From fd9201e9e0b21189592be37d253e50414a26d418 Mon Sep 17 00:00:00 2001 From: Mathieu Beligon Date: Fri, 19 Aug 2022 12:16:30 -0700 Subject: [PATCH] Merge APT22 and suckfly --- clusters/threat-actor.json | 24 ++++++------------------ 1 file changed, 6 insertions(+), 18 deletions(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 0817ac5..94217e6 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -3662,10 +3662,14 @@ "https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=62e325ae-f551-4855-b9cf-28a7d52d1534&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments", "https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=7a60af1f-7786-446c-976b-7c71a16e9d3b&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments", "https://attack.mitre.org/groups/G0039/", - "https://exchange.xforce.ibmcloud.com/collection/Suckfly-APT-aa8af56fd12d25c98fc49ca5341160ab" + "https://exchange.xforce.ibmcloud.com/collection/Suckfly-APT-aa8af56fd12d25c98fc49ca5341160ab", + "http://www.slideshare.net/CTruncer/ever-present-persistence-established-footholds-seen-in-the-wild", + "https://www.secureworks.com/research/threat-profiles/bronze-olive" ], "synonyms": [ - "G0039" + "G0039", + "APT22", + "BRONZE OLIVE" ] }, "related": [ @@ -4807,22 +4811,6 @@ "uuid": "a47b79ae-7a0c-4308-9efc-294af19cc795", "value": "APT5" }, - { - "meta": { - "attribution-confidence": "50", - "country": "CN", - "refs": [ - "http://www.slideshare.net/CTruncer/ever-present-persistence-established-footholds-seen-in-the-wild", - "https://www.secureworks.com/research/threat-profiles/bronze-olive" - ], - "synonyms": [ - "APT22", - "BRONZE OLIVE" - ] - }, - "uuid": "7a2457d6-148a-4ce1-9e79-aa43352ee842", - "value": "APT 22" - }, { "description": "Tick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese National University of Defense and Technology, which is possibly linked to the PLA. This threat actor targets organizations in the critical infrastructure, heavy industry, manufacturing, and international relations sectors for espionage purposes. The attacks appear to be centered on political, media, and engineering sectors. STALKER PANDA has been observed conducting targeted attacks against Japan, Taiwan, Hong Kong, and the United States.", "meta": {