Trusted Design

Musical Chairs: Campaign Involving New Variant of Gh0st Malware

概要

The Gh0st malware is a widely used remote administration tool (RAT) that originated in China in the early 2000s. It has been the subject of many analysis reports, including those describing targeted espionage campaigns like Operation Night Dragon and the GhostNet attacks on Tibet. Musical Chairs is a multi-year campaign which recently deployed of new variant Gh0st we’ve named “Piano Gh0st.” Our evidence suggests the actors behind these attacks have been operating for over five years and have maintained a single command and control server for almost two. They use compromised e-mail accounts to distribute their malware widely and their targeting appears opportunistic rather than specific. The overall motivation of this campaign is unclear at this time. Gh0st is very versatile as it allows an adversary to take complete control over the infected system including installing additional malware.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 24.28
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1555.003 - Credentials from Web Browsers
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
  • T1126 - Network Share Connection Removal
  • T1490 - Inhibit System Recovery
MITREへのリンク →

FIN13

Score: 10.64
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Moonstone Sleet

Score: 15.76
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1573 - Encrypted Channel
  • T1126 - Network Share Connection Removal
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Indrik Spider

Score: 6.58
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
MITREへのリンク →

Lazarus Group

Score: 30.06
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1546.016 - Installer Packages
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Contagious Interview

Score: 27.08
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1021.006 - Windows Remote Management
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1565.002 - Transmitted Data Manipulation
  • T1221 - Template Injection
  • T1126 - Network Share Connection Removal
  • T1547.008 - LSASS Driver
MITREへのリンク →

OilRig

Score: 18.38
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
MITREへのリンク →

UNC3886

Score: 19.00
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1021.006 - Windows Remote Management
  • T1136.002 - Domain Account
  • T1588.001 - Malware
  • T1547.015 - Login Items
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

LuminousMoth

Score: 7.38
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Sandworm Team

Score: 22.37
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1546.016 - Installer Packages
MITREへのリンク →

APT29

Score: 21.56
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1555.003 - Credentials from Web Browsers
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1683 - Generate Content
  • T1218.010 - Regsvr32
  • T1218.009 - Regsvcs/Regasm
  • T1547.008 - LSASS Driver
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Play

Score: 5.61
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Aoqin Dragon

Score: 6.62
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Moses Staff

Score: 4.71
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
MITREへのリンク →

Turla

Score: 23.29
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1218.001 - Compiled HTML File
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1546.016 - Installer Packages
  • T1578.001 - Create Snapshot
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Ke3chang

Score: 5.34
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Mustang Panda

Score: 21.79
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1555.003 - Credentials from Web Browsers
  • T1608.005 - Link Target
  • T1169 - Sudo
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1565.002 - Transmitted Data Manipulation
  • T1055.005 - Thread Local Storage
MITREへのリンク →

TeamTNT

Score: 10.79
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1071.003 - Mail Protocols
MITREへのリンク →

FIN7

Score: 28.19
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1011.001 - Exfiltration Over Bluetooth
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1547.002 - Authentication Package
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1578.001 - Create Snapshot
  • T1490 - Inhibit System Recovery
MITREへのリンク →

TA2541

Score: 7.29
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
MITREへのリンク →

Earth Lusca

Score: 15.51
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1546.016 - Installer Packages
MITREへのリンク →

Mustard Tempest

Score: 3.74
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

LazyScripter

Score: 8.63
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1136.002 - Domain Account
  • T1608.005 - Link Target
MITREへのリンク →

Gamaredon Group

Score: 11.36
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1554 - Compromise Host Software Binary
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

Threat Group-3390

Score: 14.91
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.003 - CMSTP
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

TA505

Score: 5.28
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

BlackByte

Score: 7.78
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BITTER

Score: 10.03
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1683 - Generate Content
  • T1218.010 - Regsvr32
MITREへのリンク →

APT32

Score: 19.20
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1027.007 - Dynamic API Resolution
  • T1490 - Inhibit System Recovery
MITREへのリンク →

HEXANE

Score: 6.87
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1622 - Debugger Evasion
MITREへのリンク →

Saint Bear

Score: 5.48
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

EXOTIC LILY

Score: 5.99
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Ember Bear

Score: 11.75
Matched TTPs:
  • T1005 - Data from Local System
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
MITREへのリンク →

menuPass

Score: 4.68
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

BRONZE BUTLER

Score: 8.89
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

Agrius

Score: 5.60
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
MITREへのリンク →

APT28

Score: 17.01
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1146 - Clear Command History
MITREへのリンク →

ZIRCONIUM

Score: 11.28
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1547.002 - Authentication Package
  • T1578.001 - Create Snapshot
MITREへのリンク →

Windshift

Score: 6.48
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Storm-1811

Score: 12.11
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1578.002 - Create Cloud Instance
  • T1565.002 - Transmitted Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Winter Vivern

Score: 9.67
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1588.001 - Malware
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

PLATINUM

Score: 3.95
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Medusa Group

Score: 20.96
Matched TTPs:
  • T1218.003 - CMSTP
  • T1555.003 - Credentials from Web Browsers
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1598 - Phishing for Information
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

CURIUM

Score: 12.27
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dragonfly

Score: 16.90
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1578.002 - Create Cloud Instance
  • T1059.012 - Hypervisor CLI
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
MITREへのリンク →

BackdoorDiplomacy

Score: 7.17
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1136.002 - Domain Account
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
MITREへのリンク →

APT39

Score: 9.06
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Tropic Trooper

Score: 9.55
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1683 - Generate Content
  • T1218.010 - Regsvr32
  • T1490 - Inhibit System Recovery
MITREへのリンク →

HAFNIUM

Score: 6.44
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1608.005 - Link Target
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Fox Kitten

Score: 5.51
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1588.001 - Malware
  • T1622 - Debugger Evasion
MITREへのリンク →

Tonto Team

Score: 3.26
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.010 - Regsvr32
MITREへのリンク →

Volt Typhoon

Score: 9.69
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT38

Score: 10.40
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1059.012 - Hypervisor CLI
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Magic Hound

Score: 22.30
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1588.001 - Malware
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1683 - Generate Content
  • T1547.002 - Authentication Package
  • T1578.002 - Create Cloud Instance
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT5

Score: 3.41
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
MITREへのリンク →

Leviathan

Score: 13.64
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1554 - Compromise Host Software Binary
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1546.016 - Installer Packages
  • T1622 - Debugger Evasion
MITREへのリンク →

Sea Turtle

Score: 6.77
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1490 - Inhibit System Recovery
MITREへのリンク →

LAPSUS$

Score: 3.31
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Metador

Score: 3.31
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
MITREへのリンク →

APT1

Score: 4.96
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Aquatic Panda

Score: 7.05
Matched TTPs:
  • T1136.002 - Domain Account
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
MITREへのリンク →

Andariel

Score: 5.72
Matched TTPs:
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Scattered Spider

Score: 12.02
Matched TTPs:
  • T1136.002 - Domain Account
  • T1199 - Trusted Relationship
  • T1090.004 - Domain Fronting
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
MITREへのリンク →

Carbanak

Score: 5.34
Matched TTPs:
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

Wizard Spider

Score: 6.99
Matched TTPs:
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

FIN6

Score: 9.51
Matched TTPs:
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

PROMETHIUM

Score: 10.66
Matched TTPs:
  • T1588.001 - Malware
  • T1547.015 - Login Items
  • T1059.012 - Hypervisor CLI
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Higaisa

Score: 6.18
Matched TTPs:
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

Storm-0501

Score: 9.16
Matched TTPs:
  • T1588.001 - Malware
  • T1090.004 - Domain Fronting
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

APT41

Score: 11.41
Matched TTPs:
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

MuddyWater

Score: 6.75
Matched TTPs:
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
MITREへのリンク →

Confucius

Score: 3.51
Matched TTPs:
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
MITREへのリンク →

POLONIUM

Score: 5.26
Matched TTPs:
  • T1608.005 - Link Target
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

Patchwork

Score: 5.76
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

Cobalt Group

Score: 6.92
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1573 - Encrypted Channel
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Thrip

Score: 3.78
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

FIN10

Score: 5.16
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1490 - Inhibit System Recovery
MITREへのリンク →

INC Ransom

Score: 4.89
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Silence

Score: 4.89
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Chimera

Score: 7.49
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1578.001 - Create Snapshot
MITREへのリンク →

Blue Mockingbird

Score: 4.89
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Daggerfly

Score: 7.53
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1059.012 - Hypervisor CLI
  • T1546.016 - Installer Packages
MITREへのリンク →

APT37

Score: 9.28
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT12

Score: 3.89
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
MITREへのリンク →

Sidewinder

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

The White Company

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

Axiom

Score: 9.44
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

APT3

Score: 6.76
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.002 - Create Cloud Instance
  • T1622 - Debugger Evasion
MITREへのリンク →

Transparent Tribe

Score: 3.26
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Elderwood

Score: 3.26
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Darkhotel

Score: 5.85
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

RTM

Score: 4.69
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Dark Caracal

Score: 4.29
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Velvet Ant

Score: 5.06
Matched TTPs:
  • T1027.007 - Dynamic API Resolution
  • T1490 - Inhibit System Recovery
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.84
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1547.008 - LSASS Driver
  • T1059.012 - Hypervisor CLI
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1216 - System Script Proxy Execution
  • T1608.005 - Link Target
  • T1622 - Debugger Evasion
  • T1546.016 - Installer Packages
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1547.002 - Authentication Package
  • T1606.002 - SAML Tokens
MITREへのリンク →

FIN7

Score: 0.81
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
  • T1608.005 - Link Target
  • T1622 - Debugger Evasion
  • T1490 - Inhibit System Recovery
  • T1091 - Replication Through Removable Media
  • T1011.001 - Exfiltration Over Bluetooth
  • T1573 - Encrypted Channel
  • T1547.002 - Authentication Package
  • T1606.002 - SAML Tokens
MITREへのリンク →

Contagious Interview

Score: 0.73
Matched TTPs:
  • T1547.008 - LSASS Driver
  • T1199 - Trusted Relationship
  • T1608.005 - Link Target
  • T1091 - Replication Through Removable Media
  • T1565.002 - Transmitted Data Manipulation
  • T1126 - Network Share Connection Removal
  • T1221 - Template Injection
  • T1558 - Steal or Forge Kerberos Tickets
  • T1021.006 - Windows Remote Management
  • T1606.002 - SAML Tokens
MITREへのリンク →

Kimsuky

Score: 0.69
Matched TTPs:
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1608.005 - Link Target
  • T1622 - Debugger Evasion
  • T1490 - Inhibit System Recovery
  • T1091 - Replication Through Removable Media
  • T1565.002 - Transmitted Data Manipulation
  • T1126 - Network Share Connection Removal
  • T1547.002 - Authentication Package
  • T1555.003 - Credentials from Web Browsers
  • T1606.002 - SAML Tokens
MITREへのリンク →

Turla

Score: 0.69
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1059.012 - Hypervisor CLI
  • T1199 - Trusted Relationship
  • T1608.005 - Link Target
  • T1490 - Inhibit System Recovery
  • T1546.016 - Installer Packages
  • T1136.002 - Domain Account
  • T1218.001 - Compiled HTML File
  • T1547.002 - Authentication Package
  • T1606.002 - SAML Tokens
MITREへのリンク →

Sandworm Team

Score: 0.67
Matched TTPs:
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1546.016 - Installer Packages
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1573 - Encrypted Channel
  • T1558 - Steal or Forge Kerberos Tickets
  • T1547.002 - Authentication Package
  • T1555.003 - Credentials from Web Browsers
  • T1606.002 - SAML Tokens
MITREへのリンク →

Magic Hound

Score: 0.67
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1683 - Generate Content
  • T1608.005 - Link Target
  • T1578.002 - Create Cloud Instance
  • T1622 - Debugger Evasion
  • T1547.002 - Authentication Package
  • T1555.003 - Credentials from Web Browsers
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT29

Score: 0.63
Matched TTPs:
  • T1547.008 - LSASS Driver
  • T1199 - Trusted Relationship
  • T1683 - Generate Content
  • T1608.005 - Link Target
  • T1490 - Inhibit System Recovery
  • T1218.009 - Regsvcs/Regasm
  • T1218.010 - Regsvr32
  • T1555.003 - Credentials from Web Browsers
  • T1606.002 - SAML Tokens
MITREへのリンク →

Mustang Panda

Score: 0.63
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1608.005 - Link Target
  • T1091 - Replication Through Removable Media
  • T1565.002 - Transmitted Data Manipulation
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1555.003 - Credentials from Web Browsers
  • T1606.002 - SAML Tokens
  • T1169 - Sudo
MITREへのリンク →

Medusa Group

Score: 0.62
Matched TTPs:
  • T1216 - System Script Proxy Execution
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
  • T1608.005 - Link Target
  • T1622 - Debugger Evasion
  • T1218.003 - CMSTP
  • T1598 - Phishing for Information
  • T1555.003 - Credentials from Web Browsers
MITREへのリンク →

UNC3886

Score: 0.59
Matched TTPs:
  • T1578.001 - Create Snapshot
  • T1588.001 - Malware
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1021.006 - Windows Remote Management
  • T1606.002 - SAML Tokens
  • T1547.015 - Login Items
MITREへのリンク →

APT32

Score: 0.57
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1588.001 - Malware
  • T1199 - Trusted Relationship
  • T1027.007 - Dynamic API Resolution
  • T1608.005 - Link Target
  • T1490 - Inhibit System Recovery
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1558 - Steal or Forge Kerberos Tickets
  • T1555.003 - Credentials from Web Browsers
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る