Skip to content

Commit

Permalink
Merge pull request #273 from Delta-Sierra/master
Browse files Browse the repository at this point in the history
update synonyms & attributions
  • Loading branch information
adulau authored Oct 4, 2018
2 parents 123099c + 2893d71 commit 276992f
Show file tree
Hide file tree
Showing 2 changed files with 16 additions and 3 deletions.
7 changes: 5 additions & 2 deletions clusters/threat-actor.json
Original file line number Diff line number Diff line change
Expand Up @@ -2069,9 +2069,11 @@
"APT 28",
"APT28",
"Pawn Storm",
"PawnStorm",
"Fancy Bear",
"Sednit",
"TsarTeam",
"Tsar Team",
"TG-4127",
"Group-4127",
"STRONTIUM",
Expand Down Expand Up @@ -4620,7 +4622,8 @@
"Islamic State Hacking Division",
"CCA",
"United Cyber Caliphate",
"UUC"
"UUC",
"CyberCaliphate"
]
},
"uuid": "76f6ad4e-2ff3-4ccb-b81d-18162f290af0",
Expand Down Expand Up @@ -5917,5 +5920,5 @@
]
}
],
"version": 68
"version": 69
}
12 changes: 11 additions & 1 deletion clusters/tool.json
Original file line number Diff line number Diff line change
Expand Up @@ -5863,7 +5863,17 @@
"type": "similar"
}
]
},
{
"value": "ZEBROCY",
"description": "ZEBROCY is a tool used by APT28, which has been observed since late 2015. The communications module used by ZEBROCY transmits using HTTP. The implant has key logging and file exfiltration functionality and utilises a file collection capability that identifies files with particular extensions.",
"meta": {
"refs": [
"https://www.ncsc.gov.uk/alerts/indicators-compromise-malware-used-apt28"
]
},
"uuid": "8a2ae47a-c7b2-11e8-b223-ab4d8f78f3ef"
}
],
"version": 90
"version": 91
}

0 comments on commit 276992f

Please sign in to comment.