Hijacking
  • T1219.001 - IDE Tunneling
  • T1574.002 - DLL Side-Loading
  • T1547.005 - Security Support Provider
  • T1057 - Process Discovery
  • T1159 - Launch Agent
  • T1065 - Uncommonly Used Port
  • T1045 - Software Packing
  • T1591.004 - Identify Roles
  • T1686.002 - Network Device Firewall
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

APT29

Score: 0.57
Matched TTPs:
  • T1027.018 - Invisible Unicode
  • T1222.002 - Linux and Mac Permissions
  • T1218.012 - Verclsid
  • T1157 - Dylib Hijacking
  • T1592.004 - Client Configurations
  • T1584.008 - Network Devices
  • T1177 - LSASS Driver
  • T1608.005 - Link Target
  • T1039 - Data from Network Shared Drive
  • T1218.005 - Mshta
  • T1223 - Compiled HTML File
  • T1547.008 - LSASS Driver
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る