Trusted Design

Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

概要

A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.

Created: 2026-08-11

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

APT28

Score: 34.64
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1071.005 - Publish/Subscribe Protocols
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1131 - Authentication Package
  • T1562.004 - Disable or Modify System Firewall
  • T1547.011 - Plist Modification
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
  • T1574.009 - Path Interception by Unquoted Path
  • T1055.008 - Ptrace System Calls
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

APT29

Score: 34.16
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1584.008 - Network Devices
  • T1202 - Indirect Command Execution
  • T1562.004 - Disable or Modify System Firewall
  • T1547.011 - Plist Modification
  • T1177 - LSASS Driver
  • T1568 - Dynamic Resolution
  • T1556.008 - Network Provider DLL
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Turla

Score: 19.55
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1063 - Security Software Discovery
  • T1003.007 - Proc Filesystem
  • T1131 - Authentication Package
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT32

Score: 28.01
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1131 - Authentication Package
  • T1590.006 - Network Security Appliances
  • T1055.013 - Process Doppelgänging
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
  • T1556 - Modify Authentication Process
MITREへのリンク →

Saint Bear

Score: 10.76
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1055.013 - Process Doppelgänging
  • T1064 - Scripting
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
MITREへのリンク →

FIN6

Score: 20.31
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1063 - Security Software Discovery
  • T1487 - Disk Structure Wipe
  • T1055.013 - Process Doppelgänging
  • T1588.001 - Malware
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sidewinder

Score: 9.71
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1487 - Disk Structure Wipe
  • T1590.006 - Network Security Appliances
  • T1090 - Proxy
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

MuddyWater

Score: 21.49
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1071.005 - Publish/Subscribe Protocols
  • T1518.002 - Backup Software Discovery
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Earth Lusca

Score: 14.95
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1562.004 - Disable or Modify System Firewall
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Winter Vivern

Score: 18.76
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1562.004 - Disable or Modify System Firewall
  • T1055.013 - Process Doppelgänging
  • T1090 - Proxy
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

Silence

Score: 11.36
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1547.011 - Plist Modification
  • T1497.002 - User Activity Based Checks
  • T1048 - Exfiltration Over Alternative Protocol
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Contagious Interview

Score: 33.75
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1071.005 - Publish/Subscribe Protocols
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1131 - Authentication Package
  • T1021.006 - Windows Remote Management
  • T1183 - Image File Execution Options Injection
  • T1064 - Scripting
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027.004 - Compile After Delivery
  • T1556 - Modify Authentication Process
MITREへのリンク →

LazyScripter

Score: 7.04
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1098.007 - Additional Local or Domain Groups
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

TA505

Score: 15.90
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1527 - Application Access Token
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

FIN7

Score: 18.55
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1055.013 - Process Doppelgänging
  • T1588.001 - Malware
  • T1497.002 - User Activity Based Checks
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Cobalt Group

Score: 15.14
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1518.002 - Backup Software Discovery
  • T1497.002 - User Activity Based Checks
  • T1027.014 - Polymorphic Code
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Higaisa

Score: 10.03
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1071.005 - Publish/Subscribe Protocols
  • T1590.006 - Network Security Appliances
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
MITREへのリンク →

Kimsuky

Score: 38.97
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1213.006 - Databases
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1131 - Authentication Package
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1546.008 - Accessibility Features
  • T1588.001 - Malware
  • T1609 - Container Administration Command
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027.014 - Polymorphic Code
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Indrik Spider

Score: 11.72
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1183 - Image File Execution Options Injection
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Leafminer

Score: 6.51
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1101 - Security Support Provider
MITREへのリンク →

Mustang Panda

Score: 33.44
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1071.005 - Publish/Subscribe Protocols
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1055.013 - Process Doppelgänging
  • T1677 - Poisoned Pipeline Execution
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1136.003 - Cloud Account
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

Star Blizzard

Score: 12.15
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1609 - Container Administration Command
MITREへのリンク →

APT37

Score: 9.22
Matched TTPs:
  • T1485.001 - Lifecycle-Triggered Deletion
  • T1055.013 - Process Doppelgänging
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Mustard Tempest

Score: 4.54
Matched TTPs:
  • T1682 - Query Public AI Services
MITREへのリンク →

Daggerfly

Score: 3.39
Matched TTPs:
  • T1584.008 - Network Devices
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

GALLIUM

Score: 11.32
Matched TTPs:
  • T1584.008 - Network Devices
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

FIN13

Score: 15.75
Matched TTPs:
  • T1584.008 - Network Devices
  • T1547.005 - Security Support Provider
  • T1590.006 - Network Security Appliances
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1134.001 - Token Impersonation/Theft
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

Dragonfly

Score: 20.13
Matched TTPs:
  • T1584.008 - Network Devices
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1562.004 - Disable or Modify System Firewall
  • T1590.006 - Network Security Appliances
  • T1055.013 - Process Doppelgänging
  • T1497.002 - User Activity Based Checks
  • T1531 - Account Access Removal
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Ke3chang

Score: 25.39
Matched TTPs:
  • T1584.008 - Network Devices
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1590.006 - Network Security Appliances
  • T1055.013 - Process Doppelgänging
  • T1198 - SIP and Trust Provider Hijacking
  • T1090 - Proxy
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
MITREへのリンク →

Agrius

Score: 8.55
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1087.004 - Cloud Account
  • T1597 - Search Closed Sources
MITREへのリンク →

APT41

Score: 26.54
Matched TTPs:
  • T1584.008 - Network Devices
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1562.004 - Disable or Modify System Firewall
  • T1590.006 - Network Security Appliances
  • T1177 - LSASS Driver
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1048 - Exfiltration Over Alternative Protocol
  • T1027 - Obfuscated Files or Information
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

APT5

Score: 12.59
Matched TTPs:
  • T1584.008 - Network Devices
  • T1180 - Screensaver
  • T1677 - Poisoned Pipeline Execution
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

menuPass

Score: 19.64
Matched TTPs:
  • T1584.008 - Network Devices
  • T1527 - Application Access Token
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Threat Group-3390

Score: 21.02
Matched TTPs:
  • T1584.008 - Network Devices
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
  • T1678 - Delay Execution
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

Wizard Spider

Score: 23.52
Matched TTPs:
  • T1584.008 - Network Devices
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1588.001 - Malware
  • T1083 - File and Directory Discovery
  • T1567.001 - Exfiltration to Code Repository
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1556 - Modify Authentication Process
MITREへのリンク →

Ember Bear

Score: 15.11
Matched TTPs:
  • T1584.008 - Network Devices
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1487 - Disk Structure Wipe
  • T1562.004 - Disable or Modify System Firewall
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Chimera

Score: 13.43
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

OilRig

Score: 30.44
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1487 - Disk Structure Wipe
  • T1566.001 - Spearphishing Attachment
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1590.006 - Network Security Appliances
  • T1055.013 - Process Doppelgänging
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1048 - Exfiltration Over Alternative Protocol
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT39

Score: 16.79
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1566.001 - Spearphishing Attachment
  • T1547.011 - Plist Modification
  • T1055.013 - Process Doppelgänging
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Tropic Trooper

Score: 18.30
Matched TTPs:
  • T1195.001 - Compromise Software Dependencies and Development Tools
  • T1487 - Disk Structure Wipe
  • T1590.006 - Network Security Appliances
  • T1090 - Proxy
  • T1055.004 - Asynchronous Procedure Call
  • T1136.003 - Cloud Account
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Scattered Spider

Score: 27.87
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1590.006 - Network Security Appliances
  • T1609 - Container Administration Command
  • T1083 - File and Directory Discovery
  • T1087.004 - Cloud Account
  • T1556.008 - Network Provider DLL
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Storm-0501

Score: 15.96
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1686.003 - Windows Host Firewall
  • T1588.001 - Malware
  • T1497.002 - User Activity Based Checks
  • T1027 - Obfuscated Files or Information
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Sandworm Team

Score: 41.99
Matched TTPs:
  • T1063 - Security Software Discovery
  • T1484.002 - Trust Modification
  • T1686.003 - Windows Host Firewall
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1562.004 - Disable or Modify System Firewall
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
  • T1075 - Pass the Hash
MITREへのリンク →

Sea Turtle

Score: 7.89
Matched TTPs:
  • T1063 - Security Software Discovery
  • T1098.007 - Additional Local or Domain Groups
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Darkhotel

Score: 7.84
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1590.006 - Network Security Appliances
  • T1064 - Scripting
MITREへのリンク →

Lazarus Group

Score: 38.72
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1677 - Poisoned Pipeline Execution
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1069.001 - Local Groups
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

ZIRCONIUM

Score: 11.92
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1098.007 - Additional Local or Domain Groups
  • T1590.006 - Network Security Appliances
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Volt Typhoon

Score: 27.42
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1686.003 - Windows Host Firewall
  • T1003.007 - Proc Filesystem
  • T1547.005 - Security Support Provider
  • T1590.006 - Network Security Appliances
  • T1083 - File and Directory Discovery
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1488 - Disk Content Wipe
  • T1584.002 - DNS Server
MITREへのリンク →

RedCurl

Score: 20.25
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1487 - Disk Structure Wipe
  • T1016.002 - Wi-Fi Discovery
  • T1090 - Proxy
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
  • T1128 - Netsh Helper DLL
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Stealth Falcon

Score: 9.11
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1590.006 - Network Security Appliances
  • T1055.013 - Process Doppelgänging
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

Inception

Score: 6.07
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1497.002 - User Activity Based Checks
  • T1027.014 - Polymorphic Code
MITREへのリンク →

APT33

Score: 12.60
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1567.001 - Exfiltration to Code Repository
  • T1497.002 - User Activity Based Checks
  • T1562.001 - Disable or Modify Tools
  • T1556 - Modify Authentication Process
MITREへのリンク →

BRONZE BUTLER

Score: 9.98
Matched TTPs:
  • T1071.005 - Publish/Subscribe Protocols
  • T1003.007 - Proc Filesystem
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Leviathan

Score: 24.03
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1098.007 - Additional Local or Domain Groups
  • T1562.004 - Disable or Modify System Firewall
  • T1183 - Image File Execution Options Injection
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1554 - Compromise Host Software Binary
  • T1027.014 - Polymorphic Code
  • T1488 - Disk Content Wipe
MITREへのリンク →

Gamaredon Group

Score: 21.93
Matched TTPs:
  • T1527 - Application Access Token
  • T1487 - Disk Structure Wipe
  • T1098.007 - Additional Local or Domain Groups
  • T1090 - Proxy
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1554 - Compromise Host Software Binary
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Rocke

Score: 12.72
Matched TTPs:
  • T1180 - Screensaver
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT38

Score: 35.27
Matched TTPs:
  • T1180 - Screensaver
  • T1566.001 - Spearphishing Attachment
  • T1098.007 - Additional Local or Domain Groups
  • T1503 - Credentials from Web Browsers
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1590 - Gather Victim Network Information
  • T1048 - Exfiltration Over Alternative Protocol
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1493 - Transmitted Data Manipulation
MITREへのリンク →

APT1

Score: 11.72
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

FIN5

Score: 7.27
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1547.011 - Plist Modification
  • T1055.013 - Process Doppelgänging
MITREへのリンク →

HAFNIUM

Score: 11.34
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1590.006 - Network Security Appliances
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
  • T1055.008 - Ptrace System Calls
MITREへのリンク →

Confucius

Score: 4.96
Matched TTPs:
  • T1487 - Disk Structure Wipe
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

TeamTNT

Score: 14.78
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1562.004 - Disable or Modify System Firewall
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
MITREへのリンク →

Aquatic Panda

Score: 9.81
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1562.004 - Disable or Modify System Firewall
  • T1588.001 - Malware
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
MITREへのリンク →

Poseidon Group

Score: 5.06
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

admin@338

Score: 5.73
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Akira

Score: 9.48
Matched TTPs:
  • T1137.005 - Outlook Rules
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Storm-1811

Score: 9.20
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1497.002 - User Activity Based Checks
  • T1027 - Obfuscated Files or Information
  • T1486 - Data Encrypted for Impact
MITREへのリンク →

HEXANE

Score: 10.74
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

APT42

Score: 12.44
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1677 - Poisoned Pipeline Execution
  • T1497.002 - User Activity Based Checks
  • T1128 - Netsh Helper DLL
MITREへのリンク →

TA2541

Score: 6.86
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
MITREへのリンク →

RedEcho

Score: 6.66
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
MITREへのリンク →

EXOTIC LILY

Score: 3.80
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
MITREへのリンク →

Silent Librarian

Score: 11.09
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1609 - Container Administration Command
MITREへのリンク →

Magic Hound

Score: 27.92
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1547.005 - Security Support Provider
  • T1009 - Binary Padding
  • T1562.004 - Disable or Modify System Firewall
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Moonstone Sleet

Score: 7.61
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

BITTER

Score: 3.61
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1588.001 - Malware
MITREへのリンク →

CURIUM

Score: 6.58
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

LAPSUS$

Score: 12.96
Matched TTPs:
  • T1547.005 - Security Support Provider
  • T1609 - Container Administration Command
  • T1556.008 - Network Provider DLL
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Carbanak

Score: 4.44
Matched TTPs:
  • T1009 - Binary Padding
  • T1588.001 - Malware
MITREへのリンク →

Salt Typhoon

Score: 5.09
Matched TTPs:
  • T1009 - Binary Padding
  • T1556 - Modify Authentication Process
MITREへのリンク →

Moses Staff

Score: 3.81
Matched TTPs:
  • T1009 - Binary Padding
  • T1590.006 - Network Security Appliances
MITREへのリンク →

ToddyCat

Score: 4.88
Matched TTPs:
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

UNC3886

Score: 17.35
Matched TTPs:
  • T1009 - Binary Padding
  • T1021.006 - Windows Remote Management
  • T1588.001 - Malware
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1488 - Disk Content Wipe
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Medusa Group

Score: 13.78
Matched TTPs:
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Velvet Ant

Score: 11.02
Matched TTPs:
  • T1009 - Binary Padding
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
MITREへのリンク →

BlackByte

Score: 14.85
Matched TTPs:
  • T1009 - Binary Padding
  • T1590.006 - Network Security Appliances
  • T1134.001 - Token Impersonation/Theft
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

SilverTerrier

Score: 3.29
Matched TTPs:
  • T1131 - Authentication Package
MITREへのリンク →

Tonto Team

Score: 5.89
Matched TTPs:
  • T1547.011 - Plist Modification
  • T1497.002 - User Activity Based Checks
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT3

Score: 12.01
Matched TTPs:
  • T1547.011 - Plist Modification
  • T1590.006 - Network Security Appliances
  • T1177 - LSASS Driver
  • T1055.004 - Asynchronous Procedure Call
  • T1087.004 - Cloud Account
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

Play

Score: 7.51
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

Lotus Blossom

Score: 3.20
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

APT19

Score: 7.36
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1055.013 - Process Doppelgänging
  • T1497.002 - User Activity Based Checks
  • T1027.014 - Polymorphic Code
MITREへのリンク →

SideCopy

Score: 5.60
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1584.002 - DNS Server
MITREへのリンク →

Naikon

Score: 3.57
Matched TTPs:
  • T1590.006 - Network Security Appliances
  • T1588.001 - Malware
MITREへのリンク →

Deep Panda

Score: 6.83
Matched TTPs:
  • T1177 - LSASS Driver
  • T1497.002 - User Activity Based Checks
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Axiom

Score: 3.29
Matched TTPs:
  • T1177 - LSASS Driver
MITREへのリンク →

Fox Kitten

Score: 8.52
Matched TTPs:
  • T1177 - LSASS Driver
  • T1055.013 - Process Doppelgänging
  • T1588.001 - Malware
  • T1497.002 - User Activity Based Checks
MITREへのリンク →

APT-C-36

Score: 4.49
Matched TTPs:
  • T1588.001 - Malware
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

BackdoorDiplomacy

Score: 3.83
Matched TTPs:
  • T1588.001 - Malware
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

INC Ransom

Score: 9.49
Matched TTPs:
  • T1083 - File and Directory Discovery
  • T1055.004 - Asynchronous Procedure Call
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

LuminousMoth

Score: 5.41
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

WIRTE

Score: 5.94
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Blue Mockingbird

Score: 3.55
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Thrip

Score: 3.55
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1556 - Modify Authentication Process
MITREへのリンク →

DarkVishnya

Score: 3.20
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

FIN8

Score: 8.63
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1027 - Obfuscated Files or Information
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

DarkHydrus

Score: 4.93
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1531 - Account Access Removal
MITREへのリンク →

GOLD SOUTHFIELD

Score: 3.55
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1122 - Component Object Model Hijacking
MITREへのリンク →

Cinnamon Tempest

Score: 3.14
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Dark Caracal

Score: 3.44
Matched TTPs:
  • T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.70
Matched TTPs:
  • T1183 - Image File Execution Options Injection
  • T1122 - Component Object Model Hijacking
  • T1063 - Security Software Discovery
  • T1016.002 - Wi-Fi Discovery
  • T1098.007 - Additional Local or Domain Groups
  • T1497.002 - User Activity Based Checks
  • T1562.004 - Disable or Modify System Firewall
  • T1484.002 - Trust Modification
  • T1546.008 - Accessibility Features
  • T1075 - Pass the Hash
  • T1027 - Obfuscated Files or Information
  • T1087.004 - Cloud Account
  • T1686.003 - Windows Host Firewall
  • T1562.001 - Disable or Modify Tools
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

Kimsuky

Score: 0.65
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1027.014 - Polymorphic Code
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1213.006 - Databases
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1546.008 - Accessibility Features
  • T1588.001 - Malware
  • T1609 - Container Administration Command
  • T1009 - Binary Padding
  • T1087.004 - Cloud Account
  • T1131 - Authentication Package
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Lazarus Group

Score: 0.65
Matched TTPs:
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1547.011 - Plist Modification
  • T1069.001 - Local Groups
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1098.007 - Additional Local or Domain Groups
  • T1556 - Modify Authentication Process
  • T1071.005 - Publish/Subscribe Protocols
  • T1055.005 - Thread Local Storage
  • T1588.001 - Malware
  • T1009 - Binary Padding
  • T1087.004 - Cloud Account
  • T1562.001 - Disable or Modify Tools
  • T1055.004 - Asynchronous Procedure Call
  • T1677 - Poisoned Pipeline Execution
MITREへのリンク →

APT38

Score: 0.59
Matched TTPs:
  • T1493 - Transmitted Data Manipulation
  • T1497.002 - User Activity Based Checks
  • T1597 - Search Closed Sources
  • T1098.007 - Additional Local or Domain Groups
  • T1590 - Gather Victim Network Information
  • T1503 - Credentials from Web Browsers
  • T1027 - Obfuscated Files or Information
  • T1009 - Binary Padding
  • T1180 - Screensaver
  • T1048 - Exfiltration Over Alternative Protocol
  • T1566.001 - Spearphishing Attachment
  • T1055.004 - Asynchronous Procedure Call
MITREへのリンク →

APT28

Score: 0.58
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1547.011 - Plist Modification
  • T1497.002 - User Activity Based Checks
  • T1098.007 - Additional Local or Domain Groups
  • T1562.004 - Disable or Modify System Firewall
  • T1071.005 - Publish/Subscribe Protocols
  • T1574.009 - Path Interception by Unquoted Path
  • T1546.007 - Netsh Helper DLL
  • T1055.008 - Ptrace System Calls
  • T1222.002 - Linux and Mac Permissions
  • T1131 - Authentication Package
  • T1487 - Disk Structure Wipe
MITREへのリンク →

APT29

Score: 0.57
Matched TTPs:
  • T1122 - Component Object Model Hijacking
  • T1547.011 - Plist Modification
  • T1556.008 - Network Provider DLL
  • T1497.002 - User Activity Based Checks
  • T1562.004 - Disable or Modify System Firewall
  • T1177 - LSASS Driver
  • T1222.002 - Linux and Mac Permissions
  • T1584.008 - Network Devices
  • T1568 - Dynamic Resolution
  • T1027.004 - Compile After Delivery
  • T1202 - Indirect Command Execution
MITREへのリンク →

Contagious Interview

Score: 0.56
Matched TTPs:
  • T1183 - Image File Execution Options Injection
  • T1547.005 - Security Support Provider
  • T1597 - Search Closed Sources
  • T1098.007 - Additional Local or Domain Groups
  • T1546.013 - PowerShell Profile
  • T1556 - Modify Authentication Process
  • T1071.005 - Publish/Subscribe Protocols
  • T1562.001 - Disable or Modify Tools
  • T1087.004 - Cloud Account
  • T1131 - Authentication Package
  • T1021.006 - Windows Remote Management
  • T1064 - Scripting
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Mustang Panda

Score: 0.56
Matched TTPs:
  • T1183 - Image File Execution Options Injection
  • T1590.006 - Network Security Appliances
  • T1136.003 - Cloud Account
  • T1497.002 - User Activity Based Checks
  • T1098.007 - Additional Local or Domain Groups
  • T1546.013 - PowerShell Profile
  • T1556 - Modify Authentication Process
  • T1055.013 - Process Doppelgänging
  • T1071.005 - Publish/Subscribe Protocols
  • T1677 - Poisoned Pipeline Execution
  • T1055.005 - Thread Local Storage
  • T1087.004 - Cloud Account
  • T1055.004 - Asynchronous Procedure Call
  • T1487 - Disk Structure Wipe
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る