mirror of
https://github.com/MISP/misp-galaxy.git
synced 2025-01-18 18:46:17 +00:00
[threat-actors] Add Storm-0940
This commit is contained in:
parent
fc27aa88a3
commit
cd32c36785
1 changed files with 11 additions and 0 deletions
|
@ -17526,6 +17526,17 @@
|
||||||
},
|
},
|
||||||
"uuid": "052519d2-1a4f-49d1-abe6-baffce51fedb",
|
"uuid": "052519d2-1a4f-49d1-abe6-baffce51fedb",
|
||||||
"value": "FunkSec"
|
"value": "FunkSec"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "Storm-0940 is a Chinese threat actor active since at least 2021, known for gaining initial access through password spray and brute-force attacks, as well as exploiting network edge applications. Microsoft has observed Storm-0940 utilizing valid credentials obtained from CovertNetwork-1658's password spray operations, indicating a close operational relationship between the two. Once inside a victim environment, Storm-0940 has been seen leveraging compromised credentials for further malicious activities. Additionally, Storm-0940 has employed botnets, such as Quad7, to facilitate password spraying attacks.",
|
||||||
|
"meta": {
|
||||||
|
"country": "CN",
|
||||||
|
"refs": [
|
||||||
|
"https://www.microsoft.com/en-us/security/blog/2024/10/31/chinese-threat-actor-storm-0940-uses-credentials-from-password-spray-attacks-from-a-covert-network/"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"uuid": "301ffea9-edd5-4d89-a65f-8add8e34e95d",
|
||||||
|
"value": "Storm-0940"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"version": 321
|
"version": 321
|
||||||
|
|
Loading…
Add table
Reference in a new issue