[threat-actors] Add TEMP_Heretic

pull/897/head
Mathieu4141 2023-11-17 02:59:55 -08:00
parent 68f70a1831
commit e333b15063
1 changed files with 12 additions and 0 deletions

View File

@ -13159,6 +13159,18 @@
},
"uuid": "8345dd24-7884-48e3-b231-4791d31afe3d",
"value": "DEV-0928"
},
{
"description": "TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Zimbra, to exfiltrate emails from government, military, and media organizations. They use multiple outlook.com email addresses and manually craft content for each email before sending it.",
"meta": {
"country": "CN",
"refs": [
"https://www.welivesecurity.com/en/eset-research/mass-spreading-campaign-targeting-zimbra-users/",
"https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/"
]
},
"uuid": "8dfac62e-395e-4e47-b6b6-8ab817ac25c1",
"value": "TEMP_Heretic"
}
],
"version": 294