From bb434b11cfb2ab99bb4e6ea6800ef0ebb489c121 Mon Sep 17 00:00:00 2001 From: Alexandre Dulaunoy Date: Mon, 9 May 2022 14:16:01 +0200 Subject: [PATCH] chg: [threat-actor] ModifiedElephant added Fix #709 --- clusters/threat-actor.json | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 69ba274..b4960dc 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -9259,7 +9259,20 @@ }, "uuid": "54ae5c75-8aab-41a8-971a-03d53db9b35c", "value": "Cosmic Lynx" + }, + { + "description": "Our research into these intrusions revealed a decade of persistent malicious activity targeting specific groups and individuals that we now attribute to a previously unknown threat actor named ModifiedElephant. This actor has operated for years, evading research attention and detection due to their limited scope of operations, the mundane nature of their tools, and their regionally-specific targeting. ModifiedElephant is still active at the time of writing.", + "meta": { + "cfr-target-category": [ + "Civil Society" + ], + "refs": [ + "https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/" + ] + }, + "uuid": "6cce6ecc-e6f5-4ae5-b8c5-cf633b7cf973", + "value": "ModifiedElephant" } ], - "version": 223 + "version": 224 }