Skip to content

Commit

Permalink
Merge branch 'Mathieu4141-threat-actors/fe99d09c-e4e7-4842-bd26-3ed3f…
Browse files Browse the repository at this point in the history
…4350bed' into main
  • Loading branch information
adulau committed Nov 16, 2023
2 parents b0a5801 + 6ab8f62 commit f14cad8
Showing 1 changed file with 24 additions and 0 deletions.
24 changes: 24 additions & 0 deletions clusters/threat-actor.json
Original file line number Diff line number Diff line change
Expand Up @@ -12976,6 +12976,30 @@
},
"uuid": "c8782e46-447c-4c6e-90c0-82f3bf49d64b",
"value": "Prolific Puma"
},
{
"description": "Bohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle East, and India. They often create fake social media profiles, particularly posing as recruiters, to trick victims into running malware on their computers. Microsoft's Digital Crimes Unit has taken legal action and seized 41 domains used by Bohrium to disrupt their activities. The group has shown a particular interest in sectors such as technology, transportation, government, and education.",
"meta": {
"country": "IR",
"refs": [
"https://twitter.com/CyberAmyHB/status/1532398956918890500"
]
},
"uuid": "111efc97-6a93-487b-8cb3-1e890ac51066",
"value": "Bohrium"
},
{
"description": "KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primarily as entry and middle points. Their main objective appears to be collecting information on Tor users and mapping their routes within the network. Despite efforts to remove their servers, KAX17 has shown resilience and continues to operate.",
"meta": {
"refs": [
"https://www.malwarebytes.com/blog/news/2021/12/was-threat-actor-kax17-de-anonymizing-the-tor-network/amp",
"https://therecord.media/a-mysterious-threat-actor-is-running-hundreds-of-malicious-tor-relays",
"https://darknetlive.com/post/who-is-responsible-for-running-hundreds-of-malicious-tor-relays/",
"https://nusenu.medium.com/is-kax17-performing-de-anonymization-attacks-against-tor-users-42e566defce8"
]
},
"uuid": "615311f0-58d4-4d1d-ac86-6ba86d119317",
"value": "KAX17"
}
],
"version": 294
Expand Down

0 comments on commit f14cad8

Please sign in to comment.