Merge pull request #707 from 3c7/ta/saintbear

Added SaintBear to the Threat Actor cluster
pull/710/head
Christophe Vandeplas 2022-04-28 10:03:07 +02:00 committed by GitHub
commit 87c1e34ce8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 20 additions and 1 deletions

View File

@ -9164,7 +9164,26 @@
},
"uuid": "ad2d6946-1ec2-4d77-b864-39980af4e103",
"value": "Killnet"
},
{
"description": "A group targeting UA state organizations using the GraphSteel and GrimPlant malware.",
"meta": {
"refs": [
"https://malpedia.caad.fkie.fraunhofer.de/details/win.graphsteel",
"https://cert.gov.ua/article/38374",
"https://blog.malwarebytes.com/threat-intelligence/2022/04/new-uac-0056-activity-theres-a-go-elephant-in-the-room/",
"https://www.intezer.com/blog/research/elephant-malware-targeting-ukrainian-orgs/",
"https://www.sentinelone.com/blog/threat-actor-uac-0056-targeting-ukraine-with-fake-translation-software/"
],
"synonyms": [
"UNC2589",
"TA471",
"UAC-0056"
]
},
"uuid": "c67d3dfb-ab39-46e1-a971-5efdfe6a5b9f",
"value": "SaintBear"
}
],
"version": 218
"version": 219
}