Trusted Design

Using SSL Certificates and Graph Theory to Uncover Threat Actors

概要

Researchers at Infoblox have developed an advanced technique leveraging graph theory and SSL certificates to uncover threat actor operational relationships. The approach analyzes Certificate Transparency logs, using the Subject Alternative Name field in certificates to identify domains under common control. By modeling domains as nodes and certificate relationships as edges, the system reveals comprehensive threat infrastructures. This method enables discovery of new malicious domains, consolidation of threat actor identities, and early detection of emerging threats. The system processes millions of certificates daily, providing actionable intelligence on threat actor operations across various types of cybercriminal activities.

Created: 2026-03-05

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

Mustang Panda

Score: 27.07
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1024 - Custom Cryptographic Protocol
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1612 - Build Image on Host
  • T1218.012 - Verclsid
  • T1087.004 - Cloud Account
MITREへのリンク →

Kimsuky

Score: 52.46
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1024 - Custom Cryptographic Protocol
  • T1009 - Binary Padding
  • T1152 - Launchctl
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1218.012 - Verclsid
  • T1087.004 - Cloud Account
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1132.002 - Non-Standard Encoding
  • T1003.003 - NTDS
  • T1008 - Fallback Channels
MITREへのリンク →

Sea Turtle

Score: 11.98
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1499.003 - Application Exhaustion Flood
  • T1555.003 - Credentials from Web Browsers
  • T1175 - Component Object Model and Distributed COM
MITREへのリンク →

Daggerfly

Score: 3.80
Matched TTPs:
  • T1584.008 - Network Devices
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

GALLIUM

Score: 8.07
Matched TTPs:
  • T1584.008 - Network Devices
  • T1555.003 - Credentials from Web Browsers
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
MITREへのリンク →

APT29

Score: 31.76
Matched TTPs:
  • T1584.008 - Network Devices
  • T1606.002 - SAML Tokens
  • T1598.003 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1555.003 - Credentials from Web Browsers
  • T1177 - LSASS Driver
  • T1568 - Dynamic Resolution
  • T1218.012 - Verclsid
  • T1218.009 - Regsvcs/Regasm
  • T1223 - Compiled HTML File
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN13

Score: 15.72
Matched TTPs:
  • T1584.008 - Network Devices
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1547.005 - Security Support Provider
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Dragonfly

Score: 21.32
Matched TTPs:
  • T1584.008 - Network Devices
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1009 - Binary Padding
  • T1555.003 - Credentials from Web Browsers
  • T1193 - Spearphishing Attachment
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Ke3chang

Score: 14.75
Matched TTPs:
  • T1584.008 - Network Devices
  • T1606.002 - SAML Tokens
  • T1027.008 - Stripped Payloads
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
MITREへのリンク →

Agrius

Score: 8.13
Matched TTPs:
  • T1584.008 - Network Devices
  • T1555.003 - Credentials from Web Browsers
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
MITREへのリンク →

APT41

Score: 48.12
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1562 - Impair Defenses
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1041 - Exfiltration Over C2 Channel
  • T1208 - Kerberoasting
  • T1027 - Obfuscated Files or Information
  • T1002 - Data Compressed
  • T1564.003 - Hidden Window
  • T1574.002 - DLL Side-Loading
  • T1037.001 - Logon Script (Windows)
  • T1008 - Fallback Channels
MITREへのリンク →

APT5

Score: 11.24
Matched TTPs:
  • T1584.008 - Network Devices
  • T1027.008 - Stripped Payloads
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

menuPass

Score: 8.79
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1590.003 - Network Trust Dependencies
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Threat Group-3390

Score: 6.97
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1555.003 - Credentials from Web Browsers
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Wizard Spider

Score: 15.08
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1038 - DLL Search Order Hijacking
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
MITREへのリンク →

Ember Bear

Score: 16.94
Matched TTPs:
  • T1584.008 - Network Devices
  • T1555.003 - Credentials from Web Browsers
  • T1175 - Component Object Model and Distributed COM
  • T1597 - Search Closed Sources
  • T1519 - Emond
  • T1003.003 - NTDS
MITREへのリンク →

Axiom

Score: 9.65
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1177 - LSASS Driver
  • T1175 - Component Object Model and Distributed COM
MITREへのリンク →

HEXANE

Score: 18.67
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1120 - Peripheral Device Discovery
  • T1024 - Custom Cryptographic Protocol
  • T1562 - Impair Defenses
  • T1547.005 - Security Support Provider
  • T1055.004 - Asynchronous Procedure Call
  • T1055.014 - VDSO Hijacking
MITREへのリンク →

Moonstone Sleet

Score: 17.31
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1175 - Component Object Model and Distributed COM
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Indrik Spider

Score: 10.08
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1552.008 - Chat Messages
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Lazarus Group

Score: 29.47
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1087.004 - Cloud Account
  • T1057 - Process Discovery
  • T1597 - Search Closed Sources
  • T1547.008 - LSASS Driver
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Contagious Interview

Score: 22.82
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1547.005 - Security Support Provider
  • T1021.006 - Windows Remote Management
  • T1045 - Software Packing
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1547.008 - LSASS Driver
MITREへのリンク →

OilRig

Score: 22.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1024 - Custom Cryptographic Protocol
  • T1562 - Impair Defenses
  • T1009 - Binary Padding
  • T1555.003 - Credentials from Web Browsers
  • T1055.004 - Asynchronous Procedure Call
  • T1592.002 - Software
  • T1547.008 - LSASS Driver
MITREへのリンク →

UNC3886

Score: 17.61
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1009 - Binary Padding
  • T1021.006 - Windows Remote Management
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1597 - Search Closed Sources
  • T1488 - Disk Content Wipe
MITREへのリンク →

LuminousMoth

Score: 9.21
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1219.001 - IDE Tunneling
  • T1584.005 - Botnet
  • T1087.004 - Cloud Account
MITREへのリンク →

Sandworm Team

Score: 28.76
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1555.003 - Credentials from Web Browsers
  • T1193 - Spearphishing Attachment
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1027 - Obfuscated Files or Information
  • T1075 - Pass the Hash
MITREへのリンク →

Salt Typhoon

Score: 8.97
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1608.002 - Upload Tool
  • T1009 - Binary Padding
MITREへのリンク →

Play

Score: 6.40
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
MITREへのリンク →

Aoqin Dragon

Score: 3.39
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1219.001 - IDE Tunneling
MITREへのリンク →

RedCurl

Score: 8.00
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
  • T1612 - Build Image on Host
MITREへのリンク →

Moses Staff

Score: 7.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1009 - Binary Padding
  • T1555.003 - Credentials from Web Browsers
MITREへのリンク →

Turla

Score: 19.42
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1176 - Software Extensions
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1612 - Build Image on Host
  • T1597 - Search Closed Sources
MITREへのリンク →

TeamTNT

Score: 17.13
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1612 - Build Image on Host
  • T1597 - Search Closed Sources
  • T1519 - Emond
MITREへのリンク →

FIN7

Score: 20.42
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1009 - Binary Padding
  • T1588.001 - Malware
  • T1218.012 - Verclsid
  • T1584.005 - Botnet
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Scattered Spider

Score: 32.59
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1566.002 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1583.001 - Domains
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1564.003 - Hidden Window
MITREへのリンク →

Storm-0501

Score: 9.77
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Sidewinder

Score: 8.18
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
MITREへのリンク →

Silent Librarian

Score: 6.30
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1584.005 - Botnet
MITREへのリンク →

ZIRCONIUM

Score: 7.73
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
MITREへのリンク →

APT32

Score: 21.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1547.005 - Security Support Provider
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1612 - Build Image on Host
  • T1218.012 - Verclsid
  • T1087.004 - Cloud Account
MITREへのリンク →

Magic Hound

Score: 27.50
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1024 - Custom Cryptographic Protocol
  • T1547.005 - Security Support Provider
  • T1009 - Binary Padding
  • T1555.003 - Credentials from Web Browsers
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT28

Score: 23.54
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1152 - Launchctl
  • T1555.003 - Credentials from Web Browsers
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1057 - Process Discovery
  • T1146 - Clear Command History
MITREへのリンク →

Star Blizzard

Score: 8.93
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1547.005 - Security Support Provider
MITREへのリンク →

CURIUM

Score: 13.32
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1555.003 - Credentials from Web Browsers
  • T1175 - Component Object Model and Distributed COM
  • T1087.004 - Cloud Account
  • T1547.008 - LSASS Driver
MITREへのリンク →

Patchwork

Score: 9.12
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
  • T1008 - Fallback Channels
MITREへのリンク →

Tropic Trooper

Score: 9.17
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

FIN6

Score: 12.48
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562 - Impair Defenses
  • T1588.001 - Malware
  • T1612 - Build Image on Host
  • T1597 - Search Closed Sources
  • T1547.008 - LSASS Driver
MITREへのリンク →

admin@338

Score: 5.11
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Windshift

Score: 4.60
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1547.008 - LSASS Driver
MITREへのリンク →

BRONZE BUTLER

Score: 7.26
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
  • T1008 - Fallback Channels
MITREへのリンク →

MuddyWater

Score: 13.89
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1562 - Impair Defenses
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
MITREへのリンク →

Gamaredon Group

Score: 22.79
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1045 - Software Packing
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1612 - Build Image on Host
  • T1218.012 - Verclsid
  • T1087.004 - Cloud Account
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
MITREへのリンク →

Darkhotel

Score: 3.38
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
MITREへのリンク →

Inception

Score: 8.24
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1219.001 - IDE Tunneling
  • T1612 - Build Image on Host
  • T1218.012 - Verclsid
MITREへのリンク →

EXOTIC LILY

Score: 5.92
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1612 - Build Image on Host
  • T1547.008 - LSASS Driver
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT33

Score: 3.54
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562 - Impair Defenses
MITREへのリンク →

TA551

Score: 3.22
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1218.012 - Verclsid
MITREへのリンク →

RTM

Score: 4.16
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1008 - Fallback Channels
MITREへのリンク →

Winter Vivern

Score: 9.97
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
MITREへのリンク →

Higaisa

Score: 8.44
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
MITREへのリンク →

Confucius

Score: 6.49
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1218.012 - Verclsid
  • T1087.004 - Cloud Account
MITREへのリンク →

BlackTech

Score: 3.16
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1590.003 - Network Trust Dependencies
MITREへのリンク →

Gorgon Group

Score: 4.96
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1590.003 - Network Trust Dependencies
  • T1597 - Search Closed Sources
MITREへのリンク →

Leviathan

Score: 14.75
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
  • T1555.003 - Credentials from Web Browsers
  • T1087.004 - Cloud Account
  • T1055.014 - VDSO Hijacking
  • T1488 - Disk Content Wipe
MITREへのリンク →

Malteiro

Score: 4.75
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1562 - Impair Defenses
MITREへのリンク →

SideCopy

Score: 6.71
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1218.012 - Verclsid
MITREへのリンク →

FIN8

Score: 6.94
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1612 - Build Image on Host
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

LazyScripter

Score: 5.74
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1612 - Build Image on Host
  • T1218.012 - Verclsid
MITREへのリンク →

TA2541

Score: 6.22
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1218.012 - Verclsid
  • T1597 - Search Closed Sources
MITREへのリンク →

TA505

Score: 7.30
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1590.003 - Network Trust Dependencies
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

APT37

Score: 7.99
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Silence

Score: 3.16
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1590.003 - Network Trust Dependencies
MITREへのリンク →

IndigoZebra

Score: 3.54
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1024 - Custom Cryptographic Protocol
MITREへのリンク →

APT38

Score: 26.15
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1009 - Binary Padding
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1493 - Transmitted Data Manipulation
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT39

Score: 8.58
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562 - Impair Defenses
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1087.004 - Cloud Account
MITREへのリンク →

HAFNIUM

Score: 13.28
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1555.003 - Credentials from Web Browsers
  • T1175 - Component Object Model and Distributed COM
  • T1219.001 - IDE Tunneling
  • T1552.008 - Chat Messages
MITREへのリンク →

Windigo

Score: 4.85
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
MITREへのリンク →

BlackByte

Score: 13.95
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1009 - Binary Padding
  • T1555.003 - Credentials from Web Browsers
  • T1175 - Component Object Model and Distributed COM
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Blue Mockingbird

Score: 3.55
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1045 - Software Packing
MITREへのリンク →

Rocke

Score: 11.15
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1009 - Binary Padding
  • T1612 - Build Image on Host
  • T1597 - Search Closed Sources
  • T1008 - Fallback Channels
MITREへのリンク →

APT3

Score: 9.50
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1177 - LSASS Driver
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
MITREへのリンク →

APT42

Score: 14.01
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1583.001 - Domains
  • T1175 - Component Object Model and Distributed COM
  • T1612 - Build Image on Host
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

Aquatic Panda

Score: 5.10
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1588.001 - Malware
  • T1597 - Search Closed Sources
MITREへのリンク →

Medusa Group

Score: 16.66
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1590.003 - Network Trust Dependencies
  • T1009 - Binary Padding
  • T1555.003 - Credentials from Web Browsers
  • T1219.001 - IDE Tunneling
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Stealth Falcon

Score: 5.84
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1562 - Impair Defenses
  • T1087.004 - Cloud Account
MITREへのリンク →

Chimera

Score: 15.45
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1059.003 - Windows Command Shell
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

ToddyCat

Score: 10.18
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1547.008 - LSASS Driver
MITREへのリンク →

Volt Typhoon

Score: 31.97
Matched TTPs:
  • T1176 - Software Extensions
  • T1562 - Impair Defenses
  • T1547.005 - Security Support Provider
  • T1555.003 - Credentials from Web Browsers
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1057 - Process Discovery
  • T1552.008 - Chat Messages
  • T1488 - Disk Content Wipe
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

LAPSUS$

Score: 25.90
Matched TTPs:
  • T1024 - Custom Cryptographic Protocol
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1193 - Spearphishing Attachment
  • T1045 - Software Packing
  • T1175 - Component Object Model and Distributed COM
  • T1564.003 - Hidden Window
  • T1132.002 - Non-Standard Encoding
MITREへのリンク →

Akira

Score: 8.68
Matched TTPs:
  • T1137.005 - Outlook Rules
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Leafminer

Score: 3.97
Matched TTPs:
  • T1562 - Impair Defenses
  • T1219.001 - IDE Tunneling
MITREへのリンク →

Carbanak

Score: 4.44
Matched TTPs:
  • T1009 - Binary Padding
  • T1588.001 - Malware
MITREへのリンク →

Velvet Ant

Score: 7.17
Matched TTPs:
  • T1009 - Binary Padding
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
MITREへのリンク →

BackdoorDiplomacy

Score: 5.60
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Deep Panda

Score: 5.05
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1177 - LSASS Driver
MITREへのリンク →

Volatile Cedar

Score: 5.90
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1002 - Data Compressed
MITREへのリンク →

Fox Kitten

Score: 13.31
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1219.001 - IDE Tunneling
  • T1588.001 - Malware
  • T1612 - Build Image on Host
MITREへのリンク →

Earth Lusca

Score: 6.42
Matched TTPs:
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
MITREへのリンク →

Dark Caracal

Score: 3.82
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1547.008 - LSASS Driver
MITREへのリンク →

Lotus Blossom

Score: 3.03
Matched TTPs:
  • T1219.001 - IDE Tunneling
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

INC Ransom

Score: 5.87
Matched TTPs:
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

SilverTerrier

Score: 3.62
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Storm-1811

Score: 4.86
Matched TTPs:
  • T1027 - Obfuscated Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1037.001 - Logon Script (Windows)
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.70
Matched TTPs:
  • T1024 - Custom Cryptographic Protocol
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1057 - Process Discovery
  • T1003.003 - NTDS
  • T1598.003 - Spearphishing Link
  • T1219.001 - IDE Tunneling
  • T1037 - Boot or Logon Initialization Scripts
  • T1555.003 - Credentials from Web Browsers
  • T1087.004 - Cloud Account
  • T1008 - Fallback Channels
  • T1606.002 - SAML Tokens
  • T1009 - Binary Padding
  • T1218.012 - Verclsid
  • T1588.001 - Malware
  • T1132.002 - Non-Standard Encoding
  • T1152 - Launchctl
  • T1041 - Exfiltration Over C2 Channel
  • T1566.002 - Spearphishing Link
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

APT41

Score: 0.64
Matched TTPs:
  • T1564.003 - Hidden Window
  • T1002 - Data Compressed
  • T1208 - Kerberoasting
  • T1008 - Fallback Channels
  • T1588.001 - Malware
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1562 - Impair Defenses
  • T1598.003 - Spearphishing Link
  • T1027 - Obfuscated Files or Information
  • T1584.008 - Network Devices
  • T1037.001 - Logon Script (Windows)
  • T1041 - Exfiltration Over C2 Channel
  • T1219.001 - IDE Tunneling
  • T1177 - LSASS Driver
  • T1574.002 - DLL Side-Loading
  • T1120 - Peripheral Device Discovery
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る