From 002728de4c9df156c77df9721f439225b21cc9a3 Mon Sep 17 00:00:00 2001 From: Christophe Vandeplas Date: Thu, 10 Nov 2016 11:16:42 +0100 Subject: [PATCH] Added Rocket Kitten --- clusters/threat-actors.json | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/clusters/threat-actors.json b/clusters/threat-actors.json index 98abb64a..1112bb72 100644 --- a/clusters/threat-actors.json +++ b/clusters/threat-actors.json @@ -534,6 +534,23 @@ ], "country": "IR" }, + { + "value": "Rocket Kitten", + "description": "Targets Saudi Arabia, Israel, US, Iran, high ranking defense officials, embassies of various target countries, notable Iran researchers, human rights activists, media and journalists, academic institutions and various scholars, including scientists in the fields of physics and nuclear sciences.", + "refs": [ + "https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-woolen-goldfish-when-kittens-go-phishing", + "https://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-the-spy-kittens-are-back.pdf", + "http://www.clearskysec.com/thamar-reservoir/", + "https://citizenlab.org/2015/08/iran_two_factor_phishing/", + "https://blog.checkpoint.com/wp-content/uploads/2015/11/rocket-kitten-report.pdf" + ], + "country": "IR", + "synonyms": [ + "TEMP.Beanie", + "Operation Woolen Goldfish", + "Thamar Reservoir" + ] + }, { "value": "Cleaver", "refs": [