mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-11-29 10:17:18 +00:00
[threat-actors] Add BrazenBamboo
This commit is contained in:
parent
7b6cb55f90
commit
19491649f2
1 changed files with 11 additions and 0 deletions
|
@ -17443,6 +17443,17 @@
|
||||||
},
|
},
|
||||||
"uuid": "4d3c9666-6e08-4186-854c-cc0f8c28f5b6",
|
"uuid": "4d3c9666-6e08-4186-854c-cc0f8c28f5b6",
|
||||||
"value": "Kairos"
|
"value": "Kairos"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families. Their infrastructure includes capabilities for zero-day exploitation, specifically targeting vulnerabilities like FortiClient, and employs a command-and-control architecture that supports multi-platform operations. Volexity's analysis indicates that BrazenBamboo is a well-resourced entity with a focus on domestic targets, utilizing custom analyst software to manage data collected from their malware. The ongoing development of their malware families is evidenced by the timestamps associated with their latest payloads.",
|
||||||
|
"meta": {
|
||||||
|
"country": "CN",
|
||||||
|
"refs": [
|
||||||
|
"https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"uuid": "305fbff0-d3ff-43e3-8741-63bad68e47ee",
|
||||||
|
"value": "BrazenBamboo"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"version": 320
|
"version": 320
|
||||||
|
|
Loading…
Reference in a new issue