mirror of
https://github.com/MISP/misp-galaxy.git
synced 2025-02-17 01:06:22 +00:00
Add POLONIUM TA.
This commit is contained in:
parent
684c6be358
commit
a86d866534
1 changed files with 34 additions and 1 deletions
|
@ -9542,7 +9542,40 @@
|
||||||
},
|
},
|
||||||
"uuid": "091a0b69-74de-44b6-bb12-16b7a8fd078b",
|
"uuid": "091a0b69-74de-44b6-bb12-16b7a8fd078b",
|
||||||
"value": "ToddyCat"
|
"value": "ToddyCat"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM.",
|
||||||
|
"meta": {
|
||||||
|
"attribution-confidence": "75",
|
||||||
|
"cfr-suspected-state-sponsor": [
|
||||||
|
"Lebanon",
|
||||||
|
"Iran"
|
||||||
|
],
|
||||||
|
"cfr-suspected-victims": [
|
||||||
|
"Israel"
|
||||||
|
],
|
||||||
|
"cfr-target-category": [
|
||||||
|
"Critical manufacturing",
|
||||||
|
"Defense industrial base",
|
||||||
|
"Financial services",
|
||||||
|
"Food and agriculture",
|
||||||
|
"Government agencies and services",
|
||||||
|
"Healthcare and public health",
|
||||||
|
"Information technology",
|
||||||
|
"Transportation systems"
|
||||||
|
],
|
||||||
|
"cfr-type-of-incident": "Espionage",
|
||||||
|
"country": [
|
||||||
|
"LB",
|
||||||
|
"IR"
|
||||||
|
],
|
||||||
|
"refs": [
|
||||||
|
"https://www.microsoft.com/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"uuid": "3c5129ea-8f18-4bcf-a33b-b5aab0720494",
|
||||||
|
"value": "POLONIUM"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"version": 229
|
"version": 230
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Reference in a new issue