From e3e5560e3741f181bd6efd80a77c25169d472c6e Mon Sep 17 00:00:00 2001 From: Mathieu Beligon Date: Wed, 2 Nov 2022 17:57:47 -0700 Subject: [PATCH] [threat-actors] Remove subaat duplicate --- clusters/threat-actor.json | 10 ---------- 1 file changed, 10 deletions(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index b4923fb4..f75bda0f 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -5810,16 +5810,6 @@ "uuid": "a3cc5105-3bc6-498b-8d53-981e12d86909", "value": "The Big Bang" }, - { - "description": "In mid-July, Palo Alto Networks Unit 42 identified a small targeted phishing campaign aimed at a government organization. While tracking the activities of this campaign, we identified a repository of additional malware, including a web server that was used to host the payloads used for both this attack as well as others.", - "meta": { - "refs": [ - "https://researchcenter.paloaltonetworks.com/2017/10/unit42-tracking-subaat-targeted-phishing-attacks-point-leader-threat-actors-repository/" - ] - }, - "uuid": "a7bc4ef2-971a-11e8-9bf0-13aa7d6d8651", - "value": "Subaat" - }, { "description": "Unit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of monitoring Subaat included realizing the actor was possibly part of a larger crew of individuals responsible for carrying out targeted attacks against worldwide governmental organizations. Technical analysis on some of the attacks as well as attribution links with Pakistan actors have been already depicted by 360 and Tuisec, in which they found interesting connections to a larger group of attackers Unit 42 researchers have been tracking, which we are calling Gorgon Group.", "meta": {