mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-11-22 23:07:19 +00:00
[threat-actors] Add Earth Yako
This commit is contained in:
parent
baaf153229
commit
cc4dca679b
1 changed files with 14 additions and 0 deletions
|
@ -14932,6 +14932,20 @@
|
|||
},
|
||||
"uuid": "3e9b98d9-0c61-4050-bafa-486622de0080",
|
||||
"value": "Operation Red Signature"
|
||||
},
|
||||
{
|
||||
"description": "Earth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails with malicious attachments to gain initial access to their targets' systems. Earth Yako's objectives and patterns suggest a possible connection to a Chinese APT group, but conclusive proof of their nationality is lacking. They have been observed using various malware delivery methods and techniques, such as the use of Winword.exe for DLL Hijacking.",
|
||||
"meta": {
|
||||
"refs": [
|
||||
"https://www.trendmicro.com/en_us/research/23/b/invitation-to-secret-event-uncovering-earth-yako-campaigns.html"
|
||||
],
|
||||
"synonyms": [
|
||||
"Operation RestyLink",
|
||||
"Enelink"
|
||||
]
|
||||
},
|
||||
"uuid": "2875aff1-2a0f-4e82-ae42-607a3a74d129",
|
||||
"value": "Earth Yako"
|
||||
}
|
||||
],
|
||||
"version": 299
|
||||
|
|
Loading…
Reference in a new issue