Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
概要
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.
Created: 2026-08-11
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 34.64
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1071.005 - Publish/Subscribe Protocols
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1131 - Authentication Package
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
- T1574.009 - Path Interception by Unquoted Path
- T1055.008 - Ptrace System Calls
- T1546.007 - Netsh Helper DLL
MITREへのリンク →
Score: 34.16
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1584.008 - Network Devices
- T1202 - Indirect Command Execution
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1568 - Dynamic Resolution
- T1556.008 - Network Provider DLL
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 19.55
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1063 - Security Software Discovery
- T1003.007 - Proc Filesystem
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 28.01
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.76
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1055.013 - Process Doppelgänging
- T1064 - Scripting
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 20.31
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1063 - Security Software Discovery
- T1487 - Disk Structure Wipe
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 9.71
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 21.49
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1071.005 - Publish/Subscribe Protocols
- T1518.002 - Backup Software Discovery
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 14.95
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 18.76
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1055.013 - Process Doppelgänging
- T1090 - Proxy
- T1588.001 - Malware
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 11.36
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1497.002 - User Activity Based Checks
- T1048 - Exfiltration Over Alternative Protocol
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 33.75
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1071.005 - Publish/Subscribe Protocols
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1021.006 - Windows Remote Management
- T1183 - Image File Execution Options Injection
- T1064 - Scripting
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 7.04
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1098.007 - Additional Local or Domain Groups
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 15.90
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1527 - Application Access Token
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 18.55
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1497.002 - User Activity Based Checks
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 15.14
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1518.002 - Backup Software Discovery
- T1497.002 - User Activity Based Checks
- T1027.014 - Polymorphic Code
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 10.03
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1071.005 - Publish/Subscribe Protocols
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 38.97
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1546.008 - Accessibility Features
- T1588.001 - Malware
- T1609 - Container Administration Command
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027.014 - Polymorphic Code
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 11.72
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1101 - Security Support Provider
MITREへのリンク →
Score: 33.44
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1071.005 - Publish/Subscribe Protocols
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1677 - Poisoned Pipeline Execution
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1136.003 - Cloud Account
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 12.15
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1609 - Container Administration Command
MITREへのリンク →
Score: 9.22
Matched TTPs:
- T1485.001 - Lifecycle-Triggered Deletion
- T1055.013 - Process Doppelgänging
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1682 - Query Public AI Services
MITREへのリンク →
Score: 3.39
Matched TTPs:
- T1584.008 - Network Devices
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 11.32
Matched TTPs:
- T1584.008 - Network Devices
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 15.75
Matched TTPs:
- T1584.008 - Network Devices
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1134.001 - Token Impersonation/Theft
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 20.13
Matched TTPs:
- T1584.008 - Network Devices
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1497.002 - User Activity Based Checks
- T1531 - Account Access Removal
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 25.39
Matched TTPs:
- T1584.008 - Network Devices
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1198 - SIP and Trust Provider Hijacking
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 8.55
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 26.54
Matched TTPs:
- T1584.008 - Network Devices
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1048 - Exfiltration Over Alternative Protocol
- T1027 - Obfuscated Files or Information
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 12.59
Matched TTPs:
- T1584.008 - Network Devices
- T1180 - Screensaver
- T1677 - Poisoned Pipeline Execution
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 19.64
Matched TTPs:
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 21.02
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
- T1678 - Delay Execution
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 23.52
Matched TTPs:
- T1584.008 - Network Devices
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1083 - File and Directory Discovery
- T1567.001 - Exfiltration to Code Repository
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 15.11
Matched TTPs:
- T1584.008 - Network Devices
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1487 - Disk Structure Wipe
- T1562.004 - Disable or Modify System Firewall
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 13.43
Matched TTPs:
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 30.44
Matched TTPs:
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1487 - Disk Structure Wipe
- T1566.001 - Spearphishing Attachment
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1048 - Exfiltration Over Alternative Protocol
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 16.79
Matched TTPs:
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1566.001 - Spearphishing Attachment
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 18.30
Matched TTPs:
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 27.87
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1087.004 - Cloud Account
- T1556.008 - Network Provider DLL
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 15.96
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1588.001 - Malware
- T1497.002 - User Activity Based Checks
- T1027 - Obfuscated Files or Information
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 41.99
Matched TTPs:
- T1063 - Security Software Discovery
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1075 - Pass the Hash
MITREへのリンク →
Score: 7.89
Matched TTPs:
- T1063 - Security Software Discovery
- T1098.007 - Additional Local or Domain Groups
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 7.84
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1590.006 - Network Security Appliances
- T1064 - Scripting
MITREへのリンク →
Score: 38.72
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1677 - Poisoned Pipeline Execution
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 11.92
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1087.004 - Cloud Account
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 27.42
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1686.003 - Windows Host Firewall
- T1003.007 - Proc Filesystem
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1488 - Disk Content Wipe
- T1584.002 - DNS Server
MITREへのリンク →
Score: 20.25
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1487 - Disk Structure Wipe
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
- T1128 - Netsh Helper DLL
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 9.11
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 6.07
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1497.002 - User Activity Based Checks
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 12.60
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1567.001 - Exfiltration to Code Repository
- T1497.002 - User Activity Based Checks
- T1562.001 - Disable or Modify Tools
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 9.98
Matched TTPs:
- T1071.005 - Publish/Subscribe Protocols
- T1003.007 - Proc Filesystem
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 24.03
Matched TTPs:
- T1484.002 - Trust Modification
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1554 - Compromise Host Software Binary
- T1027.014 - Polymorphic Code
- T1488 - Disk Content Wipe
MITREへのリンク →
Score: 21.93
Matched TTPs:
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1554 - Compromise Host Software Binary
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 12.72
Matched TTPs:
- T1180 - Screensaver
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 35.27
Matched TTPs:
- T1180 - Screensaver
- T1566.001 - Spearphishing Attachment
- T1098.007 - Additional Local or Domain Groups
- T1503 - Credentials from Web Browsers
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1590 - Gather Victim Network Information
- T1048 - Exfiltration Over Alternative Protocol
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1493 - Transmitted Data Manipulation
MITREへのリンク →
Score: 11.72
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.27
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 11.34
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 4.96
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 14.78
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 9.81
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1562.004 - Disable or Modify System Firewall
- T1588.001 - Malware
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 5.06
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 5.73
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 9.48
Matched TTPs:
- T1137.005 - Outlook Rules
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 9.20
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1497.002 - User Activity Based Checks
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 10.74
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 12.44
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1677 - Poisoned Pipeline Execution
- T1497.002 - User Activity Based Checks
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 6.86
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 6.66
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.80
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 11.09
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 27.92
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 7.61
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.61
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1588.001 - Malware
MITREへのリンク →
Score: 6.58
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 12.96
Matched TTPs:
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 4.44
Matched TTPs:
- T1009 - Binary Padding
- T1588.001 - Malware
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1009 - Binary Padding
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
MITREへのリンク →
Score: 4.88
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 17.35
Matched TTPs:
- T1009 - Binary Padding
- T1021.006 - Windows Remote Management
- T1588.001 - Malware
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1488 - Disk Content Wipe
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 13.78
Matched TTPs:
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 11.02
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 14.85
Matched TTPs:
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1134.001 - Token Impersonation/Theft
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 5.89
Matched TTPs:
- T1547.011 - Plist Modification
- T1497.002 - User Activity Based Checks
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 12.01
Matched TTPs:
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 7.51
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 3.20
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.36
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1497.002 - User Activity Based Checks
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 5.60
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1584.002 - DNS Server
MITREへのリンク →
Score: 3.57
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1588.001 - Malware
MITREへのリンク →
Score: 6.83
Matched TTPs:
- T1177 - LSASS Driver
- T1497.002 - User Activity Based Checks
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 8.52
Matched TTPs:
- T1177 - LSASS Driver
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1497.002 - User Activity Based Checks
MITREへのリンク →
Score: 4.49
Matched TTPs:
- T1588.001 - Malware
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 3.83
Matched TTPs:
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 9.49
Matched TTPs:
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 5.41
Matched TTPs:
- T1087.004 - Cloud Account
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 5.94
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.55
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.55
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 3.20
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 8.63
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 4.93
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1531 - Account Access Removal
MITREへのリンク →
Score: 3.55
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 3.14
Matched TTPs:
- T1497.002 - User Activity Based Checks
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1122 - Component Object Model Hijacking
- T1063 - Security Software Discovery
- T1016.002 - Wi-Fi Discovery
- T1098.007 - Additional Local or Domain Groups
- T1497.002 - User Activity Based Checks
- T1562.004 - Disable or Modify System Firewall
- T1484.002 - Trust Modification
- T1546.008 - Accessibility Features
- T1075 - Pass the Hash
- T1027 - Obfuscated Files or Information
- T1087.004 - Cloud Account
- T1686.003 - Windows Host Firewall
- T1562.001 - Disable or Modify Tools
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 0.65
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1027.014 - Polymorphic Code
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1213.006 - Databases
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1546.008 - Accessibility Features
- T1588.001 - Malware
- T1609 - Container Administration Command
- T1009 - Binary Padding
- T1087.004 - Cloud Account
- T1131 - Authentication Package
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 0.65
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1547.011 - Plist Modification
- T1069.001 - Local Groups
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1098.007 - Additional Local or Domain Groups
- T1556 - Modify Authentication Process
- T1071.005 - Publish/Subscribe Protocols
- T1055.005 - Thread Local Storage
- T1588.001 - Malware
- T1009 - Binary Padding
- T1087.004 - Cloud Account
- T1562.001 - Disable or Modify Tools
- T1055.004 - Asynchronous Procedure Call
- T1677 - Poisoned Pipeline Execution
MITREへのリンク →
Score: 0.59
Matched TTPs:
- T1493 - Transmitted Data Manipulation
- T1497.002 - User Activity Based Checks
- T1597 - Search Closed Sources
- T1098.007 - Additional Local or Domain Groups
- T1590 - Gather Victim Network Information
- T1503 - Credentials from Web Browsers
- T1027 - Obfuscated Files or Information
- T1009 - Binary Padding
- T1180 - Screensaver
- T1048 - Exfiltration Over Alternative Protocol
- T1566.001 - Spearphishing Attachment
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 0.58
Matched TTPs:
- T1122 - Component Object Model Hijacking
- T1547.011 - Plist Modification
- T1497.002 - User Activity Based Checks
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1071.005 - Publish/Subscribe Protocols
- T1574.009 - Path Interception by Unquoted Path
- T1546.007 - Netsh Helper DLL
- T1055.008 - Ptrace System Calls
- T1222.002 - Linux and Mac Permissions
- T1131 - Authentication Package
- T1487 - Disk Structure Wipe
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1122 - Component Object Model Hijacking
- T1547.011 - Plist Modification
- T1556.008 - Network Provider DLL
- T1497.002 - User Activity Based Checks
- T1562.004 - Disable or Modify System Firewall
- T1177 - LSASS Driver
- T1222.002 - Linux and Mac Permissions
- T1584.008 - Network Devices
- T1568 - Dynamic Resolution
- T1027.004 - Compile After Delivery
- T1202 - Indirect Command Execution
MITREへのリンク →
Score: 0.56
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1547.005 - Security Support Provider
- T1597 - Search Closed Sources
- T1098.007 - Additional Local or Domain Groups
- T1546.013 - PowerShell Profile
- T1556 - Modify Authentication Process
- T1071.005 - Publish/Subscribe Protocols
- T1562.001 - Disable or Modify Tools
- T1087.004 - Cloud Account
- T1131 - Authentication Package
- T1021.006 - Windows Remote Management
- T1064 - Scripting
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 0.56
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1136.003 - Cloud Account
- T1497.002 - User Activity Based Checks
- T1098.007 - Additional Local or Domain Groups
- T1546.013 - PowerShell Profile
- T1556 - Modify Authentication Process
- T1055.013 - Process Doppelgänging
- T1071.005 - Publish/Subscribe Protocols
- T1677 - Poisoned Pipeline Execution
- T1055.005 - Thread Local Storage
- T1087.004 - Cloud Account
- T1055.004 - Asynchronous Procedure Call
- T1487 - Disk Structure Wipe
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る