From 00ca4c865fa8944c0ca721b24f66cae35b21767b Mon Sep 17 00:00:00 2001 From: Mathieu4141 Date: Mon, 20 Nov 2023 09:29:07 -0800 Subject: [PATCH] [threat-actors] Add CostaRicto --- clusters/threat-actor.json | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 2c3da14..f7d4221 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -13329,6 +13329,17 @@ }, "uuid": "3baec27f-3827-4a38-82c8-7195a18193f9", "value": "Storm Cloud" + }, + { + "description": "CostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware tools and sophisticated techniques like VPN proxy and SSH tunnelling. While their targets are scattered across different regions, there is a concentration in South Asia.", + "meta": { + "refs": [ + "https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced", + "https://www.cybersecurityintelligence.com/blog/outsourced-cyber-spying-5335.html" + ] + }, + "uuid": "5587f082-349b-46ab-9e6f-303d9bfd1e1b", + "value": "CostaRicto" } ], "version": 294