From 89b9c0c32c40102860db281e48815f5f6b60fe64 Mon Sep 17 00:00:00 2001 From: Rony Date: Sun, 25 Apr 2021 16:53:36 +0530 Subject: [PATCH 1/4] several updates to apt27 --- clusters/threat-actor.json | 181 +++++-------------------------------- 1 file changed, 24 insertions(+), 157 deletions(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 4fc9c70..7fd880b 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -999,6 +999,8 @@ "cfr-suspected-state-sponsor": "Unknown", "cfr-suspected-victims": [ "United States", + "United Kingdom", + "France", "Japan", "Taiwan", "India", @@ -1009,7 +1011,8 @@ "Australia", "Republic of Korea", "Russia", - "Iran" + "Iran", + "Turkey" ], "cfr-target-category": [ "Government", @@ -1018,23 +1021,33 @@ "cfr-type-of-incident": "Espionage", "country": "CN", "refs": [ - "http://www.secureworks.com/cyber-threat-intelligence/threats/threat-group-3390-targets-organizations-for-cyberespionage/", "https://web.archive.org/web/20140129192702/https://www.scmagazineuk.com/iran-and-russia-blamed-for-state-sponsored-espionage/article/330401/", "https://labs.bitdefender.com/2018/02/operation-pzchao-a-possible-return-of-the-iron-tiger-apt/", "https://labs.bitdefender.com/wp-content/uploads/downloads/operation-pzchao-inside-a-highly-specialized-espionage-infrastructure/", - "https://www.cfr.org/interactive/cyber-operations/iron-tiger" + "https://www.cfr.org/interactive/cyber-operations/iron-tiger", + "https://www.bleepingcomputer.com/news/security/chinese-cyber-espionage-group-hacked-government-data-center/", + "https://www.secureworks.com/research/bronze-union", + "http://newsroom.trendmicro.com/blog/operation-iron-tiger-attackers-shift-east-asia-united-states", + "https://www.secureworks.com/research/threat-group-3390-targets-organizations-for-cyberespionage", + "https://www.threatconnect.com/blog/threatconnect-discovers-chinese-apt-activity-in-europe/", + "https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/decoding-network-data-from-a-gh0st-rat-variant/", + "https://securelist.com/luckymouse-ndisproxy-driver/87914/", + "https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2015/2015.09.17.Operation_Iron_Tiger/Operation%20Iron%20Tiger%20Appendix.pdf", + "https://arstechnica.com/information-technology/2015/08/newly-discovered-chinese-hacking-group-hacked-100-websites-to-use-as-watering-holes/", + "https://securelist.com/luckymouse-hits-national-data-center/86083/", + "https://attack.mitre.org/groups/G0027/", + "https://www.secureworks.com/research/threat-profiles/bronze-union" ], "synonyms": [ "TG-3390", "APT 27", - "TEMP.Hippo", - "Group 35", - "Bronze Union", - "ZipToken", - "HIPPOTeam", "APT27", - "Operation Iron Tiger", - "Iron Tiger APT", + "TEMP.Hippo", + "Red Phoenix", + "Budworm", + "Group 35", + "ZipToken", + "Iron Tiger", "BRONZE UNION", "Lucky Mouse" ] @@ -1046,24 +1059,10 @@ "estimative-language:likelihood-probability=\"likely\"" ], "type": "similar" - }, - { - "dest-uuid": "f1b9f7d6-6ab1-404b-91a6-a1ed1845c045", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "4af45fea-72d3-11e8-846c-d37699506c8d", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" } ], "uuid": "834e0acd-d92a-4e38-bb14-dc4159d7cb32", - "value": "Emissary Panda" + "value": "EMISSARY PANDA" }, { "meta": { @@ -3497,58 +3496,6 @@ "uuid": "a9b44750-992c-4743-8922-129880d277ea", "value": "DragonOK" }, - { - "description": "Chinese threat group that has extensively used strategic Web compromises to target victims.", - "meta": { - "attribution-confidence": "50", - "cfr-suspected-state-sponsor": " China", - "cfr-suspected-victims": [ - "United States", - "United Kingdom", - "France" - ], - "cfr-target-category": [ - "Government", - "Private sector" - ], - "cfr-type-of-incident": "Espionage", - "country": "CN", - "refs": [ - "http://www.secureworks.com/cyber-threat-intelligence/threats/threat-group-3390-targets-organizations-for-cyberespionage/", - "https://attack.mitre.org", - "https://www.cfr.org/interactive/cyber-operations/emissary-panda" - ], - "synonyms": [ - "TG-3390", - "Emissary Panda" - ] - }, - "related": [ - { - "dest-uuid": "fb366179-766c-4a4a-afa1-52bff1fd601c", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "834e0acd-d92a-4e38-bb14-dc4159d7cb32", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "4af45fea-72d3-11e8-846c-d37699506c8d", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - } - ], - "uuid": "f1b9f7d6-6ab1-404b-91a6-a1ed1845c045", - "value": "Threat Group-3390" - }, { "description": "ProjectSauron is the name for a top level modular cyber-espionage platform, designed to enable and manage long-term campaigns through stealthy survival mechanisms coupled with multiple exfiltration methods. Technical details show how attackers learned from other extremely advanced actors in order to avoid repeating their mistakes. As such, all artifacts are customized per given target, reducing their value as indicators of compromise for any other victim. Usually APT campaigns have a geographical nexus, aimed at extracting information within a specific region or from a given industry. That usually results in several infections in countries within that region, or in the targeted industry around the world. Interestingly, ProjectSauron seems to be dedicated to just a couple of countries, focused on collecting high value intelligence by compromising almost all key entities it could possibly reach within the target area. The name, ProjectSauron reflects the fact that the code authors refer to ‘Sauron’ in the Lua scripts.", "meta": { @@ -6124,86 +6071,6 @@ "uuid": "4defbf2e-4f73-11e8-807f-578d61da7568", "value": "ZooPark" }, - { - "description": "Experts assigned the codename of LuckyMouse to the group behind this hack, but they later realized the attackers were an older Chinese threat actor known under various names in the reports of other cyber-security firms, such as Emissary Panda, APT27, Threat Group 3390, Bronze Union, ZipToken, and Iron Tiger", - "meta": { - "attribution-confidence": "50", - "cfr-suspected-state-sponsor": "Unknown", - "cfr-suspected-victims": [ - "United States", - "Japan", - "Taiwan", - "India", - "Canada", - "China", - "Thailand", - "Israel", - "Australia", - "Republic of Korea", - "Russia", - "Iran" - ], - "cfr-target-category": [ - "Government", - "Private sector" - ], - "cfr-type-of-incident": "Espionage", - "refs": [ - "https://www.bleepingcomputer.com/news/security/chinese-cyber-espionage-group-hacked-government-data-center/", - "https://www.secureworks.com/research/bronze-union", - "http://newsroom.trendmicro.com/blog/operation-iron-tiger-attackers-shift-east-asia-united-states", - "https://www.secureworks.com/research/threat-group-3390-targets-organizations-for-cyberespionage", - "https://www.threatconnect.com/blog/threatconnect-discovers-chinese-apt-activity-in-europe/", - "https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/decoding-network-data-from-a-gh0st-rat-variant/", - "https://securelist.com/luckymouse-ndisproxy-driver/87914/", - "https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2015/2015.09.17.Operation_Iron_Tiger/Operation%20Iron%20Tiger%20Appendix.pdf", - "https://www.cfr.org/interactive/cyber-operations/iron-tiger", - "https://arstechnica.com/information-technology/2015/08/newly-discovered-chinese-hacking-group-hacked-100-websites-to-use-as-watering-holes/", - "https://labs.bitdefender.com/2018/02/operation-pzchao-a-possible-return-of-the-iron-tiger-apt/", - "https://securelist.com/luckymouse-hits-national-data-center/86083/", - "https://attack.mitre.org/groups/G0027/", - "https://www.secureworks.com/research/threat-profiles/bronze-union", - "https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/incident-response-polar-ransomware-apt27/" - ], - "synonyms": [ - "Emissary Panda", - "APT27", - "APT 27", - "Threat Group 3390", - "Bronze Union", - "Iron Tiger", - "TG-3390", - "TEMP.Hippo", - "Group 35", - "ZipToken" - ] - }, - "related": [ - { - "dest-uuid": "fb366179-766c-4a4a-afa1-52bff1fd601c", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "834e0acd-d92a-4e38-bb14-dc4159d7cb32", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "f1b9f7d6-6ab1-404b-91a6-a1ed1845c045", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - } - ], - "uuid": "4af45fea-72d3-11e8-846c-d37699506c8d", - "value": "LuckyMouse" - }, { "description": "The Rancor group’s attacks use two primary malware families which are naming DDKONG and PLAINTEE. DDKONG is used throughout the campaign and PLAINTEE appears to be new addition to these attackers’ toolkit. Countries Unit 42 has identified as targeted by Rancor with these malware families include, but are not limited to Singapore and Cambodia.", "meta": { From faed812fc9c38192eb82e750260e25cef234f34b Mon Sep 17 00:00:00 2001 From: Rony Date: Sun, 25 Apr 2021 19:12:20 +0530 Subject: [PATCH 2/4] Merged STALKER PANDA to Tick --- clusters/threat-actor.json | 20 +++++--------------- 1 file changed, 5 insertions(+), 15 deletions(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 7fd880b..25088e6 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -82,18 +82,6 @@ "uuid": "1cb7e1cc-d695-42b1-92f4-fd0112a3c9be", "value": "Comment Crew" }, - { - "description": "The group appears to have close ties to the Chinese National University of Defense and Technology, which is possibly linked to the PLA. Stalker Panda has been observed conducting targeted attacks against Japan, Taiwan, Hong Kong, and the United States. The attacks appear to be centered on political, media, and engineering sectors. The group appears to have been active since around 2010 and they maintain and upgrade their tools regularly.", - "meta": { - "attribution-confidence": "50", - "country": "CN", - "refs": [ - "https://wikileaks.org/vault7/document/2015-08-20150814-256-CSIR-15005-Stalker-Panda/2015-08-20150814-256-CSIR-15005-Stalker-Panda.pdf" - ] - }, - "uuid": "36843742-adf1-427c-a7c0-067d74b4aeaf", - "value": "Stalker Panda" - }, { "description": "These attackers were the subject of an extensive report by Symantec in 2011, which termed the attackers Nitro and stated: 'The goal of the attackers appears to be to collect intellectual property such as design documents, formulas, and manufacturing processes. In addition, the same attackers appear to have a lengthy operation history including attacks on other industries and organizations. Attacks on the chemical industry are merely their latest attack wave. As part of our investigations, we were also able to identify and contact one of the attackers to try and gain insights into the motivations behind these attacks.' Palo Alto Networks reported on continued activity by the attackers in 2014. ", "meta": { @@ -4774,7 +4762,7 @@ "value": "APT 22" }, { - "description": "This threat actor targets organizations in the critical infrastructure, heavy industry, manufacturing, and international relations sectors for espionage purposes.", + "description": "Tick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese National University of Defense and Technology, which is possibly linked to the PLA. This threat actor targets organizations in the critical infrastructure, heavy industry, manufacturing, and international relations sectors for espionage purposes. The attacks appear to be centered on political, media, and engineering sectors. STALKER PANDA has been observed conducting targeted attacks against Japan, Taiwan, Hong Kong, and the United States.", "meta": { "attribution-confidence": "50", "cfr-suspected-state-sponsor": "China", @@ -4790,6 +4778,7 @@ "cfr-type-of-incident": "Espionage", "country": "CN", "refs": [ + "https://wikileaks.org/vault7/document/2015-08-20150814-256-CSIR-15005-Stalker-Panda/2015-08-20150814-256-CSIR-15005-Stalker-Panda. pdf", "https://www.symantec.com/connect/blogs/tick-cyberespionage-group-zeros-japan", "https://www.secureworks.jp/resources/rp-bronze-butler", "https://researchcenter.paloaltonetworks.com/2017/07/unit42-tick-group-continues-attacks/", @@ -4801,8 +4790,9 @@ "https://www.secureworks.com/research/threat-profiles/bronze-butler" ], "synonyms": [ - "Bronze Butler", - "RedBaldKnight" + "BRONZE BUTLER", + "REDBALDKNIGHT", + "STALKER PANDA" ] }, "related": [ From d8d8221e26172c3d8a283bc0fc480bb4a107b42d Mon Sep 17 00:00:00 2001 From: Rony Date: Sun, 25 Apr 2021 19:35:37 +0530 Subject: [PATCH 3/4] FlatChestWare duplicate removed --- clusters/ransomware.json | 5 ----- 1 file changed, 5 deletions(-) diff --git a/clusters/ransomware.json b/clusters/ransomware.json index c9957c7..bd5fb45 100644 --- a/clusters/ransomware.json +++ b/clusters/ransomware.json @@ -15926,11 +15926,6 @@ "uuid": "b9f1d220-2ef0-4b1d-84ed-ae6843e5828e", "value": "Flatcher3" }, - { - "description": "ransomware", - "uuid": "76a372d0-93ec-45a4-912c-6695a21e047d", - "value": "FlatChestWare" - }, { "description": "ransomware", "uuid": "51f42a21-1963-40c5-b644-d4c1c5c3f9eb", From 4ba2db0f3abeffd2f41c00480a3b57a6b9a63211 Mon Sep 17 00:00:00 2001 From: Rony Date: Mon, 26 Apr 2021 16:24:09 +0530 Subject: [PATCH 4/4] FlatChestWare duplicate removed --- clusters/ransomware.json | 5 ----- 1 file changed, 5 deletions(-) diff --git a/clusters/ransomware.json b/clusters/ransomware.json index c9957c7..bd5fb45 100644 --- a/clusters/ransomware.json +++ b/clusters/ransomware.json @@ -15926,11 +15926,6 @@ "uuid": "b9f1d220-2ef0-4b1d-84ed-ae6843e5828e", "value": "Flatcher3" }, - { - "description": "ransomware", - "uuid": "76a372d0-93ec-45a4-912c-6695a21e047d", - "value": "FlatChestWare" - }, { "description": "ransomware", "uuid": "51f42a21-1963-40c5-b644-d4c1c5c3f9eb",