Trusted Design

Hydra Saiga: Covert Espionage and Infiltration of Critical Utilities

概要

Hydra Saiga, a suspected Kazakhstani state-sponsored threat actor, has been actively targeting government, energy, and critical infrastructure in Central Asia, Europe, and the Middle East since 2021. The group is known for using Telegram Bot API for C2 communication and employing a mix of custom implants and 'Living off the Land' techniques. Their activities align closely with Kazakhstan's geopolitical interests, particularly in water and energy sectors. The group has compromised at least 34 organizations across 8 countries, with reconnaissance extending to over 200 additional targets globally. Hydra Saiga's operations demonstrate a clear focus on water infrastructure linked to major regional rivers and gas distribution systems, reflecting strategic intelligence collection efforts.

Created: 2026-04-16

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

Mustang Panda

Score: 25.12
Matched TTPs:
  • T1557 - Adversary-in-the-Middle
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1608.001 - Upload Malware
  • T1218.005 - Mshta
  • T1052.001 - Exfiltration over USB
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

Kimsuky

Score: 45.44
Matched TTPs:
  • T1557 - Adversary-in-the-Middle
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
  • T1555.003 - Credentials from Web Browsers
  • T1218.005 - Mshta
  • T1591 - Gather Victim Org Information
  • T1071.002 - File Transfer Protocols
  • T1534 - Internal Spearphishing
  • T1562.001 - Disable or Modify Tools
  • T1593.001 - Social Media
  • T1656 - Impersonation
  • T1598 - Phishing for Information
  • T1550.002 - Pass the Hash
  • T1204.001 - Malicious Link
MITREへのリンク →

Sea Turtle

Score: 22.88
Matched TTPs:
  • T1557 - Adversary-in-the-Middle
  • T1583.002 - DNS Server
  • T1213.006 - Databases
  • T1190 - Exploit Public-Facing Application
  • T1078 - Valid Accounts
  • T1608.003 - Install Digital Certificate
  • T1584.002 - DNS Server
MITREへのリンク →

Contagious Interview

Score: 25.01
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1593.003 - Code Repositories
  • T1562.001 - Disable or Modify Tools
  • T1593.001 - Social Media
  • T1656 - Impersonation
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Mustard Tempest

Score: 7.87
Matched TTPs:
  • T1583.008 - Malvertising
  • T1608.001 - Upload Malware
  • T1204.001 - Malicious Link
MITREへのリンク →

Daggerfly

Score: 7.24
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1036.003 - Rename Legitimate Utilities
  • T1204.001 - Malicious Link
MITREへのリンク →

GALLIUM

Score: 13.06
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1190 - Exploit Public-Facing Application
  • T1078 - Valid Accounts
  • T1036.003 - Rename Legitimate Utilities
  • T1018 - Remote System Discovery
  • T1550.002 - Pass the Hash
MITREへのリンク →

APT29

Score: 43.01
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1556.007 - Hybrid Identity
  • T1110.003 - Password Spraying
  • T1546.008 - Accessibility Features
  • T1550.003 - Pass the Ticket
  • T1098.005 - Device Registration
  • T1218.005 - Mshta
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1573 - Encrypted Channel
  • T1027.006 - HTML Smuggling
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN13

Score: 15.38
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1134.003 - Make and Impersonate Token
  • T1550.002 - Pass the Hash
  • T1003.003 - NTDS
MITREへのリンク →

Dragonfly

Score: 21.59
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1598.003 - Spearphishing Link
  • T1190 - Exploit Public-Facing Application
  • T1598.002 - Spearphishing Attachment
  • T1071.002 - File Transfer Protocols
  • T1110 - Brute Force
  • T1078 - Valid Accounts
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
MITREへのリンク →

Ke3chang

Score: 15.31
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1587.001 - Malware
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1078 - Valid Accounts
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
MITREへのリンク →

Agrius

Score: 12.67
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1190 - Exploit Public-Facing Application
  • T1110.003 - Password Spraying
  • T1110 - Brute Force
  • T1562.001 - Disable or Modify Tools
  • T1018 - Remote System Discovery
MITREへのリンク →

APT41

Score: 47.67
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
  • T1555.003 - Credentials from Web Browsers
  • T1546.008 - Accessibility Features
  • T1071.002 - File Transfer Protocols
  • T1110 - Brute Force
  • T1078 - Valid Accounts
  • T1486 - Data Encrypted for Impact
  • T1595.003 - Wordlist Scanning
  • T1656 - Impersonation
  • T1213.003 - Code Repositories
  • T1018 - Remote System Discovery
  • T1550.002 - Pass the Hash
  • T1596.005 - Scan Databases
  • T1003.003 - NTDS
  • T1480.001 - Environmental Keying
MITREへのリンク →

APT5

Score: 10.37
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
MITREへのリンク →

menuPass

Score: 12.65
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1190 - Exploit Public-Facing Application
  • T1078 - Valid Accounts
  • T1036.003 - Rename Legitimate Utilities
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
MITREへのリンク →

Threat Group-3390

Score: 14.94
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1018 - Remote System Discovery
  • T1053.002 - At
MITREへのリンク →

Wizard Spider

Score: 24.42
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1055 - Process Injection
  • T1518.002 - Backup Software Discovery
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1555.004 - Windows Credential Manager
  • T1018 - Remote System Discovery
  • T1550.002 - Pass the Hash
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

Ember Bear

Score: 15.42
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1190 - Exploit Public-Facing Application
  • T1110.003 - Password Spraying
  • T1110 - Brute Force
  • T1562.001 - Disable or Modify Tools
  • T1018 - Remote System Discovery
  • T1550.002 - Pass the Hash
MITREへのリンク →

Axiom

Score: 13.65
Matched TTPs:
  • T1583.002 - DNS Server
  • T1190 - Exploit Public-Facing Application
  • T1546.008 - Accessibility Features
  • T1584.005 - Botnet
  • T1078 - Valid Accounts
MITREへのリンク →

HEXANE

Score: 18.30
Matched TTPs:
  • T1583.002 - DNS Server
  • T1608.001 - Upload Malware
  • T1555.003 - Credentials from Web Browsers
  • T1110.003 - Password Spraying
  • T1534 - Internal Spearphishing
  • T1110 - Brute Force
  • T1018 - Remote System Discovery
MITREへのリンク →

Moonstone Sleet

Score: 18.12
Matched TTPs:
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1591 - Gather Victim Org Information
  • T1486 - Data Encrypted for Impact
  • T1598 - Phishing for Information
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Indrik Spider

Score: 9.20
Matched TTPs:
  • T1587.001 - Malware
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1486 - Data Encrypted for Impact
  • T1018 - Remote System Discovery
MITREへのリンク →

Lazarus Group

Score: 19.50
Matched TTPs:
  • T1587.001 - Malware
  • T1110.003 - Password Spraying
  • T1218.005 - Mshta
  • T1591 - Gather Victim Org Information
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1036.003 - Rename Legitimate Utilities
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 19.67
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1555.003 - Credentials from Web Browsers
  • T1110 - Brute Force
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1555.004 - Windows Credential Manager
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 13.02
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1205.001 - Port Knocking
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
MITREへのリンク →

LuminousMoth

Score: 12.31
Matched TTPs:
  • T1587.001 - Malware
  • T1091 - Replication Through Removable Media
  • T1608.001 - Upload Malware
  • T1608.005 - Link Target
  • T1204.001 - Malicious Link
MITREへのリンク →

Sandworm Team

Score: 30.84
Matched TTPs:
  • T1587.001 - Malware
  • T1213.006 - Databases
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1555.003 - Credentials from Web Browsers
  • T1584.005 - Botnet
  • T1078 - Valid Accounts
  • T1486 - Data Encrypted for Impact
  • T1499 - Endpoint Denial of Service
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

Salt Typhoon

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Play

Score: 8.33
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1018 - Remote System Discovery
MITREへのリンク →

Aoqin Dragon

Score: 5.13
Matched TTPs:
  • T1587.001 - Malware
  • T1091 - Replication Through Removable Media
MITREへのリンク →

RedCurl

Score: 5.51
Matched TTPs:
  • T1587.001 - Malware
  • T1555.003 - Credentials from Web Browsers
  • T1204.001 - Malicious Link
MITREへのリンク →

Moses Staff

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Turla

Score: 28.87
Matched TTPs:
  • T1587.001 - Malware
  • T1213.006 - Databases
  • T1584.003 - Virtual Private Server
  • T1055 - Process Injection
  • T1110 - Brute Force
  • T1562.001 - Disable or Modify Tools
  • T1584.006 - Web Services
  • T1068 - Exploitation for Privilege Escalation
  • T1555.004 - Windows Credential Manager
  • T1018 - Remote System Discovery
  • T1204.001 - Malicious Link
MITREへのリンク →

TeamTNT

Score: 9.31
Matched TTPs:
  • T1587.001 - Malware
  • T1071 - Application Layer Protocol
  • T1608.001 - Upload Malware
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

FIN7

Score: 23.17
Matched TTPs:
  • T1587.001 - Malware
  • T1091 - Replication Through Removable Media
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1218.005 - Mshta
  • T1608.005 - Link Target
  • T1591 - Gather Victim Org Information
  • T1078 - Valid Accounts
  • T1486 - Data Encrypted for Impact
  • T1204.001 - Malicious Link
MITREへのリンク →

Scattered Spider

Score: 45.39
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1598.003 - Spearphishing Link
  • T1070.008 - Clear Mailbox Data
  • T1598.004 - Spearphishing Voice
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1486 - Data Encrypted for Impact
  • T1656 - Impersonation
  • T1598 - Phishing for Information
  • T1556.009 - Conditional Access Policies
  • T1213.003 - Code Repositories
  • T1018 - Remote System Discovery
  • T1538 - Cloud Service Dashboard
  • T1003.003 - NTDS
MITREへのリンク →

Storm-0501

Score: 14.60
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1190 - Exploit Public-Facing Application
  • T1110 - Brute Force
  • T1486 - Data Encrypted for Impact
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

FIN6

Score: 21.24
Matched TTPs:
  • T1213.006 - Databases
  • T1555.003 - Credentials from Web Browsers
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1134 - Access Token Manipulation
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Sidewinder

Score: 9.78
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1218.005 - Mshta
  • T1598.002 - Spearphishing Attachment
  • T1204.001 - Malicious Link
MITREへのリンク →

Silent Librarian

Score: 10.47
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1110.003 - Password Spraying
  • T1608.005 - Link Target
  • T1078 - Valid Accounts
MITREへのリンク →

ZIRCONIUM

Score: 11.41
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1555.003 - Credentials from Web Browsers
  • T1068 - Exploitation for Privilege Escalation
  • T1598 - Phishing for Information
  • T1204.001 - Malicious Link
MITREへのリンク →

APT32

Score: 24.10
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1550.003 - Pass the Ticket
  • T1218.005 - Mshta
  • T1068 - Exploitation for Privilege Escalation
  • T1036.003 - Rename Legitimate Utilities
  • T1018 - Remote System Discovery
  • T1550.002 - Pass the Hash
  • T1204.001 - Malicious Link
MITREへのリンク →

Magic Hound

Score: 25.09
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1071 - Application Layer Protocol
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1486 - Data Encrypted for Impact
  • T1573 - Encrypted Channel
  • T1018 - Remote System Discovery
  • T1591.001 - Determine Physical Locations
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT28

Score: 33.46
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1190 - Exploit Public-Facing Application
  • T1110.003 - Password Spraying
  • T1591 - Gather Victim Org Information
  • T1110 - Brute Force
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1598 - Phishing for Information
  • T1498 - Network Denial of Service
  • T1550.002 - Pass the Hash
  • T1003.003 - NTDS
  • T1204.001 - Malicious Link
MITREへのリンク →

Star Blizzard

Score: 9.48
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
  • T1078 - Valid Accounts
MITREへのリンク →

CURIUM

Score: 8.60
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1584.006 - Web Services
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Patchwork

Score: 5.87
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1555.003 - Credentials from Web Browsers
  • T1204.001 - Malicious Link
MITREへのリンク →

HAFNIUM

Score: 21.51
Matched TTPs:
  • T1583.005 - Botnet
  • T1190 - Exploit Public-Facing Application
  • T1110.003 - Password Spraying
  • T1593.003 - Code Repositories
  • T1584.005 - Botnet
  • T1068 - Exploitation for Privilege Escalation
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
MITREへのリンク →

Rocke

Score: 8.25
Matched TTPs:
  • T1071 - Application Layer Protocol
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1018 - Remote System Discovery
MITREへのリンク →

INC Ransom

Score: 10.47
Matched TTPs:
  • T1071 - Application Layer Protocol
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1486 - Data Encrypted for Impact
MITREへのリンク →

Velvet Ant

Score: 7.69
Matched TTPs:
  • T1071 - Application Layer Protocol
  • T1055 - Process Injection
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Volt Typhoon

Score: 26.10
Matched TTPs:
  • T1584.003 - Virtual Private Server
  • T1190 - Exploit Public-Facing Application
  • T1555.003 - Credentials from Web Browsers
  • T1584.005 - Botnet
  • T1591 - Gather Victim Org Information
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1018 - Remote System Discovery
  • T1596.005 - Scan Databases
  • T1003.003 - NTDS
MITREへのリンク →

Gamaredon Group

Score: 16.58
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1218.005 - Mshta
  • T1534 - Internal Spearphishing
  • T1562.001 - Disable or Modify Tools
  • T1204.001 - Malicious Link
MITREへのリンク →

Darkhotel

Score: 3.03
Matched TTPs:
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Tropic Trooper

Score: 10.79
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1052.001 - Exfiltration over USB
  • T1573 - Encrypted Channel
MITREへのリンク →

TA2541

Score: 9.93
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055 - Process Injection
  • T1218.005 - Mshta
  • T1562.001 - Disable or Modify Tools
  • T1204.001 - Malicious Link
MITREへのリンク →

Earth Lusca

Score: 12.31
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1218.005 - Mshta
  • T1584.006 - Web Services
  • T1018 - Remote System Discovery
  • T1204.001 - Malicious Link
MITREへのリンク →

LazyScripter

Score: 5.67
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1218.005 - Mshta
  • T1204.001 - Malicious Link
MITREへのリンク →

SideCopy

Score: 7.94
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1218.005 - Mshta
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

TA505

Score: 9.52
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1555.003 - Credentials from Web Browsers
  • T1562.001 - Disable or Modify Tools
  • T1486 - Data Encrypted for Impact
  • T1204.001 - Malicious Link
MITREへのリンク →

BlackByte

Score: 19.23
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1055 - Process Injection
  • T1134.003 - Make and Impersonate Token
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1486 - Data Encrypted for Impact
  • T1018 - Remote System Discovery
MITREへのリンク →

BITTER

Score: 7.69
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1068 - Exploitation for Privilege Escalation
  • T1573 - Encrypted Channel
MITREへのリンク →

Saint Bear

Score: 8.16
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1562.001 - Disable or Modify Tools
  • T1656 - Impersonation
  • T1204.001 - Malicious Link
MITREへのリンク →

EXOTIC LILY

Score: 9.70
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1593.001 - Social Media
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT42

Score: 11.19
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1070.008 - Clear Mailbox Data
  • T1555.003 - Credentials from Web Browsers
  • T1656 - Impersonation
MITREへのリンク →

Medusa Group

Score: 15.45
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1486 - Data Encrypted for Impact
  • T1650 - Acquire Access
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
MITREへのリンク →

Fox Kitten

Score: 12.59
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1546.008 - Accessibility Features
  • T1110 - Brute Force
  • T1078 - Valid Accounts
  • T1018 - Remote System Discovery
  • T1003.003 - NTDS
MITREへのリンク →

ToddyCat

Score: 5.54
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1018 - Remote System Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Blue Mockingbird

Score: 5.31
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1134 - Access Token Manipulation
MITREへのリンク →

Winter Vivern

Score: 6.45
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1584.006 - Web Services
  • T1204.001 - Malicious Link
MITREへのリンク →

Leviathan

Score: 7.88
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1534 - Internal Spearphishing
  • T1078 - Valid Accounts
  • T1204.001 - Malicious Link
MITREへのリンク →

Volatile Cedar

Score: 5.60
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1595.003 - Wordlist Scanning
MITREへのリンク →

MuddyWater

Score: 9.02
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1555.003 - Credentials from Web Browsers
  • T1218.005 - Mshta
  • T1562.001 - Disable or Modify Tools
  • T1204.001 - Malicious Link
MITREへのリンク →

APT39

Score: 8.32
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1110 - Brute Force
  • T1078 - Valid Accounts
  • T1018 - Remote System Discovery
  • T1204.001 - Malicious Link
MITREへのリンク →

APT38

Score: 16.11
Matched TTPs:
  • T1055 - Process Injection
  • T1218.005 - Mshta
  • T1110 - Brute Force
  • T1562.001 - Disable or Modify Tools
  • T1486 - Data Encrypted for Impact
  • T1036.003 - Rename Legitimate Utilities
  • T1204.001 - Malicious Link
MITREへのリンク →

Silence

Score: 5.43
Matched TTPs:
  • T1055 - Process Injection
  • T1078 - Valid Accounts
  • T1018 - Remote System Discovery
MITREへのリンク →

Cobalt Group

Score: 5.91
Matched TTPs:
  • T1055 - Process Injection
  • T1068 - Exploitation for Privilege Escalation
  • T1204.001 - Malicious Link
MITREへのリンク →

APT37

Score: 4.51
Matched TTPs:
  • T1055 - Process Injection
  • T1555.003 - Credentials from Web Browsers
MITREへのリンク →

PLATINUM

Score: 4.55
Matched TTPs:
  • T1055 - Process Injection
  • T1068 - Exploitation for Privilege Escalation
MITREへのリンク →

APT3

Score: 8.24
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1546.008 - Accessibility Features
  • T1018 - Remote System Discovery
  • T1204.001 - Malicious Link
MITREへのリンク →

APT33

Score: 9.68
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1110.003 - Password Spraying
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1204.001 - Malicious Link
MITREへのリンク →

Stealth Falcon

Score: 5.67
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Leafminer

Score: 6.34
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1110.003 - Password Spraying
  • T1018 - Remote System Discovery
MITREへのリンク →

LAPSUS$

Score: 26.90
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1598.004 - Spearphishing Voice
  • T1593.003 - Code Repositories
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1584.002 - DNS Server
  • T1656 - Impersonation
  • T1213.003 - Code Repositories
  • T1003.003 - NTDS
MITREへのリンク →

Molerats

Score: 3.41
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1204.001 - Malicious Link
MITREへのリンク →

Ajax Security Team

Score: 4.58
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Inception

Score: 4.39
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.005 - Mshta
MITREへのリンク →

Chimera

Score: 15.34
Matched TTPs:
  • T1110.003 - Password Spraying
  • T1078 - Valid Accounts
  • T1556.001 - Domain Controller Authentication
  • T1018 - Remote System Discovery
  • T1550.002 - Pass the Hash
  • T1003.003 - NTDS
MITREへのリンク →

Deep Panda

Score: 4.83
Matched TTPs:
  • T1546.008 - Accessibility Features
  • T1018 - Remote System Discovery
MITREへのリンク →

BRONZE BUTLER

Score: 11.03
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1562.001 - Disable or Modify Tools
  • T1018 - Remote System Discovery
  • T1053.002 - At
MITREへのリンク →

Confucius

Score: 3.70
Matched TTPs:
  • T1218.005 - Mshta
  • T1204.001 - Malicious Link
MITREへのリンク →

PROMETHIUM

Score: 4.13
Matched TTPs:
  • T1205.001 - Port Knocking
MITREへのリンク →

SilverTerrier

Score: 3.62
Matched TTPs:
  • T1071.002 - File Transfer Protocols
MITREへのリンク →

FIN5

Score: 5.49
Matched TTPs:
  • T1110 - Brute Force
  • T1078 - Valid Accounts
  • T1018 - Remote System Discovery
MITREへのリンク →

Akira

Score: 7.10
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1078 - Valid Accounts
  • T1486 - Data Encrypted for Impact
  • T1018 - Remote System Discovery
MITREへのリンク →

Aquatic Panda

Score: 4.54
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1550.002 - Pass the Hash
MITREへのリンク →

FIN8

Score: 8.76
Matched TTPs:
  • T1078 - Valid Accounts
  • T1068 - Exploitation for Privilege Escalation
  • T1486 - Data Encrypted for Impact
  • T1018 - Remote System Discovery
  • T1204.001 - Malicious Link
MITREへのリンク →

APT18

Score: 5.27
Matched TTPs:
  • T1078 - Valid Accounts
  • T1053.002 - At
MITREへのリンク →

Storm-1811

Score: 12.44
Matched TTPs:
  • T1486 - Data Encrypted for Impact
  • T1566.004 - Spearphishing Voice
  • T1656 - Impersonation
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Lotus Blossom

Score: 5.39
Matched TTPs:
  • T1134 - Access Token Manipulation
  • T1018 - Remote System Discovery
MITREへのリンク →

Equation

Score: 8.26
Matched TTPs:
  • T1564.005 - Hidden File System
  • T1480.001 - Environmental Keying
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Windshift

Score: 3.88
Matched TTPs:
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT41

Score: 0.70
Matched TTPs:
  • T1003.002 - Security Account Manager
  • T1018 - Remote System Discovery
  • T1190 - Exploit Public-Facing Application
  • T1546.008 - Accessibility Features
  • T1071.002 - File Transfer Protocols
  • T1486 - Data Encrypted for Impact
  • T1213.003 - Code Repositories
  • T1550.002 - Pass the Hash
  • T1596.005 - Scan Databases
  • T1480.001 - Environmental Keying
  • T1110 - Brute Force
  • T1555.003 - Credentials from Web Browsers
  • T1078 - Valid Accounts
  • T1003.003 - NTDS
  • T1656 - Impersonation
  • T1055 - Process Injection
  • T1595.003 - Wordlist Scanning
MITREへのリンク →

Kimsuky

Score: 0.67
Matched TTPs:
  • T1591 - Gather Victim Org Information
  • T1557 - Adversary-in-the-Middle
  • T1587.001 - Malware
  • T1593.001 - Social Media
  • T1190 - Exploit Public-Facing Application
  • T1071.002 - File Transfer Protocols
  • T1562.001 - Disable or Modify Tools
  • T1550.002 - Pass the Hash
  • T1608.001 - Upload Malware
  • T1218.005 - Mshta
  • T1534 - Internal Spearphishing
  • T1598 - Phishing for Information
  • T1555.003 - Credentials from Web Browsers
  • T1204.001 - Malicious Link
  • T1598.003 - Spearphishing Link
  • T1656 - Impersonation
  • T1055 - Process Injection
MITREへのリンク →

Scattered Spider

Score: 0.67
Matched TTPs:
  • T1556.009 - Conditional Access Policies
  • T1018 - Remote System Discovery
  • T1068 - Exploitation for Privilege Escalation
  • T1486 - Data Encrypted for Impact
  • T1562.001 - Disable or Modify Tools
  • T1598.004 - Spearphishing Voice
  • T1213.003 - Code Repositories
  • T1538 - Cloud Service Dashboard
  • T1598 - Phishing for Information
  • T1070.008 - Clear Mailbox Data
  • T1078 - Valid Accounts
  • T1003.003 - NTDS
  • T1484.002 - Trust Modification
  • T1598.003 - Spearphishing Link
  • T1656 - Impersonation
MITREへのリンク →

APT29

Score: 0.63
Matched TTPs:
  • T1573 - Encrypted Channel
  • T1003.002 - Security Account Manager
  • T1587.001 - Malware
  • T1550.003 - Pass the Ticket
  • T1190 - Exploit Public-Facing Application
  • T1546.008 - Accessibility Features
  • T1068 - Exploitation for Privilege Escalation
  • T1027.006 - HTML Smuggling
  • T1218.005 - Mshta
  • T1110.003 - Password Spraying
  • T1078 - Valid Accounts
  • T1204.001 - Malicious Link
  • T1566.003 - Spearphishing via Service
  • T1098.005 - Device Registration
  • T1556.007 - Hybrid Identity
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る