From 247dd8652338797ab358859b1c7a6aa16bb9d851 Mon Sep 17 00:00:00 2001 From: Mathieu4141 Date: Wed, 15 Nov 2023 08:19:01 -0800 Subject: [PATCH] [threat-actors] Add Bohrium --- clusters/threat-actor.json | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 7343e5d..44b90ad 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -12976,6 +12976,17 @@ }, "uuid": "c8782e46-447c-4c6e-90c0-82f3bf49d64b", "value": "Prolific Puma" + }, + { + "description": "Bohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle East, and India. They often create fake social media profiles, particularly posing as recruiters, to trick victims into running malware on their computers. Microsoft's Digital Crimes Unit has taken legal action and seized 41 domains used by Bohrium to disrupt their activities. The group has shown a particular interest in sectors such as technology, transportation, government, and education.", + "meta": { + "country": "IR", + "refs": [ + "https://twitter.com/CyberAmyHB/status/1532398956918890500" + ] + }, + "uuid": "111efc97-6a93-487b-8cb3-1e890ac51066", + "value": "Bohrium" } ], "version": 294