From af6241fd20e5809a28a45a9598bde8a7962bf770 Mon Sep 17 00:00:00 2001 From: Deborah Servili Date: Mon, 27 May 2019 11:47:05 +0200 Subject: [PATCH] update Anchor Panda Threat Actor --- clusters/rat.json | 29 ++++------------------------ clusters/threat-actor.json | 39 +++++++++++++++++++++++++++++++++++++- clusters/tool.json | 34 +++++++++++---------------------- 3 files changed, 53 insertions(+), 49 deletions(-) diff --git a/clusters/rat.json b/clusters/rat.json index d32547a..c22ebfe 100644 --- a/clusters/rat.json +++ b/clusters/rat.json @@ -93,32 +93,11 @@ }, "related": [ { - "dest-uuid": "b42378e0-f147-496f-992a-26a49705395b", + "dest-uuid": "c82c904f-b3b4-40a2-bf0d-008912953104", "tags": [ "estimative-language:likelihood-probability=\"likely\"" ], - "type": "similar" - }, - { - "dest-uuid": "2abe89de-46dd-4dae-ae22-b49a593aff54", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "e336aeba-b61a-44e0-a0df-cd52a5839db5", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "7789fc1b-3cbc-4a1c-8ef0-8b06760f93e7", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" + "type": "used-by" } ], "uuid": "4e104fef-8a2c-4679-b497-6e86d7d47db0", @@ -669,11 +648,11 @@ }, "related": [ { - "dest-uuid": "225fa6cf-dc9c-4b86-873b-cdf1d9dd3738", + "dest-uuid": "c82c904f-b3b4-40a2-bf0d-008912953104", "tags": [ "estimative-language:likelihood-probability=\"likely\"" ], - "type": "similar" + "type": "used-by" } ], "uuid": "255a59a7-db2d-44fc-9ca9-5859b65817c3", diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index f8a872c..2bd8567 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -1165,7 +1165,7 @@ "value": "Mirage" }, { - "description": "PLA Navy", + "description": "PLA Navy\nAnchor Panda is an adversary that CrowdStrike has tracked extensively over the last year targeting both civilian and military maritime operations in the green/brown water regions primarily in the area of operations of the South Sea Fleet of the PLA Navy. In addition to maritime operations in this region, Anchor Panda also heavily targeted western companies in the US, Germany, Sweden, the UK, and Australia, and other countries involved in maritime satellite systems, aerospace companies, and defense contractors. \nNot surprisingly, embassies and diplomatic missions in the region, foreign intelligence services, and foreign governments with space programs were also targeted.", "meta": { "attribution-confidence": "50", "cfr-suspected-state-sponsor": "China", @@ -1194,6 +1194,43 @@ "ALUMINUM" ] }, + "related": [ + { + "dest-uuid": "255a59a7-db2d-44fc-9ca9-5859b65817c3", + "tags": [ + "estimative-language:likelihood-probability=\"likely\"" + ], + "type": "uses" + }, + { + "dest-uuid": "cb8c8253-4024-4cc9-8989-b4a5f95f6c2f", + "tags": [ + "estimative-language:likelihood-probability=\"likely\"" + ], + "type": "uses" + }, + { + "dest-uuid": "4e104fef-8a2c-4679-b497-6e86d7d47db0", + "tags": [ + "estimative-language:likelihood-probability=\"likely\"" + ], + "type": "uses" + }, + { + "dest-uuid": "2abe89de-46dd-4dae-ae22-b49a593aff54", + "tags": [ + "estimative-language:likelihood-probability=\"likely\"" + ], + "type": "uses" + }, + { + "dest-uuid": "32a67552-3b31-47bb-8098-078099bbc813", + "tags": [ + "estimative-language:likelihood-probability=\"likely\"" + ], + "type": "uses" + } + ], "uuid": "c82c904f-b3b4-40a2-bf0d-008912953104", "value": "Anchor Panda" }, diff --git a/clusters/tool.json b/clusters/tool.json index c7917a5..77ca6b1 100644 --- a/clusters/tool.json +++ b/clusters/tool.json @@ -142,32 +142,11 @@ }, "related": [ { - "dest-uuid": "4e104fef-8a2c-4679-b497-6e86d7d47db0", + "dest-uuid": "c82c904f-b3b4-40a2-bf0d-008912953104", "tags": [ "estimative-language:likelihood-probability=\"likely\"" ], - "type": "similar" - }, - { - "dest-uuid": "b42378e0-f147-496f-992a-26a49705395b", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "7789fc1b-3cbc-4a1c-8ef0-8b06760f93e7", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" - }, - { - "dest-uuid": "e336aeba-b61a-44e0-a0df-cd52a5839db5", - "tags": [ - "estimative-language:likelihood-probability=\"likely\"" - ], - "type": "similar" + "type": "used-by" } ], "uuid": "2abe89de-46dd-4dae-ae22-b49a593aff54", @@ -1022,6 +1001,15 @@ "Gh0stRat, GhostRat" ] }, + "related": [ + { + "dest-uuid": "c82c904f-b3b4-40a2-bf0d-008912953104", + "tags": [ + "estimative-language:likelihood-probability=\"likely\"" + ], + "type": "used-by" + } + ], "uuid": "cb8c8253-4024-4cc9-8989-b4a5f95f6c2f", "value": "Gh0st Rat" },