Trusted Design

Phishers Abuse Business Account Manager Service

概要

An unknown threat actor exploited Meta's Business Account Manager service to send phishing emails from legitimate Meta addresses between November 2025 and June 2026. The attackers manipulated the business partner mechanism by embedding URLs in the business name field, causing emails to appear as legitimate Meta communications. The campaign evolved to incorporate Facebook Messenger chatbots and exfiltrated stolen credentials, MFA codes, phone numbers, and identity documents to a private Telegram channel. The phishing pages impersonated Meta's Agency Partner Program and Verified badge services, targeting businesses to capture account credentials. Meta responded by implementing detections and blocking accounts attempting to use URLs in business names. Vietnamese language elements in the exfiltration process suggest the attackers' possible origin.

Created: 2026-07-09

Indicators

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

HAFNIUM

Score: 11.07
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1049 - System Network Connections Discovery
  • T1552.008 - Chat Messages
  • T1056 - Input Capture
MITREへのリンク →

menuPass

Score: 13.17
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1527 - Application Access Token
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1547.011 - Plist Modification
MITREへのリンク →

Wizard Spider

Score: 20.96
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1183 - Image File Execution Options Injection
  • T1083 - File and Directory Discovery
  • T1597 - Search Closed Sources
  • T1056 - Input Capture
  • T1001.003 - Protocol or Service Impersonation
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT33

Score: 7.61
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1556 - Modify Authentication Process
MITREへのリンク →

Fox Kitten

Score: 7.22
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1177 - LSASS Driver
  • T1055.013 - Process Doppelgänging
MITREへのリンク →

Volt Typhoon

Score: 32.66
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1686.003 - Windows Host Firewall
  • T1003.007 - Proc Filesystem
  • T1547.005 - Security Support Provider
  • T1083 - File and Directory Discovery
  • T1049 - System Network Connections Discovery
  • T1552.008 - Chat Messages
  • T1584.002 - DNS Server
  • T1065 - Uncommonly Used Port
  • T1569.002 - Service Execution
MITREへのリンク →

APT1

Score: 8.80
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
MITREへのリンク →

Mustang Panda

Score: 26.54
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1055.013 - Process Doppelgänging
  • T1136.003 - Cloud Account
  • T1056 - Input Capture
  • T1565.002 - Transmitted Data Manipulation
  • T1055.005 - Thread Local Storage
  • T1556 - Modify Authentication Process
MITREへのリンク →

Play

Score: 6.83
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1597 - Search Closed Sources
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

Chimera

Score: 6.13
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1003.007 - Proc Filesystem
  • T1056 - Input Capture
MITREへのリンク →

Sea Turtle

Score: 3.11
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1098.007 - Additional Local or Domain Groups
MITREへのリンク →

APT39

Score: 20.11
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1598.003 - Spearphishing Link
  • T1547.011 - Plist Modification
  • T1055.013 - Process Doppelgänging
  • T1599 - Network Boundary Bridging
  • T1001.003 - Protocol or Service Impersonation
  • T1027.004 - Compile After Delivery
  • T1569.002 - Service Execution
MITREへのリンク →

RedCurl

Score: 18.31
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1598.003 - Spearphishing Link
  • T1016.002 - Wi-Fi Discovery
  • T1090 - Proxy
  • T1128 - Netsh Helper DLL
  • T1027.004 - Compile After Delivery
  • T1055.009 - Proc Memory
MITREへのリンク →

APT5

Score: 4.19
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
MITREへのリンク →

Agrius

Score: 5.98
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1597 - Search Closed Sources
MITREへのリンク →

GALLIUM

Score: 6.93
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1547.011 - Plist Modification
MITREへのリンク →

APT41

Score: 23.19
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1562.004 - Disable or Modify System Firewall
  • T1177 - LSASS Driver
  • T1027 - Obfuscated Files or Information
  • T1574.009 - Path Interception by Unquoted Path
  • T1001.003 - Protocol or Service Impersonation
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

MuddyWater

Score: 15.46
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1518.002 - Backup Software Discovery
  • T1547.011 - Plist Modification
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT28

Score: 28.85
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1222.002 - Linux and Mac Permissions
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1131 - Authentication Package
  • T1562.004 - Disable or Modify System Firewall
  • T1547.011 - Plist Modification
  • T1574.009 - Path Interception by Unquoted Path
  • T1585 - Establish Accounts
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Turla

Score: 18.45
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1131 - Authentication Package
  • T1597 - Search Closed Sources
  • T1056 - Input Capture
  • T1027.004 - Compile After Delivery
  • T1569.002 - Service Execution
MITREへのリンク →

BRONZE BUTLER

Score: 16.82
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1592.004 - Client Configurations
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
  • T1591.001 - Determine Physical Locations
MITREへのリンク →

UNC3886

Score: 16.74
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1689 - Downgrade Attack
  • T1009 - Binary Padding
  • T1021.006 - Windows Remote Management
  • T1597 - Search Closed Sources
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Kimsuky

Score: 46.92
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1546.013 - PowerShell Profile
  • T1213.006 - Databases
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1131 - Authentication Package
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1609 - Container Administration Command
  • T1597 - Search Closed Sources
  • T1027.014 - Polymorphic Code
  • T1690 - Prevent Command History Logging
  • T1056 - Input Capture
  • T1030 - Data Transfer Size Limits
  • T1027.004 - Compile After Delivery
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

APT3

Score: 7.62
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1547.011 - Plist Modification
  • T1177 - LSASS Driver
MITREへのリンク →

FIN8

Score: 10.30
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1598.003 - Spearphishing Link
  • T1027 - Obfuscated Files or Information
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

Ke3chang

Score: 12.33
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1003.007 - Proc Filesystem
  • T1055.013 - Process Doppelgänging
  • T1090 - Proxy
MITREへのリンク →

Lotus Blossom

Score: 4.52
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1569.002 - Service Execution
MITREへのリンク →

FIN13

Score: 14.18
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1584.008 - Network Devices
  • T1547.005 - Security Support Provider
  • T1134.001 - Token Impersonation/Theft
  • T1569.002 - Service Execution
MITREへのリンク →

Earth Lusca

Score: 18.40
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1562.004 - Disable or Modify System Firewall
  • T1110.003 - Password Spraying
  • T1056 - Input Capture
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Magic Hound

Score: 23.42
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1547.005 - Security Support Provider
  • T1009 - Binary Padding
  • T1562.004 - Disable or Modify System Firewall
  • T1183 - Image File Execution Options Injection
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Aquatic Panda

Score: 8.51
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1003.007 - Proc Filesystem
  • T1562.004 - Disable or Modify System Firewall
  • T1597 - Search Closed Sources
MITREへのリンク →

INC Ransom

Score: 13.20
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1083 - File and Directory Discovery
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1055.009 - Proc Memory
MITREへのリンク →

Akira

Score: 12.28
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1137.005 - Outlook Rules
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1056 - Input Capture
MITREへのリンク →

ToddyCat

Score: 5.95
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1009 - Binary Padding
  • T1056 - Input Capture
MITREへのリンク →

APT29

Score: 30.79
Matched TTPs:
  • T1222.002 - Linux and Mac Permissions
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1202 - Indirect Command Execution
  • T1562.004 - Disable or Modify System Firewall
  • T1547.011 - Plist Modification
  • T1177 - LSASS Driver
  • T1592.004 - Client Configurations
  • T1556.008 - Network Provider DLL
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT32

Score: 29.19
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1131 - Authentication Package
  • T1055.013 - Process Doppelgänging
  • T1592.004 - Client Configurations
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
  • T1484 - Domain or Tenant Policy Modification
  • T1556 - Modify Authentication Process
MITREへのリンク →

Saint Bear

Score: 10.02
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1055.013 - Process Doppelgänging
  • T1597 - Search Closed Sources
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

FIN6

Score: 12.48
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1055.013 - Process Doppelgänging
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sidewinder

Score: 6.13
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1090 - Proxy
MITREへのリンク →

Winter Vivern

Score: 12.58
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1562.004 - Disable or Modify System Firewall
  • T1055.013 - Process Doppelgänging
  • T1090 - Proxy
MITREへのリンク →

Silence

Score: 7.99
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1547.011 - Plist Modification
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Contagious Interview

Score: 37.22
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1131 - Authentication Package
  • T1021.006 - Windows Remote Management
  • T1183 - Image File Execution Options Injection
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1690 - Prevent Command History Logging
  • T1056 - Input Capture
  • T1030 - Data Transfer Size Limits
  • T1027.004 - Compile After Delivery
  • T1565.002 - Transmitted Data Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

LazyScripter

Score: 4.36
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
MITREへのリンク →

TA505

Score: 15.97
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1527 - Application Access Token
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

FIN7

Score: 19.42
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1055.013 - Process Doppelgänging
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
  • T1056 - Input Capture
  • T1065 - Uncommonly Used Port
MITREへのリンク →

Cobalt Group

Score: 17.01
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1518.002 - Backup Software Discovery
  • T1598.004 - Spearphishing Voice
  • T1027.014 - Polymorphic Code
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Higaisa

Score: 5.78
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1569.002 - Service Execution
MITREへのリンク →

Indrik Spider

Score: 16.78
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1003.007 - Proc Filesystem
  • T1183 - Image File Execution Options Injection
  • T1552.008 - Chat Messages
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1056 - Input Capture
MITREへのリンク →

Evilnum

Score: 4.90
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

Star Blizzard

Score: 13.02
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1609 - Container Administration Command
MITREへのリンク →

Mustard Tempest

Score: 4.54
Matched TTPs:
  • T1682 - Query Public AI Services
MITREへのリンク →

Dragonfly

Score: 18.73
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1562.004 - Disable or Modify System Firewall
  • T1055.013 - Process Doppelgänging
  • T1531 - Account Access Removal
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Threat Group-3390

Score: 18.41
Matched TTPs:
  • T1584.008 - Network Devices
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1218.003 - CMSTP
  • T1056 - Input Capture
  • T1574.009 - Path Interception by Unquoted Path
  • T1591.001 - Determine Physical Locations
MITREへのリンク →

Ember Bear

Score: 11.39
Matched TTPs:
  • T1584.008 - Network Devices
  • T1562.004 - Disable or Modify System Firewall
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1056 - Input Capture
MITREへのリンク →

Scattered Spider

Score: 35.44
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1609 - Container Administration Command
  • T1083 - File and Directory Discovery
  • T1556.008 - Network Provider DLL
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1056 - Input Capture
  • T1030 - Data Transfer Size Limits
  • T1565.002 - Transmitted Data Manipulation
  • T1022 - Data Encrypted
MITREへのリンク →

Storm-0501

Score: 26.39
Matched TTPs:
  • T1685.004 - Disable or Modify Linux Audit System Log
  • T1686.003 - Windows Host Firewall
  • T1027 - Obfuscated Files or Information
  • T1027.014 - Polymorphic Code
  • T1056 - Input Capture
  • T1565.002 - Transmitted Data Manipulation
  • T1055.009 - Proc Memory
  • T1158 - Hidden Files and Directories
MITREへのリンク →

Sandworm Team

Score: 35.61
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1686.003 - Windows Host Firewall
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1016.002 - Wi-Fi Discovery
  • T1562.004 - Disable or Modify System Firewall
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1049 - System Network Connections Discovery
  • T1562.001 - Disable or Modify Tools
  • T1027 - Obfuscated Files or Information
  • T1075 - Pass the Hash
MITREへのリンク →

Leviathan

Score: 23.73
Matched TTPs:
  • T1484.002 - Trust Modification
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1562.004 - Disable or Modify System Firewall
  • T1183 - Image File Execution Options Injection
  • T1554 - Compromise Host Software Binary
  • T1027.014 - Polymorphic Code
  • T1056 - Input Capture
  • T1001.003 - Protocol or Service Impersonation
MITREへのリンク →

Gamaredon Group

Score: 17.85
Matched TTPs:
  • T1527 - Application Access Token
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1090 - Proxy
  • T1554 - Compromise Host Software Binary
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Lazarus Group

Score: 28.31
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1547.011 - Plist Modification
  • T1069.001 - Local Groups
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1055.005 - Thread Local Storage
  • T1569.002 - Service Execution
  • T1556 - Modify Authentication Process
MITREへのリンク →

Tropic Trooper

Score: 11.04
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1090 - Proxy
  • T1136.003 - Cloud Account
  • T1128 - Netsh Helper DLL
MITREへのリンク →

admin@338

Score: 3.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
MITREへのリンク →

WIRTE

Score: 6.02
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Inception

Score: 3.62
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
MITREへのリンク →

EXOTIC LILY

Score: 8.52
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1690 - Prevent Command History Logging
MITREへのリンク →

Patchwork

Score: 4.31
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1001.003 - Protocol or Service Impersonation
MITREへのリンク →

TA551

Score: 3.62
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.014 - Polymorphic Code
MITREへのリンク →

RTM

Score: 3.80
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

APT19

Score: 5.96
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1055.013 - Process Doppelgänging
  • T1027.014 - Polymorphic Code
MITREへのリンク →

SideCopy

Score: 5.01
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1584.002 - DNS Server
MITREへのリンク →

OilRig

Score: 15.09
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1055.013 - Process Doppelgänging
  • T1128 - Netsh Helper DLL
  • T1556 - Modify Authentication Process
MITREへのリンク →

Moonstone Sleet

Score: 7.02
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

Machete

Score: 3.22
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1027.004 - Compile After Delivery
MITREへのリンク →

TA2541

Score: 6.94
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1597 - Search Closed Sources
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Tonto Team

Score: 5.96
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1547.011 - Plist Modification
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT37

Score: 5.56
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1055.013 - Process Doppelgänging
  • T1027.004 - Compile After Delivery
MITREへのリンク →

CURIUM

Score: 4.68
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
MITREへのリンク →

APT38

Score: 13.41
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1590 - Gather Victim Network Information
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

DarkHydrus

Score: 5.01
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1531 - Account Access Removal
MITREへのリンク →

APT-C-36

Score: 3.27
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

TeamTNT

Score: 18.46
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1098.007 - Additional Local or Domain Groups
  • T1009 - Binary Padding
  • T1562.004 - Disable or Modify System Firewall
  • T1110.003 - Password Spraying
  • T1597 - Search Closed Sources
  • T1022 - Data Encrypted
MITREへのリンク →

Storm-1811

Score: 18.20
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1027 - Obfuscated Files or Information
  • T1599 - Network Boundary Bridging
  • T1486 - Data Encrypted for Impact
  • T1030 - Data Transfer Size Limits
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

HEXANE

Score: 12.37
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1547.005 - Security Support Provider
  • T1183 - Image File Execution Options Injection
  • T1056 - Input Capture
  • T1065 - Uncommonly Used Port
MITREへのリンク →

APT42

Score: 13.43
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1599 - Network Boundary Bridging
  • T1128 - Netsh Helper DLL
  • T1030 - Data Transfer Size Limits
MITREへのリンク →

ZIRCONIUM

Score: 5.87
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1056 - Input Capture
  • T1027.004 - Compile After Delivery
MITREへのリンク →

RedEcho

Score: 6.66
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Silent Librarian

Score: 11.09
Matched TTPs:
  • T1098.007 - Additional Local or Domain Groups
  • T1183 - Image File Execution Options Injection
  • T1546.008 - Accessibility Features
  • T1609 - Container Administration Command
MITREへのリンク →

Medusa Group

Score: 17.66
Matched TTPs:
  • T1218.003 - CMSTP
  • T1009 - Binary Padding
  • T1183 - Image File Execution Options Injection
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
  • T1128 - Netsh Helper DLL
  • T1056 - Input Capture
MITREへのリンク →

LAPSUS$

Score: 16.87
Matched TTPs:
  • T1547.005 - Security Support Provider
  • T1609 - Container Administration Command
  • T1556.008 - Network Provider DLL
  • T1030 - Data Transfer Size Limits
  • T1065 - Uncommonly Used Port
MITREへのリンク →

Salt Typhoon

Score: 8.93
Matched TTPs:
  • T1009 - Binary Padding
  • T1110.003 - Password Spraying
  • T1556 - Modify Authentication Process
MITREへのリンク →

Rocke

Score: 12.72
Matched TTPs:
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1027.004 - Compile After Delivery
  • T1022 - Data Encrypted
MITREへのリンク →

Velvet Ant

Score: 16.34
Matched TTPs:
  • T1009 - Binary Padding
  • T1597 - Search Closed Sources
  • T1562.001 - Disable or Modify Tools
  • T1128 - Netsh Helper DLL
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BlackByte

Score: 10.61
Matched TTPs:
  • T1009 - Binary Padding
  • T1134.001 - Token Impersonation/Theft
  • T1597 - Search Closed Sources
  • T1027 - Obfuscated Files or Information
MITREへのリンク →

SilverTerrier

Score: 3.29
Matched TTPs:
  • T1131 - Authentication Package
MITREへのリンク →

FIN5

Score: 5.09
Matched TTPs:
  • T1547.011 - Plist Modification
  • T1055.013 - Process Doppelgänging
MITREへのリンク →

Deep Panda

Score: 6.03
Matched TTPs:
  • T1177 - LSASS Driver
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Axiom

Score: 6.91
Matched TTPs:
  • T1177 - LSASS Driver
  • T1049 - System Network Connections Discovery
MITREへのリンク →

LuminousMoth

Score: 5.45
Matched TTPs:
  • T1056 - Input Capture
  • T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →

Cinnamon Tempest

Score: 4.35
Matched TTPs:
  • T1056 - Input Capture
  • T1027.004 - Compile After Delivery
MITREへのリンク →

Thrip

Score: 5.67
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT18

Score: 3.84
Matched TTPs:
  • T1591.001 - Determine Physical Locations
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.70
Matched TTPs:
  • T1560.001 - Archive via Utility
  • T1546.013 - PowerShell Profile
  • T1565.002 - Transmitted Data Manipulation
  • T1056 - Input Capture
  • T1597 - Search Closed Sources
  • T1009 - Binary Padding
  • T1546.008 - Accessibility Features
  • T1003.007 - Proc Filesystem
  • T1183 - Image File Execution Options Injection
  • T1131 - Authentication Package
  • T1609 - Container Administration Command
  • T1030 - Data Transfer Size Limits
  • T1027.004 - Compile After Delivery
  • T1027.014 - Polymorphic Code
  • T1213.006 - Databases
  • T1690 - Prevent Command History Logging
  • T1098.007 - Additional Local or Domain Groups
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Contagious Interview

Score: 0.56
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1565.002 - Transmitted Data Manipulation
  • T1547.005 - Security Support Provider
  • T1056 - Input Capture
  • T1556 - Modify Authentication Process
  • T1597 - Search Closed Sources
  • T1183 - Image File Execution Options Injection
  • T1131 - Authentication Package
  • T1030 - Data Transfer Size Limits
  • T1562.001 - Disable or Modify Tools
  • T1027.004 - Compile After Delivery
  • T1021.006 - Windows Remote Management
  • T1690 - Prevent Command History Logging
  • T1098.007 - Additional Local or Domain Groups
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る