Commit graph

509 commits

Author SHA1 Message Date
Deborah Servili
1da2dc8af1
add Turla Group Symonym variant 2019-10-31 16:33:32 +01:00
Deborah Servili
efa2f43c0f
Merge pull request #467 from Delta-Sierra/master
Few updates
2019-10-31 14:31:16 +01:00
Deborah Servili
bee9b80898
jq 2019-10-31 10:37:36 +01:00
Deborah Servili
0a8f989e1c
add Winnti related tools etc. 2019-10-31 10:36:15 +01:00
Rony
1fc0f5e2e7
Update threat-actor.json 2019-10-17 09:46:56 +05:30
Deborah Servili
88025a541f
add operation soft cell 2019-10-14 16:07:35 +02:00
Deborah Servili
a4b59f647c
jq 2019-09-25 13:41:55 +02:00
309109eb27
chg: [threat-actor] new LookBack (Malware?Campaign?TA?)
Signed-off: During MISP training
2019-09-25 12:12:34 +02:00
a5ae130916
chg: [threat-actor] Evil Eye and POISON CARP
Ref: https://citizenlab.ca/2019/09/poison-carp-tibetan-groups-targeted-with-1-click-mobile-exploits/
Signed-off: Jean-Louis during training session
2019-09-25 11:27:03 +02:00
Deborah Servili
638cdd4198
version update 2019-09-20 14:54:56 +02:00
Deborah Servili
b9b4b9c651
Add Tortoiseshell thrat actor 2019-09-20 14:53:25 +02:00
StefanKelm
db2b5a13ef
Update threat-actor.json
Silent Librarian
2019-09-12 11:57:03 +02:00
Deborah Servili
718ea55dd7
Merge branch 'master' into master 2019-09-04 14:42:47 +02:00
Deborah Servili
9e3a998dfc
aff SectorJ04 group 2019-09-03 15:51:21 +02:00
Daniel Plohmann
f40b7dd132
'SectorJ04 Group' as alias introduced by NSHC for TA505
Not explicitly mentioned in the blog post but it looks like we just got an alias for TA505... https://threatrecon.nshc.net/2019/08/29/sectorj04-groups-increased-activity-in-2019/
2019-09-01 15:46:36 +02:00
0966e58da6
Merge branch 'master' of github.com:MISP/misp-galaxy 2019-08-30 11:06:29 +02:00
f5056ff02e
chg: [threat-actor] add machete-apt synonyms as reported in #445 2019-08-30 11:03:30 +02:00
StefanKelm
49f8f60a85
Update threat-actor.json
Add ITG08 as synonym for FIN6
2019-08-29 13:13:00 +02:00
8d78a2a108
chg: [threat-actor] jq all 2019-08-29 08:31:10 +02:00
791c88f2eb
Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master 2019-08-29 08:30:41 +02:00
Deborah Servili
395dd93e0f
add Asruex Backdoor 2019-08-28 15:40:03 +02:00
9926ea8826
chg: [threat-actor] LYCEUM added - 443 #fixed 2019-08-28 14:35:12 +02:00
Deborah Servili
ea68336b96
add ref for Gamaredon 2019-08-27 08:28:58 +02:00
Sebastian Wagner
38aebbf42a
remove empty strings 2019-08-19 17:04:07 +02:00
3841447e16
Merge pull request #434 from r0ny123/patch-1
added microsoft naming for the groups
2019-08-10 18:52:26 +02:00
Thomas Dupuy
df5c9057a1 add synonyme for Turla 2019-08-09 17:34:22 -04:00
Rony
feac39db6b
added microsoft naming for the groups 2019-08-09 22:19:09 +05:30
Thomas Dupuy
320e298549 update victims 2019-08-09 10:45:10 -04:00
Thomas Dupuy
1988662ee5 add APT41 2019-08-09 10:24:06 -04:00
Nils Kuhnert
17925f3e10
Remove local file link :) 2019-08-03 18:55:00 +02:00
7913adad61
chg: [threat-actor] rollback as discussed by chat with Andras until version 2.0 2019-08-02 16:08:40 +02:00
Andras Iklody
984be50396
lowercased value field for DarkHotel 2019-08-02 15:40:31 +02:00
a401ff7405
Merge branch 'master' into patch-13 2019-08-01 08:52:27 +02:00
Daniel Plohmann
0367e16ce0
adding secureworks actor names for energetic bear and teamspy 2019-07-31 14:35:09 +02:00
Daniel Plohmann
a4a72d0698
adding Proofpoint's TA428 2019-07-31 14:08:50 +02:00
Deborah Servili
2861d2d78c
jq 2019-07-16 10:13:10 +02:00
Deborah Servili
ea4d8a2d42
add SWEED threat actor 2019-07-16 10:03:07 +02:00
9517c8b878
chg: [threat-actor] version updated 2019-06-20 17:58:35 +02:00
8c90f7231c
chg: [threat-actor] duplicated refs removed 2019-06-20 17:35:35 +02:00
5e9d075ae5
chg: [threat-actor] synonyms fixed 2019-06-20 17:30:01 +02:00
195406cc6b
chg: [threat-actor] jq everything 2019-06-20 17:27:55 +02:00
d018519700
Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy 2019-06-20 17:23:04 +02:00
Deborah Servili
30f042211b
fix duplicate 2019-06-20 16:35:49 +02:00
Deborah Servili
a984786c8b
update threat actor galaxy 2019-06-20 16:25:23 +02:00
Rony
7afb9083b2
Update threat-actor.json 2019-06-19 23:29:35 +05:30
Deborah Servili
4bd37e2b2d
update threat actor galaxy 2019-06-19 16:38:04 +02:00
Deborah Servili
52e51833de
update threat actor galaxy 2019-06-18 16:05:49 +02:00
Deborah Servili
431e7a36c1
update threat actor galaxy 2019-06-17 16:36:42 +02:00
Deborah Servili
b966369933
##COMMA## 2019-06-14 16:35:55 +02:00
Deborah Servili
1e5292d999
fix duplicate 2019-06-14 16:21:33 +02:00
Deborah Servili
ead217eb28
Update version 2019-06-14 16:11:02 +02:00
Deborah Servili
98f0572d51
update threat actor galaxy 2019-06-14 16:06:09 +02:00
Deborah Servili
b040f9f57b
fix duplicate and links update (APT34) 2019-06-14 08:41:38 +02:00
Deborah Servili
2001652dae
fix duplicate 2019-06-14 08:28:44 +02:00
Deborah Servili
20e77afcc3
update threat actor galaxy 2019-06-13 16:19:21 +02:00
Deborah Servili
11c2f43c9f
tryto fix duplicate 2019-06-13 11:26:42 +02:00
Deborah Servili
e4245ee991
update threat actor galaxy 2019-06-12 16:25:24 +02:00
Deborah Servili
5a3d7e816f
fix duplicate 2019-06-12 09:24:05 +02:00
Deborah Servili
1ba7f19ca2
update threat actor galaxy 2019-06-11 16:14:58 +02:00
Deborah Servili
347ed5d529
jq 2019-06-11 15:57:21 +02:00
Deborah Servili
79f11de6db
update threat actor galaxy 2019-06-11 15:54:39 +02:00
Deborah Servili
d6b458520b
update threat actor galaxy 2019-06-11 11:57:04 +02:00
Deborah Servili
1f2e59addb
update Threat actor galaxy 2019-06-07 16:34:43 +02:00
Deborah Servili
185763a63a
update threat actor 2019-06-06 16:34:09 +02:00
Deborah Servili
b809b9cfbb
update threat actor darkhotel (nemim might be a typo) 2019-06-06 11:58:19 +02:00
Deborah Servili
189c3066a5
update threat actor 2019-06-04 16:32:39 +02:00
Deborah Servili
a6c9d335ee
fix multiple refs 2019-06-04 08:52:34 +02:00
Deborah Servili
b47863f1c1
update threat actors 2019-05-29 16:18:50 +02:00
Deborah Servili
f48167ce77
update threat actors 2019-05-29 15:34:20 +02:00
Deborah Servili
f4cf3464ce
update threat actors and tools 2019-05-28 16:05:54 +02:00
Deborah Servili
940762e0c5
update threat actor 2019-05-28 09:22:26 +02:00
Deborah Servili
0bb1420ab7
update threat-actor galaxy 2019-05-27 16:38:01 +02:00
Deborah Servili
af6241fd20
update Anchor Panda Threat Actor 2019-05-27 11:47:05 +02:00
Daniel Plohmann
1cc0137c38
adding TA542 to MUMMY SPIDER (emotet) 2019-05-17 17:36:57 +02:00
Rony
380006ecbb
merging Pacifier & Turla 2019-05-16 23:57:49 +05:30
Daniel Plohmann
a20f7fbe91
adding APT31/ZIRCONIUM 2019-05-15 22:43:33 +02:00
Rony
7c0ea4949a
Update threat-actor.json 2019-05-12 11:11:09 +05:30
Raphaël Vinot
988586fde0 fix: Duplicate values, typos. 2019-05-06 17:17:16 +02:00
StefanKelm
7e329855b2
Update threat-actor.json
Silent Librarian / COBALT DICKENS
2019-05-02 15:34:19 +02:00
37da9bebdf
chg: [threat-actor] FIN4 updates 2019-05-01 17:41:03 +02:00
Rony
0afaf81438
Update threat-actor.json 2019-05-01 15:54:38 +05:30
Rony
c565f61761
Update threat-actor.json 2019-05-01 15:51:56 +05:30
Rony
3b185d8435
Update threat-actor.json 2019-05-01 15:40:10 +05:30
Rony
ed351b4eae
updated FIN4 2019-05-01 15:24:59 +05:30
Rony
292df2360a
more report on APT36 2019-04-22 11:05:21 +05:30
Deborah Servili
8ac7aec85c
add Sea Turtle campaign 2019-04-19 13:21:11 +02:00
Christophe Vandeplas
ecc63cf166 chg; [threat-actor] validate + version bump 2019-04-17 21:01:55 +02:00
Christophe Vandeplas
d5fd896bb0
Merge pull request #385 from bartblaze/master
Add Whitefly
2019-04-17 20:53:15 +02:00
Bart
e1cab68683
Add Whitefly 2019-04-17 12:27:18 +01:00
Rony
d98aefa186
fixed the broken link 2019-04-17 09:17:23 +05:30
Bart
3256cca9e0
Add DoNot team references 2019-04-12 21:12:16 +01:00
d7b4908aa3
Merge branch 'patch-8' of https://github.com/danielplohmann/misp-galaxy into danielplohmann-patch-8 2019-04-12 05:58:47 +02:00
Daniel Plohmann
159225b6cf
Based on additional research, APT36 can actually be merged into Mythic Leopard 2019-04-11 22:29:49 +02:00
Rony
7987c8f023
Update threat-actor.json 2019-04-12 01:56:12 +05:30
Rony
2fc914b2f9
Update threat-actor.json 2019-04-12 01:06:50 +05:30
Rony
60e4a486a7
adding additional resources for APT36 2019-04-11 23:55:51 +05:30
Daniel Plohmann
df5301eab5
adding FireEye's TMP.Lapis / APT36 2019-04-09 08:38:44 +02:00
ac6276a906
Merge pull request #371 from Delta-Sierra/master
Add Operation ShadowHammer
2019-03-26 22:25:22 +01:00
Deborah Servili
6027d546f2
Add Operation ShadowHammer 2019-03-26 10:40:29 +01:00
52f088efc9
Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master 2019-03-21 20:51:59 +01:00
Daniel Plohmann
e0bb3d76a6
added APT-C-27 / GoldMouse 2019-03-21 18:06:03 +01:00
Deborah Servili
d0383b460f
jq 2019-03-21 09:15:16 +01:00
Deborah Servili
0fd04fa619
Merge branch 'master' into master 2019-03-21 08:42:30 +01:00
Deborah Servili
f86c748b8c
add AOT-C-27 Goldmouse 2019-03-20 15:45:20 +01:00
b2538a1f8a
chg: [threat-actor] change attribution confidence to be a string by default 2019-03-19 16:51:41 +01:00
4f454493b7
chg: [threat-actor] BRONZE UNION is also uppercase 2019-03-19 14:47:03 +01:00
9a6b597387
chg: [threat-actor] updated the version to avoid the past issue with 0 value for integer values 2019-03-19 14:44:49 +01:00
Deborah Servili
5ce8aae89e
add Operation Comando - hit version 100 2019-03-15 15:04:29 +01:00
5db30ba974
chg: [threat-actor] SandCat added 2019-03-14 06:18:10 +01:00
Deborah Servili
ecf76178e7
add attribution-confidence attribute to threat-actor 2019-03-11 11:18:12 +01:00
Deborah Servili
a65688ec02 Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy 2019-03-11 08:51:47 +01:00
Deborah Servili
33dbda1e1e Merge branch 'master' of https://github.com/MISP/misp-galaxy 2019-03-11 08:51:16 +01:00
Deborah Servili
59ee8a9f13
Merge branch 'master' into master 2019-03-11 08:40:38 +01:00
Deborah Servili
ddab5f7006
Merge branch 'master' into master 2019-03-11 08:40:11 +01:00
139e6c32ed
chg: [threat-actor] new attribution-confidence level introduced 2019-03-11 08:37:49 +01:00
eb665e2883
chg: [threat-actor] jq all the things 2019-03-10 11:15:13 +01:00
6fb1303570
chg: [threat-actor] IRIDIUM added
Ref: https://resecurity.com/blog/parliament_races/
2019-03-10 10:47:34 +01:00
Daniel Plohmann
1d8ada33a0
Update threat-actor.json
another actor described by 360TIC.
2019-03-07 17:50:46 +01:00
Daniel Plohmann
cfb807861a
FireEye upgraded TEMP.Periscope to APT40 2019-03-07 14:34:14 +01:00
Deborah Servili
eb0a33eab6
add operation Kabar Cobra 2019-03-06 15:52:49 +01:00
Deborah Servili
6ffb8dd437
add relation between Lazarus Group and Operation SharpShooter 2019-03-04 12:03:05 +01:00
Deborah Servili
bd3fce00e1
add Razdel 2019-02-25 16:35:06 +01:00
f2159bfaa3
chg: [threat-actor] format fixed 2019-02-22 22:50:42 +01:00
d5df0d1064
chg: [threat-actor] uuid fixed 2019-02-22 22:45:28 +01:00
38283f0f86
chg: [threat-actor] STOLEN PENCIL added 2019-02-22 22:41:06 +01:00
243a6280e0
Merge pull request #350 from bartblaze/master
Add more info on Lotus Blossom
2019-02-21 23:39:33 +01:00
Bart
06553bbec2
Add more info on Lotus Blossom
Add 2 more references, fix typo - Trend calls it "Esile", not "Eslie" as mistakenly stated by CFR. The backdoor itself is commonly referred to as Elise.
2019-02-21 22:31:14 +00:00
ed132cb1b8
chg: [threat-actor] version fixed 2019-02-21 07:18:16 +01:00
Daniel Plohmann
0cd79994cc
Two more actor names from GTR2019
I found two more actor names while going again over the crowdstrike's report and updating the cross-references to malpedia.
2019-02-19 22:38:11 +01:00
Daniel Plohmann
85ec27b4c4
Added missing actors from CrowdStrike GTR2019 2019-02-19 18:26:01 +01:00
Itay Cohen
7d9dc1ec9d
Fix 404'd reference of BuhTrap 2019-02-17 11:33:11 +02:00
Deborah Servili
5bf18ffd23
Merge branch 'master' into master 2019-02-14 16:29:04 +01:00
Deborah Servili
9c450a80d4
add Gallmaker and other clusters 2019-02-14 16:04:54 +01:00
Deborah Servili
2794a20589
add OSX/Shlayer and some refs 2019-02-14 12:42:28 +01:00
Deborah Servili
8aeed60a24
Add Siesta campaign 2019-02-11 16:30:46 +01:00
João Neto
662cc5a012
Updated "Iran" name
This extra space leads to an unnecessary key error when parsing the json file
2019-02-08 16:50:22 +01:00
Nils Kuhnert
fc16f4f69c
Added Velvet Chollima as synonym to Kimsuki 2019-02-08 08:50:05 +01:00
Christophe Vandeplas
e5f74c8fdc
Merge pull request #336 from 3c7/synonym/static-kitten
Added static kitten as synonym for MuddyWater
2019-02-07 08:54:49 +01:00
2bbb8a6a43
Merge pull request #334 from 3c7/synonym/cobalt-spider
Added Cobalt Spider as Synonym for Cobalt
2019-02-07 08:53:19 +01:00
Nils Kuhnert
9778bea81e
Added Cobalt Spider reference 2019-02-07 08:41:00 +01:00
Nils Kuhnert
523a52c4db
Added static kitten as synonym for MuddyWater 2019-02-07 08:38:52 +01:00
Nils Kuhnert
0049acd81c
Added Turbine Panda as synonym for APT 26 2019-02-07 08:28:48 +01:00
Nils Kuhnert
5a077cf838
Added Cobalt Spider as Synonym for Cobalt 2019-02-07 08:26:10 +01:00
Nils Kuhnert
a171d5aa9d
Added Ocean Buffalo synonym for Ocean Lotus 2019-02-03 21:36:21 +01:00
b9f1317941
Merge pull request #332 from Delta-Sierra/master
Add APT39 & LockerGoga
2019-02-01 18:36:12 +01:00
Nils Kuhnert
0b04046d91
Added Quilted Tiger as Synonym for Patchwork/Dropping Elephant. 2019-02-01 13:17:43 +01:00
Deborah Servili
233b7f3aff
add APT39 2019-01-31 18:48:19 +01:00
Nils Kuhnert
d45a32e9e2
Added Shadow Crane as synonym for Dark Hotel. 2019-01-30 08:22:46 +01:00
Nils Kuhnert
42ecbd801c
Added "Stardust Chollima" as synonym for Lazarus. 2019-01-29 08:36:12 +01:00
898bdaf7f8
Merge pull request #328 from Delta-Sierra/master
add Silence Group
2019-01-25 16:43:08 +01:00
Deborah Servili
c11a31b12a
add Silence Group 2019-01-25 16:19:51 +01:00
Thomas Dupuy
d38fb407ec add alternative name for DarkHydrus 2019-01-21 23:14:34 -05:00
Deborah Servili
3bdbd6646b
add Cold River Threat actor 2019-01-17 09:44:09 +01:00
Deborah Servili
5d61a75886
fix versions 2019-01-14 16:34:28 +01:00
Deborah Servili
61093f6f07
add several ransomware and threat actors 2019-01-14 16:28:15 +01:00
Deborah Servili
90d2bf7bc1
add drakhydrus ref 2019-01-11 10:17:07 +01:00
Deborah Servili
cddfd5fcd1
TA505 threat actorand affiliates malwares 2019-01-11 09:53:08 +01:00
Nils Kuhnert
1e4ebdd560
Added OilRig synonym "Helix Kitten". 2018-12-27 09:10:21 +01:00
Daniel Plohmann
cc22da1200 Microsoft alias for apt29 is YTTRIUM 2018-12-19 11:28:44 +01:00
Daniel Plohmann
c9e15b0c08 new name SNAKEMACKEREL for APT28 by Accenture 2018-12-19 10:46:58 +01:00
Deborah Servili
cb4345adf9
add operation sharpshooter 2018-12-13 13:47:54 +01:00
Deborah Servili
70d68a312c
add some clusters or info 2018-12-12 15:26:54 +01:00
Deborah Servili
169d69871a
add Goden Chickens and affiliates 2018-12-12 13:52:55 +01:00
Deborah Servili
bf77e1125a
add Operation Poison Needles 2018-12-07 16:32:09 +01:00
Deborah Servili
79828d7411
add clusters 2018-12-07 13:25:56 +01:00
Deborah Servili
5a725e71ef
add several clusters 2018-12-06 16:13:51 +01:00
Deborah Servili
be9b4ff40f
add DNSpionage cluster 2018-11-29 16:38:06 +01:00
Deborah Servili
b50c8bd805
add PNG Dropper 2018-11-23 10:38:36 +01:00
Deborah Servili
2bf5d46cc4 Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy 2018-11-22 08:59:53 +01:00
Deborah Servili
2f5031b845
add several references for Emotet and others 2018-11-22 08:37:45 +01:00
Deborah Servili
de38e7249c
Merge branch 'master' into master 2018-11-19 15:23:45 +01:00
Deborah Servili
ce61b2d2dd
update oilrig related clusters + others 2018-11-19 14:56:13 +01:00
c9fd60d14b
chg: [threat-actor] INDRIK SPIDER added 2018-11-14 20:46:06 +01:00
Deborah Servili
ca33f1c2ce Merge branch 'master' of https://github.com/MISP/misp-galaxy 2018-11-13 15:25:34 +01:00
Deborah Servili
f55277b682
add several rqansomware and HookAds campaign 2018-11-13 12:20:37 +01:00
a4c916c916
Merge branch 'master' of github.com:MISP/misp-galaxy 2018-11-13 07:01:56 +01:00
Benoit Sevens
8f8c69134e
Update threat-actor.json
Add LuckyMouse link
2018-11-12 13:12:14 +01:00
Deborah Servili
14444e4321
add several tools and refs 2018-11-08 10:39:32 +01:00
Daniel Plohmann
1f6b606f75
added APT38 as (FireEye) alias for Lazarus
cross-references in https://content.fireeye.com/apt/rpt-apt38 suggest the link to Lazarus.
2018-11-07 17:19:50 +01:00
2465235817
Merge pull request #293 from Delta-Sierra/master
add Operation EvilTraffic
2018-10-30 21:02:59 +01:00
Deborah Servili
e6b1eec329
add Chalubo botnet (+ jqallthethings) 2018-10-30 14:39:13 +01:00
Deborah Servili
41942d0daf
add Operation EvilTraffic 2018-10-30 13:28:46 +01:00
Deborah Servili
74ff4b957a
add Operation EvilTraffic 2018-10-30 13:28:27 +01:00
Nils Kuhnert
bc0bf1ca9f
Corrected DarkHotel threat actor entry 2018-10-29 09:03:30 +01:00
Deborah Servili
af6020077e
add August Stealer 2018-10-23 15:25:37 +02:00
Deborah Servili
bd68ee280e Merge branch 'master' of https://github.com/MISP/misp-galaxy 2018-10-22 11:09:37 +02:00
Deborah Servili
4564c5eb37
add DarkPulsar and affiliates + update some refs 2018-10-22 10:14:30 +02:00
Christophe Vandeplas
9dddc4427c jq 2018-10-19 10:23:09 +02:00
Christophe Vandeplas
ddccac58c8 chg: categorization of galaxies
This allows relationships to be created.
2018-10-19 10:18:14 +02:00
Christophe Vandeplas
2b24efb14a fix: add missing relations from commit b857be9cab 2018-10-17 19:15:57 +02:00
Christophe Vandeplas
873bc873b4 Merge remote-tracking branch 'MISP/master' 2018-10-17 18:28:44 +02:00
Christophe Vandeplas
1e90cac717 fix: intrusion is an actor and not a tool 2018-10-17 18:17:33 +02:00
Deborah Servili
c8cbb609a2
add GreyEnergy 2018-10-17 16:05:51 +02:00
Deborah Servili
2ea560f9a7
add refs & synonyms 2018-10-15 12:02:21 +02:00
Deborah Servili
11a27df82d
add roaming mantis group 2018-10-12 15:50:52 +02:00
Deborah Servili
b3109f6aea Merge branch 'master' of https://github.com/MISP/misp-galaxy 2018-10-12 13:55:01 +02:00
Christophe Vandeplas
f26a4f2806 fix: minor newline difference after jq_all_the 2018-10-12 12:31:29 +02:00
Christophe Vandeplas
f14d616e22 chg: magical mapping with malpedia 2018-10-12 11:00:00 +02:00
Christophe Vandeplas
2fbd8ce485 jq sort keys
Allows automation to edit the files
2018-10-12 10:35:31 +02:00
Deborah Servili
4c367737ac
add magecart ref 2018-10-10 14:52:16 +02:00