Trusted Design

Highly destructive Lotus Wiper used in a targeted attack

概要

A highly targeted destructive wiper campaign dubbed 'Lotus Wiper' was discovered targeting the energy and utilities sector in Venezuela during late 2025 and early 2026. The attack begins with batch scripts coordinating execution across networks using domain shares as trigger mechanisms. These scripts disable security services, lock out users, and prepare the environment for the final payload. The Lotus Wiper systematically destroys data by wiping physical drives with zeros, deleting restore points, clearing USN journals, and recursively deleting files. Unlike ransomware, this wiper has no financial motivation or ransom demands, designed purely for data destruction. Evidence suggests attackers maintained long-term domain access prior to the attack, with the wiper compiled months before deployment. The malware targets older Windows systems and uses legitimate system tools like diskpart, robocopy, and fsutil.

Created: 2026-04-21

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

HAFNIUM

Score: 11.50
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1027.008 - Stripped Payloads
  • T1140 - Deobfuscate/Decode Files or Information
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

menuPass

Score: 18.94
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1584.008 - Network Devices
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.004 - Asynchronous Procedure Call
  • T1174 - Password Filter DLL
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

Wizard Spider

Score: 15.76
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1038 - DLL Search Order Hijacking
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
  • T1668 - Exclusive Control
MITREへのリンク →

APT33

Score: 9.86
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1491.002 - External Defacement
  • T1562.012 - Disable or Modify Linux Audit System
  • T1051 - Shared Webroot
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Fox Kitten

Score: 20.06
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1491.002 - External Defacement
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1051 - Shared Webroot
  • T1097 - Pass the Ticket
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

CopyKittens

Score: 3.93
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1045 - Software Packing
MITREへのリンク →

Volt Typhoon

Score: 40.19
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1003.007 - Proc Filesystem
  • T1176 - Software Extensions
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.005 - Security Support Provider
  • T1562.012 - Disable or Modify Linux Audit System
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1057 - Process Discovery
  • T1039 - Data from Network Shared Drive
  • T1488 - Disk Content Wipe
  • T1065 - Uncommonly Used Port
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

APT1

Score: 9.55
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
  • T1668 - Exclusive Control
MITREへのリンク →

Mustang Panda

Score: 16.73
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1136.003 - Cloud Account
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

Play

Score: 7.36
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

Chimera

Score: 11.09
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
  • T1668 - Exclusive Control
MITREへのリンク →

Sea Turtle

Score: 14.15
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1499.003 - Application Exhaustion Flood
  • T1063 - Security Software Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.013 - Container CLI/API
MITREへのリンク →

APT39

Score: 12.89
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1097 - Pass the Ticket
  • T1134 - Access Token Manipulation
MITREへのリンク →

RedCurl

Score: 7.12
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1562.012 - Disable or Modify Linux Audit System
  • T1051 - Shared Webroot
  • T1591.004 - Identify Roles
MITREへのリンク →

APT5

Score: 16.36
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1584.008 - Network Devices
  • T1165 - Startup Items
  • T1027.008 - Stripped Payloads
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
MITREへのリンク →

Agrius

Score: 12.47
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1097 - Pass the Ticket
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

GALLIUM

Score: 15.92
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.004 - Asynchronous Procedure Call
  • T1174 - Password Filter DLL
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
  • T1668 - Exclusive Control
MITREへのリンク →

APT41

Score: 42.84
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.012 - Disable or Modify Linux Audit System
  • T1177 - LSASS Driver
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1041 - Exfiltration Over C2 Channel
  • T1097 - Pass the Ticket
  • T1027 - Obfuscated Files or Information
  • T1002 - Data Compressed
  • T1564.003 - Hidden Window
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
  • T1668 - Exclusive Control
  • T1574.002 - DLL Side-Loading
MITREへのリンク →

MuddyWater

Score: 22.63
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.012 - Disable or Modify Linux Audit System
  • T1558.001 - Golden Ticket
  • T1055.004 - Asynchronous Procedure Call
  • T1051 - Shared Webroot
  • T1218.012 - Verclsid
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
  • T1591.004 - Identify Roles
MITREへのリンク →

APT28

Score: 30.40
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1097 - Pass the Ticket
  • T1039 - Data from Network Shared Drive
  • T1197 - BITS Jobs
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1146 - Clear Command History
  • T1668 - Exclusive Control
MITREへのリンク →

Turla

Score: 26.62
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1063 - Security Software Discovery
  • T1003.007 - Proc Filesystem
  • T1176 - Software Extensions
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1097 - Pass the Ticket
  • T1597 - Search Closed Sources
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
MITREへのリンク →

Sowbug

Score: 4.48
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1591.004 - Identify Roles
MITREへのリンク →

BRONZE BUTLER

Score: 14.02
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1003.007 - Proc Filesystem
  • T1592.004 - Client Configurations
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
MITREへのリンク →

UNC3886

Score: 24.60
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1021.006 - Windows Remote Management
  • T1547.015 - Login Items
  • T1597 - Search Closed Sources
  • T1039 - Data from Network Shared Drive
  • T1488 - Disk Content Wipe
  • T1591.004 - Identify Roles
MITREへのリンク →

Kimsuky

Score: 48.65
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1566.002 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1562.012 - Disable or Modify Linux Audit System
  • T1051 - Shared Webroot
  • T1218.012 - Verclsid
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1690 - Prevent Command History Logging
  • T1197 - BITS Jobs
  • T1591.004 - Identify Roles
  • T1668 - Exclusive Control
  • T1003.003 - NTDS
MITREへのリンク →

APT3

Score: 15.62
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1562.012 - Disable or Modify Linux Audit System
  • T1177 - LSASS Driver
  • T1055.004 - Asynchronous Procedure Call
  • T1051 - Shared Webroot
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

FIN8

Score: 8.53
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

Ke3chang

Score: 18.19
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1584.008 - Network Devices
  • T1027.008 - Stripped Payloads
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

Lotus Blossom

Score: 8.72
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1055.004 - Asynchronous Procedure Call
  • T1505 - Server Software Component
  • T1134 - Access Token Manipulation
MITREへのリンク →

FIN13

Score: 24.85
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1584.008 - Network Devices
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.005 - Security Support Provider
  • T1055.004 - Asynchronous Procedure Call
  • T1051 - Shared Webroot
  • T1134.001 - Token Impersonation/Theft
  • T1591.004 - Identify Roles
  • T1668 - Exclusive Control
MITREへのリンク →

Earth Lusca

Score: 17.28
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
MITREへのリンク →

Magic Hound

Score: 33.86
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.005 - Security Support Provider
  • T1009 - Binary Padding
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
  • T1098.002 - Additional Email Delegate Permissions
  • T1547.008 - LSASS Driver
MITREへのリンク →

Aquatic Panda

Score: 11.85
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1165 - Startup Items
  • T1003.007 - Proc Filesystem
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1668 - Exclusive Control
MITREへのリンク →

INC Ransom

Score: 9.89
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

Akira

Score: 15.94
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1137.005 - Outlook Rules
  • T1597 - Search Closed Sources
  • T1601 - Modify System Image
  • T1027 - Obfuscated Files or Information
  • T1134 - Access Token Manipulation
MITREへのリンク →

ToddyCat

Score: 12.16
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT38

Score: 25.56
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1097 - Pass the Ticket
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1174 - Password Filter DLL
  • T1493 - Transmitted Data Manipulation
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Ajax Security Team

Score: 6.51
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1562.012 - Disable or Modify Linux Audit System
  • T1547.008 - LSASS Driver
MITREへのリンク →

Darkhotel

Score: 10.38
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1564.002 - Hidden Users
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Tonto Team

Score: 4.03
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Threat Group-3390

Score: 17.66
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1584.008 - Network Devices
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.004 - Asynchronous Procedure Call
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
MITREへのリンク →

Lazarus Group

Score: 29.92
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1165 - Startup Items
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1057 - Process Discovery
  • T1597 - Search Closed Sources
  • T1174 - Password Filter DLL
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
  • T1086 - PowerShell
MITREへのリンク →

Group5

Score: 3.53
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
MITREへのリンク →

PLATINUM

Score: 5.80
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1039 - Data from Network Shared Drive
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Sandworm Team

Score: 21.47
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1063 - Security Software Discovery
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.012 - Disable or Modify Linux Audit System
  • T1045 - Software Packing
  • T1055.004 - Asynchronous Procedure Call
  • T1027 - Obfuscated Files or Information
  • T1134 - Access Token Manipulation
MITREへのリンク →

OilRig

Score: 35.68
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1165 - Startup Items
  • T1003.007 - Proc Filesystem
  • T1574.014 - AppDomainManager
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1562.012 - Disable or Modify Linux Audit System
  • T1055.004 - Asynchronous Procedure Call
  • T1051 - Shared Webroot
  • T1097 - Pass the Ticket
  • T1039 - Data from Network Shared Drive
  • T1592.002 - Software
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT42

Score: 10.09
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1091 - Replication Through Removable Media
  • T1583.001 - Domains
  • T1562.012 - Disable or Modify Linux Audit System
MITREへのリンク →

HEXANE

Score: 25.78
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1499.003 - Application Exhaustion Flood
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1562.012 - Disable or Modify Linux Audit System
  • T1055.004 - Asynchronous Procedure Call
  • T1055.014 - VDSO Hijacking
  • T1097 - Pass the Ticket
  • T1065 - Uncommonly Used Port
  • T1134 - Access Token Manipulation
MITREへのリンク →

APT32

Score: 31.20
Matched TTPs:
  • T1596.003 - Digital Certificates
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1592.004 - Client Configurations
  • T1055.004 - Asynchronous Procedure Call
  • T1218.012 - Verclsid
  • T1039 - Data from Network Shared Drive
  • T1174 - Password Filter DLL
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
  • T1668 - Exclusive Control
MITREへのリンク →

Contagious Interview

Score: 26.63
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1021.006 - Windows Remote Management
  • T1045 - Software Packing
  • T1597 - Search Closed Sources
  • T1690 - Prevent Command History Logging
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

Inception

Score: 5.99
Matched TTPs:
  • T1491.002 - External Defacement
  • T1562.012 - Disable or Modify Linux Audit System
  • T1218.012 - Verclsid
MITREへのリンク →

Dark Caracal

Score: 6.84
Matched TTPs:
  • T1491.002 - External Defacement
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Elderwood

Score: 3.36
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Transparent Tribe

Score: 3.36
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Leviathan

Score: 14.53
Matched TTPs:
  • T1491.002 - External Defacement
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.014 - VDSO Hijacking
  • T1488 - Disk Content Wipe
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Sidewinder

Score: 10.01
Matched TTPs:
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
MITREへのリンク →

Saint Bear

Score: 6.32
Matched TTPs:
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

BITTER

Score: 5.66
Matched TTPs:
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

TA505

Score: 13.23
Matched TTPs:
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1562.012 - Disable or Modify Linux Audit System
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

APT19

Score: 3.36
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

TA2541

Score: 7.70
Matched TTPs:
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1597 - Search Closed Sources
MITREへのリンク →

Malteiro

Score: 3.65
Matched TTPs:
  • T1491.002 - External Defacement
  • T1562.012 - Disable or Modify Linux Audit System
MITREへのリンク →

Storm-1811

Score: 9.65
Matched TTPs:
  • T1491.002 - External Defacement
  • T1165 - Startup Items
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1547.008 - LSASS Driver
MITREへのリンク →

Blue Mockingbird

Score: 14.74
Matched TTPs:
  • T1491.002 - External Defacement
  • T1140 - Deobfuscate/Decode Files or Information
  • T1045 - Software Packing
  • T1591.004 - Identify Roles
  • T1505 - Server Software Component
  • T1001.001 - Junk Data
MITREへのリンク →

Tropic Trooper

Score: 8.42
Matched TTPs:
  • T1491.002 - External Defacement
  • T1055.004 - Asynchronous Procedure Call
  • T1136.003 - Cloud Account
  • T1591.004 - Identify Roles
MITREへのリンク →

Whitefly

Score: 3.69
Matched TTPs:
  • T1491.002 - External Defacement
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Moses Staff

Score: 5.40
Matched TTPs:
  • T1491.002 - External Defacement
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
MITREへのリンク →

TeamTNT

Score: 22.21
Matched TTPs:
  • T1491.002 - External Defacement
  • T1165 - Startup Items
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1009 - Binary Padding
  • T1071.003 - Mail Protocols
  • T1055.004 - Asynchronous Procedure Call
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

Putter Panda

Score: 3.39
Matched TTPs:
  • T1491.002 - External Defacement
  • T1597 - Search Closed Sources
MITREへのリンク →

Moonstone Sleet

Score: 17.61
Matched TTPs:
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1197 - BITS Jobs
  • T1547.008 - LSASS Driver
MITREへのリンク →

Mustard Tempest

Score: 8.28
Matched TTPs:
  • T1682 - Query Public AI Services
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Daggerfly

Score: 7.64
Matched TTPs:
  • T1584.008 - Network Devices
  • T1174 - Password Filter DLL
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT29

Score: 31.77
Matched TTPs:
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1592.004 - Client Configurations
  • T1568 - Dynamic Resolution
  • T1218.012 - Verclsid
  • T1039 - Data from Network Shared Drive
  • T1546.018 - Python Startup Hooks
  • T1223 - Compiled HTML File
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dragonfly

Score: 22.89
Matched TTPs:
  • T1584.008 - Network Devices
  • T1566.002 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1097 - Pass the Ticket
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
MITREへのリンク →

Ember Bear

Score: 19.33
Matched TTPs:
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1051 - Shared Webroot
  • T1097 - Pass the Ticket
  • T1597 - Search Closed Sources
  • T1134 - Access Token Manipulation
  • T1668 - Exclusive Control
  • T1003.003 - NTDS
MITREへのリンク →

Axiom

Score: 10.37
Matched TTPs:
  • T1499.003 - Application Exhaustion Flood
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Scattered Spider

Score: 44.48
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1566.002 - Spearphishing Link
  • T1165 - Startup Items
  • T1583.001 - Domains
  • T1547.005 - Security Support Provider
  • T1019 - System Firmware
  • T1045 - Software Packing
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1197 - BITS Jobs
  • T1564.003 - Hidden Window
  • T1134 - Access Token Manipulation
  • T1027.002 - Software Packing
MITREへのリンク →

Storm-0501

Score: 10.47
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1140 - Deobfuscate/Decode Files or Information
  • T1097 - Pass the Ticket
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

FIN6

Score: 18.43
Matched TTPs:
  • T1063 - Security Software Discovery
  • T1562.012 - Disable or Modify Linux Audit System
  • T1597 - Search Closed Sources
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
  • T1505 - Server Software Component
  • T1134 - Access Token Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Silent Librarian

Score: 6.30
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1584.005 - Botnet
MITREへのリンク →

ZIRCONIUM

Score: 11.00
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1562.012 - Disable or Modify Linux Audit System
  • T1039 - Data from Network Shared Drive
  • T1197 - BITS Jobs
  • T1591.004 - Identify Roles
MITREへのリンク →

Star Blizzard

Score: 10.98
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1547.005 - Security Support Provider
  • T1657 - Financial Theft
MITREへのリンク →

CURIUM

Score: 6.75
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Patchwork

Score: 7.23
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1562.012 - Disable or Modify Linux Audit System
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

FIN7

Score: 28.54
Matched TTPs:
  • T1165 - Startup Items
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1218.012 - Verclsid
  • T1584.005 - Botnet
  • T1564.002 - Hidden Users
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1065 - Uncommonly Used Port
  • T1591.004 - Identify Roles
MITREへのリンク →

BlackTech

Score: 3.71
Matched TTPs:
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Salt Typhoon

Score: 6.05
Matched TTPs:
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
MITREへのリンク →

Indrik Spider

Score: 13.92
Matched TTPs:
  • T1165 - Startup Items
  • T1003.007 - Proc Filesystem
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

Rocke

Score: 13.01
Matched TTPs:
  • T1165 - Startup Items
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
  • T1134 - Access Token Manipulation
MITREへのリンク →

Poseidon Group

Score: 4.26
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

admin@338

Score: 5.21
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
MITREへのリンク →

Strider

Score: 8.26
Matched TTPs:
  • T1574.014 - AppDomainManager
  • T1130 - Install Root Certificate
MITREへのリンク →

LuminousMoth

Score: 5.82
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1584.005 - Botnet
MITREへのリンク →

LazyScripter

Score: 5.27
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1591.004 - Identify Roles
MITREへのリンク →

Gamaredon Group

Score: 25.32
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1045 - Software Packing
  • T1218.012 - Verclsid
  • T1055.014 - VDSO Hijacking
  • T1597 - Search Closed Sources
  • T1061 - Graphical User Interface
  • T1059.013 - Container CLI/API
  • T1591.004 - Identify Roles
  • T1086 - PowerShell
MITREへのリンク →

SideCopy

Score: 7.94
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1657 - Financial Theft
MITREへのリンク →

BlackByte

Score: 18.65
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1134.001 - Token Impersonation/Theft
  • T1597 - Search Closed Sources
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1134 - Access Token Manipulation
MITREへのリンク →

EXOTIC LILY

Score: 8.34
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1690 - Prevent Command History Logging
  • T1547.008 - LSASS Driver
MITREへのリンク →

BackdoorDiplomacy

Score: 3.20
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Medusa Group

Score: 14.98
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1598 - Phishing for Information
  • T1134 - Access Token Manipulation
MITREへのリンク →

Cinnamon Tempest

Score: 4.77
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1045 - Software Packing
  • T1591.004 - Identify Roles
MITREへのリンク →

Winter Vivern

Score: 4.19
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Volatile Cedar

Score: 5.60
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1002 - Data Compressed
MITREへのリンク →

LAPSUS$

Score: 25.15
Matched TTPs:
  • T1547.005 - Security Support Provider
  • T1562.012 - Disable or Modify Linux Audit System
  • T1019 - System Firmware
  • T1045 - Software Packing
  • T1039 - Data from Network Shared Drive
  • T1601 - Modify System Image
  • T1065 - Uncommonly Used Port
  • T1564.003 - Hidden Window
MITREへのリンク →

Velvet Ant

Score: 5.87
Matched TTPs:
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
MITREへのリンク →

Leafminer

Score: 12.42
Matched TTPs:
  • T1562.012 - Disable or Modify Linux Audit System
  • T1101 - Security Support Provider
  • T1051 - Shared Webroot
  • T1059.012 - Hypervisor CLI
  • T1134 - Access Token Manipulation
MITREへのリンク →

APT37

Score: 4.77
Matched TTPs:
  • T1562.012 - Disable or Modify Linux Audit System
  • T1591.004 - Identify Roles
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Deep Panda

Score: 4.83
Matched TTPs:
  • T1177 - LSASS Driver
  • T1134 - Access Token Manipulation
MITREへのリンク →

MoustachedBouncer

Score: 4.44
Matched TTPs:
  • T1045 - Software Packing
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Windigo

Score: 4.11
Matched TTPs:
  • T1045 - Software Packing
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Equation

Score: 8.67
Matched TTPs:
  • T1589.003 - Employee Names
  • T1130 - Install Root Certificate
MITREへのリンク →

Andariel

Score: 3.50
Matched TTPs:
  • T1055.004 - Asynchronous Procedure Call
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

TA551

Score: 3.30
Matched TTPs:
  • T1218.012 - Verclsid
  • T1591.004 - Identify Roles
MITREへのリンク →

PROMETHIUM

Score: 5.90
Matched TTPs:
  • T1547.015 - Login Items
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

SilverTerrier

Score: 3.62
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

FIN5

Score: 4.07
Matched TTPs:
  • T1097 - Pass the Ticket
  • T1134 - Access Token Manipulation
MITREへのリンク →

Cobalt Group

Score: 3.05
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1591.004 - Identify Roles
MITREへのリンク →

Windshift

Score: 4.29
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.70
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1009 - Binary Padding
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1668 - Exclusive Control
  • T1218.012 - Verclsid
  • T1003.007 - Proc Filesystem
  • T1003.003 - NTDS
  • T1051 - Shared Webroot
  • T1197 - BITS Jobs
  • T1057 - Process Discovery
  • T1566.002 - Spearphishing Link
  • T1690 - Prevent Command History Logging
  • T1560.001 - Archive via Utility
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1055.014 - VDSO Hijacking
  • T1596.003 - Digital Certificates
  • T1562.012 - Disable or Modify Linux Audit System
MITREへのリンク →

Scattered Spider

Score: 0.64
Matched TTPs:
  • T1051 - Shared Webroot
  • T1197 - BITS Jobs
  • T1583.001 - Domains
  • T1045 - Software Packing
  • T1134 - Access Token Manipulation
  • T1027.002 - Software Packing
  • T1039 - Data from Network Shared Drive
  • T1566.002 - Spearphishing Link
  • T1027 - Obfuscated Files or Information
  • T1547.005 - Security Support Provider
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1165 - Startup Items
  • T1597 - Search Closed Sources
  • T1019 - System Firmware
  • T1564.003 - Hidden Window
MITREへのリンク →

APT41

Score: 0.62
Matched TTPs:
  • T1055.004 - Asynchronous Procedure Call
  • T1140 - Deobfuscate/Decode Files or Information
  • T1564.003 - Hidden Window
  • T1596.003 - Digital Certificates
  • T1097 - Pass the Ticket
  • T1041 - Exfiltration Over C2 Channel
  • T1668 - Exclusive Control
  • T1045 - Software Packing
  • T1134 - Access Token Manipulation
  • T1177 - LSASS Driver
  • T1562.012 - Disable or Modify Linux Audit System
  • T1002 - Data Compressed
  • T1591.004 - Identify Roles
  • T1027 - Obfuscated Files or Information
  • T1560.001 - Archive via Utility
  • T1574.002 - DLL Side-Loading
  • T1584.008 - Network Devices
MITREへのリンク →

Volt Typhoon

Score: 0.58
Matched TTPs:
  • T1488 - Disk Content Wipe
  • T1055.004 - Asynchronous Procedure Call
  • T1140 - Deobfuscate/Decode Files or Information
  • T1596.003 - Digital Certificates
  • T1045 - Software Packing
  • T1134 - Access Token Manipulation
  • T1039 - Data from Network Shared Drive
  • T1176 - Software Extensions
  • T1003.007 - Proc Filesystem
  • T1562.012 - Disable or Modify Linux Audit System
  • T1057 - Process Discovery
  • T1065 - Uncommonly Used Port
  • T1547.005 - Security Support Provider
  • T1560.001 - Archive via Utility
  • T1574.002 - DLL Side-Loading
  • T1591.004 - Identify Roles
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る