Trusted Design

An analysis of exploit supply chains and digital quartermasters

概要

On July 5, 2015 an unknown hacker publicly announced on Twitter that he had breached the internal network of Hacking Team – an Italian pentesting company known to purchase 0-day exploits and produce their own trojans. The hacker proceeded to leak archives of internal Hacking Team tools and communications. A number of tools and previously unknown exploits were discovered in the trove of data posted online. In the attached paper we will focus on two exploits which at the time of discovery in the Hacking Team archives were unpatched. The two 0-days in question targeted Adobe Flash and were subsequently labeled CVE-2015-5119 and CVE-2015-5122.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT41

Score: 15.11
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
MITREへのリンク →

Scattered Spider

Score: 6.12
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

TA505

Score: 4.91
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Volt Typhoon

Score: 22.34
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1488 - Disk Content Wipe
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
  • T1578.001 - Create Snapshot
  • T1569.002 - Service Execution
MITREへのリンク →

APT3

Score: 6.76
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1120 - Peripheral Device Discovery
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN13

Score: 12.61
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1569.002 - Service Execution
MITREへのリンク →

Kimsuky

Score: 10.53
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1003.003 - NTDS
MITREへのリンク →

Moonstone Sleet

Score: 6.60
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Lazarus Group

Score: 20.65
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
  • T1569.002 - Service Execution
  • T1556 - Modify Authentication Process
MITREへのリンク →

Contagious Interview

Score: 9.42
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

OilRig

Score: 21.72
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

UNC3886

Score: 14.94
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1488 - Disk Content Wipe
  • T1218.010 - Regsvr32
  • T1055.015 - ListPlanting
  • T1578.001 - Create Snapshot
MITREへのリンク →

LuminousMoth

Score: 3.72
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Sandworm Team

Score: 18.17
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1686.003 - Windows Host Firewall
  • T1120 - Peripheral Device Discovery
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Salt Typhoon

Score: 7.16
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT29

Score: 11.80
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Play

Score: 6.40
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Aoqin Dragon

Score: 4.44
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 6.05
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Moses Staff

Score: 6.40
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Turla

Score: 10.45
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1578.001 - Create Snapshot
  • T1569.002 - Service Execution
MITREへのリンク →

Ke3chang

Score: 6.40
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Mustang Panda

Score: 16.45
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1169 - Sudo
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
MITREへのリンク →

TeamTNT

Score: 6.67
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1562.004 - Disable or Modify System Firewall
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN7

Score: 12.43
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
  • T1578.001 - Create Snapshot
MITREへのリンク →

Storm-0501

Score: 6.52
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Windigo

Score: 3.95
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1159 - Launch Agent
MITREへのリンク →

BlackByte

Score: 3.45
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

ZIRCONIUM

Score: 4.57
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1547.013 - XDG Autostart Entries
  • T1578.001 - Create Snapshot
MITREへのリンク →

Blue Mockingbird

Score: 3.52
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

HEXANE

Score: 5.58
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Darkhotel

Score: 6.07
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1578.001 - Create Snapshot
MITREへのリンク →

TA2541

Score: 5.58
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Rocke

Score: 3.45
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT37

Score: 3.48
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT32

Score: 7.07
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
MITREへのリンク →

Inception

Score: 6.29
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
MITREへのリンク →

Higaisa

Score: 8.22
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
  • T1569.002 - Service Execution
MITREへのリンク →

CURIUM

Score: 6.32
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT38

Score: 7.37
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1059.005 - Visual Basic
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

MuddyWater

Score: 8.54
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Sidewinder

Score: 8.81
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
  • T1578.001 - Create Snapshot
MITREへのリンク →

Magic Hound

Score: 9.42
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT42

Score: 4.80
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

SideCopy

Score: 4.73
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN8

Score: 8.32
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
MITREへのリンク →

Tropic Trooper

Score: 8.97
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Aquatic Panda

Score: 5.42
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Winter Vivern

Score: 6.04
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Wizard Spider

Score: 5.58
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
MITREへのリンク →

Patchwork

Score: 4.33
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Windshift

Score: 7.25
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Medusa Group

Score: 11.18
Matched TTPs:
  • T1120 - Peripheral Device Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Ember Bear

Score: 13.53
Matched TTPs:
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

Threat Group-3390

Score: 8.72
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT28

Score: 16.26
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1588.003 - Code Signing Certificates
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

BackdoorDiplomacy

Score: 3.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

BlackTech

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Sea Turtle

Score: 8.35
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1685 - Disable or Modify Tools
MITREへのリンク →

Cinnamon Tempest

Score: 3.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

menuPass

Score: 3.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

GALLIUM

Score: 3.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Earth Lusca

Score: 4.91
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
MITREへのリンク →

Leviathan

Score: 10.18
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1488 - Disk Content Wipe
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Volatile Cedar

Score: 4.84
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

INC Ransom

Score: 3.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Dragonfly

Score: 7.18
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT39

Score: 6.02
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1569.002 - Service Execution
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1055.003 - Thread Execution Hijacking
MITREへのリンク →

DarkVishnya

Score: 5.39
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1213.003 - Code Repositories
MITREへのリンク →

BITTER

Score: 3.12
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Storm-1811

Score: 4.15
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

BRONZE BUTLER

Score: 8.46
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1159 - Launch Agent
  • T1547.013 - XDG Autostart Entries
  • T1578.001 - Create Snapshot
MITREへのリンク →

FIN6

Score: 8.86
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Cobalt Group

Score: 5.87
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Thrip

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1556 - Modify Authentication Process
MITREへのリンク →

Lotus Blossom

Score: 3.78
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1569.002 - Service Execution
MITREへのリンク →

APT33

Score: 5.87
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
MITREへのリンク →

Chimera

Score: 4.22
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1578.001 - Create Snapshot
MITREへのリンク →

The White Company

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

EXOTIC LILY

Score: 4.02
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Velvet Ant

Score: 5.67
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1569.002 - Service Execution
MITREへのリンク →

Ajax Security Team

Score: 3.30
Matched TTPs:
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Volt Typhoon

Score: 0.82
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1578.001 - Create Snapshot
  • T1569.002 - Service Execution
  • T1547.013 - XDG Autostart Entries
  • T1488 - Disk Content Wipe
  • T1560.003 - Archive via Custom Method
  • T1159 - Launch Agent
  • T1686.003 - Windows Host Firewall
  • T1199 - Trusted Relationship
MITREへのリンク →

OilRig

Score: 0.78
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
  • T1055.015 - ListPlanting
  • T1606.002 - SAML Tokens
  • T1005 - Data from Local System
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
MITREへのリンク →

Lazarus Group

Score: 0.77
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
  • T1569.002 - Service Execution
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
  • T1055.015 - ListPlanting
  • T1606.002 - SAML Tokens
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
MITREへのリンク →

Sandworm Team

Score: 0.69
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1606.002 - SAML Tokens
  • T1005 - Data from Local System
  • T1686.003 - Windows Host Firewall
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
MITREへのリンク →

APT28

Score: 0.63
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1588.003 - Code Signing Certificates
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1546.007 - Netsh Helper DLL
  • T1199 - Trusted Relationship
MITREへのリンク →

Mustang Panda

Score: 0.62
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1169 - Sudo
  • T1547.013 - XDG Autostart Entries
  • T1556 - Modify Authentication Process
  • T1606.002 - SAML Tokens
  • T1159 - Launch Agent
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
MITREへのリンク →

UNC3886

Score: 0.61
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1578.001 - Create Snapshot
  • T1218.010 - Regsvr32
  • T1055.015 - ListPlanting
  • T1488 - Disk Content Wipe
  • T1606.002 - SAML Tokens
MITREへのリンク →

APT41

Score: 0.59
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1562.004 - Disable or Modify System Firewall
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
  • T1560.003 - Archive via Custom Method
  • T1120 - Peripheral Device Discovery
  • T1199 - Trusted Relationship
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る