Trusted Design

Black Vine: Formidable cyberespionage group

概要

Earlier this year, the second largest health insurance provider in the US publicly disclosed that it had been the victim of a major cyberattack. The attack against Anthem resulted in the largest known healthcare data breach to date, with 80 million patient records exposed. Symantec believes that the attackers behind the Anthem breach are part of a highly resourceful cyberespionage group called Black Vine. The Anthem attack is only one of multiple campaigns that Symantec has attributed to this group. Symantec’s latest whitepaper documents multiple Black Vine operations that have been occurring since 2012. Black Vine’s targets include gas turbine manufacturers, large aerospace and aviation companies, healthcare providers, and more. The group has access to zero-day exploits, most likely obtained through the Elderwood framework, and uses custom-developed back door malware. By connecting multiple Black Vine campaigns, we traced how the attack group has evolved over the last three years.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 8.64
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1003.003 - NTDS
MITREへのリンク →

Sea Turtle

Score: 6.00
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
MITREへのリンク →

Ember Bear

Score: 13.97
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

Indrik Spider

Score: 3.03
Matched TTPs:
  • T1033 - System Owner/User Discovery
MITREへのリンク →

Agrius

Score: 4.50
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Contagious Interview

Score: 16.28
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1021.006 - Windows Remote Management
  • T1562.010 - Downgrade Attack
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sandworm Team

Score: 13.69
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1193 - Spearphishing Attachment
  • T1218.010 - Regsvr32
MITREへのリンク →

Star Blizzard

Score: 3.03
Matched TTPs:
  • T1033 - System Owner/User Discovery
MITREへのリンク →

LAPSUS$

Score: 12.23
Matched TTPs:
  • T1216.001 - PubPrn
  • T1193 - Spearphishing Attachment
  • T1588.005 - Exploits
MITREへのリンク →

APT41

Score: 6.25
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
MITREへのリンク →

Scattered Spider

Score: 11.67
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1027.002 - Software Packing
  • T1588.005 - Exploits
MITREへのリンク →

TA505

Score: 3.29
Matched TTPs:
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

Volt Typhoon

Score: 4.76
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

APT3

Score: 4.78
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1218.010 - Regsvr32
MITREへのリンク →

FIN13

Score: 4.76
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

OilRig

Score: 13.35
Matched TTPs:
  • T1005 - Data from Local System
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT28

Score: 19.32
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1588.003 - Code Signing Certificates
  • T1546.007 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Magic Hound

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Medusa Group

Score: 4.22
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Storm-0501

Score: 5.31
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.009 - Proc Memory
MITREへのリンク →

Fox Kitten

Score: 5.31
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.005 - Exploits
MITREへのリンク →

BlackByte

Score: 5.31
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.010 - Downgrade Attack
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT29

Score: 5.49
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

INC Ransom

Score: 5.31
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1055.009 - Proc Memory
MITREへのリンク →

UNC3886

Score: 7.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
  • T1218.010 - Regsvr32
MITREへのリンク →

Dragonfly

Score: 9.96
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1193 - Spearphishing Attachment
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Salt Typhoon

Score: 4.22
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556 - Modify Authentication Process
MITREへのリンク →

Gamaredon Group

Score: 11.53
Matched TTPs:
  • T1562.010 - Downgrade Attack
  • T1061 - Graphical User Interface
  • T1200 - Hardware Additions
MITREへのリンク →

APT33

Score: 8.37
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1218.010 - Regsvr32
  • T1556 - Modify Authentication Process
MITREへのリンク →

Wizard Spider

Score: 6.88
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1556 - Modify Authentication Process
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Lazarus Group

Score: 10.90
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Confucius

Score: 4.65
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Cobalt Group

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Mustang Panda

Score: 8.37
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

Tropic Trooper

Score: 7.39
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1200 - Hardware Additions
MITREへのリンク →

Inception

Score: 4.65
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

APT32

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1556 - Modify Authentication Process
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

RedCurl

Score: 6.59
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1055.009 - Proc Memory
MITREへのリンク →

FIN6

Score: 8.02
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

FIN8

Score: 5.49
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

DarkHydrus

Score: 3.15
Matched TTPs:
  • T1200 - Hardware Additions
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.85
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1588.003 - Code Signing Certificates
  • T1546.007 - Netsh Helper DLL
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Contagious Interview

Score: 0.67
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1556 - Modify Authentication Process
  • T1562.010 - Downgrade Attack
  • T1547.008 - LSASS Driver
  • T1021.006 - Windows Remote Management
MITREへのリンク →

Sandworm Team

Score: 0.63
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1193 - Spearphishing Attachment
  • T1005 - Data from Local System
  • T1218.010 - Regsvr32
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

LAPSUS$

Score: 0.62
Matched TTPs:
  • T1193 - Spearphishing Attachment
  • T1588.005 - Exploits
  • T1216.001 - PubPrn
MITREへのリンク →

Ember Bear

Score: 0.61
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1005 - Data from Local System
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

OilRig

Score: 0.57
Matched TTPs:
  • T1556 - Modify Authentication Process
  • T1128 - Netsh Helper DLL
  • T1005 - Data from Local System
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Scattered Spider

Score: 0.56
Matched TTPs:
  • T1588.005 - Exploits
  • T1027.002 - Software Packing
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る