mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-11-22 14:57:18 +00:00
[threat-actors] Add MalKamak
This commit is contained in:
parent
f066061f4b
commit
9c0f18e9b9
1 changed files with 11 additions and 0 deletions
|
@ -13526,6 +13526,17 @@
|
|||
},
|
||||
"uuid": "e06e1bcd-7da2-4732-934a-9fa1efa427ad",
|
||||
"value": "Blacktail"
|
||||
},
|
||||
{
|
||||
"description": "MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against global aerospace and telecommunications companies. MalKamak utilizes a sophisticated remote access Trojan called ShellClient, which evades antivirus tools and uses cloud services like Dropbox for command and control.",
|
||||
"meta": {
|
||||
"country": "IR",
|
||||
"refs": [
|
||||
"https://www.cybereason.com/blog/research/operation-ghostshell-novel-rat-targets-global-aerospace-and-telecoms-firms"
|
||||
]
|
||||
},
|
||||
"uuid": "4915bfa3-5f0a-48ec-8ed5-bcd878cba504",
|
||||
"value": "MalKamak"
|
||||
}
|
||||
],
|
||||
"version": 295
|
||||
|
|
Loading…
Reference in a new issue