Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
概要
Cybercriminals orchestrated a sophisticated malvertising operation leveraging Google Ads to impersonate popular AI developer tools including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains. Over seven weeks spanning April to June 2026, attackers deployed 106 unique malicious hostnames across six distinct waves, initially hosting ClickFix social engineering pages on GitLab infrastructure before pivoting to weaponize claude.ai's legitimate shared chat feature. The campaign targeted technically proficient users searching for AI development tools, tricking them into executing terminal commands that deployed the MacSync infostealer. This credential-harvesting malware collected browser data, SSH keys, and cryptocurrency wallets. The Asia-Pacific region sustained the heaviest impact with 67.2% of over 2,000 victims, particularly concentrated in Taiwan. Anthropic responded by banning malicious accounts and implementing additional abuse mitigations.
Created: 2026-06-19
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 29.80
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1131 - Authentication Package
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1097 - Pass the Ticket
- T1574.009 - Path Interception by Unquoted Path
- T1585 - Establish Accounts
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 31.15
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1543.003 - Windows Service
- T1202 - Indirect Command Execution
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1608.005 - Link Target
- T1556.008 - Network Provider DLL
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 26.00
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1543.003 - Windows Service
- T1003.007 - Proc Filesystem
- T1131 - Authentication Package
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 27.65
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1134.002 - Create Process with Token
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1565 - Data Manipulation
- T1027.014 - Polymorphic Code
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 8.31
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1134.002 - Create Process with Token
- T1608.005 - Link Target
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 6.52
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1597 - Search Closed Sources
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 9.45
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1090 - Proxy
- T1159 - Launch Agent
MITREへのリンク →
Score: 18.27
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1159 - Launch Agent
MITREへのリンク →
Score: 15.02
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1003.007 - Proc Filesystem
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 3.42
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
MITREへのリンク →
Score: 8.25
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
MITREへのリンク →
Score: 10.56
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1048 - Exfiltration Over Alternative Protocol
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 34.25
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1021.006 - Windows Remote Management
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1565 - Data Manipulation
- T1027.004 - Compile After Delivery
- T1565.002 - Transmitted Data Manipulation
- T1126 - Network Share Connection Removal
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 6.95
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
MITREへのリンク →
Score: 16.54
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1527 - Application Access Token
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 13.16
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 10.70
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1598.004 - Spearphishing Voice
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 4.81
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 55.09
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1543.003 - Windows Service
- T1003.007 - Proc Filesystem
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1131 - Authentication Package
- T1134.002 - Create Process with Token
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
- T1608 - Stage Capabilities
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1565 - Data Manipulation
- T1027.014 - Polymorphic Code
- T1027.004 - Compile After Delivery
- T1565.002 - Transmitted Data Manipulation
- T1126 - Network Share Connection Removal
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 8.63
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.42
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1101 - Security Support Provider
MITREへのリンク →
Score: 37.60
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1055.004 - Asynchronous Procedure Call
- T1608 - Stage Capabilities
- T1608.005 - Link Target
- T1169 - Sudo
- T1136.003 - Cloud Account
- T1565.002 - Transmitted Data Manipulation
- T1159 - Launch Agent
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
MITREへのリンク →
Score: 6.35
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1543.003 - Windows Service
- T1565.002 - Transmitted Data Manipulation
MITREへのリンク →
Score: 12.20
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1565 - Data Manipulation
MITREへのリンク →
Score: 28.88
Matched TTPs:
- T1099 - Timestomp
- T1543.003 - Windows Service
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1134.002 - Create Process with Token
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1565 - Data Manipulation
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 19.06
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1134.002 - Create Process with Token
- T1055.004 - Asynchronous Procedure Call
- T1097 - Pass the Ticket
- T1565 - Data Manipulation
- T1159 - Launch Agent
MITREへのリンク →
Score: 30.12
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1608 - Stage Capabilities
- T1608.005 - Link Target
- T1554 - Compromise Host Software Binary
- T1597 - Search Closed Sources
- T1061 - Graphical User Interface
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 9.52
Matched TTPs:
- T1099 - Timestomp
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 4.48
Matched TTPs:
- T1099 - Timestomp
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 15.60
Matched TTPs:
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1547.005 - Security Support Provider
- T1055.004 - Asynchronous Procedure Call
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 12.88
Matched TTPs:
- T1099 - Timestomp
- T1140 - Deobfuscate/Decode Files or Information
- T1134.002 - Create Process with Token
- T1608.005 - Link Target
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 31.10
Matched TTPs:
- T1099 - Timestomp
- T1686.003 - Windows Host Firewall
- T1003.007 - Proc Filesystem
- T1556.002 - Password Filter DLL
- T1140 - Deobfuscate/Decode Files or Information
- T1547.005 - Security Support Provider
- T1134.002 - Create Process with Token
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1159 - Launch Agent
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 9.28
Matched TTPs:
- T1099 - Timestomp
- T1543.003 - Windows Service
- T1027 - Obfuscated Files or Information
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 5.98
Matched TTPs:
- T1682 - Query Public AI Services
- T1543.003 - Windows Service
MITREへのリンク →
Score: 6.44
Matched TTPs:
- T1584.008 - Network Devices
- T1530 - Data from Cloud Storage
MITREへのリンク →
Score: 8.54
Matched TTPs:
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 14.58
Matched TTPs:
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1097 - Pass the Ticket
- T1531 - Account Access Removal
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 16.14
Matched TTPs:
- T1584.008 - Network Devices
- T1003.007 - Proc Filesystem
- T1140 - Deobfuscate/Decode Files or Information
- T1198 - SIP and Trust Provider Hijacking
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 8.38
Matched TTPs:
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 24.26
Matched TTPs:
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1048 - Exfiltration Over Alternative Protocol
- T1097 - Pass the Ticket
- T1027 - Obfuscated Files or Information
- T1574.009 - Path Interception by Unquoted Path
- T1001.003 - Protocol or Service Impersonation
MITREへのリンク →
Score: 9.64
Matched TTPs:
- T1584.008 - Network Devices
- T1180 - Screensaver
- T1140 - Deobfuscate/Decode Files or Information
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 13.91
Matched TTPs:
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 14.89
Matched TTPs:
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1218.003 - CMSTP
- T1055.004 - Asynchronous Procedure Call
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 19.26
Matched TTPs:
- T1584.008 - Network Devices
- T1543.003 - Windows Service
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1001.003 - Protocol or Service Impersonation
- T1556.009 - Conditional Access Policies
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.78
Matched TTPs:
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 28.89
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1565 - Data Manipulation
- T1027 - Obfuscated Files or Information
- T1565.002 - Transmitted Data Manipulation
MITREへのリンク →
Score: 19.99
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1140 - Deobfuscate/Decode Files or Information
- T1097 - Pass the Ticket
- T1027 - Obfuscated Files or Information
- T1027.014 - Polymorphic Code
- T1565.002 - Transmitted Data Manipulation
MITREへのリンク →
Score: 35.75
Matched TTPs:
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1543.003 - Windows Service
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1134.002 - Create Process with Token
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1562.001 - Disable or Modify Tools
- T1565 - Data Manipulation
- T1027 - Obfuscated Files or Information
- T1075 - Pass the Hash
MITREへのリンク →
Score: 21.23
Matched TTPs:
- T1484.002 - Trust Modification
- T1543.003 - Windows Service
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1554 - Compromise Host Software Binary
- T1565 - Data Manipulation
- T1027.014 - Polymorphic Code
- T1001.003 - Protocol or Service Impersonation
MITREへのリンク →
Score: 11.85
Matched TTPs:
- T1180 - Screensaver
- T1140 - Deobfuscate/Decode Files or Information
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 34.66
Matched TTPs:
- T1180 - Screensaver
- T1566.001 - Spearphishing Attachment
- T1098.007 - Additional Local or Domain Groups
- T1503 - Credentials from Web Browsers
- T1055.004 - Asynchronous Procedure Call
- T1590 - Gather Victim Network Information
- T1048 - Exfiltration Over Alternative Protocol
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1493 - Transmitted Data Manipulation
MITREへのリンク →
Score: 4.89
Matched TTPs:
- T1543.003 - Windows Service
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 6.29
Matched TTPs:
- T1543.003 - Windows Service
- T1608.005 - Link Target
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 3.79
Matched TTPs:
- T1543.003 - Windows Service
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 9.21
Matched TTPs:
- T1543.003 - Windows Service
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.22
Matched TTPs:
- T1543.003 - Windows Service
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 32.77
Matched TTPs:
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1134.002 - Create Process with Token
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1565 - Data Manipulation
- T1055.005 - Thread Local Storage
- T1665 - Hide Infrastructure
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 6.59
Matched TTPs:
- T1543.003 - Windows Service
- T1562.001 - Disable or Modify Tools
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 7.32
Matched TTPs:
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 7.83
Matched TTPs:
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1134.002 - Create Process with Token
- T1565 - Data Manipulation
MITREへのリンク →
Score: 23.40
Matched TTPs:
- T1543.003 - Windows Service
- T1566.001 - Spearphishing Attachment
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1055.004 - Asynchronous Procedure Call
- T1048 - Exfiltration Over Alternative Protocol
- T1097 - Pass the Ticket
- T1556.009 - Conditional Access Policies
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 4.19
Matched TTPs:
- T1543.003 - Windows Service
- T1159 - Launch Agent
MITREへのリンク →
Score: 10.69
Matched TTPs:
- T1543.003 - Windows Service
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 12.77
Matched TTPs:
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
- T1565.002 - Transmitted Data Manipulation
MITREへのリンク →
Score: 11.56
Matched TTPs:
- T1543.003 - Windows Service
- T1530 - Data from Cloud Storage
- T1001.003 - Protocol or Service Impersonation
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 17.81
Matched TTPs:
- T1543.003 - Windows Service
- T1566.001 - Spearphishing Attachment
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1097 - Pass the Ticket
- T1001.003 - Protocol or Service Impersonation
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 22.26
Matched TTPs:
- T1689 - Downgrade Attack
- T1556.002 - Password Filter DLL
- T1140 - Deobfuscate/Decode Files or Information
- T1546.011 - Application Shimming
- T1021.006 - Windows Remote Management
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 9.41
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1159 - Launch Agent
MITREへのリンク →
Score: 10.41
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 4.32
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.09
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1530 - Data from Cloud Storage
MITREへのリンク →
Score: 3.20
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 14.09
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1218.003 - CMSTP
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1565 - Data Manipulation
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 9.62
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1097 - Pass the Ticket
- T1565 - Data Manipulation
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 9.74
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1134.001 - Token Impersonation/Theft
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 6.04
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1055.004 - Asynchronous Procedure Call
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 4.22
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 10.96
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
MITREへのリンク →
Score: 6.71
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1597 - Search Closed Sources
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 4.22
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 8.68
Matched TTPs:
- T1137.005 - Outlook Rules
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.53
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
MITREへのリンク →
Score: 3.92
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 11.32
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1134.002 - Create Process with Token
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 12.57
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1134.002 - Create Process with Token
- T1565 - Data Manipulation
- T1027 - Obfuscated Files or Information
- T1126 - Network Share Connection Removal
MITREへのリンク →
Score: 3.86
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1565 - Data Manipulation
MITREへのリンク →
Score: 12.74
Matched TTPs:
- T1547.005 - Security Support Provider
- T1134.002 - Create Process with Token
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 5.27
Matched TTPs:
- T1547.011 - Plist Modification
- T1097 - Pass the Ticket
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 5.27
Matched TTPs:
- T1134.002 - Create Process with Token
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 6.03
Matched TTPs:
- T1177 - LSASS Driver
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 14.73
Matched TTPs:
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1159 - Launch Agent
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 5.93
Matched TTPs:
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1055.002 - Portable Executable Injection
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →
Score: 9.46
Matched TTPs:
- T1097 - Pass the Ticket
- T1562.001 - Disable or Modify Tools
- T1213.003 - Code Repositories
MITREへのリンク →
Score: 5.14
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 4.68
Matched TTPs:
- T1565 - Data Manipulation
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1531 - Account Access Removal
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1027.014 - Polymorphic Code
- T1159 - Launch Agent
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 5.67
Matched TTPs:
- T1565.002 - Transmitted Data Manipulation
- T1556 - Modify Authentication Process
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1565.002 - Transmitted Data Manipulation
- T1546.008 - Accessibility Features
- T1027.004 - Compile After Delivery
- T1597 - Search Closed Sources
- T1608 - Stage Capabilities
- T1543.003 - Windows Service
- T1098.007 - Additional Local or Domain Groups
- T1546.013 - PowerShell Profile
- T1134.002 - Create Process with Token
- T1027.014 - Polymorphic Code
- T1609 - Container Administration Command
- T1126 - Network Share Connection Removal
- T1546.011 - Application Shimming
- T1213.006 - Databases
- T1608.005 - Link Target
- T1131 - Authentication Package
- T1565 - Data Manipulation
- T1140 - Deobfuscate/Decode Files or Information
- T1003.007 - Proc Filesystem
- T1665 - Hide Infrastructure
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る