Rony
|
112f9e4a08
|
Adding alias Thallium and merging STOLEN PENCIL
Pretty much confirmed from the crowdstrike talk at ATT&CKon 2.0.
And also Netscout named the campaign as STOLEN PENCIL.
|
2020-04-26 23:47:37 +05:30 |
|
Rony
|
aa34775390
|
typo
thanks to @patricksvgr
|
2020-04-19 23:17:44 +05:30 |
|
Rony
|
ddfa280672
|
Update threat-actor.json
|
2020-04-19 23:06:57 +05:30 |
|
Rony
|
7ac2648dbc
|
more fix
|
2020-04-19 23:00:42 +05:30 |
|
Rony
|
573b4807ee
|
fix broken links
|
2020-04-19 16:03:21 +05:30 |
|
Rony
|
42a4820823
|
dead link
|
2020-04-19 11:45:45 +05:30 |
|
Rony
|
0aa34187e9
|
add link
|
2020-04-19 11:29:36 +05:30 |
|
Rony
|
d6bf42254f
|
Merging APT23 & Tropic Trooper
|
2020-04-18 13:22:25 +05:30 |
|
Rony
|
c161080175
|
Update threat-actor.json
|
2020-04-15 21:36:48 +05:30 |
|
Daniel Plohmann
|
aba625dee5
|
removed duplicate entry
|
2020-04-07 08:49:33 +02:00 |
|
Daniel Plohmann
|
e15a4a6525
|
fixing/removing some more dead links
|
2020-04-06 15:25:22 +02:00 |
|
Deborah Servili
|
7859c8dbd7
|
Add coronavirus ransomware
|
2020-04-03 16:19:45 +02:00 |
|
Deborah Servili
|
8a3422acb4
|
add Pyta ransomnotes
|
2020-04-03 11:58:02 +02:00 |
|
Deborah Servili
|
c566c89f2a
|
add pyza ransomware
|
2020-03-27 14:22:34 +01:00 |
|
|
c7104e8819
|
chg: [country] jq all
|
2020-03-23 13:09:14 +01:00 |
|
iglocska
|
777c3188db
|
new: [country] galaxy added
|
2020-03-23 12:10:16 +01:00 |
|
|
35a57c36bf
|
Merge pull request #526 from Delta-Sierra/master
PARINACOTA group
|
2020-03-12 23:23:05 +01:00 |
|
Deborah Servili
|
a706b8ef2e
|
PARINACOTA group
|
2020-03-12 13:11:46 +01:00 |
|
|
e37f320df5
|
Merge pull request #523 from danielplohmann/patch-24
adding aliases MERCURY, HOLMIUM
|
2020-03-09 21:56:27 +01:00 |
|
Daniel Plohmann
|
ab49ef3c1a
|
Kimsuki -> Black Banshee
PWC refers to Kimsuki as Black Banshee (https://www.pwc.co.uk/issues/cyber-security-data-privacy/research/tracking-kimsuky-north-korea-based-cyber-espionage-group-part-2.html)
|
2020-03-09 18:20:56 +01:00 |
|
Daniel Plohmann
|
1260ab156a
|
adding aliases MERCURY, HOLMIUM
Muddywater->MERCURY: https://twitter.com/moranned/status/1234071210822184960
APT33->HOLMIUM: https://www.zdnet.com/article/microsoft-notified-10000-victims-of-nation-state-attacks/
|
2020-03-09 08:50:08 +01:00 |
|
|
e81c91e3e9
|
Merge pull request #522 from Delta-Sierra/master
add sdbbot
|
2020-03-06 15:24:14 +01:00 |
|
Deborah Servili
|
b007d5d3ce
|
add SdBbot
|
2020-03-06 14:33:19 +01:00 |
|
|
a407ddcc5b
|
Merge branch 'master' of github.com:MISP/misp-galaxy
|
2020-03-05 10:49:15 +01:00 |
|
|
375db26505
|
chg: [malpedia] fixes
|
2020-03-05 10:48:28 +01:00 |
|
|
4a64d0a4ad
|
Merge pull request #519 from danielplohmann/crowdstrike2020report
adding new/updated threat actor names from CrowdStrike 2020 report
|
2020-03-05 09:07:16 +01:00 |
|
Corsin Camichel
|
66aa5c3b13
|
fixing a comma error
|
2020-03-04 21:13:01 +01:00 |
|
Daniel Plohmann (jupiter)
|
0c2b0b76eb
|
while we are at it, we can also do Longhorn = APT-C-39
|
2020-03-04 21:09:06 +01:00 |
|
Corsin Camichel
|
a5a7c21c79
|
adding Raccoon (win.raccoon)
|
2020-03-04 21:02:51 +01:00 |
|
Daniel Plohmann (jupiter)
|
184f193342
|
IMPERIAL KITTEN as alias for Tortoiseshell
|
2020-03-04 19:39:14 +01:00 |
|
pnx@pyrite
|
3dc460e795
|
adding new/updated threat actor names from CrowdStrike 2020 report
|
2020-03-04 13:36:34 +01:00 |
|
Daniel Plohmann
|
dc059d1f4d
|
Accenture calls APT32 - "POND LOACH"
|
2020-03-03 19:40:50 +01:00 |
|
Deborah Servili
|
d8ea0f865c
|
add clop ransomware extension
|
2020-03-02 13:33:38 +01:00 |
|
|
b4b91b1e5d
|
chg: [threat-actor] JSON fixed
|
2020-02-28 16:37:24 +01:00 |
|
|
4c7532984a
|
Merge branch 'master' of https://github.com/nyx0/misp-galaxy into nyx0-master
|
2020-02-28 16:36:56 +01:00 |
|
Deborah Servili
|
0d4745d55f
|
Merge branch 'master' of https://github.com/MISP/misp-galaxy
|
2020-02-28 11:38:20 +01:00 |
|
Deborah Servili
|
a61f8d7049
|
add extension to clop ransomware
|
2020-02-28 11:37:54 +01:00 |
|
|
ee63756cc5
|
Merge pull request #516 from rmkml/master
add MedusaLocker ransomware
|
2020-02-23 16:06:45 +01:00 |
|
rmkml
|
590e292b68
|
add MedusaLocker ransomware
|
2020-02-23 16:01:45 +01:00 |
|
Deborah Servili
|
29bf20e89b
|
add razor ransomware
|
2020-02-19 15:55:29 +01:00 |
|
Thomas Dupuy
|
0daeb675f5
|
Add InvisiMole cluster
|
2020-02-18 13:28:32 -05:00 |
|
|
c98093e6fe
|
Merge pull request #513 from danielplohmann/patch-20
adding APT-C-12
|
2020-02-13 21:56:34 +01:00 |
|
Daniel Plohmann
|
e481e9bb50
|
adding APT-C-12
|
2020-02-13 17:44:45 +01:00 |
|
Deborah Servili
|
f196bad4a1
|
add tools used by TA505 + others
|
2020-02-12 15:39:16 +01:00 |
|
Deborah Servili
|
66a721fcd3
|
Merge branch 'master' of https://github.com/MISP/misp-galaxy
|
2020-02-12 15:00:30 +01:00 |
|
Deborah Servili
|
b46f9b68fe
|
add warzone RAT
|
2020-02-06 13:39:58 +01:00 |
|
|
33aa1c8f3f
|
Merge pull request #510 from Delta-Sierra/master
add ransomwares
|
2020-02-06 09:53:19 +01:00 |
|
Deborah Servili
|
46fe9cb82b
|
add ransomwares
|
2020-02-06 09:29:33 +01:00 |
|
Rony
|
22c9badee0
|
Update threat-actor.json
those are the name of aliases of the same malware family sykipot. so removing it.
|
2020-02-05 18:00:31 +05:30 |
|
Deborah Servili
|
5da17d51aa
|
Merge branch 'master' into master
|
2020-01-24 09:33:33 +01:00 |
|