diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 4406ed1..2cbb3f8 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -17526,6 +17526,17 @@ }, "uuid": "052519d2-1a4f-49d1-abe6-baffce51fedb", "value": "FunkSec" + }, + { + "description": "Storm-0940 is a Chinese threat actor active since at least 2021, known for gaining initial access through password spray and brute-force attacks, as well as exploiting network edge applications. Microsoft has observed Storm-0940 utilizing valid credentials obtained from CovertNetwork-1658's password spray operations, indicating a close operational relationship between the two. Once inside a victim environment, Storm-0940 has been seen leveraging compromised credentials for further malicious activities. Additionally, Storm-0940 has employed botnets, such as Quad7, to facilitate password spraying attacks.", + "meta": { + "country": "CN", + "refs": [ + "https://www.microsoft.com/en-us/security/blog/2024/10/31/chinese-threat-actor-storm-0940-uses-credentials-from-password-spray-attacks-from-a-covert-network/" + ] + }, + "uuid": "301ffea9-edd5-4d89-a65f-8add8e34e95d", + "value": "Storm-0940" } ], "version": 321