From 2bc8e1e719641e7134d897c0071133586085259f Mon Sep 17 00:00:00 2001 From: Deborah Servili Date: Mon, 24 Sep 2018 11:51:09 +0200 Subject: [PATCH] add Cobalt Dickensthreat actor --- clusters/threat-actor.json | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index b0006a7..83d8a44 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -5859,7 +5859,21 @@ ] }, "uuid": "bea5e256-bcc0-11e8-a478-bbf7e7585a1e" + }, + { + "value": "COBALT DICKENS", + "description": "”A threat group associated with the Iranian government. The threat group created lookalike domains to phish targets and used credentials to steal intellectual property from specific resources, including library systems.”", + "meta": { + "refs": [ + "https://www.bleepingcomputer.com/news/security/iranian-hackers-charged-in-march-are-still-actively-phishing-universities/", + "https://www.cyberscoop.com/cobalt-dickens-iran-mabna-institiute-dell-secureworks/" + ], + "synonyms": [ + "Cobalt Dickens" + ] + }, + "uuid": "6c79bd1a-bfde-11e8-8c33-db4d9968671a" } ], - "version": 64 + "version": 65 }