Toy Ghouls’ new toy: the GenieLocker ransomware
概要
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
Created: 2026-07-31
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 27.47
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1139 - Bash History
- T1131 - Authentication Package
- T1547.011 - Plist Modification
- T1218.010 - Regsvr32
- T1197 - BITS Jobs
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 36.10
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1202 - Indirect Command Execution
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1592.004 - Client Configurations
- T1568 - Dynamic Resolution
- T1556.008 - Network Provider DLL
- T1218.010 - Regsvr32
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 25.81
Matched TTPs:
- T1044 - File System Permissions Weakness
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 21.49
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1063 - Security Software Discovery
- T1003.007 - Proc Filesystem
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 27.83
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1592.004 - Client Configurations
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1562.001 - Disable or Modify Tools
- T1218.010 - Regsvr32
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 7.60
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1055.013 - Process Doppelgänging
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 19.51
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1063 - Security Software Discovery
- T1487 - Disk Structure Wipe
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.41
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 17.69
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1518.002 - Backup Software Discovery
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 15.40
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1110.003 - Password Spraying
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 13.40
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1055.013 - Process Doppelgänging
- T1090 - Proxy
- T1588.001 - Malware
MITREへのリンク →
Score: 7.12
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 3.49
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
MITREへのリンク →
Score: 18.38
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1560.003 - Archive via Custom Method
- T1527 - Application Access Token
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 15.59
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 17.81
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1518.002 - Backup Software Discovery
- T1598.004 - Spearphishing Voice
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 9.87
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1218.010 - Regsvr32
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 45.36
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1546.008 - Accessibility Features
- T1588.001 - Malware
- T1609 - Container Administration Command
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
- T1665 - Hide Infrastructure
- T1003.003 - NTDS
MITREへのリンク →
Score: 10.92
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 29.86
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1218.010 - Regsvr32
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 12.15
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1609 - Container Administration Command
MITREへのリンク →
Score: 24.94
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 12.68
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 26.45
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1554 - Compromise Host Software Binary
- T1597 - Search Closed Sources
- T1061 - Graphical User Interface
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 8.81
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 5.95
Matched TTPs:
- T1099 - Timestomp
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 24.83
Matched TTPs:
- T1099 - Timestomp
- T1560.003 - Archive via Custom Method
- T1584.008 - Network Devices
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1144 - Gatekeeper Bypass
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 14.16
Matched TTPs:
- T1099 - Timestomp
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1049 - System Network Connections Discovery
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 32.74
Matched TTPs:
- T1099 - Timestomp
- T1560.003 - Archive via Custom Method
- T1686.003 - Windows Host Firewall
- T1003.007 - Proc Filesystem
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1049 - System Network Connections Discovery
- T1584.002 - DNS Server
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 10.58
Matched TTPs:
- T1099 - Timestomp
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1682 - Query Public AI Services
MITREへのリンク →
Score: 29.61
Matched TTPs:
- T1560.003 - Archive via Custom Method
- T1584.008 - Network Devices
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1208 - Kerberoasting
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 39.51
Matched TTPs:
- T1560.003 - Archive via Custom Method
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1144 - Gatekeeper Bypass
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1197 - BITS Jobs
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 14.01
Matched TTPs:
- T1560.003 - Archive via Custom Method
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 5.52
Matched TTPs:
- T1584.008 - Network Devices
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 8.54
Matched TTPs:
- T1584.008 - Network Devices
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 14.68
Matched TTPs:
- T1584.008 - Network Devices
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 20.67
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1198 - SIP and Trust Provider Hijacking
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 6.58
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 4.33
Matched TTPs:
- T1584.008 - Network Devices
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 16.09
Matched TTPs:
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 13.92
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 16.61
Matched TTPs:
- T1584.008 - Network Devices
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 14.60
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1218.010 - Regsvr32
- T1003.003 - NTDS
MITREへのリンク →
Score: 16.26
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1588.001 - Malware
- T1027 - Obfuscated Files or Information
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 41.92
Matched TTPs:
- T1063 - Security Software Discovery
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1049 - System Network Connections Discovery
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1075 - Pass the Hash
MITREへのリンク →
Score: 6.63
Matched TTPs:
- T1063 - Security Software Discovery
- T1098.007 - Additional Local or Domain Groups
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 13.56
Matched TTPs:
- T1484.002 - Trust Modification
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1554 - Compromise Host Software Binary
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 18.03
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1128 - Netsh Helper DLL
- T1027.004 - Compile After Delivery
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 11.72
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.27
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1218.010 - Regsvr32
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 23.30
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1055.004 - Asynchronous Procedure Call
- T1218.010 - Regsvr32
- T1592.002 - Software
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1218.010 - Regsvr32
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 19.88
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1218.010 - Regsvr32
- T1128 - Netsh Helper DLL
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 10.75
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 12.00
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1592.004 - Client Configurations
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 15.72
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1110.003 - Password Spraying
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 10.26
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1144 - Gatekeeper Bypass
- T1588.001 - Malware
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.22
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 8.68
Matched TTPs:
- T1137.005 - Outlook Rules
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 8.02
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.01
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 10.86
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
MITREへのリンク →
Score: 6.66
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 31.79
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1218.010 - Regsvr32
- T1055.005 - Thread Local Storage
- T1665 - Hide Infrastructure
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 5.30
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 11.09
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 16.47
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1055.004 - Asynchronous Procedure Call
- T1590 - Gather Victim Network Information
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1493 - Transmitted Data Manipulation
MITREへのリンク →
Score: 13.98
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1197 - BITS Jobs
MITREへのリンク →
Score: 5.11
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1588.001 - Malware
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 3.80
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 16.11
Matched TTPs:
- T1546.011 - Application Shimming
- T1588.001 - Malware
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
- T1027.004 - Compile After Delivery
- T1003.006 - DCSync
MITREへのリンク →
Score: 14.06
Matched TTPs:
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 10.64
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 7.43
Matched TTPs:
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.58
Matched TTPs:
- T1547.011 - Plist Modification
- T1218.010 - Regsvr32
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.59
Matched TTPs:
- T1110.003 - Password Spraying
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 3.27
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 9.74
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1134.001 - Token Impersonation/Theft
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 5.60
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1584.002 - DNS Server
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 3.57
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1177 - LSASS Driver
- T1049 - System Network Connections Discovery
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 7.72
Matched TTPs:
- T1177 - LSASS Driver
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
MITREへのリンク →
Score: 6.17
Matched TTPs:
- T1055.013 - Process Doppelgänging
- T1218.010 - Regsvr32
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.49
Matched TTPs:
- T1588.001 - Malware
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 3.83
Matched TTPs:
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 13.34
Matched TTPs:
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 3.23
Matched TTPs:
- T1055.004 - Asynchronous Procedure Call
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 8.68
Matched TTPs:
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.57
Matched TTPs:
- T1055.004 - Asynchronous Procedure Call
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 6.54
Matched TTPs:
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.64
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1218.010 - Regsvr32
- T1556 - Modify Authentication Process
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1131 - Authentication Package
- T1597 - Search Closed Sources
- T1183 - Image File Execution Options Injection
- T1588.001 - Malware
- T1546.008 - Accessibility Features
- T1003.003 - NTDS
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1546.013 - PowerShell Profile
- T1546.011 - Application Shimming
- T1197 - BITS Jobs
- T1213.006 - Databases
- T1027.004 - Compile After Delivery
- T1590.006 - Network Security Appliances
- T1609 - Container Administration Command
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 0.65
Matched TTPs:
- T1686.003 - Windows Host Firewall
- T1183 - Image File Execution Options Injection
- T1016.002 - Wi-Fi Discovery
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1484.002 - Trust Modification
- T1027 - Obfuscated Files or Information
- T1075 - Pass the Hash
- T1098.007 - Additional Local or Domain Groups
- T1573 - Encrypted Channel
- T1063 - Security Software Discovery
- T1049 - System Network Connections Discovery
- T1218.010 - Regsvr32
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 0.61
Matched TTPs:
- T1560.003 - Archive via Custom Method
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1564.003 - Hidden Window
- T1027 - Obfuscated Files or Information
- T1144 - Gatekeeper Bypass
- T1197 - BITS Jobs
- T1098.007 - Additional Local or Domain Groups
- T1685.004 - Disable or Modify Linux Audit System Log
- T1590.006 - Network Security Appliances
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
MITREへのリンク →
Score: 0.56
Matched TTPs:
- T1568 - Dynamic Resolution
- T1099 - Timestomp
- T1218.010 - Regsvr32
- T1584.008 - Network Devices
- T1027.004 - Compile After Delivery
- T1547.011 - Plist Modification
- T1222.002 - Linux and Mac Permissions
- T1592.004 - Client Configurations
- T1177 - LSASS Driver
- T1202 - Indirect Command Execution
- T1556.008 - Network Provider DLL
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る