mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-12-03 12:17:20 +00:00
[threat-actors] Add BlueHornet
This commit is contained in:
parent
5347bcb95c
commit
0ad87ccef4
1 changed files with 16 additions and 0 deletions
|
@ -16256,6 +16256,22 @@
|
||||||
},
|
},
|
||||||
"uuid": "2bd6c045-2ec2-438e-af66-0d97a0163290",
|
"uuid": "2bd6c045-2ec2-438e-af66-0d97a0163290",
|
||||||
"value": "ALTDOS"
|
"value": "ALTDOS"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "BlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked data from other APT groups like Kryptonite Panda and Lazarus Group. BlueHornet has been involved in campaigns such as Operation Renminbi, Operation Ruble, and Operation EUSec, focusing on exfiltrating region-specific data and selling it on the dark web. They have also been known to collaborate with different threat actors and have recently disclosed a zero-day exploit in NGINX 1.18.",
|
||||||
|
"meta": {
|
||||||
|
"refs": [
|
||||||
|
"https://cyberint.com/blog/research/bluehornet-one-apt-to-terrorize-them-all/",
|
||||||
|
"https://www.mandiant.com/resources/blog/killnet-new-capabilities-older-tactics",
|
||||||
|
"https://www.csoonline.com/article/3684668/cyberattacks-against-governments-jumped-95-in-last-half-of-2022-cloudsek-says.html"
|
||||||
|
],
|
||||||
|
"synonyms": [
|
||||||
|
"APT49",
|
||||||
|
"AgainstTheWest"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"uuid": "06a615dc-fa13-4d6a-ac8b-3d2a8c9501c4",
|
||||||
|
"value": "BlueHornet"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"version": 312
|
"version": 312
|
||||||
|
|
Loading…
Reference in a new issue