diff --git a/clusters/threat-actors.json b/clusters/threat-actors.json index 1112bb7..1d56cf4 100644 --- a/clusters/threat-actors.json +++ b/clusters/threat-actors.json @@ -98,14 +98,6 @@ "value": "Eloquent Panda", "country": "CN" }, - { - "value": "Emissary Panda", - "description": "A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.", - "refs": [ - "http://www.scmagazineuk.com/iran-and-russia-blamed-for-state-sponsored-espionage/article/330401/" - ], - "country": "CN" - }, { "value": "Dizzy Panda", "synonyms": [ @@ -288,8 +280,10 @@ }, { "value": "Emissary Panda", + "description": "A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.", "refs": [ - "http://www.secureworks.com/cyber-threat-intelligence/threats/threat-group-3390-targets-organizations-for-cyberespionage/" + "http://www.secureworks.com/cyber-threat-intelligence/threats/threat-group-3390-targets-organizations-for-cyberespionage/", + "http://www.scmagazineuk.com/iran-and-russia-blamed-for-state-sponsored-espionage/article/330401/" ], "country": "CN", "synonyms": [ @@ -506,6 +500,10 @@ }, { "value": "Cutting Kitten", + "description": "While tracking a suspected Iran-based threat group known as Threat Group-2889[1] (TG-2889), Dell SecureWorks Counter Threat Unitâ„¢ (CTU) researchers uncovered a network of fake LinkedIn profiles. These convincing profiles form a self-referenced network of seemingly established LinkedIn users. CTU researchers assess with high confidence the purpose of this network is to target potential victims through social engineering. Most of the legitimate LinkedIn accounts associated with the fake accounts belong to individuals in the Middle East, and CTU researchers assess with medium confidence that these individuals are likely targets of TG-2889.", + "refs": [ + "http://www.secureworks.com/cyber-threat-intelligence/threats/suspected-iran-based-hacker-group-creates-network-of-fake-linkedin-profiles/" + ], "synonyms": [ "ITSecTeam", "Threat Group 2889", @@ -565,17 +563,6 @@ "value": "Sands Casino", "country": "IR" }, - { - "value": "Threat Group-2889", - "description": "While tracking a suspected Iran-based threat group known as Threat Group-2889[1] (TG-2889), Dell SecureWorks Counter Threat Unitâ„¢ (CTU) researchers uncovered a network of fake LinkedIn profiles. These convincing profiles form a self-referenced network of seemingly established LinkedIn users. CTU researchers assess with high confidence the purpose of this network is to target potential victims through social engineering. Most of the legitimate LinkedIn accounts associated with the fake accounts belong to individuals in the Middle East, and CTU researchers assess with medium confidence that these individuals are likely targets of TG-2889.", - "refs": [ - "http://www.secureworks.com/cyber-threat-intelligence/threats/suspected-iran-based-hacker-group-creates-network-of-fake-linkedin-profiles/" - ], - "synonyms": [ - "TG-2889" - ], - "country": "IR" - }, { "value": "Rebel Jackal", "synonyms": [ diff --git a/clusters/tools.json b/clusters/tools.json index 084effa..c370738 100644 --- a/clusters/tools.json +++ b/clusters/tools.json @@ -342,10 +342,6 @@ { "value": "Preshin" }, - { - "value": "Rekaf", - "refs": ["https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks"] - }, { "value": "Oficla" },