Threat Group Cards: a Threat Actor Encyclopedia

Total Page:16

File Type:pdf, Size:1020Kb

Threat Group Cards: a Threat Actor Encyclopedia Threat Group Cards: A Threat Actor Encyclopedia Compiled by ThaiCERT, a member of the Electronic Transactions Development Agency TLP:WHITE Version 1.0 (12 June 2019) Threat Group Cards: A Threat Actor Encyclopedia Contents Introduction .................................................................................................................................................. 8 Approach ................................................................................................................................................. 8 Legal Notice ............................................................................................................................................ 9 Acknowledgements ................................................................................................................................ 9 Advanced Persistent Threat (APT) Groups .......................................................................................... 10 Anchor Panda, APT 14 ........................................................................................................................ 11 Allanite ................................................................................................................................................... 12 APT 3, Gothic Panda, Buckeye.......................................................................................................... 13 APT 5 ..................................................................................................................................................... 15 APT 6 ..................................................................................................................................................... 16 APT 12, Numbered Panda .................................................................................................................. 17 APT 16, SVCMONDR .......................................................................................................................... 19 APT 17, Deputy Dog ............................................................................................................................ 20 APT 18, Dynamite Panda, Wekby ..................................................................................................... 21 APT 19, C0d0so ................................................................................................................................... 22 APT 20, Violin Panda ........................................................................................................................... 23 APT 29, Cozy Bear, The Dukes ......................................................................................................... 24 APT 30, Override Panda ..................................................................................................................... 27 APT 32, OceanLotus, SeaLotus ........................................................................................................ 29 APT 33, Elfin ......................................................................................................................................... 33 Axiom, Group 72................................................................................................................................... 34 Bahamut ................................................................................................................................................ 35 Barium .................................................................................................................................................... 37 Berserk Bear, Dragonfly 2.0 ............................................................................................................... 39 Blackgear ............................................................................................................................................... 40 BlackOasis ............................................................................................................................................ 41 BlackTech .............................................................................................................................................. 42 Blind Eagle ............................................................................................................................................ 44 Blue Termite, Cloudy Omega ............................................................................................................. 45 Bookworm .............................................................................................................................................. 46 Bronze Butler, Tick ............................................................................................................................... 47 Buhtrap .................................................................................................................................................. 48 2 Threat Group Cards: A Threat Actor Encyclopedia Cadelle ................................................................................................................................................... 50 Callisto Group ....................................................................................................................................... 51 Carbanak, Anunak ............................................................................................................................... 52 Careto, The Mask ................................................................................................................................. 53 Chafer, APT 39 ..................................................................................................................................... 54 Charming Kitten, Newscaster, NewsBeef ........................................................................................ 56 Clever Kitten .......................................................................................................................................... 58 Cobalt Group ......................................................................................................................................... 59 Cold River .............................................................................................................................................. 62 Comment Crew, APT 1 ....................................................................................................................... 63 Confucius ............................................................................................................................................... 65 CopyKittens, Slayer Kitten .................................................................................................................. 66 Corkow, Metel ....................................................................................................................................... 67 Covellite ................................................................................................................................................. 68 Cutting Kitten, TG-2889 ....................................................................................................................... 69 Dark Caracal ......................................................................................................................................... 71 DarkHotel ............................................................................................................................................... 72 DarkHydrus, LazyMeerkat .................................................................................................................. 74 Deep Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens ............................................... 75 Desert Falcons ...................................................................................................................................... 78 DNSpionage .......................................................................................................................................... 80 Domestic Kitten..................................................................................................................................... 81 Donot Team........................................................................................................................................... 82 DragonOK .............................................................................................................................................. 83 DustSquad ............................................................................................................................................. 84 Dust Storm............................................................................................................................................. 85 Elderwood, Sneaky Panda ................................................................................................................. 86 El Machete ............................................................................................................................................ 88 Energetic Bear, Dragonfly ................................................................................................................... 89 Equation Group..................................................................................................................................... 92 Emissary Panda, APT 27, LuckyMouse, Bronze
Recommended publications
  • Country of Origin Information Report Syria June 2021
    Country of origin information report Syria June 2021 Page 1 of 102 Country of origin information report Syria | June 2021 Publication details City The Hague Assembled by Country of Origin Information Reports Section (DAF/AB) Disclaimer: The Dutch version of this report is leading. The Ministry of Foreign Affairs of the Netherlands cannot be held accountable for misinterpretations based on the English version of the report. Page 2 of 102 Country of origin information report Syria | June 2021 Table of contents Publication details ............................................................................................2 Table of contents ..........................................................................................3 Introduction ....................................................................................................5 1 Political and security situation .................................................................... 6 1.1 Political and administrative developments ...........................................................6 1.1.1 Government-held areas ....................................................................................6 1.1.2 Areas not under government control. ............................................................... 11 1.1.3 COVID-19 ..................................................................................................... 13 1.2 Armed groups ............................................................................................... 13 1.2.1 Government forces .......................................................................................
    [Show full text]
  • Rethinking Documentary Photography
    RETHINKING DOCUMENTARY PHOTOGRAPHY: DOCUMENTARY AND POLITICS IN TIMES OF RIOTS AND UPRISINGS —————————————————— A Thesis Presented to The Honors Tutorial College Ohio University —————————————————— In Partial Fulfillment of the Requirements for Graduation from the Honors Tutorial College with the degree of Bachelor of Arts in Art History —————————————————— by Jack Opal May 2013 Introduction I would like to think about documentary photography. In particular, I would like to rethink the limits of documentary photography for the contemporary. Documentary, traditionally, concerns itself with the (re)presentation of factual information, constitutes a record.1 For decades, documentary – and especially social documentary – has been under siege; its ability to capture and convey and adequately represent “truth” thrown into question, victim to the aestheticization of the objects, fading trust in their authors, and technological development. So much so that the past three decades have prompted photographer, documentarian, and art historian Martha Rosler to question first its utility, then its role, and finally its future in society. All of this has opened up the possibility and perhaps the need to reconsider the conditions and purpose of documentary practice, and to consider the ways in which it has been impacted by recent technological and historical developments. The invention of the internet and the refinement of the (video) camera into ever more portable devices and finally into the smartphone, and the rise to ubiquity within society of these inventions, signifies a major shift in documentary. So, too, have certain events of the past two decades – namely, the beating of Rodney King (and the circulation of the video of that event) and the development and adoption of the occupation as a major tactic within the political left.
    [Show full text]
  • Officials Say Flynn Discussed Sanctions
    Officials say Flynn discussed sanctions The Washington Post February 10, 2017 Friday, Met 2 Edition Copyright 2017 The Washington Post All Rights Reserved Distribution: Every Zone Section: A-SECTION; Pg. A08 Length: 1971 words Byline: Greg Miller;Adam Entous;Ellen Nakashima Body Talks with Russia envoy said to have occurred before Trump took office National security adviser Michael Flynn privately discussed U.S. sanctions against Russia with that country's ambassador to the United States during the month before President Trump took office, contrary to public assertions by Trump officials, current and former U.S. officials said. Flynn's communications with Russian Ambassador Sergey Kislyak were interpreted by some senior U.S. officials as an inappropriate and potentially illegal signal to the Kremlin that it could expect a reprieve from sanctions that were being imposed by the Obama administration in late December to punish Russia for its alleged interference in the 2016 election. Flynn on Wednesday denied that he had discussed sanctions with Kislyak. Asked in an interview whether he had ever done so, he twice said, "No." On Thursday, Flynn, through his spokesman, backed away from the denial. The spokesman said Flynn "indicated that while he had no recollection of discussing sanctions, he couldn't be certain that the topic never came up." Officials said this week that the FBI is continuing to examine Flynn's communications with Kislyak. Several officials emphasized that while sanctions were discussed, they did not see evidence that Flynn had an intent to convey an explicit promise to take action after the inauguration. Flynn's contacts with the ambassador attracted attention within the Obama administration because of the timing.
    [Show full text]
  • Deterring Iran After the Nuclear Deal
    MARCH 2017 COVER PHOTO NIEL HESTER | FLICKR 1616 Rhode Island Avenue NW Washington, DC 20036 202 887 0200 | www.csis.org Lanham • Boulder • New York • London 4501 Forbes Boulevard Lanham, MD 20706 301 459 3366 | www.rowman.com Deterring Iran After the Nuclear Deal PROJECT DIRECTORS AND EDITORS Kathleen H. Hicks Melissa G. Dalton CONTRIBUTING AUTHORS Melissa G. Dalton Thomas Karako Jon B. Alterman J. Matthew McInnis Michael Connell Hijab Shah Michael Eisenstadt Michael Sulmeyer ISBN 978-1-4422-7993-3 Farideh Farhi Ian Williams Kathleen H. Hicks 1616 Rhode Island Avenue NW Washington,Ë|xHSLEOCy279933z DC 20036v*:+:!:+:! 202-887-0200 | www.csis.org Blank MARCH 2017 Deterring Iran after the Nuclear Deal PROJ ECT DIRECTORS AND EDITORS Kathleen H. Hicks Melissa G. Dalton CONTRIBUTING AUTHORS Melissa G. Dalton Thomas Karako Jon B. Alterman J. Matthew McInnis Michael Connell Hijab Shah Michael Eisenstadt Michael Sulmeyer Farideh Farhi Ian Williams Kathleen H. Hicks Lanham • Boulder • New York • London 594-68742_ch00_6P.indd 1 3/13/17 7:13 AM About CSIS For over 50 years, the Center for Strategic and International Studies (CSIS) has worked to develop solutions to the world’s greatest policy challenges. T oday, CSIS scholars are providing strategic insights and bipartisan policy solutions to help decisionmakers chart a course toward a better world. CSIS is a nonprofit organ ization headquartered in Washington, D.C. The Center’s 220 full- time staff and large network of affiliated scholars conduct research and analy sis and develop policy initiatives that look into the future and anticipate change. Founded at the height of the Cold War by David M.
    [Show full text]
  • Reporting, and General Mentions Seem to Be in Decline
    CYBER THREAT ANALYSIS Return to Normalcy: False Flags and the Decline of International Hacktivism By Insikt Group® CTA-2019-0821 CYBER THREAT ANALYSIS Groups with the trappings of hacktivism have recently dumped Russian and Iranian state security organization records online, although neither have proclaimed themselves to be hacktivists. In addition, hacktivism has taken a back seat in news reporting, and general mentions seem to be in decline. Insikt Group utilized the Recorded FutureⓇ Platform and reports of historical hacktivism events to analyze the shifting targets and players in the hacktivism space. The target audience of this research includes security practitioners whose enterprises may be targets for hacktivism. Executive Summary Hacktivism often brings to mind a loose collective of individuals globally that band together to achieve a common goal. However, Insikt Group research demonstrates that this is a misleading assumption; the hacktivist landscape has consistently included actors reacting to regional events, and has also involved states operating under the guise of hacktivism to achieve geopolitical goals. In the last 10 years, the number of large-scale, international hacking operations most commonly associated with hacktivism has risen astronomically, only to fall off just as dramatically after 2015 and 2016. This constitutes a return to normalcy, in which hacktivist groups are usually small sets of regional actors targeting specific organizations to protest regional events, or nation-state groups operating under the guise of hacktivism. Attack vectors used by hacktivist groups have remained largely consistent from 2010 to 2019, and tooling has assisted actors to conduct larger-scale attacks. However, company defenses have also become significantly better in the last decade, which has likely contributed to the decline in successful hacktivist operations.
    [Show full text]
  • Zerohack Zer0pwn Youranonnews Yevgeniy Anikin Yes Men
    Zerohack Zer0Pwn YourAnonNews Yevgeniy Anikin Yes Men YamaTough Xtreme x-Leader xenu xen0nymous www.oem.com.mx www.nytimes.com/pages/world/asia/index.html www.informador.com.mx www.futuregov.asia www.cronica.com.mx www.asiapacificsecuritymagazine.com Worm Wolfy Withdrawal* WillyFoReal Wikileaks IRC 88.80.16.13/9999 IRC Channel WikiLeaks WiiSpellWhy whitekidney Wells Fargo weed WallRoad w0rmware Vulnerability Vladislav Khorokhorin Visa Inc. Virus Virgin Islands "Viewpointe Archive Services, LLC" Versability Verizon Venezuela Vegas Vatican City USB US Trust US Bankcorp Uruguay Uran0n unusedcrayon United Kingdom UnicormCr3w unfittoprint unelected.org UndisclosedAnon Ukraine UGNazi ua_musti_1905 U.S. Bankcorp TYLER Turkey trosec113 Trojan Horse Trojan Trivette TriCk Tribalzer0 Transnistria transaction Traitor traffic court Tradecraft Trade Secrets "Total System Services, Inc." Topiary Top Secret Tom Stracener TibitXimer Thumb Drive Thomson Reuters TheWikiBoat thepeoplescause the_infecti0n The Unknowns The UnderTaker The Syrian electronic army The Jokerhack Thailand ThaCosmo th3j35t3r testeux1 TEST Telecomix TehWongZ Teddy Bigglesworth TeaMp0isoN TeamHav0k Team Ghost Shell Team Digi7al tdl4 taxes TARP tango down Tampa Tammy Shapiro Taiwan Tabu T0x1c t0wN T.A.R.P. Syrian Electronic Army syndiv Symantec Corporation Switzerland Swingers Club SWIFT Sweden Swan SwaggSec Swagg Security "SunGard Data Systems, Inc." Stuxnet Stringer Streamroller Stole* Sterlok SteelAnne st0rm SQLi Spyware Spying Spydevilz Spy Camera Sposed Spook Spoofing Splendide
    [Show full text]
  • Cyberwar: the ISIL Threat & Resiliency in Operational Technology
    Cyberwar: The ISIL Threat & Resiliency in Operational Technology Thesis Presented to the Faculty of the Department of Information and Logistics Technology University of Houston In Partial Fulfillment of the Requirements for the Degree Master’s of Information Systems Security By Gregory S. Anderson May 2017 Cyberwar: The ISIL Threat & Resiliency in Operational Technology ____________________________________ Gregory S. Anderson Approved: Committee Chair: ____________________________________ Wm. Arthur Conklin, PhD Computer Information Systems and Information System Security Committee Member: ____________________________________ Chris Bronk, PhD Computer Information Systems and Information System Security Committee Member: ____________________________________ Paula deWitte, PhD Computer Information Systems and Information System Security ____________________________________ ____________________________________ Rupa Iyer, PhD Dan Cassler Associate Dean for Research and Graduate Interim Chair for Department of Information Studies, College of Technology and Logistics Technology THIS PAGE INTENTIONALLY LEFT BLANK Acknowledgments First, I would like to thank Dr. Chris Bronk and Dr. Art Conklin for their support and guidance throughout my time at the University of Houston. Their dedication to students is unparalleled for any other professor I have come across during my education. I would also like to thank my family for their ongoing encouragement and love. The fostering environment to peruse knowledge and “never settle for less” has been a constant inspiration throughout my life. Lastly, to my partner of 7 years, Lorelei. None of my achievements these past few years would have come to fruition without her continuous love, support, and willingness to sacrifice for the greater good is deeply appreciated. Thank you for being the most patient and steadfast person I have ever known, I love you.
    [Show full text]
  • Ethical Hacking
    Ethical Hacking Alana Maurushat University of Ottawa Press ETHICAL HACKING ETHICAL HACKING Alana Maurushat University of Ottawa Press 2019 The University of Ottawa Press (UOP) is proud to be the oldest of the francophone university presses in Canada and the only bilingual university publisher in North America. Since 1936, UOP has been “enriching intellectual and cultural discourse” by producing peer-reviewed and award-winning books in the humanities and social sciences, in French or in English. Library and Archives Canada Cataloguing in Publication Title: Ethical hacking / Alana Maurushat. Names: Maurushat, Alana, author. Description: Includes bibliographical references. Identifiers: Canadiana (print) 20190087447 | Canadiana (ebook) 2019008748X | ISBN 9780776627915 (softcover) | ISBN 9780776627922 (PDF) | ISBN 9780776627939 (EPUB) | ISBN 9780776627946 (Kindle) Subjects: LCSH: Hacking—Moral and ethical aspects—Case studies. | LCGFT: Case studies. Classification: LCC HV6773 .M38 2019 | DDC 364.16/8—dc23 Legal Deposit: First Quarter 2019 Library and Archives Canada © Alana Maurushat, 2019, under Creative Commons License Attribution— NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) https://creativecommons.org/licenses/by-nc-sa/4.0/ Printed and bound in Canada by Gauvin Press Copy editing Robbie McCaw Proofreading Robert Ferguson Typesetting CS Cover design Édiscript enr. and Elizabeth Schwaiger Cover image Fragmented Memory by Phillip David Stearns, n.d., Personal Data, Software, Jacquard Woven Cotton. Image © Phillip David Stearns, reproduced with kind permission from the artist. The University of Ottawa Press gratefully acknowledges the support extended to its publishing list by Canadian Heritage through the Canada Book Fund, by the Canada Council for the Arts, by the Ontario Arts Council, by the Federation for the Humanities and Social Sciences through the Awards to Scholarly Publications Program, and by the University of Ottawa.
    [Show full text]
  • Make Technology Great Again
    Make Technology Great Again Michał „rysiek” Woźniak [email protected] Everything is Broken – Quinn Norton https://medium.com/message/everything-is-broken-81e5f33a24e1 "Malicious Word Doc Uses ActiveX To Infect" https://www.vmray.com/blog/malicious-word-doc-uses-activex-infect/ "Word Malware: OLE Exploited in Zero-Day Attack" https://www.vadesecure.com/en/word-doc-malware/ "Dynamic Data Exchange was frst introduced in 1987 with the release of Windows 2.0” https://en.wikipedia.org/wiki/Dynamic_Data_Exchange "As part of the December 2017 Patch Tuesday, Microsoft has shipped an Ofce update that disables the DDE feature in Word applications, after several malware campaigns have abused this feature to install malware.” https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-dde-feature-in-word- to-prevent-further-malware-attacks/ "Dynamic Data Exchange was frst introduced in 1987 with the release of Windows 2.0” https://en.wikipedia.org/wiki/Dynamic_Data_Exchange "As part of the December 2017 Patch Tuesday, Microsoft has shipped an Ofce update that disables the DDE feature in Word applications, after several malware campaigns have abused this feature to install malware.” https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-dde-feature-in-word- to-prevent-further-malware-attacks/ "Microsoft Ofce macro malware targets Macs" https://blog.malwarebytes.com/cybercrime/2017/02/microsoft-ofce-macro- malware-targets-macs/ "Beware PowerSniff Malware uses Word macros and PowerShell scripts" https://www.grahamcluley.com/beware-powersnif-malware/
    [Show full text]
  • Cyber Activities in the Syrian Conflict CSS CY
    CSS CYBER DEFENSE PROJECT Hotspot Analysis The use of cybertools in an internationalized civil war context: Cyber activities in the Syrian conflict Zürich, October 2017 Version 1 Risk and Resilience Team Center for Security Studies (CSS), ETH Zürich The use of cybertools in an internationalized civil war context: Cyber activities in the Syrian conflict Authors: Marie Baezner, Patrice Robin © 2017 Center for Security Studies (CSS), ETH Zürich Contact: Center for Security Studies Haldeneggsteig 4 ETH Zürich CH-8092 Zürich Switzerland Tel.: +41-44-632 40 25 [email protected] www.css.ethz.ch Analysis prepared by: Center for Security Studies (CSS), ETH Zürich ETH-CSS project management: Tim Prior, Head of the Risk and Resilience Research Group; Myriam Dunn Cavelty, Deputy Head for Research and Teaching; Andreas Wenger, Director of the CSS Disclaimer: The opinions presented in this study exclusively reflect the authors’ views. Please cite as: Baezner, Marie; Robin, Patrice (2017): Hotspot Analysis: The use of cybertools in an internationalized civil war context: Cyber activities in the Syrian conflict, October 2017, Center for Security Studies (CSS), ETH Zürich. 2 The use of cybertools in an internationalized civil war context: Cyber activities in the Syrian conflict Table of Contents 1 Introduction 5 2 Background and chronology 6 3 Description 9 3.1 Attribution and actors 9 Pro-government groups 9 Anti-government groups 11 Islamist groups 11 State actors 12 Non-aligned groups 13 3.2 Targets 13 3.3 Tools and techniques 14 Data breaches 14
    [Show full text]
  • Ashour: Expats Gain Most from Subsidies
    SUBSCRIPTION SUNDAY, DECEMBER 27, 2015 RABI ALAWWAL 16, 1437 AH www.kuwaittimes.net Crunching Iraqi forces In final year, Stoke leave numbers in fierce Obama seeks Van Gaal behind the battles with to stave off on Man scenes 5 IS in Ramadi7 lame-duck14 tag United20 brink Ashour: Expats gain Min 09º Max 18º most from subsidies High Tide 14:05 MP claims ‘medical visitors’, consultants a drain on budget Low Tide 07:35 & 19:22 40 PAGES NO: 16738 150 FILS By A Saleh Storms kill 15 in southern US KUWAIT: MP Saleh Ashour claimed that according to reports made by the parliamentary finance and budget committees on the total cost of subsidies and how they CHICAGO: Millions of residents in the southern United are spent, the majority of subsidies benefit expats. States struggled yesterday to recover from the deadly “Millions of dinars are spent on medicine and the major- storms and floods that struck the region over the past ity who benefits from this is expat residents, in addition days. At least 15 people have been killed in the states to visitors who come for medical treatment, mainly sur- of Mississippi, Tennessee and Arkansas since Thursday, geries,” he said, noting that the same applies to electrici- officials said. With more severe weather expected ty subsidies. across the central United States, forecasters are warn- Kuwait began selling ing of airport delays and flooded roads as travelers diesel and kerosene at mar- return home after the Christmas holiday. ket prices at the start of 2015, Feeding on unseasonably warm air, storms left a cut spending by 17 percent trail of destruction in rural communities from Alabama and is in the process of rais- to Illinois.
    [Show full text]
  • How Cyber-Geopolitics Will Destabalize the Middle East
    Policy Brief 2017 | No. 35 Cheap Havoc: How Cyber-Geopolitics Will Destabilize the Middle East By Kristina Kausch Since a hack on a Qatari government website in June 2017 triggered the Gulf Cooperation Council’s (GCC) deepest diplomatic crisis since its inception, the Gulf states have been stepping up their efforts to enhance their cyber reach and keep up with the rapid strides of regional cyber powers Iran and Israel. Planting a seed of misinformation in a bed of long-standing tensions, a fake news story exploited regional polarization and anti-Iranian sentiments to rip the region further apart. Over the past few years, governments and non-state The Qatar crisis not only escalated long-simmering groups in the Middle East and North Africa have tensions in a region key to U.S. and EU interests and gone to great lengths to build cyber capabilities. put in question its regional security arrangements; it The proliferation of cyber weapons in the region also provided a glimpse of how the pursuit of expansive and their use as geopolitical tools has the potential geopolitical ambitions by means of targeted cyber- to further shake and unsettle regional crises and attacks can generate conflict and trigger political larger Western interests. landslides in the glimpse of an eye. The biggest risk for Western powers is to leave In the Middle East, global geopolitical trends tend any doubt about their readiness to retaliate or to manifest themselves early, and intensely. Digital to support their allies against any actors’ cyber innovation offers political adversaries increasing aggressions. As actors around the world begin opportunity to find vulnerabilities that have the to grasp the opportunities offered by conducting potential to undo the capacities of a nation’s economic geopolitical operations in cyberspace, the window and military force.
    [Show full text]