[threat-actors] Add UTG-Q-008

This commit is contained in:
Mathieu4141 2024-06-18 04:51:29 -07:00
parent 1b34a49453
commit fb177f95db

View file

@ -16089,6 +16089,16 @@
},
"uuid": "4b32ad58-972e-4aa2-be3d-ff875ed06eba",
"value": "Hunt3r Kill3rs"
},
{
"description": "UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network for espionage activities, including reconnaissance, brute-forcing, and Trojan component delivery. The actor has a history of compromising thousands of servers in China using a password dictionary based on Chinese Pinyin. UTG-Q-008 operates during standard working hours in the UTC+8 time zone, with potential ties to Eastern Europe.",
"meta": {
"refs": [
"https://ti.qianxin.com/blog/articles/Operation-Veles-Decade-Long-Espionage-Targeting-the-Global-Research-and-Education-Sector-EN/"
]
},
"uuid": "fd17cd3c-5131-4907-be7d-83a0c7dabd36",
"value": "UTG-Q-008"
}
],
"version": 310