diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 1f2574f..efa585c 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -1047,7 +1047,6 @@ ], "synonyms": [ "GreedyTaotie", - "Emissary Panda", "TG-3390", "APT 27", "APT27", @@ -9862,12 +9861,14 @@ "meta": { "country": "CN", "refs": [ + "https://i.blackhat.com/Asia-22/Friday-Materials/AS-22-Li-To-Loot-Or-Not-To-Loot-That-Is-Not-a-Question.pdf", "https://www.microsoft.com/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself", "https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation", "https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility", "https://twitter.com/cglyer/status/1480734487000453121" ], "synonyms": [ + "SLIME34", "DEV-0401" ] }, @@ -10037,21 +10038,6 @@ }, "uuid": "d58030e2-5673-4836-9aff-ab6d55da0bc0", "value": "SLIME29" - }, - { - "meta": { - "attribution-confidence": "75", - "cfr-suspected-state-sponsor": "China", - "cfr-target-category": [ - "Private Sector" - ], - "country": "CN", - "refs": [ - "https://i.blackhat.com/Asia-22/Friday-Materials/AS-22-Li-To-Loot-Or-Not-To-Loot-That-Is-Not-a-Question.pdf" - ] - }, - "uuid": "a8c39768-92b2-4d9f-8adf-03f06e327785", - "value": "SLIME34" } ], "version": 239