Trusted Design

When ELF.BillGates met Windows

概要

The “Elf.BillGates” version targets Linux operating system. We have followed the activities of this botnet for several months and during our investigations we found some versions of a Windows fork of the malware. This article attempts to detail this variant. The primary infection vector is the exploit of the vulnerability CVE-2014-6332[3], which drops the binary file hosted on an HTTPd File Server (HFS)[4]. This vulnerability allows an attacker to escape the Internet Explorer sandbox with a VBScript script and execute an arbitrary binary file downloaded from the Internet.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Lazarus Group

Score: 49.73
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1558.005 - Ccache Files
  • T1059.010 - AutoHotKey & AutoIT
  • T1070.008 - Clear Mailbox Data
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1069.001 - Local Groups
  • T1597 - Search Closed Sources
  • T1174 - Password Filter DLL
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1055.005 - Thread Local Storage
  • T1547.008 - LSASS Driver
  • T1216 - System Script Proxy Execution
MITREへのリンク →

TA577

Score: 3.84
Matched TTPs:
  • T1132.001 - Standard Encoding
MITREへのリンク →

Moonstone Sleet

Score: 13.87
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1087.002 - Domain Account
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Mustang Panda

Score: 34.81
Matched TTPs:
  • T1003 - OS Credential Dumping
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1136.001 - Local Account
  • T1218.012 - Verclsid
  • T1608 - Stage Capabilities
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1055.005 - Thread Local Storage
MITREへのリンク →

Winnti Group

Score: 4.06
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT41

Score: 21.20
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1048 - Exfiltration Over Alternative Protocol
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Rocke

Score: 13.90
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

TeamTNT

Score: 19.44
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1176.001 - Browser Extensions
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1153 - Source
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT28

Score: 17.71
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1558 - Steal or Forge Kerberos Tickets
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

UNC3886

Score: 9.43
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
MITREへのリンク →

Cobalt Group

Score: 21.94
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1518.002 - Backup Software Discovery
  • T1598.004 - Spearphishing Voice
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN7

Score: 23.95
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1011.001 - Exfiltration Over Bluetooth
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

MuddyWater

Score: 25.88
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1518.002 - Backup Software Discovery
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Sidewinder

Score: 11.28
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1218.012 - Verclsid
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT37

Score: 13.12
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1590.003 - Network Trust Dependencies
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Gallmaker

Score: 3.53
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
MITREへのリンク →

Leviathan

Score: 16.14
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

BITTER

Score: 7.78
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

TA505

Score: 20.47
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1685.002 - Disable or Modify Cloud Log
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1138 - Application Shimming
  • T1597 - Search Closed Sources
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Patchwork

Score: 10.32
Matched TTPs:
  • T1206 - Sudo Caching
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Malteiro

Score: 3.76
Matched TTPs:
  • T1087.002 - Domain Account
  • T1059.010 - AutoHotKey & AutoIT
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Kimsuky

Score: 28.17
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.012 - Verclsid
  • T1608 - Stage Capabilities
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.014 - Polymorphic Code
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1003.003 - NTDS
MITREへのリンク →

Machete

Score: 5.48
Matched TTPs:
  • T1087.002 - Domain Account
  • T1685.002 - Disable or Modify Cloud Log
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Elderwood

Score: 3.06
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Transparent Tribe

Score: 3.68
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Dragonfly

Score: 5.91
Matched TTPs:
  • T1087.002 - Domain Account
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

WIRTE

Score: 7.28
Matched TTPs:
  • T1087.002 - Domain Account
  • T1059.010 - AutoHotKey & AutoIT
  • T1027.014 - Polymorphic Code
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Contagious Interview

Score: 22.45
Matched TTPs:
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1064 - Scripting
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1221 - Template Injection
  • T1547.008 - LSASS Driver
MITREへのリンク →

Aoqin Dragon

Score: 4.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1558 - Steal or Forge Kerberos Tickets
  • T1218.010 - Regsvr32
MITREへのリンク →

CURIUM

Score: 3.31
Matched TTPs:
  • T1087.002 - Domain Account
  • T1547.008 - LSASS Driver
MITREへのリンク →

Tropic Trooper

Score: 11.96
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Dark Caracal

Score: 6.75
Matched TTPs:
  • T1087.002 - Domain Account
  • T1048 - Exfiltration Over Alternative Protocol
  • T1547.008 - LSASS Driver
MITREへのリンク →

RedCurl

Score: 7.70
Matched TTPs:
  • T1087.002 - Domain Account
  • T1558.005 - Ccache Files
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
MITREへのリンク →

PLATINUM

Score: 8.29
Matched TTPs:
  • T1087.002 - Domain Account
  • T1558 - Steal or Forge Kerberos Tickets
  • T1547.013 - XDG Autostart Entries
  • T1686 - Disable or Modify System Firewall
MITREへのリンク →

menuPass

Score: 15.48
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1558 - Steal or Forge Kerberos Tickets
  • T1174 - Password Filter DLL
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

TA551

Score: 8.84
Matched TTPs:
  • T1087.002 - Domain Account
  • T1558 - Steal or Forge Kerberos Tickets
  • T1218.012 - Verclsid
  • T1027.014 - Polymorphic Code
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

HEXANE

Score: 4.94
Matched TTPs:
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Threat Group-3390

Score: 16.27
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

LazyScripter

Score: 11.48
Matched TTPs:
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT39

Score: 18.86
Matched TTPs:
  • T1087.002 - Domain Account
  • T1499.002 - Service Exhaustion Flood
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1564.007 - VBA Stomping
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Higaisa

Score: 12.42
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
  • T1546.017 - Udev Rules
MITREへのリンク →

Rancor

Score: 6.25
Matched TTPs:
  • T1087.002 - Domain Account
  • T1685.002 - Disable or Modify Cloud Log
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Wizard Spider

Score: 9.08
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

OilRig

Score: 27.85
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1558 - Steal or Forge Kerberos Tickets
  • T1048 - Exfiltration Over Alternative Protocol
  • T1218.010 - Regsvr32
  • T1592.002 - Software
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Sandworm Team

Score: 26.64
Matched TTPs:
  • T1087.002 - Domain Account
  • T1686.003 - Windows Host Firewall
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1558 - Steal or Forge Kerberos Tickets
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Magic Hound

Score: 12.15
Matched TTPs:
  • T1087.002 - Domain Account
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Storm-1811

Score: 9.58
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Inception

Score: 8.77
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.012 - Verclsid
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
MITREへのリンク →

EXOTIC LILY

Score: 6.78
Matched TTPs:
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Ajax Security Team

Score: 4.09
Matched TTPs:
  • T1087.002 - Domain Account
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Saint Bear

Score: 11.91
Matched TTPs:
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1064 - Scripting
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
MITREへのリンク →

FIN6

Score: 8.89
Matched TTPs:
  • T1087.002 - Domain Account
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1027.007 - Dynamic API Resolution
  • T1547.008 - LSASS Driver
MITREへのリンク →

Whitefly

Score: 3.30
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

TA459

Score: 3.68
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Nomadic Octopus

Score: 3.75
Matched TTPs:
  • T1087.002 - Domain Account
  • T1558 - Steal or Forge Kerberos Tickets
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Gorgon Group

Score: 8.62
Matched TTPs:
  • T1087.002 - Domain Account
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1597 - Search Closed Sources
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT19

Score: 8.77
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1027.014 - Polymorphic Code
MITREへのリンク →

TA2541

Score: 14.24
Matched TTPs:
  • T1087.002 - Domain Account
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

Earth Lusca

Score: 15.22
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1027.010 - Command Obfuscation
MITREへのリンク →

SideCopy

Score: 15.44
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1584.002 - DNS Server
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Mofang

Score: 3.94
Matched TTPs:
  • T1087.002 - Domain Account
  • T1546.017 - Udev Rules
MITREへのリンク →

Tonto Team

Score: 4.79
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Andariel

Score: 3.06
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

BRONZE BUTLER

Score: 13.13
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT38

Score: 34.15
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1685.002 - Disable or Modify Cloud Log
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1138 - Application Shimming
  • T1218.012 - Verclsid
  • T1048 - Exfiltration Over Alternative Protocol
  • T1597 - Search Closed Sources
  • T1174 - Password Filter DLL
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Molerats

Score: 10.97
Matched TTPs:
  • T1087.002 - Domain Account
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.010 - AutoHotKey & AutoIT
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

Gamaredon Group

Score: 26.94
Matched TTPs:
  • T1087.002 - Domain Account
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1218.012 - Verclsid
  • T1608 - Stage Capabilities
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1059.013 - Container CLI/API
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

Darkhotel

Score: 8.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1059.010 - AutoHotKey & AutoIT
  • T1064 - Scripting
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT32

Score: 26.45
Matched TTPs:
  • T1087.002 - Domain Account
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1027.014 - Polymorphic Code
  • T1174 - Password Filter DLL
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

The White Company

Score: 3.66
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
MITREへのリンク →

IndigoZebra

Score: 3.58
Matched TTPs:
  • T1087.002 - Domain Account
  • T1608.005 - Link Target
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT33

Score: 4.46
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Silence

Score: 12.47
Matched TTPs:
  • T1087.002 - Domain Account
  • T1590.003 - Network Trust Dependencies
  • T1048 - Exfiltration Over Alternative Protocol
  • T1070.009 - Clear Persistence
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Indrik Spider

Score: 3.36
Matched TTPs:
  • T1087.002 - Domain Account
  • T1597 - Search Closed Sources
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT29

Score: 33.53
Matched TTPs:
  • T1087.002 - Domain Account
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1138 - Application Shimming
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1218.009 - Regsvcs/Regasm
  • T1546.018 - Python Startup Hooks
  • T1070.009 - Clear Persistence
  • T1555.004 - Windows Credential Manager
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Confucius

Score: 8.81
Matched TTPs:
  • T1087.002 - Domain Account
  • T1218.012 - Verclsid
  • T1608.005 - Link Target
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

BlackTech

Score: 7.77
Matched TTPs:
  • T1087.002 - Domain Account
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
MITREへのリンク →

Windshift

Score: 7.68
Matched TTPs:
  • T1087.002 - Domain Account
  • T1558 - Steal or Forge Kerberos Tickets
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
  • T1547.008 - LSASS Driver
MITREへのリンク →

Medusa Group

Score: 17.68
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1590.003 - Network Trust Dependencies
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Aquatic Panda

Score: 7.62
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Blue Mockingbird

Score: 8.55
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

BlackByte

Score: 13.30
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Ke3chang

Score: 8.15
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT3

Score: 10.61
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1177 - LSASS Driver
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Agrius

Score: 8.96
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1558 - Steal or Forge Kerberos Tickets
  • T1597 - Search Closed Sources
MITREへのリンク →

Cinnamon Tempest

Score: 7.48
Matched TTPs:
  • T1176.001 - Browser Extensions
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Volt Typhoon

Score: 20.93
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1070.008 - Clear Mailbox Data
  • T1049 - System Network Connections Discovery
  • T1584.002 - DNS Server
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Storm-0501

Score: 8.06
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Chimera

Score: 8.58
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1590.003 - Network Trust Dependencies
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Velvet Ant

Score: 5.93
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1597 - Search Closed Sources
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

GALLIUM

Score: 7.27
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1174 - Password Filter DLL
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Evilnum

Score: 3.89
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

LuminousMoth

Score: 4.48
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1091 - Replication Through Removable Media
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN13

Score: 9.14
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1558 - Steal or Forge Kerberos Tickets
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Daggerfly

Score: 5.80
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1174 - Password Filter DLL
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

BackdoorDiplomacy

Score: 3.98
Matched TTPs:
  • T1089 - Disabling Security Tools
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

ZIRCONIUM

Score: 9.83
Matched TTPs:
  • T1685.002 - Disable or Modify Cloud Log
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1608.005 - Link Target
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Turla

Score: 9.84
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1608.005 - Link Target
  • T1597 - Search Closed Sources
  • T1027.010 - Command Obfuscation
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

ToddyCat

Score: 6.28
Matched TTPs:
  • T1590.003 - Network Trust Dependencies
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Winter Vivern

Score: 6.00
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1140 - Deobfuscate/Decode Files or Information
  • T1558 - Steal or Forge Kerberos Tickets
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT42

Score: 3.38
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Ember Bear

Score: 16.31
Matched TTPs:
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1558 - Steal or Forge Kerberos Tickets
  • T1597 - Search Closed Sources
  • T1218.010 - Regsvr32
  • T1070.009 - Clear Persistence
  • T1003.003 - NTDS
MITREへのリンク →

Sea Turtle

Score: 6.59
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
MITREへのリンク →

Fox Kitten

Score: 5.53
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

INC Ransom

Score: 7.82
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Axiom

Score: 9.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1177 - LSASS Driver
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
MITREへのリンク →

Play

Score: 5.42
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1597 - Search Closed Sources
  • T1070.009 - Clear Persistence
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

HAFNIUM

Score: 7.88
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1049 - System Network Connections Discovery
  • T1608.005 - Link Target
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Deep Panda

Score: 6.03
Matched TTPs:
  • T1177 - LSASS Driver
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Akira

Score: 5.93
Matched TTPs:
  • T1597 - Search Closed Sources
  • T1601 - Modify System Image
MITREへのリンク →

LAPSUS$

Score: 4.13
Matched TTPs:
  • T1601 - Modify System Image
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.76
Matched TTPs:
  • T1218.012 - Verclsid
  • T1218.010 - Regsvr32
  • T1597 - Search Closed Sources
  • T1089 - Disabling Security Tools
  • T1132.001 - Standard Encoding
  • T1176.001 - Browser Extensions
  • T1590.003 - Network Trust Dependencies
  • T1069.001 - Local Groups
  • T1174 - Password Filter DLL
  • T1070.009 - Clear Persistence
  • T1558.005 - Ccache Files
  • T1547.013 - XDG Autostart Entries
  • T1055.005 - Thread Local Storage
  • T1059.010 - AutoHotKey & AutoIT
  • T1547.008 - LSASS Driver
  • T1087.002 - Domain Account
  • T1216 - System Script Proxy Execution
  • T1070.008 - Clear Mailbox Data
  • T1027.010 - Command Obfuscation
  • T1608.005 - Link Target
MITREへのリンク →

APT29

Score: 0.57
Matched TTPs:
  • T1555.004 - Windows Credential Manager
  • T1177 - LSASS Driver
  • T1218.012 - Verclsid
  • T1218.009 - Regsvcs/Regasm
  • T1070.009 - Clear Persistence
  • T1608.005 - Link Target
  • T1547.013 - XDG Autostart Entries
  • T1087.002 - Domain Account
  • T1547.008 - LSASS Driver
  • T1546.018 - Python Startup Hooks
  • T1218.010 - Regsvr32
  • T1140 - Deobfuscate/Decode Files or Information
  • T1138 - Application Shimming
MITREへのリンク →

APT38

Score: 0.57
Matched TTPs:
  • T1597 - Search Closed Sources
  • T1218.012 - Verclsid
  • T1048 - Exfiltration Over Alternative Protocol
  • T1176.001 - Browser Extensions
  • T1590.003 - Network Trust Dependencies
  • T1059.010 - AutoHotKey & AutoIT
  • T1027.010 - Command Obfuscation
  • T1174 - Password Filter DLL
  • T1070.009 - Clear Persistence
  • T1087.002 - Domain Account
  • T1216 - System Script Proxy Execution
  • T1547.013 - XDG Autostart Entries
  • T1685.002 - Disable or Modify Cloud Log
  • T1027.007 - Dynamic API Resolution
  • T1138 - Application Shimming
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る