From fb177f95dbb64712879ebd66fad3670552865ff1 Mon Sep 17 00:00:00 2001 From: Mathieu4141 Date: Tue, 18 Jun 2024 04:51:29 -0700 Subject: [PATCH] [threat-actors] Add UTG-Q-008 --- clusters/threat-actor.json | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 418b273..9086466 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -16089,6 +16089,16 @@ }, "uuid": "4b32ad58-972e-4aa2-be3d-ff875ed06eba", "value": "Hunt3r Kill3rs" + }, + { + "description": "UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network for espionage activities, including reconnaissance, brute-forcing, and Trojan component delivery. The actor has a history of compromising thousands of servers in China using a password dictionary based on Chinese Pinyin. UTG-Q-008 operates during standard working hours in the UTC+8 time zone, with potential ties to Eastern Europe.", + "meta": { + "refs": [ + "https://ti.qianxin.com/blog/articles/Operation-Veles-Decade-Long-Espionage-Targeting-the-Global-Research-and-Education-Sector-EN/" + ] + }, + "uuid": "fd17cd3c-5131-4907-be7d-83a0c7dabd36", + "value": "UTG-Q-008" } ], "version": 310