Trusted Design

Silver Dragon Targets Organizations in Southeast Asia and Europe

概要

Check Point Research has identified a Chinese-nexus advanced persistent threat group named Silver Dragon, targeting organizations in Southeast Asia and Europe since mid-2024. The group, likely operating under APT41, exploits public-facing servers and uses phishing emails for initial access. They deploy custom tools including GearDoor, a backdoor using Google Drive for command and control, SSHcmd for remote access, and SilverScreen for covert screen monitoring. Silver Dragon primarily focuses on government entities, utilizing Cobalt Strike beacons and DNS tunneling for communication. The group's sophisticated tactics and evolving toolkit demonstrate a well-resourced and adaptable threat actor.

Created: 2026-03-04

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

Mustang Panda

Score: 18.06
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
MITREへのリンク →

Kimsuky

Score: 40.63
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1566.002 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1557.003 - DHCP Spoofing
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1055.014 - VDSO Hijacking
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

Sea Turtle

Score: 20.49
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1499.003 - Application Exhaustion Flood
  • T1587.003 - Digital Certificates
  • T1497.001 - System Checks
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1059.013 - Container CLI/API
MITREへのリンク →

Contagious Interview

Score: 27.68
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1021.006 - Windows Remote Management
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1547.008 - LSASS Driver
MITREへのリンク →

GALLIUM

Score: 8.15
Matched TTPs:
  • T1584.008 - Network Devices
  • T1557.003 - DHCP Spoofing
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

APT29

Score: 24.00
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.016 - Junk Code Insertion
  • T1177 - LSASS Driver
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1608.006 - SEO Poisoning
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN13

Score: 9.76
Matched TTPs:
  • T1584.008 - Network Devices
  • T1547.005 - Security Support Provider
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
MITREへのリンク →

Dragonfly

Score: 22.05
Matched TTPs:
  • T1584.008 - Network Devices
  • T1566.002 - Spearphishing Link
  • T1009 - Binary Padding
  • T1193 - Spearphishing Attachment
  • T1219.001 - IDE Tunneling
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

Ke3chang

Score: 15.28
Matched TTPs:
  • T1584.008 - Network Devices
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1027.008 - Stripped Payloads
  • T1003.007 - Proc Filesystem
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

Agrius

Score: 7.14
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.016 - Junk Code Insertion
  • T1597 - Search Closed Sources
MITREへのリンク →

APT41

Score: 38.55
Matched TTPs:
  • T1584.008 - Network Devices
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1071.004 - DNS
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1041 - Exfiltration Over C2 Channel
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1002 - Data Compressed
  • T1564.003 - Hidden Window
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

APT5

Score: 7.74
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.008 - Stripped Payloads
  • T1219.001 - IDE Tunneling
MITREへのリンク →

menuPass

Score: 6.16
Matched TTPs:
  • T1584.008 - Network Devices
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

Threat Group-3390

Score: 13.07
Matched TTPs:
  • T1584.008 - Network Devices
  • T1091 - Replication Through Removable Media
  • T1218.003 - CMSTP
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Wizard Spider

Score: 13.30
Matched TTPs:
  • T1584.008 - Network Devices
  • T1038 - DLL Search Order Hijacking
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
MITREへのリンク →

Ember Bear

Score: 9.88
Matched TTPs:
  • T1584.008 - Network Devices
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1027.016 - Junk Code Insertion
  • T1597 - Search Closed Sources
MITREへのリンク →

Axiom

Score: 8.55
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1177 - LSASS Driver
  • T1157 - Dylib Hijacking
MITREへのリンク →

HEXANE

Score: 19.81
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1091 - Replication Through Removable Media
  • T1070.006 - Timestomp
  • T1547.005 - Security Support Provider
  • T1027.016 - Junk Code Insertion
  • T1055.014 - VDSO Hijacking
  • T1199 - Trusted Relationship
MITREへのリンク →

Chimera

Score: 14.87
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1587.003 - Digital Certificates
  • T1003.007 - Proc Filesystem
  • T1027.016 - Junk Code Insertion
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

LazyScripter

Score: 9.07
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
MITREへのリンク →

Cobalt Group

Score: 9.82
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1518.002 - Backup Software Discovery
  • T1199 - Trusted Relationship
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

OilRig

Score: 16.48
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT39

Score: 6.32
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

Tropic Trooper

Score: 4.05
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1219.001 - IDE Tunneling
MITREへのリンク →

APT18

Score: 5.47
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1219.001 - IDE Tunneling
  • T1157 - Dylib Hijacking
MITREへのリンク →

FIN7

Score: 25.25
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1588.001 - Malware
  • T1218.012 - Verclsid
  • T1584.005 - Botnet
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Lazarus Group

Score: 30.40
Matched TTPs:
  • T1071.004 - DNS
  • T1070.006 - Timestomp
  • T1009 - Binary Padding
  • T1027.016 - Junk Code Insertion
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT28

Score: 24.55
Matched TTPs:
  • T1071.004 - DNS
  • T1566.002 - Spearphishing Link
  • T1027.016 - Junk Code Insertion
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

RedCurl

Score: 4.58
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1219.001 - IDE Tunneling
MITREへのリンク →

APT1

Score: 6.66
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1003.007 - Proc Filesystem
  • T1199 - Trusted Relationship
MITREへのリンク →

Magic Hound

Score: 30.81
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1566.002 - Spearphishing Link
  • T1547.005 - Security Support Provider
  • T1009 - Binary Padding
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1098.002 - Additional Email Delegate Permissions
  • T1547.008 - LSASS Driver
MITREへのリンク →

Winter Vivern

Score: 11.22
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1548 - Abuse Elevation Control Mechanism
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
MITREへのリンク →

Scattered Spider

Score: 33.78
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1566.002 - Spearphishing Link
  • T1583.001 - Domains
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1564.003 - Hidden Window
MITREへのリンク →

Storm-0501

Score: 8.57
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1588.001 - Malware
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

TeamTNT

Score: 18.09
Matched TTPs:
  • T1497.001 - System Checks
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1071.003 - Mail Protocols
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
MITREへのリンク →

Salt Typhoon

Score: 11.35
Matched TTPs:
  • T1497.001 - System Checks
  • T1608.002 - Upload Tool
  • T1009 - Binary Padding
  • T1199 - Trusted Relationship
MITREへのリンク →

Rocke

Score: 11.38
Matched TTPs:
  • T1497.001 - System Checks
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
MITREへのリンク →

Sidewinder

Score: 9.72
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
MITREへのリンク →

Sandworm Team

Score: 27.64
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1557.003 - DHCP Spoofing
  • T1193 - Spearphishing Attachment
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1075 - Pass the Hash
MITREへのリンク →

Silent Librarian

Score: 11.32
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1027.016 - Junk Code Insertion
  • T1584.005 - Botnet
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

ZIRCONIUM

Score: 12.79
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1039 - Data from Network Shared Drive
  • T1608.006 - SEO Poisoning
MITREへのリンク →

APT32

Score: 18.05
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Star Blizzard

Score: 16.54
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1657 - Financial Theft
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

Moonstone Sleet

Score: 12.58
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 8.27
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1557.003 - DHCP Spoofing
  • T1547.008 - LSASS Driver
MITREへのリンク →

Patchwork

Score: 4.61
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
MITREへのリンク →

HAFNIUM

Score: 15.84
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1027.016 - Junk Code Insertion
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1552.008 - Chat Messages
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

BRONZE BUTLER

Score: 6.47
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

Indrik Spider

Score: 11.93
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1552.008 - Chat Messages
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Turla

Score: 17.05
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1176 - Software Extensions
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Aquatic Panda

Score: 7.26
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

Earth Lusca

Score: 15.32
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1557.003 - DHCP Spoofing
  • T1045 - Software Packing
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
MITREへのリンク →

Volt Typhoon

Score: 48.50
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1556.002 - Password Filter DLL
  • T1176 - Software Extensions
  • T1070.006 - Timestomp
  • T1547.005 - Security Support Provider
  • T1164 - Re-opened Applications
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1057 - Process Discovery
  • T1552.008 - Chat Messages
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1488 - Disk Content Wipe
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

admin@338

Score: 3.82
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1219.001 - IDE Tunneling
MITREへのリンク →

UNC3886

Score: 23.16
Matched TTPs:
  • T1556.002 - Password Filter DLL
  • T1009 - Binary Padding
  • T1021.006 - Windows Remote Management
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1488 - Disk Content Wipe
MITREへのリンク →

TA2541

Score: 8.97
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
MITREへのリンク →

LuminousMoth

Score: 7.97
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1219.001 - IDE Tunneling
  • T1584.005 - Botnet
  • T1199 - Trusted Relationship
MITREへのリンク →

Mustard Tempest

Score: 5.26
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1557.003 - DHCP Spoofing
MITREへのリンク →

Gamaredon Group

Score: 19.86
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1055.014 - VDSO Hijacking
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
MITREへのリンク →

SideCopy

Score: 7.94
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
MITREへのリンク →

TA505

Score: 6.96
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

BlackByte

Score: 11.97
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

BITTER

Score: 7.01
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Saint Bear

Score: 5.78
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

EXOTIC LILY

Score: 9.03
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1149 - LC_MAIN Hijacking
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT42

Score: 6.95
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1583.001 - Domains
  • T1199 - Trusted Relationship
MITREへのリンク →

Akira

Score: 10.10
Matched TTPs:
  • T1137.005 - Outlook Rules
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

MuddyWater

Score: 16.05
Matched TTPs:
  • T1518.002 - Backup Software Discovery
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
MITREへのリンク →

Medusa Group

Score: 16.20
Matched TTPs:
  • T1218.003 - CMSTP
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

LAPSUS$

Score: 26.00
Matched TTPs:
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1193 - Spearphishing Attachment
  • T1045 - Software Packing
  • T1596.004 - CDNs
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1564.003 - Hidden Window
MITREへのリンク →

Carbanak

Score: 6.71
Matched TTPs:
  • T1009 - Binary Padding
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

Moses Staff

Score: 3.19
Matched TTPs:
  • T1009 - Binary Padding
  • T1199 - Trusted Relationship
MITREへのリンク →

ToddyCat

Score: 6.16
Matched TTPs:
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT38

Score: 15.51
Matched TTPs:
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1493 - Transmitted Data Manipulation
MITREへのリンク →

Velvet Ant

Score: 5.44
Matched TTPs:
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
MITREへのリンク →

APT33

Score: 7.12
Matched TTPs:
  • T1027.016 - Junk Code Insertion
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Leafminer

Score: 4.89
Matched TTPs:
  • T1027.016 - Junk Code Insertion
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
MITREへのリンク →

APT3

Score: 4.58
Matched TTPs:
  • T1177 - LSASS Driver
  • T1219.001 - IDE Tunneling
MITREへのリンク →

Deep Panda

Score: 3.29
Matched TTPs:
  • T1177 - LSASS Driver
MITREへのリンク →

Fox Kitten

Score: 10.45
Matched TTPs:
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1157 - Dylib Hijacking
MITREへのリンク →

CopyKittens

Score: 3.19
Matched TTPs:
  • T1045 - Software Packing
  • T1199 - Trusted Relationship
MITREへのリンク →

Blue Mockingbird

Score: 3.19
Matched TTPs:
  • T1045 - Software Packing
  • T1199 - Trusted Relationship
MITREへのリンク →

Cinnamon Tempest

Score: 4.61
Matched TTPs:
  • T1045 - Software Packing
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

MoustachedBouncer

Score: 4.44
Matched TTPs:
  • T1045 - Software Packing
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Windigo

Score: 3.64
Matched TTPs:
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
MITREへのリンク →

POLONIUM

Score: 6.63
Matched TTPs:
  • T1045 - Software Packing
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
MITREへのリンク →

Equation

Score: 4.54
Matched TTPs:
  • T1589.003 - Employee Names
MITREへのリンク →

Inception

Score: 4.49
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1199 - Trusted Relationship
MITREへのリンク →

Dark Caracal

Score: 3.82
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1547.008 - LSASS Driver
MITREへのリンク →

Play

Score: 5.37
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
MITREへのリンク →

Confucius

Score: 5.65
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
MITREへのリンク →

FIN6

Score: 10.78
Matched TTPs:
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1547.008 - LSASS Driver
MITREへのリンク →

SilverTerrier

Score: 3.62
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Leviathan

Score: 8.89
Matched TTPs:
  • T1055.014 - VDSO Hijacking
  • T1157 - Dylib Hijacking
  • T1488 - Disk Content Wipe
MITREへのリンク →

Storm-1811

Score: 5.71
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027 - Obfuscated Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN8

Score: 6.71
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

INC Ransom

Score: 6.41
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Volatile Cedar

Score: 4.13
Matched TTPs:
  • T1002 - Data Compressed
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Volt Typhoon

Score: 0.70
Matched TTPs:
  • T1552.008 - Chat Messages
  • T1219.001 - IDE Tunneling
  • T1547.005 - Security Support Provider
  • T1164 - Re-opened Applications
  • T1003.007 - Proc Filesystem
  • T1057 - Process Discovery
  • T1574.002 - DLL Side-Loading
  • T1045 - Software Packing
  • T1102.003 - One-Way Communication
  • T1199 - Trusted Relationship
  • T1039 - Data from Network Shared Drive
  • T1070.006 - Timestomp
  • T1556.002 - Password Filter DLL
  • T1157 - Dylib Hijacking
  • T1176 - Software Extensions
  • T1488 - Disk Content Wipe
MITREへのリンク →

Kimsuky

Score: 0.59
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1009 - Binary Padding
  • T1003.007 - Proc Filesystem
  • T1055.014 - VDSO Hijacking
  • T1057 - Process Discovery
  • T1091 - Replication Through Removable Media
  • T1102.003 - One-Way Communication
  • T1041 - Exfiltration Over C2 Channel
  • T1199 - Trusted Relationship
  • T1597 - Search Closed Sources
  • T1566.002 - Spearphishing Link
  • T1557.003 - DHCP Spoofing
  • T1608.005 - Link Target
  • T1218.012 - Verclsid
MITREへのリンク →

APT41

Score: 0.56
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1177 - LSASS Driver
  • T1588.001 - Malware
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1002 - Data Compressed
  • T1574.002 - DLL Side-Loading
  • T1071.004 - DNS
  • T1045 - Software Packing
  • T1584.008 - Network Devices
  • T1041 - Exfiltration Over C2 Channel
  • T1199 - Trusted Relationship
  • T1157 - Dylib Hijacking
  • T1027 - Obfuscated Files or Information
  • T1564.003 - Hidden Window
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る