From cc22da120035a89ad6b417b299a49df0247b18e6 Mon Sep 17 00:00:00 2001 From: Daniel Plohmann Date: Wed, 19 Dec 2018 11:28:44 +0100 Subject: [PATCH] Microsoft alias for apt29 is YTTRIUM --- clusters/threat-actor.json | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index f18181b..f4d6886 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -2175,7 +2175,8 @@ "https://www.us-cert.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf", "https://www.fireeye.com/blog/threat-research/2017/03/dissecting_one_ofap.html", "https://www.cfr.org/interactive/cyber-operations/dukes", - "https://pylos.co/2018/11/18/cozybear-in-from-the-cold/" + "https://pylos.co/2018/11/18/cozybear-in-from-the-cold/", + "https://cloudblogs.microsoft.com/microsoftsecure/2018/12/03/analysis-of-cyberattack-on-u-s-think-tanks-non-profits-public-sector-by-unidentified-attackers/" ], "synonyms": [ "Dukes", @@ -2193,7 +2194,8 @@ "The Dukes", "Minidionis", "SeaDuke", - "Hammer Toss" + "Hammer Toss", + "YTTRIUM" ] }, "related": [