From 02710714bd172367a087d5134e60f6991da2628b Mon Sep 17 00:00:00 2001 From: Daniel Plohmann Date: Fri, 29 Sep 2017 11:43:38 +0200 Subject: [PATCH] add APT33 as identified by FireEye --- clusters/threat-actor.json | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 8392d19..5ab379b 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -663,6 +663,17 @@ "value": "Charming Kitten", "description": "Charming Kitten (aka Parastoo, aka Newscaster) is an group with a suspected nexus to Iran that targets organizations involved in government, defense technology, military, and diplomacy sectors." }, + { + "meta": { + "country": "IR", + "synonyms": [], + "refs": [ + "https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html" + ] + }, + "description": "Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.", + "value": "APT33" + }, { "meta": { "country": "IR",