From 83fd4a9af90be1baeadb730cd320db610753a51c Mon Sep 17 00:00:00 2001 From: "Daniel Plohmann (jupiter)" Date: Sat, 17 Mar 2018 11:57:10 +0100 Subject: [PATCH] added leviathan --- clusters/threat-actor.json | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 39ffe8e8..65eb512d 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -2477,6 +2477,20 @@ ], "country": "KP" } + }, + { + "value": "Leviathan", + "description": "Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated research institutions in the United States and Western Europe.", + "meta": { + "refs": [ + "https://www.proofpoint.com/us/threat-insight/post/leviathan-espionage-actor-spearphishes-maritime-and-defense-targets", + "https://www.fireeye.com/blog/threat-research/2018/03/suspected-chinese-espionage-group-targeting-maritime-and-engineering-industries.html" + ], + "synonyms": [ + "TEMP.Periscope" + ], + "country": "CN" + } } ], "name": "Threat actor",