From 14301a9c4cb5f607d3c0de744556de94cc921fb9 Mon Sep 17 00:00:00 2001 From: iglocska Date: Thu, 25 May 2023 07:29:48 +0200 Subject: [PATCH] chg: [threat actors] added Volt Typhoon --- clusters/threat-actor.json | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 871d273..582daca 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -11337,7 +11337,22 @@ }, "uuid": "aac49b4e-74e9-49fa-84f9-e340cf8bafbc", "value": "APT43" + }, + { + "description": "[Microsoft] Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.\n\n[Secureworks] BRONZE SILHOUETTE likely operates on behalf the PRC. The targeting of U.S. government and defense organizations for intelligence gain aligns with PRC requirements, and the tradecraft observed in these engagements overlap with other state-sponsored Chinese threat groups.", + "meta": { + "country": "CN", + "refs": [ + "https://www.secureworks.com/blog/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations", + "https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/" + ], + "synonyms": [ + "BRONZE SILHOUETTE" + ] + }, + "uuid": "f02679fa-5e85-4050-8eb5-c2677d93306f", + "value": "Volt Typhoon" } ], - "version": 273 + "version": 274 }