From a77dc82c0a9f0a369f82d713c3f515528d29e1d7 Mon Sep 17 00:00:00 2001 From: Sebastien Larinier Date: Wed, 19 Apr 2023 15:35:36 +0200 Subject: [PATCH] Update threat-actor.json new apt30 group --- clusters/threat-actor.json | 38 +++++++++++++++++++++++++++++++++++--- 1 file changed, 35 insertions(+), 3 deletions(-) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index ebc0a36e..cd9e0c04 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -671,13 +671,12 @@ "https://www.fireeye.com/blog/threat-research/2014/03/spear-phishing-the-news-cycle-apt-actors-leverage-interest-in-the-disappearance-of-malaysian-flight-mh-370.html", "https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07205555/TheNaikonAPT-MsnMM1.pdf", "https://usa.kaspersky.com/resource-center/threats/naikon-targeted-attacks", - "https://blog.trendmicro.com/trendlabs-security-intelligence/bkdr_rarstone-new-rat-to-watch-out-for/", + "https://web.archive.org/web/20210925164035/https://blog.trendmicro.com/trendlabs-security-intelligence/bkdr_rarstone-new-rat-to-watch-out-for/", "https://threatconnect.com/blog/tag/naikon/", "https://attack.mitre.org/groups/G0019/", "https://www.secureworks.com/research/threat-profiles/bronze-geneva", "https://cyware.com/news/chinese-naikon-group-back-with-new-espionage-attack-66a8413d", "https://cluster25.io/2022/04/29/lotus-panda-awake-last-strike/", - "https://attack.mitre.org/wiki/Group/G0013", "https://www.mandiant.com/resources/insights/apt-groups", "https://www.fireeye.com/content/dam/fireeye-www/summit/cds-2019/presentations/cds19-executive-s08-achievement-unlocked.pdf" ], @@ -716,7 +715,40 @@ } ], "uuid": "2f1fd017-9df6-4759-91fb-e7039609b5ff", - "value": "APT30" + "value": "Naikon" + }, + { + "description": "APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches", + "meta": { + "country": "CN", + "attribution-confidence": "50", + "cfr-suspected-state-sponsor": "China", + "refs":[ + "https://attack.mitre.org/wiki/Group/G0013", + "https://www2.fireeye.com/rs/fireye/images/rpt-apt30.pdf", + "https://www.mandiant.com/resources/insights/apt-groups" + ], + + "cfr-suspected-victims":[ + "United States", + "South Korea", + "Saudi Arabia", + "Thailand", + "Vietnam", + "Malaysia", + "India" + ], + "cfr-target-category":[ + "Government" + ], + "synonyms": [ + "G0013" + ] + + + }, + "related": [], + "value":"APT30" }, { "description": "Lotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.",