Trusted Design

ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security

概要

Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...

Created: 2026-08-05

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

APT32

Score: 31.70
Matched TTPs:
  • T1113 - Screen Capture
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1592.004 - Client Configurations
  • T1055.004 - Asynchronous Procedure Call
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1556 - Modify Authentication Process
MITREへのリンク →

Turla

Score: 25.70
Matched TTPs:
  • T1113 - Screen Capture
  • T1546.013 - PowerShell Profile
  • T1099 - Timestomp
  • T1063 - Security Software Discovery
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

Scattered Spider

Score: 37.77
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
  • T1560.003 - Archive via Custom Method
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1165 - Startup Items
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1083 - File and Directory Discovery
  • T1552.003 - Shell History
  • T1087.004 - Cloud Account
  • T1556.008 - Network Provider DLL
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1197 - BITS Jobs
MITREへのリンク →

FIN4

Score: 5.01
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Saint Bear

Score: 7.61
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

FIN6

Score: 18.76
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1063 - Security Software Discovery
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sidewinder

Score: 10.18
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1090 - Proxy
  • T1601.001 - Patch System Image
MITREへのリンク →

MuddyWater

Score: 18.27
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1547.011 - Plist Modification
  • T1055.004 - Asynchronous Procedure Call
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

Earth Lusca

Score: 15.95
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1110.003 - Password Spraying
  • T1055.004 - Asynchronous Procedure Call
  • T1608.005 - Link Target
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Winter Vivern

Score: 16.05
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1587.003 - Digital Certificates
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1090 - Proxy
  • T1087.004 - Cloud Account
  • T1591.004 - Identify Roles
MITREへのリンク →

Silence

Score: 14.25
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1547.011 - Plist Modification
  • T1048 - Exfiltration Over Alternative Protocol
  • T1562.001 - Disable or Modify Tools
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

Contagious Interview

Score: 31.45
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1021.006 - Windows Remote Management
  • T1183 - Image File Execution Options Injection
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1556 - Modify Authentication Process
MITREへのリンク →

LazyScripter

Score: 9.20
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

TA505

Score: 22.07
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1560.003 - Archive via Custom Method
  • T1527 - Application Access Token
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

FIN7

Score: 25.06
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1165 - Startup Items
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1608.005 - Link Target
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
  • T1573 - Encrypted Channel
  • T1065 - Uncommonly Used Port
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

Cobalt Group

Score: 18.62
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1598.004 - Spearphishing Voice
  • T1027.014 - Polymorphic Code
  • T1573 - Encrypted Channel
  • T1128 - Netsh Helper DLL
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

Higaisa

Score: 8.61
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1087.004 - Cloud Account
  • T1591.004 - Identify Roles
  • T1665 - Hide Infrastructure
MITREへのリンク →

Kimsuky

Score: 46.51
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1213.006 - Databases
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1027.014 - Polymorphic Code
  • T1027.004 - Compile After Delivery
  • T1197 - BITS Jobs
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1665 - Hide Infrastructure
  • T1003.003 - NTDS
MITREへのリンク →

Indrik Spider

Score: 14.11
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1165 - Startup Items
  • T1003.007 - Proc Filesystem
  • T1183 - Image File Execution Options Injection
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

Leafminer

Score: 8.37
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1101 - Security Support Provider
  • T1601.001 - Patch System Image
MITREへのリンク →

Mustang Panda

Score: 26.52
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1055.004 - Asynchronous Procedure Call
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1136.003 - Cloud Account
  • T1591.004 - Identify Roles
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

TA578

Score: 3.99
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1608.005 - Link Target
MITREへのリンク →

Star Blizzard

Score: 9.58
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
MITREへのリンク →

Magic Hound

Score: 31.83
Matched TTPs:
  • T1099 - Timestomp
  • T1587.003 - Digital Certificates
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1547.005 - Security Support Provider
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1055.004 - Asynchronous Procedure Call
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

HEXANE

Score: 16.70
Matched TTPs:
  • T1099 - Timestomp
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1055.004 - Asynchronous Procedure Call
  • T1065 - Uncommonly Used Port
  • T1601.001 - Patch System Image
MITREへのリンク →

APT29

Score: 28.82
Matched TTPs:
  • T1099 - Timestomp
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1202 - Indirect Command Execution
  • T1547.011 - Plist Modification
  • T1177 - LSASS Driver
  • T1592.004 - Client Configurations
  • T1608.005 - Link Target
  • T1556.008 - Network Provider DLL
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Gamaredon Group

Score: 34.12
Matched TTPs:
  • T1099 - Timestomp
  • T1527 - Application Access Token
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1090 - Proxy
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1554 - Compromise Host Software Binary
  • T1597 - Search Closed Sources
  • T1061 - Graphical User Interface
  • T1562.001 - Disable or Modify Tools
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

TA2541

Score: 11.69
Matched TTPs:
  • T1099 - Timestomp
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Lotus Blossom

Score: 4.48
Matched TTPs:
  • T1099 - Timestomp
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

FIN13

Score: 23.13
Matched TTPs:
  • T1099 - Timestomp
  • T1560.003 - Archive via Custom Method
  • T1584.008 - Network Devices
  • T1165 - Startup Items
  • T1547.005 - Security Support Provider
  • T1055.004 - Asynchronous Procedure Call
  • T1552.003 - Shell History
  • T1134.001 - Token Impersonation/Theft
  • T1591.004 - Identify Roles
MITREへのリンク →

HAFNIUM

Score: 12.03
Matched TTPs:
  • T1099 - Timestomp
  • T1487 - Disk Structure Wipe
  • T1608.005 - Link Target
  • T1591.004 - Identify Roles
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

Volt Typhoon

Score: 32.23
Matched TTPs:
  • T1099 - Timestomp
  • T1560.003 - Archive via Custom Method
  • T1686.003 - Windows Host Firewall
  • T1003.007 - Proc Filesystem
  • T1547.005 - Security Support Provider
  • T1083 - File and Directory Discovery
  • T1055.004 - Asynchronous Procedure Call
  • T1584.002 - DNS Server
  • T1065 - Uncommonly Used Port
  • T1591.004 - Identify Roles
  • T1665 - Hide Infrastructure
MITREへのリンク →

FIN8

Score: 14.27
Matched TTPs:
  • T1099 - Timestomp
  • T1598.003 - Spearphishing Link
  • T1027 - Obfuscated Files or Information
  • T1128 - Netsh Helper DLL
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT41

Score: 24.87
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1177 - LSASS Driver
  • T1055.004 - Asynchronous Procedure Call
  • T1048 - Exfiltration Over Alternative Protocol
  • T1027 - Obfuscated Files or Information
  • T1573 - Encrypted Channel
  • T1574.009 - Path Interception by Unquoted Path
  • T1591.004 - Identify Roles
MITREへのリンク →

APT3

Score: 13.98
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1547.011 - Plist Modification
  • T1177 - LSASS Driver
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1591.004 - Identify Roles
MITREへのリンク →

Daggerfly

Score: 9.37
Matched TTPs:
  • T1584.008 - Network Devices
  • T1530 - Data from Cloud Storage
  • T1573 - Encrypted Channel
MITREへのリンク →

GALLIUM

Score: 10.00
Matched TTPs:
  • T1584.008 - Network Devices
  • T1547.011 - Plist Modification
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1591.004 - Identify Roles
MITREへのリンク →

Dragonfly

Score: 13.55
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1573 - Encrypted Channel
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
MITREへのリンク →

Ke3chang

Score: 19.79
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1198 - SIP and Trust Provider Hijacking
  • T1090 - Proxy
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1591.004 - Identify Roles
MITREへのリンク →

Agrius

Score: 9.50
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

APT5

Score: 7.52
Matched TTPs:
  • T1584.008 - Network Devices
  • T1165 - Startup Items
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
MITREへのリンク →

menuPass

Score: 18.69
Matched TTPs:
  • T1584.008 - Network Devices
  • T1527 - Application Access Token
  • T1165 - Startup Items
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1547.011 - Plist Modification
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
MITREへのリンク →

Threat Group-3390

Score: 24.20
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1218.003 - CMSTP
  • T1055.004 - Asynchronous Procedure Call
  • T1573 - Encrypted Channel
  • T1574.009 - Path Interception by Unquoted Path
  • T1591.004 - Identify Roles
  • T1591.001 - Determine Physical Locations
MITREへのリンク →

Wizard Spider

Score: 18.71
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1183 - Image File Execution Options Injection
  • T1083 - File and Directory Discovery
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1556 - Modify Authentication Process
MITREへのリンク →

Ember Bear

Score: 13.11
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1003.003 - NTDS
MITREへのリンク →

RedCurl

Score: 19.29
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1016.002 - Wi-Fi Discovery
  • T1090 - Proxy
  • T1128 - Netsh Helper DLL
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
MITREへのリンク →

Sea Turtle

Score: 8.42
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1063 - Security Software Discovery
  • T1098.007 - Additional Local or Domain Groups
MITREへのリンク →

APT1

Score: 15.36
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
MITREへのリンク →

Chimera

Score: 17.35
Matched TTPs:
  • T1587.003 - Digital Certificates
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1665 - Hide Infrastructure
MITREへのリンク →

Storm-0501

Score: 15.59
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1686.003 - Windows Host Firewall
  • T1552.003 - Shell History
  • T1027 - Obfuscated Files or Information
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Sandworm Team

Score: 36.98
Matched TTPs:
  • T1063 - Security Software Discovery
  • T1484.002 - Trust Modification
  • T1686.003 - Windows Host Firewall
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
  • T1573 - Encrypted Channel
  • T1601.001 - Patch System Image
MITREへのリンク →

Leviathan

Score: 19.90
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1165 - Startup Items
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1087.004 - Cloud Account
  • T1554 - Compromise Host Software Binary
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Lazarus Group

Score: 37.12
Matched TTPs:
  • T1165 - Startup Items
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1547.011 - Plist Modification
  • T1055.004 - Asynchronous Procedure Call
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1069.001 - Local Groups
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1591.004 - Identify Roles
  • T1055.005 - Thread Local Storage
  • T1665 - Hide Infrastructure
  • T1556 - Modify Authentication Process
MITREへのリンク →

BlackTech

Score: 3.11
Matched TTPs:
  • T1165 - Startup Items
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Aquatic Panda

Score: 9.37
Matched TTPs:
  • T1165 - Startup Items
  • T1003.007 - Proc Filesystem
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

Fox Kitten

Score: 8.34
Matched TTPs:
  • T1165 - Startup Items
  • T1177 - LSASS Driver
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

TeamTNT

Score: 19.78
Matched TTPs:
  • T1165 - Startup Items
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1110.003 - Password Spraying
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
  • T1665 - Hide Infrastructure
MITREへのリンク →

Storm-1811

Score: 19.28
Matched TTPs:
  • T1165 - Startup Items
  • T1098.007 - Additional Local or Domain Groups
  • T1205.001 - Port Knocking
  • T1027 - Obfuscated Files or Information
  • T1599 - Network Boundary Bridging
  • T1486 - Data Encrypted for Impact
  • T1591.004 - Identify Roles
MITREへのリンク →

Salt Typhoon

Score: 11.17
Matched TTPs:
  • T1165 - Startup Items
  • T1009 - Binary Padding
  • T1110.003 - Password Spraying
  • T1556 - Modify Authentication Process
MITREへのリンク →

OilRig

Score: 27.84
Matched TTPs:
  • T1165 - Startup Items
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1048 - Exfiltration Over Alternative Protocol
  • T1592.002 - Software
  • T1128 - Netsh Helper DLL
  • T1591.004 - Identify Roles
  • T1556 - Modify Authentication Process
MITREへのリンク →

UNC3886

Score: 13.80
Matched TTPs:
  • T1165 - Startup Items
  • T1009 - Binary Padding
  • T1021.006 - Windows Remote Management
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
MITREへのリンク →

Rocke

Score: 11.11
Matched TTPs:
  • T1165 - Startup Items
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT39

Score: 14.01
Matched TTPs:
  • T1165 - Startup Items
  • T1598.003 - Spearphishing Link
  • T1547.011 - Plist Modification
  • T1087.004 - Cloud Account
  • T1599 - Network Boundary Bridging
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Tropic Trooper

Score: 18.75
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1090 - Proxy
  • T1055.004 - Asynchronous Procedure Call
  • T1136.003 - Cloud Account
  • T1128 - Netsh Helper DLL
  • T1591.004 - Identify Roles
  • T1665 - Hide Infrastructure
MITREへのリンク →

APT28

Score: 25.15
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1547.011 - Plist Modification
  • T1608.005 - Link Target
  • T1205.001 - Port Knocking
  • T1574.009 - Path Interception by Unquoted Path
  • T1197 - BITS Jobs
  • T1591.004 - Identify Roles
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

admin@338

Score: 6.09
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
MITREへのリンク →

BRONZE BUTLER

Score: 16.18
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1592.004 - Client Configurations
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
  • T1591.001 - Determine Physical Locations
MITREへのリンク →

WIRTE

Score: 6.02
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Inception

Score: 3.62
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
MITREへのリンク →

EXOTIC LILY

Score: 4.68
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
MITREへのリンク →

APT33

Score: 6.02
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1556 - Modify Authentication Process
MITREへのリンク →

Patchwork

Score: 12.56
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1530 - Data from Cloud Storage
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
  • T1665 - Hide Infrastructure
MITREへのリンク →

TA551

Score: 6.44
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

Confucius

Score: 9.88
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1487 - Disk Structure Wipe
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1665 - Hide Infrastructure
MITREへのリンク →

Gorgon Group

Score: 3.63
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1597 - Search Closed Sources
  • T1591.004 - Identify Roles
MITREへのリンク →

APT12

Score: 5.41
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1055.002 - Portable Executable Injection
MITREへのリンク →

APT19

Score: 5.48
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
  • T1601.001 - Patch System Image
MITREへのリンク →

Malteiro

Score: 3.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1552.003 - Shell History
MITREへのリンク →

SideCopy

Score: 5.01
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1584.002 - DNS Server
MITREへのリンク →

Moonstone Sleet

Score: 13.39
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1027 - Obfuscated Files or Information
  • T1573 - Encrypted Channel
  • T1197 - BITS Jobs
MITREへのリンク →

Machete

Score: 4.17
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
MITREへのリンク →

Tonto Team

Score: 5.96
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1547.011 - Plist Modification
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT37

Score: 4.17
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
MITREへのリンク →

CURIUM

Score: 10.50
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1205.001 - Port Knocking
  • T1087.004 - Cloud Account
MITREへのリンク →

IndigoZebra

Score: 4.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
MITREへのリンク →

APT38

Score: 24.07
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1590 - Gather Victim Network Information
  • T1048 - Exfiltration Over Alternative Protocol
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1493 - Transmitted Data Manipulation
  • T1591.004 - Identify Roles
MITREへのリンク →

APT-C-36

Score: 3.27
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

FIN5

Score: 4.93
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1547.011 - Plist Modification
MITREへのリンク →

Poseidon Group

Score: 4.26
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

PROMETHIUM

Score: 3.84
Matched TTPs:
  • T1530 - Data from Cloud Storage
MITREへのリンク →

APT42

Score: 10.40
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1599 - Network Boundary Bridging
  • T1128 - Netsh Helper DLL
MITREへのリンク →

ZIRCONIUM

Score: 12.24
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1087.004 - Cloud Account
  • T1027.004 - Compile After Delivery
  • T1197 - BITS Jobs
  • T1591.004 - Identify Roles
MITREへのリンク →

RedEcho

Score: 6.66
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Silent Librarian

Score: 7.65
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
MITREへのリンク →

Medusa Group

Score: 23.00
Matched TTPs:
  • T1218.003 - CMSTP
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1552.003 - Shell History
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1128 - Netsh Helper DLL
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

LAPSUS$

Score: 10.40
Matched TTPs:
  • T1547.005 - Security Support Provider
  • T1556.008 - Network Provider DLL
  • T1065 - Uncommonly Used Port
MITREへのリンク →

ToddyCat

Score: 7.86
Matched TTPs:
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1591.004 - Identify Roles
  • T1665 - Hide Infrastructure
MITREへのリンク →

Velvet Ant

Score: 11.02
Matched TTPs:
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
MITREへのリンク →

BlackByte

Score: 13.54
Matched TTPs:
  • T1009 - Binary Padding
  • T1134.001 - Token Impersonation/Theft
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

Deep Panda

Score: 6.03
Matched TTPs:
  • T1177 - LSASS Driver
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Axiom

Score: 3.29
Matched TTPs:
  • T1177 - LSASS Driver
MITREへのリンク →

INC Ransom

Score: 12.97
Matched TTPs:
  • T1083 - File and Directory Discovery
  • T1055.004 - Asynchronous Procedure Call
  • T1552.003 - Shell History
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1591.004 - Identify Roles
MITREへのリンク →

Cinnamon Tempest

Score: 5.82
Matched TTPs:
  • T1552.003 - Shell History
  • T1027.004 - Compile After Delivery
  • T1591.004 - Identify Roles
MITREへのリンク →

Akira

Score: 6.66
Matched TTPs:
  • T1552.003 - Shell History
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Water Galura

Score: 4.86
Matched TTPs:
  • T1552.003 - Shell History
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Play

Score: 10.58
Matched TTPs:
  • T1552.003 - Shell History
  • T1597 - Search Closed Sources
  • T1574.009 - Path Interception by Unquoted Path
  • T1591.004 - Identify Roles
  • T1601.001 - Patch System Image
MITREへのリンク →

LuminousMoth

Score: 5.41
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

Dark Caracal

Score: 4.39
Matched TTPs:
  • T1048 - Exfiltration Over Alternative Protocol
  • T1591.004 - Identify Roles
MITREへのリンク →

Blue Mockingbird

Score: 3.70
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1591.004 - Identify Roles
MITREへのリンク →

GOLD SOUTHFIELD

Score: 4.79
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1601.001 - Patch System Image
MITREへのリンク →

APT18

Score: 4.80
Matched TTPs:
  • T1591.004 - Identify Roles
  • T1591.001 - Determine Physical Locations
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.70
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1027.014 - Polymorphic Code
  • T1665 - Hide Infrastructure
  • T1003.007 - Proc Filesystem
  • T1087.004 - Cloud Account
  • T1598.003 - Spearphishing Link
  • T1197 - BITS Jobs
  • T1009 - Binary Padding
  • T1003.003 - NTDS
  • T1546.008 - Accessibility Features
  • T1213.006 - Databases
  • T1546.013 - PowerShell Profile
  • T1183 - Image File Execution Options Injection
  • T1591.004 - Identify Roles
  • T1552.003 - Shell History
  • T1597 - Search Closed Sources
  • T1608.005 - Link Target
  • T1601.001 - Patch System Image
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Scattered Spider

Score: 0.57
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1098.007 - Additional Local or Domain Groups
  • T1556.008 - Network Provider DLL
  • T1165 - Startup Items
  • T1197 - BITS Jobs
  • T1666 - Modify Cloud Resource Hierarchy
  • T1083 - File and Directory Discovery
  • T1560.003 - Archive via Custom Method
  • T1547.005 - Security Support Provider
  • T1027 - Obfuscated Files or Information
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1552.003 - Shell History
MITREへのリンク →

Lazarus Group

Score: 0.56
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1598.003 - Spearphishing Link
  • T1597 - Search Closed Sources
  • T1183 - Image File Execution Options Injection
  • T1098.007 - Additional Local or Domain Groups
  • T1608.005 - Link Target
  • T1055.005 - Thread Local Storage
  • T1165 - Startup Items
  • T1009 - Binary Padding
  • T1556 - Modify Authentication Process
  • T1591.004 - Identify Roles
  • T1665 - Hide Infrastructure
  • T1562.001 - Disable or Modify Tools
  • T1069.001 - Local Groups
  • T1055.004 - Asynchronous Procedure Call
  • T1547.011 - Plist Modification
MITREへのリンク →

Sandworm Team

Score: 0.56
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1484.002 - Trust Modification
  • T1573 - Encrypted Channel
  • T1601.001 - Patch System Image
  • T1063 - Security Software Discovery
  • T1027 - Obfuscated Files or Information
  • T1686.003 - Windows Host Firewall
  • T1016.002 - Wi-Fi Discovery
  • T1546.008 - Accessibility Features
  • T1562.001 - Disable or Modify Tools
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る