mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-11-22 23:07:19 +00:00
update threat actor
This commit is contained in:
parent
0bb1420ab7
commit
940762e0c5
2 changed files with 39 additions and 2 deletions
|
@ -92,6 +92,34 @@
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"related": [
|
"related": [
|
||||||
|
{
|
||||||
|
"dest-uuid": "b42378e0-f147-496f-992a-26a49705395b",
|
||||||
|
"tags": [
|
||||||
|
"estimative-language:likelihood-probability=\"likely\""
|
||||||
|
],
|
||||||
|
"type": "similar"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"dest-uuid": "2abe89de-46dd-4dae-ae22-b49a593aff54",
|
||||||
|
"tags": [
|
||||||
|
"estimative-language:likelihood-probability=\"likely\""
|
||||||
|
],
|
||||||
|
"type": "similar"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"dest-uuid": "e336aeba-b61a-44e0-a0df-cd52a5839db5",
|
||||||
|
"tags": [
|
||||||
|
"estimative-language:likelihood-probability=\"likely\""
|
||||||
|
],
|
||||||
|
"type": "similar"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"dest-uuid": "7789fc1b-3cbc-4a1c-8ef0-8b06760f93e7",
|
||||||
|
"tags": [
|
||||||
|
"estimative-language:likelihood-probability=\"likely\""
|
||||||
|
],
|
||||||
|
"type": "similar"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"dest-uuid": "c82c904f-b3b4-40a2-bf0d-008912953104",
|
"dest-uuid": "c82c904f-b3b4-40a2-bf0d-008912953104",
|
||||||
"tags": [
|
"tags": [
|
||||||
|
|
|
@ -1471,6 +1471,7 @@
|
||||||
"value": "Impersonating Panda"
|
"value": "Impersonating Panda"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
"description": "We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer. Watering hole attacks are an increasingly popular component of APT campaigns, as many people are more aware of spear phishing and are less likely to open documents or click on links in unsolicited emails. Watering hole attacks offer a much better chance of success because they involve compromising legitimate websites and installing malware intended to compromise website visitors. These are often popular websites frequented by people who work in specific industries or have political sympathies to which the actors want to gain access.\nIn contrast to many other APT campaigns, which tend to rely heavily on spear phishing to gain victims, “th3bug” is known for compromising legitimate websites their intended visitors are likely to frequent. Over the summer they compromised several sites, including a well-known Uyghur website written in that native language.",
|
||||||
"meta": {
|
"meta": {
|
||||||
"attribution-confidence": "50",
|
"attribution-confidence": "50",
|
||||||
"country": "CN",
|
"country": "CN",
|
||||||
|
@ -1852,7 +1853,11 @@
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html"
|
"https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html"
|
||||||
],
|
],
|
||||||
"synonyms": []
|
"synonyms": [
|
||||||
|
"APT 33",
|
||||||
|
"Elfin",
|
||||||
|
"MAGNALLIUM"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
"related": [
|
"related": [
|
||||||
{
|
{
|
||||||
|
@ -2301,7 +2306,9 @@
|
||||||
"Minidionis",
|
"Minidionis",
|
||||||
"SeaDuke",
|
"SeaDuke",
|
||||||
"Hammer Toss",
|
"Hammer Toss",
|
||||||
"YTTRIUM"
|
"YTTRIUM",
|
||||||
|
"Iron Hemlock",
|
||||||
|
"Grizzly Steppe"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"related": [
|
"related": [
|
||||||
|
@ -4080,9 +4087,11 @@
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"OceanLotus Group",
|
"OceanLotus Group",
|
||||||
"Ocean Lotus",
|
"Ocean Lotus",
|
||||||
|
"OceanLotus",
|
||||||
"Cobalt Kitty",
|
"Cobalt Kitty",
|
||||||
"APT-C-00",
|
"APT-C-00",
|
||||||
"SeaLotus",
|
"SeaLotus",
|
||||||
|
"Sea Lotus",
|
||||||
"APT-32",
|
"APT-32",
|
||||||
"APT 32",
|
"APT 32",
|
||||||
"Ocean Buffalo"
|
"Ocean Buffalo"
|
||||||
|
|
Loading…
Reference in a new issue