diff --git a/clusters/botnet.json b/clusters/botnet.json index 714be72..0919053 100644 --- a/clusters/botnet.json +++ b/clusters/botnet.json @@ -890,6 +890,15 @@ } ], "uuid": "025ab0ce-bffc-11e8-be19-d70ec22c5d56" + }, + { + "value": "Torii", + "description": " we have been observing a new malware strain, which we call Torii, that differs from Mirai and other botnets we know of, particularly in the advanced techniques it uses.", + "meta": { + "refs": [ + "https://blog.avast.com/new-torii-botnet-threat-research" + ] + } } ], "version": 13 diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 678d0dc..84a92f6 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -5761,7 +5761,8 @@ "cfr-type-of-incident": "Espionage", "cfr-target-category": [ "Private sector" - ] + ], + "country": "RU" }, "uuid": "75ae52b2-bca3-11e8-af90-a78f33eee6c1" }, @@ -5797,7 +5798,8 @@ "cfr-target-category": [ "Government", "Private sector" - ] + ], + "country": "RU" }, "uuid": "358b8982-bcaa-11e8-8a5b-4b618197c5b0", "related": [ @@ -5828,7 +5830,8 @@ "cfr-type-of-incident": "Espionage", "cfr-target-category": [ "Government" - ] + ], + "country": "RU" }, "uuid": "1572f618-bcb3-11e8-841b-1fd7f9cfe126", "related": [ @@ -5859,7 +5862,8 @@ "cfr-target-category": [ "Civil society", "Government" - ] + ], + "country": "CN" }, "uuid": "bea5e256-bcc0-11e8-a478-bbf7e7585a1e" },