Trusted Design

A New Name in the Data Extortion Ecosystem?

概要

A data extortion group called Helix has been identified conducting multi-target campaigns using vishing, device code phishing, and automated SharePoint exfiltration. The group likely emerged from the BlackFile and ShinyHunters ecosystem after BlackFile shut down in April 2026. Helix uses sophisticated social engineering, impersonating managers by name during vishing calls to initiate device code authentication flows. The operation employs shared infrastructure including phishing domains registered through NICENIC with target-specific subdomains. After gaining access, attackers register MFA on compromised accounts, enumerate SharePoint using automated tools with python-requests user-agent, and conduct bulk data exfiltration. Infrastructure analysis reveals connections to BlackFile through hosting on the same autonomous system. The group demonstrates operational flexibility with varying dwell times and uses residential proxies geo-matched to targets to evade detection.

Created: 2026-07-23

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

APT28

Score: 32.21
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1487 - Disk Structure Wipe
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1131 - Authentication Package
  • T1547.011 - Plist Modification
  • T1608.005 - Link Target
  • T1122 - Component Object Model Hijacking
  • T1574.009 - Path Interception by Unquoted Path
  • T1585 - Establish Accounts
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

APT29

Score: 40.84
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1099 - Timestomp
  • T1584.008 - Network Devices
  • T1202 - Indirect Command Execution
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.011 - Plist Modification
  • T1177 - LSASS Driver
  • T1592.004 - Client Configurations
  • T1568 - Dynamic Resolution
  • T1608.005 - Link Target
  • T1556.008 - Network Provider DLL
  • T1122 - Component Object Model Hijacking
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Scattered Spider

Score: 37.38
Matched TTPs:
  • T1213.002 - Sharepoint
  • T1666 - Modify Cloud Resource Hierarchy
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1590.006 - Network Security Appliances
  • T1609 - Container Administration Command
  • T1083 - File and Directory Discovery
  • T1051 - Shared Webroot
  • T1556.008 - Network Provider DLL
  • T1597 - Search Closed Sources
  • T1564.003 - Hidden Window
MITREへのリンク →

Volt Typhoon

Score: 37.17
Matched TTPs:
  • T1213.002 - Sharepoint
  • T1099 - Timestomp
  • T1686.003 - Windows Host Firewall
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1070.006 - Timestomp
  • T1547.005 - Security Support Provider
  • T1590.006 - Network Security Appliances
  • T1083 - File and Directory Discovery
  • T1584.002 - DNS Server
  • T1065 - Uncommonly Used Port
  • T1665 - Hide Infrastructure
MITREへのリンク →

FIN4

Score: 4.13
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
MITREへのリンク →

Turla

Score: 25.39
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1099 - Timestomp
  • T1063 - Security Software Discovery
  • T1003.007 - Proc Filesystem
  • T1131 - Authentication Package
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1218.001 - Compiled HTML File
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT32

Score: 17.03
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1131 - Authentication Package
  • T1590.006 - Network Security Appliances
  • T1592.004 - Client Configurations
  • T1608.005 - Link Target
MITREへのリンク →

Saint Bear

Score: 5.78
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

FIN6

Score: 9.58
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1063 - Security Software Discovery
  • T1487 - Disk Structure Wipe
  • T1597 - Search Closed Sources
MITREへのリンク →

Sidewinder

Score: 8.91
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1487 - Disk Structure Wipe
  • T1590.006 - Network Security Appliances
  • T1090 - Proxy
MITREへのリンク →

MuddyWater

Score: 16.33
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1051 - Shared Webroot
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Earth Lusca

Score: 16.93
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1218.001 - Compiled HTML File
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Winter Vivern

Score: 14.05
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1487 - Disk Structure Wipe
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1090 - Proxy
  • T1218.001 - Compiled HTML File
MITREへのリンク →

Silence

Score: 8.16
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1547.011 - Plist Modification
  • T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →

Contagious Interview

Score: 25.43
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1131 - Authentication Package
  • T1183 - Image File Execution Options Injection
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
  • T1656 - Impersonation
  • T1126 - Network Share Connection Removal
MITREへのリンク →

LazyScripter

Score: 5.50
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
MITREへのリンク →

TA505

Score: 15.28
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1527 - Application Access Token
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
MITREへのリンク →

FIN7

Score: 13.52
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1573 - Encrypted Channel
  • T1065 - Uncommonly Used Port
MITREへのリンク →

Cobalt Group

Score: 9.44
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.004 - Spearphishing Voice
  • T1573 - Encrypted Channel
MITREへのリンク →

Higaisa

Score: 6.28
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1590.006 - Network Security Appliances
  • T1665 - Hide Infrastructure
MITREへのリンク →

Kimsuky

Score: 45.14
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1213.006 - Databases
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1131 - Authentication Package
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1546.008 - Accessibility Features
  • T1609 - Container Administration Command
  • T1051 - Shared Webroot
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
  • T1656 - Impersonation
  • T1126 - Network Share Connection Removal
  • T1665 - Hide Infrastructure
MITREへのリンク →

Indrik Spider

Score: 11.10
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1183 - Image File Execution Options Injection
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
MITREへのリンク →

Leafminer

Score: 9.03
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1101 - Security Support Provider
  • T1051 - Shared Webroot
MITREへのリンク →

Mustang Panda

Score: 19.71
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1136.003 - Cloud Account
  • T1055.005 - Thread Local Storage
MITREへのリンク →

TA578

Score: 3.99
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1608.005 - Link Target
MITREへのリンク →

Star Blizzard

Score: 12.15
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1609 - Container Administration Command
MITREへのリンク →

Magic Hound

Score: 19.85
Matched TTPs:
  • T1099 - Timestomp
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

HEXANE

Score: 18.42
Matched TTPs:
  • T1099 - Timestomp
  • T1098.007 - Additional Local or Domain Groups
  • T1070.006 - Timestomp
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1065 - Uncommonly Used Port
MITREへのリンク →

Gamaredon Group

Score: 21.52
Matched TTPs:
  • T1099 - Timestomp
  • T1527 - Application Access Token
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1090 - Proxy
  • T1608.005 - Link Target
  • T1554 - Compromise Host Software Binary
  • T1597 - Search Closed Sources
MITREへのリンク →

TA2541

Score: 8.07
Matched TTPs:
  • T1099 - Timestomp
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

Lotus Blossom

Score: 4.22
Matched TTPs:
  • T1099 - Timestomp
  • T1590.006 - Network Security Appliances
MITREへのリンク →

FIN13

Score: 17.86
Matched TTPs:
  • T1099 - Timestomp
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.005 - Security Support Provider
  • T1590.006 - Network Security Appliances
  • T1051 - Shared Webroot
  • T1134.001 - Token Impersonation/Theft
MITREへのリンク →

HAFNIUM

Score: 16.76
Matched TTPs:
  • T1099 - Timestomp
  • T1487 - Disk Structure Wipe
  • T1140 - Deobfuscate/Decode Files or Information
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1122 - Component Object Model Hijacking
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

Mustard Tempest

Score: 4.54
Matched TTPs:
  • T1682 - Query Public AI Services
MITREへのリンク →

Daggerfly

Score: 9.37
Matched TTPs:
  • T1584.008 - Network Devices
  • T1530 - Data from Cloud Storage
  • T1573 - Encrypted Channel
MITREへのリンク →

GALLIUM

Score: 8.28
Matched TTPs:
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
MITREへのリンク →

Dragonfly

Score: 16.45
Matched TTPs:
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1531 - Account Access Removal
  • T1573 - Encrypted Channel
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Ke3chang

Score: 18.06
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1590.006 - Network Security Appliances
  • T1198 - SIP and Trust Provider Hijacking
  • T1090 - Proxy
MITREへのリンク →

Agrius

Score: 8.05
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
MITREへのリンク →

APT41

Score: 22.47
Matched TTPs:
  • T1584.008 - Network Devices
  • T1140 - Deobfuscate/Decode Files or Information
  • T1590.006 - Network Security Appliances
  • T1177 - LSASS Driver
  • T1048 - Exfiltration Over Alternative Protocol
  • T1573 - Encrypted Channel
  • T1574.009 - Path Interception by Unquoted Path
  • T1564.003 - Hidden Window
MITREへのリンク →

APT5

Score: 7.91
Matched TTPs:
  • T1584.008 - Network Devices
  • T1180 - Screensaver
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

menuPass

Score: 18.57
Matched TTPs:
  • T1584.008 - Network Devices
  • T1527 - Application Access Token
  • T1487 - Disk Structure Wipe
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Threat Group-3390

Score: 22.48
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1218.003 - CMSTP
  • T1590.006 - Network Security Appliances
  • T1122 - Component Object Model Hijacking
  • T1573 - Encrypted Channel
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

Wizard Spider

Score: 11.77
Matched TTPs:
  • T1584.008 - Network Devices
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1083 - File and Directory Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

Ember Bear

Score: 14.01
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1140 - Deobfuscate/Decode Files or Information
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1656 - Impersonation
MITREへのリンク →

Storm-0501

Score: 9.45
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Sandworm Team

Score: 34.55
Matched TTPs:
  • T1063 - Security Software Discovery
  • T1484.002 - Trust Modification
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1122 - Component Object Model Hijacking
  • T1573 - Encrypted Channel
  • T1075 - Pass the Hash
MITREへのリンク →

Sea Turtle

Score: 9.36
Matched TTPs:
  • T1063 - Security Software Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Leviathan

Score: 13.54
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1140 - Deobfuscate/Decode Files or Information
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1554 - Compromise Host Software Binary
MITREへのリンク →

Rocke

Score: 9.45
Matched TTPs:
  • T1180 - Screensaver
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT38

Score: 24.21
Matched TTPs:
  • T1180 - Screensaver
  • T1098.007 - Additional Local or Domain Groups
  • T1503 - Credentials from Web Browsers
  • T1590 - Gather Victim Network Information
  • T1048 - Exfiltration Over Alternative Protocol
  • T1597 - Search Closed Sources
  • T1493 - Transmitted Data Manipulation
MITREへのリンク →

RedCurl

Score: 16.70
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1016.002 - Wi-Fi Discovery
  • T1090 - Proxy
  • T1051 - Shared Webroot
  • T1122 - Component Object Model Hijacking
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT1

Score: 9.98
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
MITREへのリンク →

FIN5

Score: 4.93
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1547.011 - Plist Modification
MITREへのリンク →

Confucius

Score: 7.03
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1608.005 - Link Target
  • T1665 - Hide Infrastructure
MITREへのリンク →

OilRig

Score: 13.66
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1051 - Shared Webroot
  • T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →

Patchwork

Score: 8.86
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1530 - Data from Cloud Storage
  • T1665 - Hide Infrastructure
MITREへのリンク →

Tropic Trooper

Score: 13.91
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1590.006 - Network Security Appliances
  • T1090 - Proxy
  • T1136.003 - Cloud Account
  • T1665 - Hide Infrastructure
MITREへのリンク →

Chimera

Score: 13.55
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1590.006 - Network Security Appliances
  • T1574 - Hijack Execution Flow
  • T1665 - Hide Infrastructure
MITREへのリンク →

BRONZE BUTLER

Score: 10.51
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1592.004 - Client Configurations
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

TeamTNT

Score: 12.66
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1051 - Shared Webroot
  • T1597 - Search Closed Sources
  • T1665 - Hide Infrastructure
MITREへのリンク →

Aquatic Panda

Score: 4.32
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1597 - Search Closed Sources
MITREへのリンク →

admin@338

Score: 3.99
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1590.006 - Network Security Appliances
MITREへのリンク →

PROMETHIUM

Score: 3.84
Matched TTPs:
  • T1530 - Data from Cloud Storage
MITREへのリンク →

GOLD SOUTHFIELD

Score: 7.14
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1122 - Component Object Model Hijacking
  • T1573 - Encrypted Channel
MITREへのリンク →

Medusa Group

Score: 13.17
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
MITREへのリンク →

Fox Kitten

Score: 10.72
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1051 - Shared Webroot
  • T1656 - Impersonation
MITREへのリンク →

Cinnamon Tempest

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.004 - Compile After Delivery
MITREへのリンク →

BlackByte

Score: 8.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1590.006 - Network Security Appliances
  • T1134.001 - Token Impersonation/Theft
  • T1597 - Search Closed Sources
MITREへのリンク →

ToddyCat

Score: 4.30
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1665 - Hide Infrastructure
MITREへのリンク →

INC Ransom

Score: 6.89
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1083 - File and Directory Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

UNC3886

Score: 5.61
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Axiom

Score: 4.76
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
MITREへのリンク →

Play

Score: 8.18
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1590.006 - Network Security Appliances
  • T1597 - Search Closed Sources
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

APT39

Score: 6.56
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.011 - Plist Modification
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Akira

Score: 6.34
Matched TTPs:
  • T1137.005 - Outlook Rules
  • T1597 - Search Closed Sources
MITREへのリンク →

Storm-1811

Score: 6.06
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1486 - Data Encrypted for Impact
MITREへのリンク →

APT42

Score: 5.27
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
MITREへのリンク →

IndigoZebra

Score: 3.53
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
MITREへのリンク →

ZIRCONIUM

Score: 7.34
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Lazarus Group

Score: 27.18
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1070.006 - Timestomp
  • T1183 - Image File Execution Options Injection
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1608.005 - Link Target
  • T1069.001 - Local Groups
  • T1597 - Search Closed Sources
  • T1055.005 - Thread Local Storage
  • T1665 - Hide Infrastructure
MITREへのリンク →

EXOTIC LILY

Score: 3.80
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
MITREへのリンク →

Silent Librarian

Score: 11.09
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1609 - Container Administration Command
MITREへのリンク →

Moonstone Sleet

Score: 12.05
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1573 - Encrypted Channel
  • T1126 - Network Share Connection Removal
MITREへのリンク →

CURIUM

Score: 7.43
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1218.001 - Compiled HTML File
MITREへのリンク →

LAPSUS$

Score: 24.96
Matched TTPs:
  • T1547.005 - Security Support Provider
  • T1020 - Automated Exfiltration
  • T1609 - Container Administration Command
  • T1556.008 - Network Provider DLL
  • T1122 - Component Object Model Hijacking
  • T1065 - Uncommonly Used Port
  • T1564.003 - Hidden Window
MITREへのリンク →

SilverTerrier

Score: 3.29
Matched TTPs:
  • T1131 - Authentication Package
MITREへのリンク →

Tonto Team

Score: 5.09
Matched TTPs:
  • T1547.011 - Plist Modification
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT3

Score: 10.02
Matched TTPs:
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1177 - LSASS Driver
  • T1051 - Shared Webroot
MITREへのリンク →

SideCopy

Score: 5.60
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1584.002 - DNS Server
MITREへのリンク →

Deep Panda

Score: 3.29
Matched TTPs:
  • T1177 - LSASS Driver
MITREへのリンク →

APT17

Score: 5.45
Matched TTPs:
  • T1608.005 - Link Target
  • T1656 - Impersonation
MITREへのリンク →

POLONIUM

Score: 4.76
Matched TTPs:
  • T1608.005 - Link Target
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Dark Caracal

Score: 3.44
Matched TTPs:
  • T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →

DarkHydrus

Score: 4.13
Matched TTPs:
  • T1531 - Account Access Removal
MITREへのリンク →

LuminousMoth

Score: 3.44
Matched TTPs:
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

DarkVishnya

Score: 4.54
Matched TTPs:
  • T1213.003 - Code Repositories
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.70
Matched TTPs:
  • T1051 - Shared Webroot
  • T1003.007 - Proc Filesystem
  • T1027.004 - Compile After Delivery
  • T1546.008 - Accessibility Features
  • T1609 - Container Administration Command
  • T1126 - Network Share Connection Removal
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1665 - Hide Infrastructure
  • T1597 - Search Closed Sources
  • T1131 - Authentication Package
  • T1656 - Impersonation
  • T1546.013 - PowerShell Profile
  • T1608.005 - Link Target
  • T1213.006 - Databases
  • T1140 - Deobfuscate/Decode Files or Information
  • T1183 - Image File Execution Options Injection
MITREへのリンク →

APT29

Score: 0.63
Matched TTPs:
  • T1556.008 - Network Provider DLL
  • T1222.002 - Linux and Mac Permissions
  • T1099 - Timestomp
  • T1027.004 - Compile After Delivery
  • T1202 - Indirect Command Execution
  • T1568 - Dynamic Resolution
  • T1584.008 - Network Devices
  • T1592.004 - Client Configurations
  • T1122 - Component Object Model Hijacking
  • T1177 - LSASS Driver
  • T1547.011 - Plist Modification
  • T1608.005 - Link Target
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Scattered Spider

Score: 0.58
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1051 - Shared Webroot
  • T1556.008 - Network Provider DLL
  • T1547.005 - Security Support Provider
  • T1666 - Modify Cloud Resource Hierarchy
  • T1609 - Container Administration Command
  • T1564.003 - Hidden Window
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1213.002 - Sharepoint
  • T1083 - File and Directory Discovery
  • T1597 - Search Closed Sources
MITREへのリンク →

Volt Typhoon

Score: 0.58
Matched TTPs:
  • T1099 - Timestomp
  • T1070.006 - Timestomp
  • T1003.007 - Proc Filesystem
  • T1547.005 - Security Support Provider
  • T1065 - Uncommonly Used Port
  • T1590.006 - Network Security Appliances
  • T1584.002 - DNS Server
  • T1213.002 - Sharepoint
  • T1083 - File and Directory Discovery
  • T1665 - Hide Infrastructure
  • T1140 - Deobfuscate/Decode Files or Information
  • T1686.003 - Windows Host Firewall
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る