[threat-actors] Add CostaRicto

This commit is contained in:
Mathieu4141 2023-11-20 09:29:07 -08:00
parent 4c9063b772
commit 00ca4c865f

View file

@ -13329,6 +13329,17 @@
}, },
"uuid": "3baec27f-3827-4a38-82c8-7195a18193f9", "uuid": "3baec27f-3827-4a38-82c8-7195a18193f9",
"value": "Storm Cloud" "value": "Storm Cloud"
},
{
"description": "CostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware tools and sophisticated techniques like VPN proxy and SSH tunnelling. While their targets are scattered across different regions, there is a concentration in South Asia.",
"meta": {
"refs": [
"https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced",
"https://www.cybersecurityintelligence.com/blog/outsourced-cyber-spying-5335.html"
]
},
"uuid": "5587f082-349b-46ab-9e6f-303d9bfd1e1b",
"value": "CostaRicto"
} }
], ],
"version": 294 "version": 294