From ccfd207e590f464d4ccf86f5ce822b3284bf8981 Mon Sep 17 00:00:00 2001 From: Mathieu4141 Date: Tue, 20 Feb 2024 05:22:26 -0800 Subject: [PATCH] [threat-actors] Add LabHost --- clusters/threat-actor.json | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/clusters/threat-actor.json b/clusters/threat-actor.json index 0a0e1d4..5038d30 100644 --- a/clusters/threat-actor.json +++ b/clusters/threat-actor.json @@ -15228,6 +15228,16 @@ }, "uuid": "24a7e1eb-b7c7-486b-96b2-8d313d65bf70", "value": "ShadowSyndicate" + }, + { + "description": "LabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for real-time campaign management and SMS lures. LabHost's phishing campaigns have similarities to Frappo campaigns, but they operate separately and offer different subscription packages.", + "meta": { + "refs": [ + "https://www.phishlabs.com/blog/phishing-service-profile-labhost-threat-actor-group" + ] + }, + "uuid": "583cdea6-1d72-44d4-824f-f965e8a23f3e", + "value": "LabHost" } ], "version": 301