mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-11-29 18:27:19 +00:00
[threat-actors] Add Bignosa
This commit is contained in:
parent
bb09f64e8b
commit
2cf8b058bb
1 changed files with 11 additions and 0 deletions
|
@ -15560,6 +15560,17 @@
|
||||||
},
|
},
|
||||||
"uuid": "21ad5aad-0a55-457d-b94d-3b4565e82e0a",
|
"uuid": "21ad5aad-0a55-457d-b94d-3b4565e82e0a",
|
||||||
"value": "CyberNiggers"
|
"value": "CyberNiggers"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with disguised Agent Tesla attachments protected by Cassandra Protector. They compromised servers by installing Plesk and RoundCube, connected via SSH and RDP, and used advanced obfuscation methods to evade detection. Bignosa collaborated with another cybercriminal named Gods, who provided advice and assistance in their malicious activities. The actor has been linked to multiple phishing attacks and malware distribution campaigns, showcasing a high level of sophistication in their operations.",
|
||||||
|
"meta": {
|
||||||
|
"country": "KE",
|
||||||
|
"refs": [
|
||||||
|
"https://research.checkpoint.com/2024/agent-tesla-targeting-united-states-and-australia/"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"uuid": "07232925-bd1b-49a9-adca-46536ff6fdd8",
|
||||||
|
"value": "Bignosa"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"version": 305
|
"version": 305
|
||||||
|
|
Loading…
Reference in a new issue