diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 7500353..415303e 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -7861,7 +7861,18 @@ }, "uuid": "f9702059-97f4-4fc0-810b-3041b918f5d7", "value": "BRONZE PRESIDENT" + }, + { + "description": "An actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian company. To spread the malware, they use unique implementations to leverage the exploits of known vulnerabilities (such as CVE-2017-11882) and later deploy a Powershell payload in the final stages.", + "meta": { + "refs": [ + "https://securelist.com/apt-trends-report-q1-2018/85280/", + "https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/" + ] + }, + "uuid": "c4ce1174-9462-47e9-8038-794f40a184b3", + "value": "SideWinder" } ], - "version": 148 + "version": 149 } diff --git a/clusters/tool.json b/clusters/tool.json index 93501b3..cb02fa6 100644 --- a/clusters/tool.json +++ b/clusters/tool.json @@ -7945,7 +7945,27 @@ }, "uuid": "4a60dc72-1ca0-4503-a635-96e119c5278d", "value": "Autochk Rootkit" + }, + { + "description": "New trojan called Lampion has spread using template emails from the Portuguese Government Finance & Tax during the last days of 2019.", + "meta": { + "refs": [ + "https://seguranca-informatica.pt/targeting-portugal-a-new-trojan-lampion-has-spread-using-template-emails-from-the-portuguese-government-finance-tax/" + ] + }, + "uuid": "dd299e22-bf82-4317-8c81-c6b1f7514571", + "value": "Lampion" + }, + { + "description": "Bitdefender researchers tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has recently incorporated Monero cryptocurrency mining features.", + "meta": { + "refs": [ + "https://labs.bitdefender.com/2020/01/hold-my-beer-mirai-spinoff-named-liquorbot-incorporates-cryptomining/" + ] + }, + "uuid": "e537e165-ea8b-4e75-8813-6519632d3f6a", + "value": "LiquorBot" } ], - "version": 131 + "version": 132 }