# Changelog ## %%version%% (unreleased) ### Other * Merge pull request #952 from Delta-Sierra/main. [Alexandre Dulaunoy] add Germany as target for several Threat actors * Merge. [Delta-Sierra] * Merge pull request #951 from Mathieu4141/threat-actors/13974650-c2bd-47da-ac93-48b80420210b. [Alexandre Dulaunoy] [threat actors] 3 new actors, 1 added aliases * [threat-actors] Add Earth Krahang. [Mathieu4141] * [threat-actors] Add MuddyWater aliases. [Mathieu4141] * [threat-actors] Add Earth Kapre. [Mathieu4141] * [threat-actors] Add UNC5325. [Mathieu4141] * Add Germany as target for several Threat actors. [Delta-Sierra] ## v2.4.188 (2024-03-20) ### New * [tmss] Add Threat Matrix for Storage Services fixes #947. [Christophe Vandeplas] new: [tmss] Add Threat Matrix for Storage Services fixes #947 * [tmss] Add Threat Matrix for Storage Services fixes #947. [Christophe Vandeplas] * [tools] generator for Threat Matrix for Storage Services #947. [Christophe Vandeplas] ### Changes * [doc] Index of clusters updated. [Alexandre Dulaunoy] * [atrm] changed namespace to microsoft. [Christophe Vandeplas] * [tools] rename gen_atrm.py to gen_ms_atrms.py. [Christophe Vandeplas] * [disarm] New Version 1.4 of Red Framework. [Christophe Vandeplas] * [doc] README updated with the recent changes. [Alexandre Dulaunoy] * [tools] add requirements file for IntelAgencies. [Alexandre Dulaunoy] * [intel] use UUIDv5 for clusters. [niclas] ### Fix * [tmss] remove duplicate author entry. [Christophe Vandeplas] * [tools] add external_id to TMSS. [Christophe Vandeplas] * [threat-actor] fix #942. [Alexandre Dulaunoy] `Hyppo Team` was present in two clusters. We just kept the alias for `Turla`. ### Other * Merge branch 'main' of https://github.com/MISP/misp-galaxy. [Christophe Vandeplas] * Merge pull request #949 from cvandeplas/main. [Christophe Vandeplas] chg: [disarm] New Version 1.4 of Red Framework * Merge pull request #948 from NMD03/main. [Alexandre Dulaunoy] Add buttons for editing and hiding TOC + Nav * Add [index] navigation buttons. [niclas] * Add [graph + table] scaling based on window. [niclas] * Add [toc] optional hiding. [niclas] * Add [website] edit button. [niclas] * Merge pull request #946 from NMD03/intel. [Alexandre Dulaunoy] Inteligence Agencies * Chg [intel] mistakes on wikipedia got fixed. [niclas] * Fix [cluster] duplicates. [niclas] * Update. [niclas] * Add [cluster] authors. [niclas] * Fix [synonyms] [niclas] * Add [cluster] country code. [niclas] * Add [synonyms] and fixed indivdual mistakes. [niclas] * Add [agencies] refs. [niclas] * Add [intel-agencies] build script. [niclas] * Merge pull request #945 from danielplohmann/patch-38. [Alexandre Dulaunoy] adding aliases from UA's H1'2023 report * Adding aliases from UA's H1'2023 report. [Daniel Plohmann] ## v2.4.187 (2024-03-07) ### Other * Merge pull request #944 from Delta-Sierra/main. [Alexandre Dulaunoy] update producers * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Update producers. [Delta-Sierra] * Merge pull request #943 from NMD03/main. [Alexandre Dulaunoy] Fix [relations] add uuid to header to get unique parent node * Fix [relations] add uuid to header to get unique parent node. [niclas] * Merge pull request #941 from NMD03/main. [Alexandre Dulaunoy] Add [galaxies] Tidal Cyber * Fix [galaxies] typo. [niclas] * Fix [config] uuids. [niclas] * Fix [config] typo. [niclas] * Fix [tidal] check for existing sub clusters. [niclas] * Fix [duplicates] list. [niclas] * Add [techniques] codeblock for duplicates. [niclas] * Chg [tidal] add associated to name. [niclas] * Chg [groups] change name for Volt Typhoon duplicate. [niclas] * Fix [references] no empty refs. [niclas] * Fix [software] type as array. [niclas] * Fix [galaxies] add version. [niclas] * Fix [graph] typo. [niclas] * Fix [clusters] authors. [niclas] * Fix [tidal] exclude empty meta fields. [niclas] * Add [galaxies] Cyber Tidal. [niclas] * Add [tidal] sub option. [niclas] * Add [graph] cluster description. [niclas] * Merge pull request #6 from NMD03/visual. [Niclas Dauster] Visual * Add [graph] pre filtering for large data. [niclas] * Add [graph] opacity adjustment. [niclas] * Add [graph] galaxy visualisation while hovering. [niclas] * Add [graph] node enlargement while hovering. [niclas] * Fix [graph] replace . from galaxy class names. [niclas] * Add [graph] legend. [niclas] * Chg [tool] code formatting. [niclas] * Merge pull request #5 from NMD03/refactor. [Niclas Dauster] Refactor * Add [tool] multithreading. [niclas] * Add [tool] statistics. [niclas] * Fix [tool] file creation. [niclas] * Update. [niclas] * Merge pull request #4 from NMD03/icon. [Niclas Dauster] Add [tidal] icons * Add [tidal] icons. [niclas] * Merge pull request #3 from NMD03/parallel. [Niclas Dauster] Galaxy filtering * Fix [graph] parent node bug. [niclas] * Add [graph] galaxy filtering. [niclas] * Ref [cluster] remove duplicates. [niclas] * Refactor [generator] [niclas] * Merge branch 'MISP:main' into main. [Niclas Dauster] * Merge pull request #2 from NMD03/tidal. [Niclas Dauster] Tidal * Add [tidal] relations for associated objects. [niclas] * Add [tidal] relation enrichment with mitre. [niclas] * Add [technique] subtechnique. [niclas] * Refactor [tool] code. [niclas] * Add [config] optional "private" relations. [niclas] * Fix [config] metadata mapping. [niclas] * Chg [config] external config file. [niclas] * Refactor [creation] script. [niclas] * Chg [tidal] only generate set metadata. [niclas] * Add [tidal] scipts to create new galaxies. [niclas] * Merge pull request #940 from Mathieu4141/threat-actors/1f1d97d1-e00f-4dea-a6b7-00e0118ca5e0. [Alexandre Dulaunoy] [threat actors] add 5 new actors * [threat-actors] Add R00tK1T. [Mathieu4141] * [threat-actors] Add Mogilevich. [Mathieu4141] * [threat-actors] Add UNC1549. [Mathieu4141] * [threat-actors] Add UAC-0184. [Mathieu4141] * [threat-actors] Add SPIKEDWINE. [Mathieu4141] ## v2.4.186 (2024-02-27) ### New * [producer] Skeleton for threat intelligence producer to be attached as producer of Intelligence in MISP feed. [Alexandre Dulaunoy] In the realm of cybersecurity, numerous security firms produce feeds and threat intelligence conforming to the MISP standards. However, a significant challenge arises due to the often insufficient or vague descriptions of the origins of this intelligence within these standards. This lack of clarity hinders the effectiveness and credibility of the threat intelligence shared across platforms and organizations. ### Changes * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [producer] Sophos added. [Alexandre Dulaunoy] * [threat-actor] version updated. [Alexandre Dulaunoy] * [mkdocs] rsync fixed. [Alexandre Dulaunoy] * [threat-actor] fixed. [Alexandre Dulaunoy] ### Other * Merge pull request #939 from Delta-Sierra/main. [Alexandre Dulaunoy] add producer names [wip] * Fix double. [Delta-Sierra] * Typo~ [Delta-Sierra] * Fix ENORMOUS TYPO and add a few description (wip) [Delta-Sierra] * Add producer names. [Delta-Sierra] * Merge pull request #938 from MISP/dependabot/pip/tools/mkdocs/cryptography-42.0.4. [Alexandre Dulaunoy] Bump cryptography from 42.0.2 to 42.0.4 in /tools/mkdocs * Bump cryptography from 42.0.2 to 42.0.4 in /tools/mkdocs. [dependabot[bot]] Bumps [cryptography](https://github.com/pyca/cryptography) from 42.0.2 to 42.0.4. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](https://github.com/pyca/cryptography/compare/42.0.2...42.0.4) --- updated-dependencies: - dependency-name: cryptography dependency-type: direct:production ... * Merge pull request #937 from Mathieu4141/threat-actors/3160867e-66ab-44bf-82d3-edd21e7ee3ab. [Alexandre Dulaunoy] [threat-actors] Add 6 new actors + aliases for 2 existing * [threat-actors] Add GoldFactory. [Mathieu4141] * [threat-actors] Add Winter Vivern aliases. [Mathieu4141] * [threat-actors] Add Cyber.Anarchy.Squad. [Mathieu4141] * [threat-actors] Add LabHost. [Mathieu4141] * [threat-actors] Add ShadowSyndicate. [Mathieu4141] * [threat-actors] Add ResumeLooters. [Mathieu4141] * [threat-actors] Add Charming Kitten aliases. [Mathieu4141] * [threat-actors] Add ProCC. [Mathieu4141] * Merge pull request #936 from NMD03/fix. [Alexandre Dulaunoy] Fix [mitre] delete double relations * Fix [mitre] new galaxy enrichments. [niclas] * Reset enrichment. [niclas] * Merge pull request #935 from MISP/dependabot/pip/tools/mkdocs/cryptography-42.0.2. [Alexandre Dulaunoy] Bump cryptography from 42.0.1 to 42.0.2 in /tools/mkdocs * Bump cryptography from 42.0.1 to 42.0.2 in /tools/mkdocs. [dependabot[bot]] Bumps [cryptography](https://github.com/pyca/cryptography) from 42.0.1 to 42.0.2. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](https://github.com/pyca/cryptography/compare/42.0.1...42.0.2) --- updated-dependencies: - dependency-name: cryptography dependency-type: direct:production ... * Merge pull request #934 from jstnk9/main. [Alexandre Dulaunoy] [Threat-Actors] added new information in relation to the Mandiant-Google TAG Report * Added new information in relation to the Mandiant-Google TAG Report. [jstnk9] New information added via https://services.google.com/fh/files/misc/tool-of-first-resort-israel-hamas-war-cyber.pdf * Merge pull request #933 from Delta-Sierra/main. [Alexandre Dulaunoy] add relationships between surveillance vendors * Add relationships between surveillance vendors. [Delta-Sierra] ## v2.4.185 (2024-02-16) ### Changes * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [surveillance-vendor] updated. [Alexandre Dulaunoy] * [surveillance-vendor] updated following https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Buying_Spying_-_Insights_into_Commercial_Surveillance_Vendors_-_TAG_report.pdf. [Alexandre Dulaunoy] * [threat-actor] version updated. [Alexandre Dulaunoy] * [ATRM] bump to latest ATRM version. [Christophe Vandeplas] ### Other * Merge pull request #932 from NMD03/formatted. [Alexandre Dulaunoy] Ignore deprecated galaxies + bugfix * Fix [generator] bug displaying relations to priv clusters multiple times in table. [niclas] * Chg [generator] run black code formatter. [niclas] * Merge pull request #1 from NMD03/feature/exclude_deprecated. [Niclas Dauster] Feature/exclude deprecated * Merge branch 'main' into feature/exclude_deprecated. [Niclas Dauster] * Merge pull request #931 from NMD03/enrich_new_mitre. [Alexandre Dulaunoy] Add [mitre] relations from deprecated galaxies * Fix [mitre] running jq_all_the_things.sh. [niclas] * Add [mitre] relations from deprecated galaxies. [niclas] * Merge pull request #930 from Mathieu4141/threat-actors/b72eaadd-01a5-4232-951d-e0190999b2a7. [Alexandre Dulaunoy] [threat-actors] Add 2 actors * [threat-actors] Add Blackatom. [Mathieu4141] * [threat-actors] Add TA2725. [Mathieu4141] * Merge pull request #929 from NMD03/relations. [Alexandre Dulaunoy] Fix mkdocs graph physics * Formatted code using black. [niclas] * Fix [graph] links + pairwise distance using Fruchterman-Reingold (https://arxiv.org/pdf/1201.3011.pdf) [niclas] * Merge pull request #928 from danielplohmann/patch-37. [Alexandre Dulaunoy] merge KNOCKOUT SPIDER -> Evilnum * Merge KNOCKOUT SPIDER -> Evilnum. [Daniel Plohmann] Based on newer public reporting grouping these. * Merge pull request #926 from NMD03/relations. [Alexandre Dulaunoy] Mkdocs relations and statistics * Refactor code. [niclas] * Add [statistics] text. [niclas] * Chg [generator] cleanup. [niclas] * Chg [build] dependency check. [niclas] * Ref [tool] mkdocs. [niclas] * Fix [statistics] linking. [niclas] * Chg [modules] get rid of npm. [niclas] * Add [script] npm setup. [niclas] * Fix [tool] internal linking. [niclas] * Fix [tablefilter] base path to local. [niclas] * Fix [simulation] update graph. [niclas] * Fix [generator] relation level. [niclas] * Fix [statistics] bar graph margin. [niclas] * Improve [statistics] graphs for statistics. [niclas] * Change [deps] use npm packages. [niclas] * Add [graph] node names. [niclas] * Add [graph] drag by user. [niclas] * Add [graph] filtering based on table. [niclas] * Add [graph] basic graph. [niclas] * Add [table gen] relation level. [niclas] * Add [display relations] table with filters. [niclas] * Add [generator] statistics. [niclas] * Rename [geerator] global variables. [niclas] * Fix [generator] relations. [niclas] * Add [generator] statistics. [niclas] * Add [generator] get related containers. [niclas] * Refactor [generator] generate mkdocs site. [niclas] * Merge pull request #927 from Delta-Sierra/main. [Alexandre Dulaunoy] add COATHANGER RAT * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #925 from Mathieu4141/threat-actors/65b96fc7-5da9-448a-b567-dce5fe7e6057. [Alexandre Dulaunoy] [threat actors] Add some missing aliases/actors from Trend Micro * [threat-actors] Add TwoSail Junk aliases. [Mathieu4141] * [threat-actors] Add Operation Emmental. [Mathieu4141] * [threat-actors] Add Urpage. [Mathieu4141] * [threat-actors] Add APT23 aliases. [Mathieu4141] * [threat-actors] Add Operation C-Major aliases. [Mathieu4141] * [threat-actors] Add Tonto Team aliases. [Mathieu4141] * [threat-actors] Add Earth Yako. [Mathieu4141] * [threat-actors] Add Operation Red Signature. [Mathieu4141] * [threat-actors] Add Earth Berberoka aliases. [Mathieu4141] * [threat-actors] Add Domestic Kitten aliases. [Mathieu4141] * Merge pull request #924 from Delta-Sierra/main. [Deborah Servili] adding several webshells and open source tools * Add COATHANGER ref. [Delta-Sierra] * Add COATHANGER RAT. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #923 from Mathieu4141/threat-actors/cc5adecb-fa3e-4128-b059-1a8216fb1d08. [Alexandre Dulaunoy] [threat actors] Add some missing actors named by Kasperky * [threat-actors] Add Ferocious Kitten. [Mathieu4141] * [threat-actors] Add APT5 aliases. [Mathieu4141] * [threat-actors] Add CardinalLizard. [Mathieu4141] * [threat-actors] Add Operation Ghoul. [Mathieu4141] * [threat-actors] Add Operation Triangulation. [Mathieu4141] * [threat-actors] Add GhostEmperor. [Mathieu4141] * [threat-actors] Add RevengeHotels. [Mathieu4141] * [threat-actors] Add Fishing Elephant. [Mathieu4141] * [threat-actors] Add ShaggyPanther. [Mathieu4141] * [threat-actors] Add Tomiris. [Mathieu4141] * [threat-actors] Add Karkadann. [Mathieu4141] * Merge pull request #922 from Mathieu4141/threat-actors/133b2e2d-4948-4361-a9c5-d1798d1b7f4e. [Alexandre Dulaunoy] [threat actors] Add some missing Proofpoint aliases * [threat-actors] Add Silent Librarian aliases. [Mathieu4141] * [threat-actors] Add MuddyWater aliases. [Mathieu4141] * [threat-actors] Add TA2719. [Mathieu4141] * [threat-actors] Add APT10 aliases. [Mathieu4141] * [threat-actors] Add OilRig aliases. [Mathieu4141] * [threat-actors] Add Lazarus Group aliases. [Mathieu4141] * [threat-actors] Add TA2722. [Mathieu4141] * [threat-actors] Add APT39 aliases. [Mathieu4141] * [threat-actors] Add Evilnum aliases. [Mathieu4141] * [threat-actors] Add APT33 aliases. [Mathieu4141] * [threat-actors] Add MUSTANG PANDA aliases. [Mathieu4141] * [threat-actors] Add TA2552. [Mathieu4141] * [threat-actors] Add APT31 aliases. [Mathieu4141] * Adding several webshells and open source tools. [Delta-Sierra] * Fix [generator] move statistics in toc. [niclas] * Add [generator] func to ignore deprecated galaxies for site creation. [niclas] ## v2.4.184 (2024-02-02) ### New * [mitre] MITRE Data Sources and Data Components fixes #914. [Christophe Vandeplas] ### Changes * [microsoft] updated version. [Alexandre Dulaunoy] * [threat-actor] version updated. [Alexandre Dulaunoy] * [sigma] updated. [Alexandre Dulaunoy] * [mitre] updated to latest version. [Christophe Vandeplas] * [threat-actor] version updated. [Alexandre Dulaunoy] ### Fix * [mitre] fixed duplicate cluster uuid. [Christophe Vandeplas] ### Other * Merge pull request #921 from Mathieu4141/threat-actors/f4b1e157-e3e3-429a-8150-eb096f0b8cef. [Alexandre Dulaunoy] [threat-actors] Update with new Microsoft taxonomy * [threat-actors] Add Storm-1575. [Mathieu4141] * [threat-actors] Add Storm-0835. [Mathieu4141] * [threat-actors] Add Storm-1674. [Mathieu4141] * [threat-actors] Add Storm-0829. [Mathieu4141] * [threat-actors] Add Storm-1567. [Mathieu4141] * [threat-actors] Add Storm-1152. [Mathieu4141] * [threat-actors] Add SaintBear aliases. [Mathieu4141] * [threat-actors] Add Storm-0539. [Mathieu4141] * [threat-actors] Add DarkHotel aliases. [Mathieu4141] * [threat-actors] Add Storm-0530. [Mathieu4141] * [threat-actors] Add Storm-0381. [Mathieu4141] * [threat-actors] Add Storm-1101. [Mathieu4141] * [threat-actors] Add Ghostwriter aliases. [Mathieu4141] * [threat-actors] Add Storm-1286. [Mathieu4141] * [threat-actors] Add Storm-1099. [Mathieu4141] * [threat-actors] Add TA2101 aliases. [Mathieu4141] * [threat-actors] Add LYCEUM aliases. [Mathieu4141] * [threat-actors] Add Storm-1084. [Mathieu4141] * [threat-actors] Add Sandworm aliases. [Mathieu4141] * [threat-actors] Add Lazarus Group aliases. [Mathieu4141] * [threat-actors] Add FIN7 aliases. [Mathieu4141] * [threat-actors] Add POLONIUM aliases. [Mathieu4141] * [threat-actors] Add Pink Sandstorm. [Mathieu4141] * [threat-actors] Add Storm-1044. [Mathieu4141] * [threat-actors] Add Opal Sleet. [Mathieu4141] * [threat-actors] Add APT15 aliases. [Mathieu4141] * [threat-actors] Add APT5 aliases. [Mathieu4141] * [threat-actors] Add Storm-1167. [Mathieu4141] * [threat-actors] Add Storm-1295. [Mathieu4141] * [threat-actors] Add Scattered Spider aliases. [Mathieu4141] * [threat-actors] Add MuddyWater aliases. [Mathieu4141] * [threat-actors] Add TA505 aliases. [Mathieu4141] * [threat-actors] Add Phlox Tempest. [Mathieu4141] * [threat-actors] Add Raspberry Typhoon. [Mathieu4141] * [threat-actors] Add Silent Chollima aliases. [Mathieu4141] * [threat-actors] Add APT33 aliases. [Mathieu4141] * [threat-actors] Add PARINACOTA aliases. [Mathieu4141] * [threat-actors] Add Bohrium aliases. [Mathieu4141] * [threat-actors] Add Ruby Sleet. [Mathieu4141] * [threat-actors] Add WIZARD SPIDER aliases. [Mathieu4141] * [threat-actors] Add MosesStaff aliases. [Mathieu4141] * [threat-actors] Add Lilac Typhoon. [Mathieu4141] * [threat-actors] Add Fox Kitten aliases. [Mathieu4141] * [threat-actors] Add OilRig aliases. [Mathieu4141] * [threat-actors] Add APT31 aliases. [Mathieu4141] * [threat-actors] Add Vanilla Tempest. [Mathieu4141] * [threat-actors] Add ENERGETIC BEAR aliases. [Mathieu4141] * [threat-actors] Add Kimsuky aliases. [Mathieu4141] * [threat-actors] Add Sunglow Blizzard. [Mathieu4141] * [threat-actors] Add Velvet Tempest. [Mathieu4141] * [threat-actors] Add Storm-0867. [Mathieu4141] * [threat-actors] Add BRONZE STARLIGHT aliases. [Mathieu4141] * [threat-actors] Add Earth Lusca aliases. [Mathieu4141] * [threat-actors] Add Caramel Tsunami. [Mathieu4141] * [threat-actors] Add FIN6 aliases. [Mathieu4141] * [threat-actors] Add UNC4990. [Mathieu4141] * [threat-actors] Add Mustard Tempest. [Mathieu4141] * [threat-actors] Add GALLIUM aliases. [Mathieu4141] * [threat-actors] Add LAPSUS aliases. [Mathieu4141] * [threat-actors] Add APT28 aliases. [Mathieu4141] * [threat-actors] Add Carmine Tsunami. [Mathieu4141] * [threat-actors] Add APT32 aliases. [Mathieu4141] * [threat-actors] Add TiltedTemple aliases. [Mathieu4141] * [threat-actors] Add HAFNIUM aliases. [Mathieu4141] * [threat-actors] Add Turla aliases. [Mathieu4141] * [threat-actors] Add Pearl Sleet. [Mathieu4141] * [threat-actors] Add Cuboid Sandstorm. [Mathieu4141] * [threat-actors] Add DEV-0586 aliases. [Mathieu4141] * [threat-actors] Add Blue Tsunami. [Mathieu4141] * [threat-actors] Add APT40 aliases. [Mathieu4141] * [threat-actors] Add Denim Tsunami. [Mathieu4141] * [threat-actors] Add Gamaredon Group aliases. [Mathieu4141] * Merge pull request #920 from Delta-Sierra/main. [Deborah Servili] add mars and oski stealers * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #919 from Mathieu4141/threat-actors/56cfa5a2-e4c0-48a2-8462-12184db0e375. [Alexandre Dulaunoy] [threat actor] Add Blackwood & aliases for 2 other actors * [threat-actors] Add UNC2452 aliases. [Mathieu4141] * [threat-actors] Add UTA0178 aliases. [Mathieu4141] * [threat-actors] Add Blackwood. [Mathieu4141] * Add mars and oski stealers. [Delta-Sierra] * Merge pull request #917 from Mathieu4141/threat-actors/abf6de28-2204-4585-9066-1f6271e7897b. [Alexandre Dulaunoy] [threat-actors] Add 5 actors * [threat-actors] Add Cotton Sandstorm. [Mathieu4141] * [threat-actors] Add Caliente Bandits. [Mathieu4141] * [threat-actors] Add Cyber Partisans. [Mathieu4141] * [threat-actors] Add Hezb aliases. [Mathieu4141] * [threat-actors] Add Flax Typhoon. [Mathieu4141] * [threat-actors] Add TAG-28. [Mathieu4141] * Merge pull request #915 from Mathieu4141/threat-actors/b72c2c66-872d-4933-8052-496938c9a5a4. [Alexandre Dulaunoy] [threat-actors] Add 2 actors * [threat-actors] Add UTA0178. [Mathieu4141] * [threat-actors] Add Water Curupira. [Mathieu4141] * Merge pull request #913 from HiS3/main. [Alexandre Dulaunoy] update malpedia galaxy * Update malpedia galaxy. [HiS3] * Merge pull request #912 from Mathieu4141/threat-actors/e9aabcbd-e284-4f9a-8fe1-866cc0a8cd5a. [Alexandre Dulaunoy] [threa-actors] Add 10 actors * [threat-actors] Add Cyber Toufan. [Mathieu4141] * [threat-actors] Add Threatsec. [Mathieu4141] * [threat-actors] Add Gray Sandstorm. [Mathieu4141] * [threat-actors] Add UAC-0099. [Mathieu4141] * [threat-actors] Add HomeLand Justice. [Mathieu4141] * [threat-actors] Add Storm-1113. [Mathieu4141] * [threat-actors] Add KelvinSecurity. [Mathieu4141] * [threat-actors] Add Team-Xecuter. [Mathieu4141] * [threat-actors] Add PhantomControl. [Mathieu4141] * [threat-actors] Add GREF. [Mathieu4141] ## v2.4.183 (2024-01-04) ### New * [misp-galaxy.org] First version of misp-galaxy.org. [Alexandre Dulaunoy] * [mkdocs] basic generator for the mkdocs-material website for all the MISP galaxy. [Alexandre Dulaunoy] Work-in-progress * [disarm] add Actor Types. [Christophe Vandeplas] * [disarm] add Detections. [Christophe Vandeplas] * [disarm] add Countermeasures. [Christophe Vandeplas] * [mitre] New MITRE ATLAS Galaxy. [Christophe Vandeplas] ### Changes * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [mkdocs] add a visual. [Alexandre Dulaunoy] * [mkdocs] add the authors box per cluster. [Alexandre Dulaunoy] * [mkdocs] add the contributing part. [Alexandre Dulaunoy] * [mkdocs] add RSS support. [Alexandre Dulaunoy] * [mkdocs] fix the title page generation. [Alexandre Dulaunoy] * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [disarm] relations. [Christophe Vandeplas] * [doc] index updated. [Alexandre Dulaunoy] ### Fix * [mitre-atlas] tactics links fixed. [Alexandre Dulaunoy] * [mitre-atlas] reference to Markdown link updated. [Alexandre Dulaunoy] * [disarm] drop duplicate values. [Christophe Vandeplas] * [tests] missing sudo. [Christophe Vandeplas] * [tests] Use local Galaxies and not the misp-galaxies main branch. [Christophe Vandeplas] * [disarm] remove galaxy/cluster due to duplicates. [Christophe Vandeplas] see https://github.com/DISARMFoundation/DISARMframeworks/issues/24 and the feature/disarm branch here * [disarm] fix UUID. [Christophe Vandeplas] * [disarm] fix UUIDs. [Christophe Vandeplas] to be generated based on a disarm specific UUID * [mitre-atlas] better sorting of data. [Christophe Vandeplas] * [disarm] value without ID. [Christophe Vandeplas] * [mitre-atlas] value without ID. [Christophe Vandeplas] * [mitre] Correct order of Kill-Chain of ATLAS. [Christophe Vandeplas] * [threat-actor] fix JSON. [Alexandre Dulaunoy] ### Other * Merge pull request #911 from MISP/fix/duplicates. [Christophe Vandeplas] fix: [disarm] drop duplicate values * Merge pull request #910 from MISP/feature/disarm. [Alexandre Dulaunoy] Feature/disarm * Merge remote-tracking branch 'MISP/main' into feature/disarm. [Christophe Vandeplas] * Merge pull request #909 from Mathieu4141/threat-actors/7f195239-b9da-45a5-b1f7-daa87deaf347. [Alexandre Dulaunoy] [threat-actors] Add 5 new actors + some aliases on 2 existing ones * [threat-actors] Add GambleForce. [Mathieu4141] * [threat-actors] Add Tortoiseshell aliases. [Mathieu4141] * [threat-actors] Add Taidoor aliases. [Mathieu4141] * [threat-actors] Add UNC4736. [Mathieu4141] * [threat-actors] Add Solntsepek. [Mathieu4141] * [threat-actors] Add Storm-1283. [Mathieu4141] * [threat-actors] Add BiBiGun. [Mathieu4141] * Merge pull request #908 from MISP/feature/atlas. [Alexandre Dulaunoy] new: [mitre] New MITRE ATLAS Galaxy * Merge branch 'jstnk9-main' into main. [Alexandre Dulaunoy] * New threat actor - Sandman APT. [jstnk9] new threat actor - Sandman APT * Merge pull request #906 from Mathieu4141/threat-actors/253231ea-d8c6-47f5-a1c6-a5e1500a9c3a. [Alexandre Dulaunoy] [threat actors] Add some aliases * [threat-actors] Add Callisto aliases. [Mathieu Beligon] * [threat-actors] Add Hagga aliases. [Mathieu Beligon] * [threat-actors] Add Sandworm aliases. [Mathieu Beligon] ## v2.4.182 (2023-12-14) ### New * [disarm] Initial DISARM galaxy #783. [Christophe Vandeplas] ### Changes * [cluster] Sigma rules updated. [Alexandre Dulaunoy] * [sigma] updated to the latest version. [Alexandre Dulaunoy] ### Other * Merge pull request #905 from Mathieu4141/threat-actors/dd7fd198-7ead-48ee-b763-50f2f9faa1c5. [Alexandre Dulaunoy] [threat-actors] Add 10 actors * [threat-actors] jq. [Mathieu Beligon] * [threat-actors] Add UNC2630. [Mathieu Beligon] * [threat-actors] Add UAC-0050. [Mathieu Beligon] * [threat-actors] Add UAC-0118. [Mathieu Beligon] * [threat-actors] Add DEV-0569. [Mathieu Beligon] * [threat-actors] Add UNC215. [Mathieu Beligon] * [threat-actors] Add RomCom aliases. [Mathieu Beligon] * [threat-actors] Add UNC2447. [Mathieu Beligon] * [threat-actors] Add WIP19. [Mathieu Beligon] * [threat-actors] Add AeroBlade. [Mathieu Beligon] * [threat-actors] Add UNC2659. [Mathieu Beligon] * [threat-actors] Add UNC2717. [Mathieu Beligon] * Merge pull request #904 from Mathieu4141/threat-actor/scattered-spider-65667349-6932-4ae5-a356-356f71a6a1f5. [Alexandre Dulaunoy] [threat-actors] Add Scattered Spider aliases * [threat-actors] Update Scattered Spider. [Mathieu Beligon] * Merge pull request #903 from Mathieu4141/threat-actors/harmonize-ref-field. [Alexandre Dulaunoy] [threat-actors] harmonize reference field * [threat-actors] hormonize reference field. [Mathieu Beligon] * Merge pull request #902 from Mathieu4141/threat-actors/97bd510f-7f92-4d35-b389-3c269c47094b. [Alexandre Dulaunoy] [threat actors] Add 3 actors * [threat-actors] Add Daixin Team. [Mathieu4141] * [threat-actors] Add ScamClub. [Mathieu4141] * [threat-actors] Add TunnelSnake. [Mathieu4141] ## v2.4.180 (2023-11-30) ### Fix * [botnet] duplicate UUID removed. [Alexandre Dulaunoy] * [botnet] replace duplicate UUID. [Alexandre Dulaunoy] * [botnet] updated version. [Alexandre Dulaunoy] ### Other * Merge pull request #901 from Mathieu4141/threat-actors/c88f2604-d67f-4674-b59f-7f2eb7364879. [Alexandre Dulaunoy] [threat actors] Add 7 actors * [threat-actors] Add WildPressure. [Mathieu Beligon] * [threat-actors] Add WildCard. [Mathieu Beligon] * [threat-actors] Add Red-Lili. [Mathieu Beligon] * [threat-actors] Add LightBasin. [Mathieu Beligon] * [threat-actors] Add DragonForce. [Mathieu Beligon] * [threat-actors] Add MalKamak. [Mathieu Beligon] * [threat-actors] Add Blacktail. [Mathieu Beligon] * Merge pull request #900 from semelnyk/main. [Alexandre Dulaunoy] Updated botnet.json with new entries * Ran once again jq_all_the_things.sh to format JSON files. [semelnyk] * Ran jq_all_the_things.sh to format JSON files. [semelnyk] * Updated botnet.json with new entries. [semelnyk] ## v2.4.179 (2023-11-23) ### New * [threat-actor] Storm-0558 added + Fix #880. [Alexandre Dulaunoy] ### Changes * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [surveillance] version updated and duplicates removed. [Alexandre Dulaunoy] * [threat-actor] TA499 added. [Alexandre Dulaunoy] * [threat-actor] version updated. [Alexandre Dulaunoy] * [threat-actor] version updated. [Alexandre Dulaunoy] * [mitre-attack] updated to ATT&CK v14.0 Enterprise. [Alexandre Dulaunoy] ### Fix * [mitre-tool] fix following request the lead developer of flowintel-cm. [Alexandre Dulaunoy] * [threat-actor] replace `aliases` -> `synonyms` + version updated. [Alexandre Dulaunoy] * [threat-actor] `synonyms` not `aliases` [Alexandre Dulaunoy] * [malpedia] restore original MISP UUID for the cluster. [Alexandre Dulaunoy] * [aics] namespace added. [Alexandre Dulaunoy] ### Other * Merge pull request #899 from Delta-Sierra/main. [Alexandre Dulaunoy] Kimsuky targets and relations * Fix version. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #898 from Mathieu4141/threat-actors/2d4f4a51-5a1e-4d21-acdc-5516fe781ba2. [Alexandre Dulaunoy] [threat-actors] add 10 actors * [threat-actors] Add SilverFish. [Mathieu4141] * [threat-actors] Add TA402. [Mathieu4141] * [threat-actors] Add CostaRicto. [Mathieu4141] * [threat-actors] Add Storm Cloud. [Mathieu4141] * [threat-actors] Add OldGremlin. [Mathieu4141] * [threat-actors] Add TiltedTemple. [Mathieu4141] * [threat-actors] Add Moshen Dragon. [Mathieu4141] * [threat-actors] Add N4ughtysecTU. [Mathieu4141] * [threat-actors] Add Webworm. [Mathieu4141] * [threat-actors] Add PerSwaysion. [Mathieu4141] * Merge pull request #897 from Mathieu4141/threat-actors/424bc9c9-2bc3-4db7-88a3-6773417deab8. [Alexandre Dulaunoy] [threat-actors] add 9 actors * [threat-actors] Add DefrayX. [Mathieu4141] * [threat-actors] Add NewsPenguin. [Mathieu4141] * [threat-actors] Add UAC-0006. [Mathieu4141] * [threat-actors] Add TA444. [Mathieu4141] * [threat-actors] Add WeedSec. [Mathieu4141] * [threat-actors] Add TEMP_Heretic. [Mathieu4141] * [threat-actors] Add DEV-0928. [Mathieu4141] * [threat-actors] Add CL-STA-0043. [Mathieu4141] * [threat-actors] Add UNC4841. [Mathieu4141] * Merge pull request #896 from Mathieu4141/threat-actors/43ef0656-b566-46d8-a518-11c1c513bce4. [Alexandre Dulaunoy] [threat actors] Add 10 actors * [threat-actors] Add AppMilad. [Mathieu4141] * [threat-actors] Add Earth Kitsune. [Mathieu4141] * [threat-actors] Add FusionCore. [Mathieu4141] * [threat-actors] Add DragonSpark. [Mathieu4141] * [threat-actors] Add UNC4191. [Mathieu4141] * [threat-actors] Add DriftingCloud. [Mathieu4141] * [threat-actors] Add MurenShark. [Mathieu4141] * [threat-actors] Add Chernovite. [Mathieu4141] * [threat-actors] Add VulzSecTeam. [Mathieu4141] * [threat-actors] Add MirrorFace. [Mathieu4141] * Merge branch 'Mathieu4141-threat-actors/fe99d09c-e4e7-4842-bd26-3ed3f4350bed' into main. [Alexandre Dulaunoy] * Merge branch 'threat-actors/fe99d09c-e4e7-4842-bd26-3ed3f4350bed' of https://github.com/Mathieu4141/misp-galaxy into Mathieu4141-threat-actors/fe99d09c-e4e7-4842-bd26-3ed3f4350bed. [Alexandre Dulaunoy] * [threat-actors] Add KAX17. [Mathieu4141] * [threat-actors] Add Bohrium. [Mathieu4141] * Kimsuky target. [Delta-Sierra] * Kimsuky relations. [Delta-Sierra] * Merge pull request #894 from semelnyk/main. [Alexandre Dulaunoy] Updated surveillance-vendor.json with new entries * Updated surveillance-vendor.json with new entries. [semelnyk] * Merge pull request #893 from danielplohmann/patch-36. [Alexandre Dulaunoy] adding Prolific Puma * Adding Prolific Puma. [Daniel Plohmann] * Merge pull request #892 from Mathieu4141/threat-actors/b780c817-c1d2-4f6b-b03f-b9405d7d1473. [Alexandre Dulaunoy] [threat actors] Add 10 actors * [threat-actors] Add DarkCasino. [Mathieu4141] * [threat-actors] Add Zarya. [Mathieu4141] * [threat-actors] Add XakNet. [Mathieu4141] * [threat-actors] Add TA482. [Mathieu4141] * [threat-actors] Add TAG-56. [Mathieu4141] * [threat-actors] Add Water Labbu. [Mathieu4141] * [threat-actors] Add Caracal Kitten. [Mathieu4141] * [threat-actors] Add WIRTE. [Mathieu4141] * [threat-actors] Add WeRedEvils. [Mathieu4141] * [threat-actors] Add DEV-0950. [Mathieu4141] * Merge pull request #891 from Mathieu4141/threat-actors/289ae672-5442-436d-bc65-0548dba509dc. [Alexandre Dulaunoy] [threat actors] Add 3 actors * [threat-actors] Add DiceyF. [Mathieu4141] * [threat-actors] Add SCARLETEEL. [Mathieu4141] * [threat-actors] Add SingularityMD. [Mathieu4141] * Merge pull request #890 from Mathieu4141/threat-actors/7ca42298-3f55-49c0-b88d-dc7b14733dbb. [Alexandre Dulaunoy] [threat-actors] Add 10 actors * [threat-actors] Add Dalbit. [Mathieu4141] * [threat-actors] Add BlueBottle. [Mathieu4141] * [threat-actors] Add Xcatze. [Mathieu4141] * [threat-actors] Add TwoSail Junk. [Mathieu4141] * [threat-actors] Add DEV-1028. [Mathieu4141] * [threat-actors] Add Kiss-a-Dog. [Mathieu4141] * [threat-actors] Add Confucious. [Mathieu4141] * [threat-actors] Add Desorden Group. [Mathieu4141] * [threat-actors] Add UNC2565. [Mathieu4141] * [threat-actors] Add TheDarkOverlord. [Mathieu4141] * Merge branch 'Mathieu4141-threat-actors/9cc9036f-b31c-44a7-b8da-38287c3b95ef' into main. [Alexandre Dulaunoy] * [threat-actors] Add TraderTraitor. [Mathieu Beligon] * [threat-actors] Add UAC-0094. [Mathieu Beligon] * [threat-actors] Add UserSec. [Mathieu Beligon] * [threat-actors] Add IronHusky. [Mathieu Beligon] * [threat-actors] Add ShinyHunters. [Mathieu Beligon] * [threat-actors] Add ShroudedSnooper. [Mathieu Beligon] * [threat-actors] Add 1937CN. [Mathieu Beligon] * [threat-actors] Add Altahrea Team. [Mathieu Beligon] * [threat-actors] Add Cyber Av3ngers. [Mathieu Beligon] * [threat-actors] Add KromSec. [Mathieu Beligon] * [threat-actors] Add DustSquad. [Mathieu Beligon] * [threat-actors] Add Guacamaya. [Mathieu Beligon] * [threat-actors] Add SharpPanda. [Mathieu Beligon] * [threat-actors] Add BadRory. [Mathieu Beligon] * Merge pull request #888 from Mathieu4141/threat-actors/e8e0bf88-5b60-436f-8f61-ddafab6ca141. [Alexandre Dulaunoy] [threat actors] Add 10 actors * [threat-actors] Add Storm-1133. [Mathieu4141] * [threat-actors] Add REF2924. [Mathieu4141] * [threat-actors] Add REF5961. [Mathieu4141] * [threat-actors] Add HiddenArt. [Mathieu4141] * [threat-actors] Add OilAlpha. [Mathieu4141] * [threat-actors] Add GhostSec. [Mathieu4141] * [threat-actors] Add IndigoZebra. [Mathieu4141] * [threat-actors] Add NB65. [Mathieu4141] * [threat-actors] Add Witchetty. [Mathieu4141] * [threat-actors] Add RedStinger. [Mathieu4141] * Merge pull request #887 from Mathieu4141/threat-actors/04da55b3-acda-4e77-b687-e7f9329d0fd1. [Christophe Vandeplas] [threat-actors] Adding 10 actors * [threat-actors] remove duplicate. [Mathieu Beligon] * [threat-actors] Add UNC3890. [Mathieu Beligon] * [threat-actors] Add Carderbee. [Mathieu Beligon] * [threat-actors] Add RansomVC. [Mathieu Beligon] * [threat-actors] Add SiegedSec. [Mathieu Beligon] * [threat-actors] Add Metador. [Mathieu Beligon] * [threat-actors] Add YoroTrooper. [Mathieu Beligon] * [threat-actors] Add Kasablanka. [Mathieu Beligon] * [threat-actors] Add SparklingGoblin. [Mathieu Beligon] * [threat-actors] Add Storm-0062. [Mathieu Beligon] * [threat-actors] Add LofyGang. [Mathieu Beligon] * Merge pull request #886 from Mathieu4141/threat-actors/8c381db4-079a-4f37-9265-dfd12fe50e10. [Alexandre Dulaunoy] [threat actors] Add 10 threat actors * [threat-actors] jq. [Mathieu Beligon] * [threat-actors] Add Lancefly. [Mathieu Beligon] * [threat-actors] Add GoldenJackal. [Mathieu Beligon] * [threat-actors] Add Earth Estries. [Mathieu Beligon] * [threat-actors] Add TetrisPhantom. [Mathieu Beligon] * [threat-actors] Add Redfly. [Mathieu Beligon] * [threat-actors] Add Earth Longzhi. [Mathieu Beligon] * [threat-actors] Add UNC3886. [Mathieu Beligon] * [threat-actors] Add Winter Vivern. [Mathieu Beligon] * [threat-actors] Add Xiaoqiying. [Mathieu Beligon] * [threat-actors] Add Keksec. [Mathieu Beligon] * Merge pull request #885 from Mathieu4141/threat-actor/keksec-ba96cbce-c2bc-4b6b-9404-43ded4c97a19. [Alexandre Dulaunoy] [threat-actors] Add Keksec * [threat-actors] Add Keksec. [Mathieu4141] * Merge pull request #884 from Mathieu4141/threat-actor/scarred-manticore-6a6965e2-0843-47b1-990d-d43016dd4dd1. [Alexandre Dulaunoy] [threat-actors] Add Scarred Manticore * [threat-actors] jq. [Mathieu Beligon] * Merge branch 'main' into threat-actor/scarred-manticore-6a6965e2-0843-47b1-990d-d43016dd4dd1. [Mathieu Béligon] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #883 from Delta-Sierra/main. [Alexandre Dulaunoy] add naics generation script * Add naics generation script. [Delta-Sierra] * Merge branch 'HiS3-main' into main. [Alexandre Dulaunoy] * Merge branch 'main' of https://github.com/HiS3/misp-galaxy into HiS3-main. [Alexandre Dulaunoy] * Update malpedia galaxy. [Sebastian Himmler] * Merge pull request #882 from Delta-Sierra/main. [Alexandre Dulaunoy] Add NAICS galaxy * Jq. [Delta-Sierra] * Add authors. [Delta-Sierra] * Add categ. [Delta-Sierra] * Trim. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Add NAICS galaxy. [Delta-Sierra] * [threat-actors] Add Scarred Manticore. [Mathieu4141] ## v2.4.178 (2023-10-30) ### Changes * [threat-actor] increased version number. [Christophe Vandeplas] * [sigma] updated. [Alexandre Dulaunoy] * [doc] Index updated. [Alexandre Dulaunoy] * [description_value] reprocess clusters to avoid duplicate on value. [Alexandre Dulaunoy] * [adoc_galaxy] exclude firearms and ammunitions. [Alexandre Dulaunoy] * [firearms] remove duplicate firearms having similar SKU. [Alexandre Dulaunoy] * [ammunitions] duplicate values replaced with the complete description. [Alexandre Dulaunoy] * [threat-actor] clean-up. [Alexandre Dulaunoy] * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [galaxy] duplicate UUIDs removed. [Alexandre Dulaunoy] * [malpedia] duplicate refs removed. [Alexandre Dulaunoy] * [malpedia] jq all the things. [Alexandre Dulaunoy] * [sigma] updated. [Alexandre Dulaunoy] ### Fix * [threat-actor] JQ all the things + version updated. [Alexandre Dulaunoy] * [ammunition] too many ammunitions. [Alexandre Dulaunoy] * [threat-actor] version updated + jq all the things. [Alexandre Dulaunoy] ### Other * Merge pull request #881 from feedly/threat-actors/add-camaro-dragon. [Alexandre Dulaunoy] [threat-actors] Add Camaro Dragon * [threat-actors] Add Camaro Dragon. [Mathieu Beligon] * Merge branch 'jstnk9-main' into main. [Alexandre Dulaunoy] * Threat actors update. [jstnk9] * Merge pull request #878 from jstnk9/main. [Alexandre Dulaunoy] threat actor updated * Threat actor updated. [jstnk9] * Merge pull request #876 from Mathieu4141/threat-actors/cobalt-mirage. [Christophe Vandeplas] [threat-actors] More aliases of Iranian apts * [threat-actors] More aliases of iranian apts. [Mathieu Beligon] * Merge pull request #875 from Mathieu4141/threat-actors/add-void-rabisu. [Alexandre Dulaunoy] [threat-actors] Add Void Rabisu * [threat-actors] Add Void Rabisu. [Mathieu Beligon] * Merge branch 'o1mate-FirearmsAndAmmo' into main. [Alexandre Dulaunoy] * Merge branch 'FirearmsAndAmmo' of https://github.com/o1mate/misp-galaxy into o1mate-FirearmsAndAmmo. [Alexandre Dulaunoy] * Merging the handguns and shotguns clusters into a single firearm cluster. [o1mate] * Added two new galaxies : An ammunition galaxy containing a list of known sold ammunitions ordered by brands, and a firearm galaxy containing two clusters (handguns, shotguns) scrapped from a famous vendor and ordered by model name (Format : Model name - SKU). [o1mate] * Merge branch 'jstnk9-main' into main. [Alexandre Dulaunoy] * Added information related to Wizard Spider. [jstnk9] * Added suspected victims to Gelsemium. [jstnk9] * Merge pull request #872 from Delta-Sierra/main. [Alexandre Dulaunoy] add AtlasCross * Add AtlasCross. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Adding targeted sectors. [Delta-Sierra] * Merge pull request #871 from danielplohmann/patch-35. [Alexandre Dulaunoy] adding aliases to ProphetSpider * Adding aliases to ProphetSpider. [Daniel Plohmann] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #870 from cipherlock/chg-nigeria-country-code. [Alexandre Dulaunoy] chg [misp-galaxy] update Nigeria from name to 2-digit code * Chg [misp-galaxy] update Nigeria from name to 2-digit code. [Paul Stark] * Merge branch 'jstnk9-main' into main. [Alexandre Dulaunoy] * Updated TA505 countries and industries affected. [jstnk9] updated TA505 countries and industries affected * Merge pull request #868 from Mathieu4141/threat-actors/add-scattered-ta. [Alexandre Dulaunoy] [threat-actors] Add Scattered Canary and Scattered Spider * Fixes. [Mathieu Beligon] * Fixes. [Mathieu Beligon] * Fixes. [Mathieu Beligon] * [threat-actors] bump version. [Mathieu Beligon] * [threa-actors] Add Scattered Spider. [Mathieu Beligon] * [threa-actors] Add Scattered Canary. [Mathieu Beligon] * Merge branch 'fl0x2208-master' into main. [Alexandre Dulaunoy] * Malpedia 2023 September update. [fl0x2208] malpedia 2023 September update * Merge pull request #866 from Mathieu4141/actors/add-storm-0324. [Alexandre Dulaunoy] [threat-actors] Add Storm-0324 * [threat-actors] Add Storm-0324. [Mathieu Beligon] * Merge pull request #865 from Delta-Sierra/main. [Alexandre Dulaunoy] adding targeted sectors * Fix caps. [Delta-Sierra] * Adding targeted sectors. [Delta-Sierra] * Finish fixing Botswana infos into Brazil cluster. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Adding targeted sectors. [Delta-Sierra] * Fix caps. [Delta-Sierra] ## v2.4.176 (2023-09-14) ### Other * Merge pull request #864 from fabionitto/patch-1. [Alexandre Dulaunoy] Update target-information.json * Update target-information.json. [Fabio Nitto] Fixing information about Brazil. * Merge pull request #863 from Delta-Sierra/main. [Alexandre Dulaunoy] Add targeted sectors * Add targeted sectors. [Delta-Sierra] * Merge pull request #862 from Delta-Sierra/main. [Alexandre Dulaunoy] more targeted-sectors meta * More targeted-sectors meta. [Delta-Sierra] * Merge pull request #861 from Delta-Sierra/main. [Alexandre Dulaunoy] add some targeted-sectors meta on threat actor * Add Non-profit organisation sector. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #860 from danielplohmann/main-3. [Alexandre Dulaunoy] * RecordedFuture: RedHotel == EarthLusca. [Daniel Plohmann] * Merge pull request #859 from jloehel/darkgate. [Alexandre Dulaunoy] chg [tool] Add DarkGate * Chg [tool] Add DarkGate. [Jürgen Löhel] * Add targeted sectors meta. [Delta-Sierra] ## v2.4.175 (2023-08-23) ### Changes * [sigma] updated. [Alexandre Dulaunoy] * [sigma] updated. [Alexandre Dulaunoy] ### Other * Merge pull request #858 from danielplohmann/ref-update. [Alexandre Dulaunoy] updating multiple references * Version bump. [Daniel Plohmann (Saturn)] * Replaced various broken links with reachable equivalents. [Daniel Plohmann (Saturn)] * Merge pull request #857 from danielplohmann/main-2. [Alexandre Dulaunoy] adding MoustachedBouncer * Jq fix. [Daniel Plohmann] * Adding MoustachedBouncer. [Daniel Plohmann] * Merge pull request #856 from danielplohmann/main-1. [Alexandre Dulaunoy] alias Callisto -> BlueCharlie * Alias Callisto -> BlueCharlie. [Daniel Plohmann] not sure, if you also want to have the Microsoft names in here (I think they are tracked separately?), otherwise, that would be Star Blizzard according to the article. ## v2.4.174 (2023-07-31) ### Changes * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [threat-actor] added references, origin country, aliases to `Sea Turtle` [Rony] * [sigma] updated to the latest rules. [Alexandre Dulaunoy] ### Other * Merge pull request #855 from r0ny123/Sea-Turtle. [Alexandre Dulaunoy] Update to `Sea Turtle` * Merge branch 'MISP:main' into Sea-Turtle. [Rony] * Merge pull request #854 from nyx0/main. [Alexandre Dulaunoy] upd: Add Worok TA and update APT-Q-12 to APT-C-60 as it was the first * Upd: Add Worok TA and update APT-Q-12 to APT-C-60 as it was the first name mention in an article. [Thomas Dupuy] * Merge pull request #853 from Delta-Sierra/main. [Alexandre Dulaunoy] add SmugX & RedDelta * Add SmugX & RedDelta. [Delta-Sierra] ## v2.4.173 (2023-07-04) ### Changes * [sigma] updated. [Alexandre Dulaunoy] ### Other * Merge pull request #852 from Delta-Sierra/main. [Alexandre Dulaunoy] add Parties/Observers to the Budapest Convention * Add Parties/Observers to the Budapest Convention. [Delta-Sierra] * Merge. [Delta-Sierra] * Complete VENOM SPIDER threat actor. [Delta-Sierra] * Add Hagga threat actor. [Delta-Sierra] ## v2.4.172 (2023-06-09) ### Changes * [sigma] updated. [Alexandre Dulaunoy] * [galaxy] fixed icons. [Alexandre Dulaunoy] * [threat actors] added Volt Typhoon. [iglocska] * [attck4fraud] Full merge of E.A.S.T. data + updated script. [Christophe Vandeplas] * [attck4fraud] more manual updates with E.A.S.T. data. [Christophe Vandeplas] ### Fix * [attck4fraud] update README numbers. [Christophe Vandeplas] * [tools] clarify validate all output. [Christophe Vandeplas] ### Other * Merge pull request #851 from Delta-Sierra/main. [Alexandre Dulaunoy] add APT43 + tools * Fix metasploit desc in value (ty cvandeplas) [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #850 from marjatech/main. [Alexandre Dulaunoy] update malpedia galaxy * Update malpedia. [marjatech] * Add APT43 + tools. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] ## v2.4.171 (2023-05-11) ### New * [tools] gen E.A.S.T. galaxy tool - not functional. [Christophe Vandeplas] * [tool] Initial version of a Relationship generator. [Christophe Vandeplas] * [online-service] online service added. [Alexandre Dulaunoy] ### Changes * [doc] Index updated. [Alexandre Dulaunoy] * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [mitre] bump to v13. [Thomas Dupuy] * [attck4fraud] initial updates with E.A.S.T. data. [Christophe Vandeplas] https://www.association-secure-transactions.eu/industry-information/fraud-definitions/ * [sigma] rules updated. [Alexandre Dulaunoy] * [attck4fraud] add ATM cash trapping in the matrix. [Alexandre Dulaunoy] * [rels] more threat actor relations. [Christophe Vandeplas] * [rels] more threat actor relations. [Christophe Vandeplas] * [rels] more relations on cluster "value" [Christophe Vandeplas] * [tool] gen_relationships is now interactive. [Christophe Vandeplas] * [rels] threat-actor & MS activity group - on synonym. [Christophe Vandeplas] * [rels] threat-actor & MS activity group - on value. [Christophe Vandeplas] * [atrm] updated to latest version. [Christophe Vandeplas] * [doc] updated. [Alexandre Dulaunoy] * [microsoft-activity-group] country code added. [Alexandre Dulaunoy] * [microsoft activity group] remove duplicate. [Alexandre Dulaunoy] * Chg: [microsoft-activity-group] updated following contribution from @botlabsDev script. [Alexandre Dulaunoy] * [sigma] rules updated. [Alexandre Dulaunoy] * [microsoft-activity-group] jq all the things. [Alexandre Dulaunoy] * [microsoft-activity-group] updated to map the new funky Microsoft "taxonomy" [Alexandre Dulaunoy] Script to generate the cluster is the following, UUIDv5 based on standard misp-stix source UUIDv4. ~~~python lcluster = [] for v in data: cluster = {} cluster['value'] = v['threat_actor'] cluster['meta'] = {} cluster['meta']['sector'] = v['sector'] cluster['meta']['synonyms'] = v['synonyms'] cluster['meta']['refs'] = [] cluster['meta']['refs'].append('https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide') _uuid = uuid.uuid5(uuid.UUID("76beed5f-7251-457e-8c2a-b45f7b589d3d"), "{}".format(cluster['value'])) cluster['uuid'] = str(_uuid) lcluster.append(cluster) ~~~ Relationships might be added in a later stage to map with the MISP threat actor galaxy. ### Fix * [tool] minor cosmetic fix. [Christophe Vandeplas] * [tool] minor cosmetic fix. [Christophe Vandeplas] * [tools] 360net cosmetic fix. [Christophe Vandeplas] * [microsoft activity group] duplicate in Microsoft source. [Alexandre Dulaunoy] ### Other * Merge pull request #849 from danielplohmann/patch-34. [Alexandre Dulaunoy] adding APT43 (Mandiant) for Kimsuky. * Adding APT43 (Mandiant) for Kimsuky. [Daniel Plohmann] * Merge pull request #848 from nyx0/main. [Alexandre Dulaunoy] chg: [mitre] bump to v13. * Merge pull request #847 from Delta-Sierra/main. [Alexandre Dulaunoy] add VEILEDSIGNAL and more * Add VEILEDSIGNALand more. [Delta-Sierra] * Merge pull request #846 from sebdraven/main. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Sebastien Larinier] * Update threat-actor.json. [Sebastien Larinier] fix mistake * Update threat-actor.json. [Sebastien Larinier] * Merge pull request #844 from jloehel/redgolf. [Alexandre Dulaunoy] chg [threat-actors] Add RedGolf * Chg [threat-actors] Add RedGolf. [Jürgen Löhel] * Merge pull request #831 from sebdraven/main. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Sebastien Larinier] * Update threat-actor.json. [Sebastien Larinier] * Merge branch 'MISP:main' into main. [Sebastien Larinier] * Merge pull request #843 from Delta-Sierra/main. [Alexandre Dulaunoy] Update Snowyamber, Halfrig & quarterrig relationships * Jq? [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Add relationships for HALFRIG & QUATTERRIG. [Delta-Sierra] * Fix versions. [Delta-Sierra] * Add relationship SNOWYAMBER & Notion. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Add some SNOWYAMBER relationships. [Delta-Sierra] * Merge pull request #842 from neok0/main. [Alexandre Dulaunoy] replace "sector" tag with "country" for matching data. this allows to… * Replace "sector" tag with "country" for matching data. this allows to be confirm with existing clusters. [Tobias Mainka] * Update threat-actor.json. [Sebastien Larinier] * Update threat-actor.json. [Sebastien Larinier] new apt30 group * Merge branch 'MISP:main' into main. [Sebastien Larinier] * Merge pull request #840 from danielplohmann/patch-33. [Alexandre Dulaunoy] adding Trend Micro alias Earth Smilodon for APT27 * Adding Trend Micro alias Earth Smilodon for APT27. [Daniel Plohmann] * Merge pull request #839 from danielplohmann/patch-32. [Alexandre Dulaunoy] adding Google alias HOODOO for APT41 * Adding Google alias HOODOO for APT41. [Daniel Plohmann] * Merge pull request #838 from Delta-Sierra/main. [Alexandre Dulaunoy] Adding SNOWYAMBER, HALFRIG, QUARTERRIG tools & PowerMagic backdoor * Add SNOWYAMBER, HALFRIG, QUARTERRIG tools. [Delta-Sierra] * Add PowerMagic backdoor. [Delta-Sierra] * Merge pull request #835 from danielplohmann/patch-31. [Alexandre Dulaunoy] adding Trend Micro alias Earth Preta for Mustang Panda * Adding Trend Micro alias Earth Preta for Mustang Panda. [Daniel Plohmann] * Update threat-actor.json. [Sebdraven] add new ref for sidecopy * Update threat-actor.json. [Sebdraven] delete ref to APT30 for Naikon ## v2.4.170 (2023-04-12) ### New * [stealer] add Sordeal Stealer. [Alexandre Dulaunoy] ### Changes * [sigma] Sigma rules updated. [Alexandre Dulaunoy] * [doc] index updated. [Alexandre Dulaunoy] * [sigma] updated. [Alexandre Dulaunoy] ### Fix * [ransomware] fix duplicate Value "Cuba" [Alexandre Dulaunoy] ### Other * Merge pull request #834 from Delta-Sierra/main. [Alexandre Dulaunoy] more ransomwares from ransomlook * Jq. [Delta-Sierra] * Merge. [Delta-Sierra] * Merge pull request #833 from jloehel/HinataBot. [Alexandre Dulaunoy] chg[botnet]: Add HinataBot * Chg[botnet]: Add HinataBot. [Jürgen Löhel] * Merge pull request #830 from sebdraven/main. [Christophe Vandeplas] chg: [threat-actor] added ref to Aoqin Dragon * Update threat-actor.json. [Sebdraven] add ref to Aoqin Dragon * Merge pull request #829 from Delta-Sierra/main. [Alexandre Dulaunoy] update based on ransomlook+1 * Merge pull request #828 from Mathieu4141/threat-actors/add-anonymous-suddan. [Alexandre Dulaunoy] [threat-actors] Add Anonymous Sudan * [threat-actors] Add Anonymous Sudan. [Mathieu Beligon] * Merge pull request #827 from danielplohmann/patch-30. [Alexandre Dulaunoy] add sofacy alias to apt28 * Update threat-actor.json. [Daniel Plohmann] when value "Sofacy" was changed to "APT28", it seems Sofacy was not added to aliases, so it's missing right now. * Add more ransomwares from ransomlook. [Delta-Sierra] * Update based on ransomlook. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * More from ransomlook. [Delta-Sierra] ## v2.4.169 (2023-03-10) ### Changes * [sigma] updated. [Alexandre Dulaunoy] * [ransomware] fixing duplicate cluster element Avaddon. [Alexandre Dulaunoy] * [mitre] updated with correct ID parsing. [Tom King] * [doc] update README. [Christophe Vandeplas] * [first-dns] Adds FIRST DNS Abuse Techniques Matrix. [Christophe Vandeplas] * [360net] updated to latest online version. [Christophe Vandeplas] * [threat-actor] version updated. [Alexandre Dulaunoy] * [tools] TgToxic added. [Alexandre Dulaunoy] * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [sigma] updated to the latest version. [Alexandre Dulaunoy] * [stealer] Adds Album Stealer. [Jürgen Löhel] * [backdoor] Adds BOLDMOVE. [Jürgen Löhel] * [stealer] Removes BluStealer. [Jürgen Löhel] The BluStealer is already in the malpedia cluster. * [stealer] Adds DarkCloud and BluStealer. [Jürgen Löhel] * [region] Updated the `region` Galaxy Cluster. [Christian Studer] - Added missing entry (Antarctica) - Ordered the `subregions` meta field ### Fix * [first-dns] corrected typo. [Christophe Vandeplas] * [region] JQed all the things !! [Christian Studer] * [tools] Added missing closing `'` [Christian Studer] ### Other * Merge pull request #826 from jloehel/wasabi. [Alexandre Dulaunoy] [Proofpoint] [Campaign] Screentime * Chg [tool]: Add tools used by TA866 during the Screentime campaign. [Jürgen Löhel] * Chg [stealer]: Add Rhadamanthys. [Jürgen Löhel] * Chg [tds]: Add 404 TDS. [Jürgen Löhel] * Chg [threat-actors] Add TA866. [Jürgen Löhel] * Merge pull request #824 from Delta-Sierra/main. [Alexandre Dulaunoy] update based on ransomlook * Fix stupid duplicate-bis. [Delta-Sierra] * Fix stupid duplicate. [Delta-Sierra] * Update based on ransomlook. [Delta-Sierra] * Merge pull request #823 from Mathieu4141/threat-actors/add-some-actors. [Alexandre Dulaunoy] Add a few threat actors and aliases * [threat-actors] bump version. [Mathieu Beligon] * [threat-actors] Add SLIPPY SPIDER alias to LAPSUS. [Mathieu Beligon] * [threat-actors] Add PROPHET SPIDER. [Mathieu Beligon] * [threat-actors] Add Nemesis Kitten. [Mathieu Beligon] * [threat-actors] Add Karakurt. [Mathieu Beligon] * [threat-actors] Add CYBORG SPIDER alias to GOCLD BURLAP. [Mathieu Beligon] * [threat-actors] Add Chamelgang. [Mathieu Beligon] * [threat-actors] Add TA453. [Mathieu Beligon] * [threat-actors] Add APT42. [Mathieu Beligon] * [threat-actors] Add TA406. [Mathieu Beligon] * Merge pull request #822 from r0ny123/patch-1. [Alexandre Dulaunoy] add other actor synonyms from Google's report https://services.google.com/fh/files/blogs/google_fog_of_war_research_report.pdf * Add DEV-0147 https://twitter.com/MsftSecIntel/status/1625181255754039318. [Rony] * Add other actor synonyms from Google's report https://services.google.com/fh/files/blogs/google_fog_of_war_research_report.pdf. [Rony] * Merge pull request #821 from Delta-Sierra/main. [Alexandre Dulaunoy] add/update ransomware based on ransomlook * Synonyms must be an array. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #820 from tomking2/bug/mitre-attack-external-id-parsing. [Alexandre Dulaunoy] [fix] Mitre ATT&CK parsing to pull correct external_id value and update cluster * Add/update ransomware based on ransomlook. [Delta-Sierra] * Merge pull request #819 from danielplohmann/patch-29. [Alexandre Dulaunoy] adding Google names for RU threat actors * Adding Google names for RU threat actors. [Daniel Plohmann] https://blog.google/threat-analysis-group/fog-of-war-how-the-ukraine-conflict-transformed-the-cyber-threat-landscape/ * Merge pull request #818 from Mathieu4141/threat-actors/proofpoint-aliases. [Alexandre Dulaunoy] [threat actors] Adding some actors from ProofPoint * [threat-actors] Fix: country was in the wrong place. [Mathieu Beligon] * [threat-actors] fix: Add missing uuids. [Mathieu Beligon] * Fix. [Mathieu Beligon] * [threat-actors] bump version. [Mathieu Beligon] * [threat-actors] Add TA2536. [Mathieu Beligon] * [threat-actors] Add TA577. [Mathieu Beligon] * [threat-actors] Add TA575. [Mathieu Beligon] * [threat-actors] Add TA570. [Mathieu Beligon] * [threat-actors] Add Moskalvzapoe. [Mathieu Beligon] * Merge pull request #817 from danielplohmann/patch-28. [Alexandre Dulaunoy] adding Broadcom name for SaintBear. * Adding Broadcom name for SaintBear. [Daniel Plohmann] * Merge pull request #816 from Mathieu4141/threat-actors/noname057-aliases. [Alexandre Dulaunoy] [threat-actors] Add more information about NoName057(16) * [threat-actors] Add more information about NoName057(16) [Mathieu Beligon] * Merge pull request #815 from danielplohmann/patch-27. [Alexandre Dulaunoy] new APT29 name used by Recorded Future * New APT29 name used by Recorded Future. [Daniel Plohmann] cf. https://go.recordedfuture.com/hubfs/reports/cta-2023-0127.pdf * Merge pull request #814 from jloehel/album. [Alexandre Dulaunoy] chg: [stealer] Adds Album Stealer * Merge pull request #812 from jloehel/boldmove. [Alexandre Dulaunoy] chg: [backdoor] Adds BOLDMOVE * Merge pull request #813 from jloehel/darkcloud. [Alexandre Dulaunoy] chg: [stealer] Adds DarkCloud * Merge pull request #809 from MISP/dev. [Alexandre Dulaunoy] Updated the `region` cluster * Add: [region] Added script to update the `region` cluster based on the UNSD M49 csv file. [Christian Studer] * Merge pull request #789 from Mathieu4141/threat-actors/fix-sectorj04. [Alexandre Dulaunoy] [threat-actors] Remove SectorJ04 duplicate * [threat-actors] pr.review: Add SectorJ04 as alias of TA505. [Mathieu Beligon] * [threat-actors] Remove SectorJ04 duplicate. [Mathieu Beligon] * Merge pull request #810 from Delta-Sierra/main. [Alexandre Dulaunoy] add Anubis & Godfather android banking trojans * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #808 from 0xOFenomeno/uavs-final. [Alexandre Dulaunoy] Adding UAVs' galaxy and related cluster * Adding uavs. [ofenomeno] * Merge branch 'main' of github.com:MISP/misp-galaxy. [Christian Studer] * Fix missing brackets. [Delta-Sierra] * Add Anubis & Godfather android banking trojans. [Delta-Sierra] ## v2.4.168 (2023-01-23) ### New * [tools] Sigma export tool added based on https://github.com/jstnk9/MISP/pull/1. [Alexandre Dulaunoy] ### Changes * [sigma] updated. [Alexandre Dulaunoy] * [sigma] updated. [Alexandre Dulaunoy] * [country] Clarified the US cluster value. [Christian Studer] * [sigma] version must be an integer. [Alexandre Dulaunoy] * [tools] sigma tools updated. [Alexandre Dulaunoy] * [sigma] new version of the cluster. [Alexandre Dulaunoy] * [sigma] updated with latest version + new relationship script. [Alexandre Dulaunoy] * [threat-actor] added the missing synonyms. [Alexandre Dulaunoy] * [sigma] regenerated from the test script (also updated the script to ensure UUID consistency for the galaxy) [Alexandre Dulaunoy] * [sigma] jq all the things. [Alexandre Dulaunoy] * [ransomware] Extends the entry for JCrypt. [Jürgen Löhel] * Add the reference to MafiaWare666 based on the latest research from the Avast Threat Lab: https://decoded.avast.io/threatresearch/decrypted-mafiaware666-ransomware/ * Add more infos from Andrew Ivanovs the great blog post: https://id-ransomware.blogspot.com/2020/12/jcrypt-ransomware.html ### Fix * [sigma] version must be an int. [Alexandre Dulaunoy] ### Other * Add: [country] Manually added the missing relations to some `country` cluster values. [Christian Studer] - The previous commit (071ecb8) that added the mahority of relations between countries and regions were automatically added based on the country names specified in the `region` cluster. The relations added here are the remaining countries that are not litterally defined the same way they are in the `region` cluster * Add: [country] Added references between `country` cluster values and the related region they're located in, from the `region` galaxy cluster. [Christian Studer] * Merge branch 'main' of github.com:MISP/misp-galaxy. [Christian Studer] * Merge branch 'jstnk9-main' into main. [Alexandre Dulaunoy] * Merge branch 'main' of https://github.com/jstnk9/misp-galaxy into jstnk9-main. [Alexandre Dulaunoy] * Merge branch 'MISP:main' into main. [jstnk9] * Galaxy for sigma rules. [jstnk9] * Merge pull request #805 from jloehel/mafiaware666. [Alexandre Dulaunoy] chg: [ransomware] Extends the entry for JCrypt * Merge branch 'main' of github.com:MISP/misp-galaxy. [Christian Studer] * Merge branch 'main' of github.com:MISP/misp-galaxy. [Christian Studer] ## v2.4.167 (2022-12-22) ### Other * Merge pull request #804 from Delta-Sierra/main. [Alexandre Dulaunoy] add Malteiro, TAG-53 * Add Malteiro. [Delta-Sierra] * Add TAG-53. [Delta-Sierra] * Merge pull request #801 from Delta-Sierra/main. [Alexandre Dulaunoy] Update Ransomwares & others small updates * Version Update. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Fix Duplicate. [Delta-Sierra] * Update several RAT & Ransomwares. [Delta-Sierra] ## v2.4.166 (2022-11-28) ### Changes * [mitre] updated. [Alexandre Dulaunoy] * [target-information] fix the duplicate. [Alexandre Dulaunoy] * [target-information] duplicate removal. [Alexandre Dulaunoy] * [target] fix duplicate synonyms. [Alexandre Dulaunoy] * [sigma] duplicate value changed. [Alexandre Dulaunoy] * [sigma] jq all the things. [Alexandre Dulaunoy] * [botnets] Adds KmsdBot. [Jürgen Löhel] ### Fix * [att&ck converter] allow multiple external IDs. [Andras Iklody] - There are in some cases external ID references to CAPEC in addition to ATT&CK in techniques - convert external ID to a list rather than a single string - as reported by @SYNchroACK - as hurried along by a disappointed @deresz * [clusters] Fixed some other few `meta` field names. [Christian Studer] * [target-information] Fixed `synonyms` meta field name. [Christian Studer] * [tool] Houdini relationship to something which exist (ok I know it's Houdini) [Alexandre Dulaunoy] * [sigma rules] until new the PR and tool is done for sigma. The galaxy is removed. [Alexandre Dulaunoy] * [sigma] remove duplicate references. [Alexandre Dulaunoy] * [handicap] fix galaxy icon + name + type. [Terrtia] ### Other * Fix; [mitre-ics-assets] Fixed some `refs` meta field names. [Christian Studer] * Merge branch 'main' of github.com:MISP/misp-galaxy. [Christian Studer] * Merge pull request #800 from Delta-Sierra/main. [Alexandre Dulaunoy] Add ransomwares * Add VJw0rm description. [Delta-Sierra] * Fix versions. [Delta-Sierra] * Merge. [Delta-Sierra] * Add several ransomwares. [Delta-Sierra] * Add qakbot ref. [Delta-Sierra] * Add BazarCall campaign. [Delta-Sierra] * Add Bazarbackdoor Synonyms. [Delta-Sierra] * Merge pull request #799 from nyx0/main. [Alexandre Dulaunoy] Add Evasive Panda Threat Actor * Add Evasive Panda Threat Actor. [Thomas Dupuy] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #798 from Terrtia/main. [Alexandre Dulaunoy] Fix handicap type and icon * Merge branch 'jstnk9-main' into main. [Alexandre Dulaunoy] * Merge branch 'main' of https://github.com/jstnk9/misp-galaxy into jstnk9-main. [Alexandre Dulaunoy] * Galaxy related to sigma rtules. [Jstnk9] galaxy related to sigma rtules * Merge pull request #797 from jloehel/kmsd. [Alexandre Dulaunoy] chg: [botnets] Adds KmsdBot * Merge pull request #795 from Delta-Sierra/main. [Alexandre Dulaunoy] add raspberry Robin worm & others * Fix tool type. [Delta-Sierra] * Version fix. [Delta-Sierra] * Version fix. [Delta-Sierra] * Merge. [Delta-Sierra] * Add raspberry Robin worm & others. [Delta-Sierra] ## v2.4.165 (2022-11-08) ### Changes * [mitre-attack] updated to version 12.0. [Alexandre Dulaunoy] * [threat-actor] JSON fix. [Alexandre Dulaunoy] * [mitre] bump to v11.3. [Christophe Vandeplas] * [tool] make mitre script easier to find. [Christophe Vandeplas] ### Other * Merge pull request #792 from nyx0/main. [Alexandre Dulaunoy] Add RomCom TA. * Add RomCom TA. [Thomas Dupuy] * Merge pull request #791 from Mathieu4141/threat-actors/add-phosphorus-alias-to-apt-35. [Alexandre Dulaunoy] [threat-actors] Add Phosphorus in APT35 aliases * [threat-actors] Add Phosphorus in APT35 aliases. [Mathieu Beligon] * Merge pull request #790 from Mathieu4141/threat-actors/fix-dust-storm. [Alexandre Dulaunoy] [threat-actors] Remove DustStorm alias from APT10 * [threat-actors] Remove DustStorm alias from APT10. [Mathieu Beligon] * Merge pull request #788 from Mathieu4141/threat-actors/fix-cobalt-dickens. [Alexandre Dulaunoy] [threat-actors] Remove cobalt dickens duplicate * [threat-actors] Remove cobalt dickens duplicate. [Mathieu Beligon] * Merge pull request #787 from Mathieu4141/threat-actors/fix-subaat-duplicate. [Alexandre Dulaunoy] [threat-actors] Remove subaat duplicate * [threat-actors] Remove subaat duplicate. [Mathieu Beligon] * Merge pull request #786 from Mathieu4141/threat-actors/remove-skeleton-spider-duplicate. [Alexandre Dulaunoy] [threat-actors] Remove Skeleton Spider duplicate * [threat-actors] Remove Skeleton Spider duplicate. [Mathieu Beligon] * Merge pull request #785 from Delta-Sierra/main. [Alexandre Dulaunoy] add Prynt Stealer & variants * Add Prynt Stealer & variants. [Delta-Sierra] * Merge pull request #784 from Delta-Sierra/main. [Alexandre Dulaunoy] add Volatile Cedar synonym * Fix metadata in wrong slot. [Delta-Sierra] * Add Volatile Cedar synonym. [Delta-Sierra] * Merge pull request #782 from nyx0/main. [Alexandre Dulaunoy] Add SharPyShell tool. * Add SharPyShell tool. [Thomas Dupuy] * Merge pull request #781 from Mathieu4141/threat-actors/fix-neodymium. [Alexandre Dulaunoy] [threat-actors] Fix G0055 (NEODYMIUM) alias * [threat-actors] Fix G0055 (NEODYMIUM) alias. [Mathieu Beligon] * Merge pull request #780 from Mathieu4141/threat-actors/fix-svmondr. [Alexandre Dulaunoy] [threat-actors] Remove SVCMONDR duplicate * [threat-actors] Remove SVCMONDR duplicate. [Mathieu Beligon] * Merge pull request #778 from Mathieu4141/threat-actors/fix-malware-reuser-duplicate. [Alexandre Dulaunoy] [threat-actors] Fix Volatile Cedar and Dancing Salome conflicts * [threat-actors] Fix Volatile Cedar and Dancing Salome conflicts. [Mathieu Beligon] * Merge pull request #777 from Mathieu4141/threat-actors/fix-equation-group-conflict. [Alexandre Dulaunoy] [threat-actors] Equation group: separate from Lamberts and add tools * [threat-actors] Equation group: separate from Lamberts and add tools. [Mathieu Beligon] * Merge pull request #774 from nyx0/main. [Alexandre Dulaunoy] Add APT-Q-12 Threat Actor. * Add APT-Q-12 Threat Actor. [Thomas Dupuy] * Merge branch 'nyx0-main' into main. [Alexandre Dulaunoy] * Merge branch 'main' of https://github.com/nyx0/misp-galaxy into nyx0-main. [Alexandre Dulaunoy] * Add Void Balaur. [Thomas Dupuy] ## v2.4.163 (2022-09-26) ### New * [malpedia] remove duplicate UUIDs objects (coming from Malpedia API) [Alexandre Dulaunoy] * [threat-actor] hezb added. [Alexandre Dulaunoy] ### Changes * [360net] add 360.net APT list fixes #764. [Christophe Vandeplas] ### Fix * [atrm] fix bug in authors. [Christophe Vandeplas] * [360net] fixes null entries in lists. [Christophe Vandeplas] ### Other * Merge pull request #771 from Delta-Sierra/main. [Alexandre Dulaunoy] fetch malpedia * Fetch malpedia. [Delta-Sierra] * Merge pull request #770 from Mathieu4141/threat-actors/add-bitwise-spider. [Alexandre Dulaunoy] [threat-actors] Add BITWISE SPIDER * [threat-actors] Add BITWISE SPIDER. [Mathieu Beligon] * Merge pull request #769 from Mathieu4141/threat-actors-add/no-name-057-06. [Alexandre Dulaunoy] [threat-actors] Add NoName057(16) * [threat-actors] Add NoName057(16) [Mathieu Beligon] * Merge pull request #766 from Mathieu4141/threat-actors/fix-ta505. [Alexandre Dulaunoy] [threat-actors] Clean TA505 aliases * [threat-actors] Clean TA505 aliases. [Mathieu Beligon] * Merge pull request #768 from Delta-Sierra/main. [Alexandre Dulaunoy] New clusters * Add PlugX ref. [Delta-Sierra] * Add Chisel. [Delta-Sierra] * Add Lorenz ransomware. [Delta-Sierra] * Add Dark.IoT. [Delta-Sierra] * Add hezb. [Delta-Sierra] * Add BumbleBee backdoor. [Delta-Sierra] * Merge pull request #767 from cvandeplas/360net. [Christophe Vandeplas] chg: [360net] add 360.net APT list fixes #764 * Merge pull request #765 from Mathieu4141/threat-actors/fix-xenotime. [Alexandre Dulaunoy] [threat-actors] Remove Xenotime duplicate * [threat-actors] Keep meta from old Xenotime. [Mathieu Beligon] * [threat-actors] Remove Xenotime duplicate. [Mathieu Beligon] ## v2.4.162 (2022-09-09) ### Changes * [threat-actor] version bump. [Rony] * [threat-actor] add Aoqin Dragon. [Rony] * [threat-actor] miscellaneous updates. [Rony] * [doc] index updated. [Alexandre Dulaunoy] * [threat-actor] add avast blog to APT40. [Rony] * [threat-actor] add Microsoft and PwC report to actors' references. [Rony] * [threat-actor] add recorded future reference to RedAlpha. [Rony] * [threat-actor] add Adam Kozy's testimony ro APT41 and APT26. [Rony] * [threat-actor] miscellaneous updates including merge of some actors and fix the error committed in 9cfcc0d9ac2388b2579cbc7971492bbef0245273. [Rony] * [atrm] bump to latest ATRM version. [Christophe Vandeplas] * [threat-actor] jq all the things. [Alexandre Dulaunoy] * [doc] index updated. [Christophe Vandeplas] * [atrm] Add Azure Threat Research Matrix Galaxy and generation script. [Christophe Vandeplas] ### Fix * [threat-actor] remove duplicate entries. [Rony] * [threat-actor] remove duplicate entries from APT9. [Rony] * [threat-actor] UUID reused fixed (UUIDs cannot be reused across different cluster) [Alexandre Dulaunoy] Add the missing the relationship for the new UUID * [threat-actor] add missing refs for APT33 including CFR link. [Alexandre Dulaunoy] ### Other * Merge pull request #763 from Delta-Sierra/main. [Alexandre Dulaunoy] add DangerousSavanna campaign & Lockbit synonym * Add DangerousSavanna campaign. [Delta-Sierra] * Add Lockbit synonym. [Delta-Sierra] * Add Lockbit synonym. [Delta-Sierra] * Merge pull request #762 from r0ny123/CN. [Alexandre Dulaunoy] Update threat-actor.json * Merge branch 'CN' of https://github.com/r0ny123/misp-galaxy into CN. [Rony] * Add Red Dev 17 and Aoqin Dragon. [Rony] * Merge pull request #761 from danielplohmann/patch-26. [Christophe Vandeplas] mini-fix: adding https protocol to a reference * Mini-fix: adding https protocol to a reference. [Daniel Plohmann] in automated processing and display, this may otherwise lead to a malformed local / relative link. * Merge pull request #760 from Delta-Sierra/main. [Alexandre Dulaunoy] Add GootLoader & MOUSEISLAND in tool * Add GootLoader. [Delta-Sierra] * Add MOUSEISLAND. [Delta-Sierra] * Merge pull request #759 from r0ny123/CN-actors. [Alexandre Dulaunoy] Updates to Chinese actor * Merge pull request #755 from Mathieu4141/threat-actors/fix-winnti. [Alexandre Dulaunoy] [threat-actors] Fix Axiom/Winnti/Suckfly/APT41 conflicts * Add aliases to APT41. [Mathieu Béligon] * [threat-actors] Fix aliases. [Mathieu Beligon] * [threat-actors] Merge Axiom into APT17. [Mathieu Beligon] * Fix axiom related field. [Mathieu Beligon] * Merge into apt41. [Mathieu Beligon] * Merge APT22 and suckfly. [Mathieu Beligon] * [threat-actors] Fix Axiom/Winnti/Suckfly/APT41 conflicts. [Mathieu Beligon] * Merge pull request #758 from Delta-Sierra/main. [Alexandre Dulaunoy] update Guildma * Jq. [Delta-Sierra] * Update Guildma. [Delta-Sierra] * Merge pull request #757 from Yosirion95/main. [Alexandre Dulaunoy] Add synonyms to Sector galaxy clusters * Add synonyms to sector.json. [Yosirion95] * Merge pull request #756 from r0ny123/microsoft-activity-group. [Alexandre Dulaunoy] Remove `Transperent Tribe` from microsoft-activity-group * Add PARINACOTA to threat-actor.json. [Rony] MSTIC names digital crime actors based on global volcanoes * Remove APT36/ Transpert Tribe from microsoft-activity-group.json cause we don't know any MSTIC name yet. [Rony] * Merge pull request #749 from Mathieu4141/threat-actors/fix-naikon-cluster. [Alexandre Dulaunoy] [threat actors] Fix threat actors related to Lotus Panda * Fix hellsing ref. [Mathieu Beligon] * Capitalize override panda alias. [Mathieu Béligon] * Capitalize lotus panda alias. [Mathieu Béligon] * Normalize APT30 alias. [Mathieu Béligon] * Move Lotus Panda alias to Lotus Blossom. [Mathieu Beligon] * Merge APT30 and Naikon. [Mathieu Beligon] * Merge branch 'main' into threat-actors/fix-naikon-cluster. [Mathieu Beligon] * Remove ATK34 alias. [Mathieu Beligon] * Fix ATK aliases. [Mathieu Beligon] * Merge branch 'main' into threat-actors/fix-naikon-cluster. [Mathieu Beligon] * Add ATK78 alias for Thrip. [Mathieu Beligon] * Branch out Goblin Panda from Hellsing. [Mathieu Beligon] * Create a tool for Esile. [Mathieu Beligon] * [threat actor] Fix aliases related to Lotus Panda. [Mathieu Beligon] * Merge pull request #753 from Mathieu4141/threat-actors/fix-bronze-president. [Alexandre Dulaunoy] [threat-actors] Remove duplicated BRONZE PRESIDENT entity * [threat-actors] Remove duplicated BRONZE PRESIDENT entity. [Mathieu Beligon] * Merge pull request #754 from Mathieu4141/threat-actors/fix-apt-c-27. [Alexandre Dulaunoy] [threat actors] fix APT-C-27 * Add DarkCommet as a tool of GoldenRAT. [Mathieu Beligon] * [threat-actors] Add more data about APT-C-27. [Mathieu Beligon] * [threat-actors] Remove duplicated APT-C-27. [Mathieu Beligon] * Merge pull request #752 from Delta-Sierra/main. [Alexandre Dulaunoy] add TA558 * Add TA558. [Delta-Sierra] * Merge pull request #751 from r0ny123/vicious-panda. [Alexandre Dulaunoy] Merge microcin/sixlittlemonkeys to vicious panda * Addresses https://github.com/MISP/misp-galaxy/pull/751#issuecomment-1217680586. [Rony] * Remove duplicate reference. [Rony] * Merge microcin/sixlittlemonkeys to vicious panda. [Rony] * Merge pull request #748 from r0ny123/patch-2. [Alexandre Dulaunoy] Update threat-actor.json * Add uac-0010 references from cert-ua. [Rony] * Merge "red october" and "cloud atlas" to inception framework" [Rony] * Fix duplicates. [Rony] * Fix duplicate. [Rony] * Updates to russian actors. [Rony] * Update threat-actor.json. [Rony] * Updates to tianwu. [Rony] * Merge branch 'Mathieu4141-threat-actors/fix-apt33' into main. [Alexandre Dulaunoy] * [threat-actors] Remove duplicate APT33. [Mathieu Beligon] * Merge branch 'nyx0-main' into main. [Alexandre Dulaunoy] * Add link for SLIME29. [Thomas Dupuy] * Update commit based on feeback. [Thomas Dupuy] * Add Threat Actors from BH Asia22 prez. [Thomas Dupuy] * Merge pull request #746 from cvandeplas/main. [Alexandre Dulaunoy] chg: [atrm] Add Azure Threat Research Matrix Galaxy and generation script ## v2.4.160 (2022-08-04) ### Changes * [doc] index updated. [Alexandre Dulaunoy] * [doc] index updated. [Alexandre Dulaunoy] * [fix] resolve conflict. [Rony] * [threat-actor] fixed. [Rony] * [ransomware] fixed. [Alexandre Dulaunoy] ### Fix * [threat-actor] incorrect merge fixed. [Alexandre Dulaunoy] ### Other * Merge pull request #745 from danielplohmann/patch-25. [Christophe Vandeplas] removing a leading double quote in a URL. * Removing a leading double quote in a URL. [Daniel Plohmann] * Merge pull request #744 from danielplohmann/patch-24. [Alexandre Dulaunoy] merging TG2003 / Elephant Beetle into FIN13 * Merging TG2003 / Elephant Beetle into FIN13. [Daniel Plohmann] as indicated in the respective resources published by the organizations using these aliases. * Merge pull request #727 from Mathieu4141/threat-actors/merge-cutting-kitten-cleaver. [Alexandre Dulaunoy] Fix Cleaver aliases * Reduce diff with old version. [Mathieu Beligon] * R0ny123.review: Use Cutting Kitten as main value for ITSecTeam. [Mathieu Beligon] * Merge remote-tracking branch 'upstream/main' into threat-actors/merge-cutting-kitten-cleaver. [Mathieu Beligon] * [threat actor] Break Cleaver aliases into respective entries. [Mathieu Beligon] * [threat-actors] Separate ITSecTeam from Cleaver. [Mathieu Beligon] * Merge Cutting Kitten and Cleaver. [Mathieu Beligon] * Merge pull request #742 from r0ny123/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Fix. [Rony] * Update threat-actor.json. [Rony] Merge aquatic panda & earth lusca * Merge pull request #743 from danielplohmann/patch-23. [Alexandre Dulaunoy] more aliases from Unit 42 * More aliases from Unit 42. [Daniel Plohmann] * Merge branch 'r0ny123-main' into main. [Alexandre Dulaunoy] * Merge branch 'main' of https://github.com/r0ny123/misp-galaxy into r0ny123-main. [Alexandre Dulaunoy] * Merge branch 'main' of https://github.com/r0ny123/misp-galaxy. [Rony] * Update. [Rony] * Update. [Rony] * Update. [Rony] * Added Red Nue. [Rony] * Added CN actors from secureworks threat profile https://www.secureworks.com/research/threat-profiles?filter=item-china and fixed some AKAs. [Rony] * Add APT9/Red Pegasus & BRONZE EDGEWOOD/Red Hariasa. [Rony] * Add PwC naming to CN actors. [Rony] * Add Earth Berberoka, Earth Lusca and Earth Wendigo. [Rony] * Merge branch 'danielplohmann-patch-22' into main. [Alexandre Dulaunoy] * Removed duplicate UUID for Kinsing. [Daniel Plohmann] my apologies, looks like I had not rolled a new UUID for one of the entries added... * Merge pull request #740 from danielplohmann/patch-21. [Alexandre Dulaunoy] added more Unit 42 aliases / groups * Added more Unit 42 aliases / groups. [Daniel Plohmann] * Merge pull request #738 from danielplohmann/patch-19. [Alexandre Dulaunoy] adding new Unit 42 names * Adding new Unit 42 names. [Daniel Plohmann] First PR: those are the directly mappable names. I will follow up after deconfliction and then with a few new entries. * Merge pull request #737 from danielplohmann/patch-18. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Daniel Plohmann] adding Predatory Sparrow due to recent events. * Merge pull request #736 from Delta-Sierra/main. [Alexandre Dulaunoy] add Qbot * Update version. [Delta-Sierra] * Add Qbot. [Delta-Sierra] * Fix typo. [Delta-Sierra] * Merge pull request #735 from nyx0/main. [Alexandre Dulaunoy] Add POLONIUM TA. * Set country to LB instead of IR based on operational activity. [Thomas Dupuy] * Remove list from POLONIUM TA. [Thomas Dupuy] * Add POLONIUM TA. [Thomas Dupuy] * Merge pull request #734 from Delta-Sierra/main. [Alexandre Dulaunoy] Add EnemyBot +relationships * Jq. [Delta-Sierra] * Fix caps typo. [Delta-Sierra] * Merge https://github.com/Delta-Sierra/misp-galaxy into main. [Delta-Sierra] * Add EnemyBot +relationships. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy into main. [Delta-Sierra] * Merge branch 'Delta-Sierra-main' into main. [Alexandre Dulaunoy] * Merge branch 'main' into main. [Deborah Servili] * Merge pull request #730 from Delta-Sierra/main. [Alexandre Dulaunoy] add HelloXD ransomware * Add Maui ransomware. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy into main. [Delta-Sierra] * Merge pull request #729 from Delta-Sierra/main. [Alexandre Dulaunoy] Update Medusa Locker and others * Add HelloXD ransomware. [Delta-Sierra] * Fix duplicate extension-2. [Delta-Sierra] * Fix duplicate extension. [Delta-Sierra] * Merge + update medusalocker. [Delta-Sierra] * Merge pull request #728 from marjatech/main. [Alexandre Dulaunoy] update Malpedia incl automation * Add script to automate malpedia update. [marjatech] * Update malpedia. [marjatech] * Merge pull request #726 from cudeso/main. [Alexandre Dulaunoy] Add RCS Lab S.p.A. to surveillance-vendor * Update surveillance-vendor.json. [Koen Van Impe] * Add RCS Lab S.p.A. to surveillance-vendor. [Koen Van Impe] * Merge pull request #725 from Mathieu4141/threat-actors/add-toddy-cat. [Alexandre Dulaunoy] Add ToddyCat Threat actor * Add ToddyCat Threat actor. [Mathieu Beligon] * Merge pull request #723 from r0ny123/patch-1. [Alexandre Dulaunoy] chg: [threat-actor] added PwC naming for Indian actors * [threat-actor] added PwC naming for Indian actors. [Rony] https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in-retrospect/yir-cyber-threats-report-download.pdf * Merge pull request #722 from Th4nat0s/thales_atk. [Alexandre Dulaunoy] Y en a un peut plus je vous le mets quand meme ? * Y en a un peut plus je vous le mets quand meme ? [Thanat0s] * Merge pull request #720 from Th4nat0s/thales_atk. [Alexandre Dulaunoy] Add Mitre vs Thales RosettaStone * Jq all the things. [Thanat0s] * Attck link + typo on TA551. [Thanat0s] * Typo on TA551. [Thanat0s] * Add Mitre vs Thales RosettaStone. [Thanat0s] * Merge pull request #719 from r0ny123/patch-1. [Alexandre Dulaunoy] chg: [threat-actor] add reference to bitter & sidewinder group * [threat-actor] add reference to bitter & sidewinder group. [Rony] * Update Medusa Locker and others. [Delta-Sierra] ## v2.4.159 (2022-05-30) ### Changes * [cryptominers] Adds Krane. [Jürgen Löhel] * [android] Adds Vulture. [Jürgen Löhel] * [threat-actor] add exotic lily, ta578, ta579. [Rony] * [backdoors] Adds BPFDoor. [Jürgen Löhel] * [threat-actor] add TG2003 synomym to Elephant Beetle. [Alexandre Dulaunoy] * [threat-actor] Elephant Beetle added. [Alexandre Dulaunoy] Fix #708 * [threat-actor] ModifiedElephant added. [Alexandre Dulaunoy] Fix #709 * [threat-actor] fix refs field -> it's always an array. [Alexandre Dulaunoy] * [threat-actor] added actor Red Menshen. [Rony] https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in-retrospect/yir-cyber-threats-report-download.pdf * [threat-actor] added Curious Gorge. [Rony] * [mitre] bump to MITRE ATT&CK v11.0. [Christophe Vandeplas] * [threat-actor] Killnet description added. [Alexandre Dulaunoy] * [threat-actor] version updated. [Alexandre Dulaunoy] ### Other * [mitre] bump to MITRE ATT&CK v11.2. [Christophe Vandeplas] * [mitre] update sorting algo. [Christophe Vandeplas] will make future ATT&CK updates less noisy in the git diff * Merge pull request #718 from Mathieu4141/ta/ransom-house. [Alexandre Dulaunoy] Add `RansomHouse` group * [threat-actors] validate file. [Mathieu Beligon] * [threat actors] Remove dead link for sandworm threat actor. [Mathieu Beligon] * [threat-actors] Add RansomHouse. [Mathieu Beligon] * Merge pull request #717 from jloehel/krane. [Alexandre Dulaunoy] chg: [cryptominers] Adds Krane * Merge pull request #716 from jloehel/vulture. [Alexandre Dulaunoy] chg: [android] Adds Vulture * Merge pull request #715 from r0ny123/crime. [Alexandre Dulaunoy] Add EXOTIC LILY, TA578, TA579 * Merge pull request #713 from jloehel/BPFDoor. [Alexandre Dulaunoy] chg: [backdoors] Adds BPFDoor * Merge branch 'adammchugh-threatactor-cosmiclynx-add' into main. [Alexandre Dulaunoy] * Merge branch 'threatactor-cosmiclynx-add' of https://github.com/adammchugh/MISP-Galaxy-Updates into adammchugh-threatactor-cosmiclynx-add. [Alexandre Dulaunoy] * Added Cosmic Lynx Threat Actor from Agari Whitepaper advisory. [Adam McHugh] * Added Cosmic Lynx Threat Actor from Agari Whitepaper advisory. [Adam McHugh] * Merge pull request #712 from r0ny123/patch-1. [Alexandre Dulaunoy] Update to Chinese Actors * Merge pull request #711 from danielplohmann/patch-17. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Daniel Plohmann] adding Red Dev 4 as alias for GALLIUM as used by PwC. * Merge pull request #710 from danielplohmann/patch-16. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Daniel Plohmann] adding UNC3524 to the actor galaxy cluster. * Merge pull request #707 from 3c7/ta/saintbear. [Christophe Vandeplas] Added SaintBear to the Threat Actor cluster * Forgot to jq all the things. [3c7] * Added SaintBear. [3c7] * Merge pull request #706 from Mathieu4141/add-killnet. [Alexandre Dulaunoy] [actors] Add killnet * [actors] Add killnet. [Mathieu Beligon] ## v2.4.157 (2022-04-19) ### Changes * [ransomware] jq all the things. [Alexandre Dulaunoy] * [tools] add skip list in index generation (to focus on intelligence/cyber) [Alexandre Dulaunoy] * [doc] index updated. [Alexandre Dulaunoy] * [adoc] updated with the non-cyber releated lists. [Alexandre Dulaunoy] * [handicap] fixed more fields. [Alexandre Dulaunoy] * [handicap] more cleanup. [Alexandre Dulaunoy] * [handicap] more clean-up of uuid values. [Alexandre Dulaunoy] * [handicap] fix name of the clusters. [Alexandre Dulaunoy] * Jq all 2. [Sami Mokaddem] * [mitre-attack] Bumped matrix structure. [Sami Mokaddem] * Jq all. [Sami Mokaddem] * [tools] adoc export now includes a skip list. [Alexandre Dulaunoy] * [threat-actor] added LAPSUS$/DEV-05737 Merge pull request #693 from danielplohmann/patch-15. [Christophe Vandeplas] adding threat actor group LAPSUS$ / DEV-0537. * [ransomware] UUID fixed. [Alexandre Dulaunoy] * [botnet] duplicate UUIDs replaced. [Alexandre Dulaunoy] * [ransomware] replace duplicate UUIDs. [Alexandre Dulaunoy] ### Fix * [ransomware] refs are within meta. [Alexandre Dulaunoy] * [ransom] remove empty ref. [Alexandre Dulaunoy] ### Other * Merge pull request #701 from adammchugh/ransomware-conti-update. [Alexandre Dulaunoy] Ammended Conti ransomware entry with ACSC 2021-010 advisory data * Ammended Conti ransomware entry with ACSC 2021-010 advisory data. [Adam McHugh] * Merge pull request #704 from adammchugh/cryptominers-bluemockingbird-add. [Alexandre Dulaunoy] Added Cryptominer Blue Mockingbird from RedCanary advisory. * Added Cryptominer Blue Mockingbird from RedCanary advisory. [Adam McHugh] * Merge pull request #703 from adammchugh/threatactor-copypaste-add. [Alexandre Dulaunoy] Added Copy-Paste Threat Actor from ACSC Advisory 2020-008 * Added Copy-Paste Threat Actor from ACSC Advisory 2020-008. [Adam McHugh] * Merge pull request #702 from adammchugh/ransomware-blackcat-update. [Alexandre Dulaunoy] Ammended Blackcat ransomware entry with ACSC 2022-004 advisory data * Ammended Blackcat ransomware entry with ACSC 2022-004 advisory data. [Adam McHugh] * Merge pull request #700 from nyx0/main. [Alexandre Dulaunoy] upd: [cluster] add Threat Actor BladeHawk. * Upd: [cluster] add Threat Actor BladeHawk. [Thomas Dupuy] * Merge pull request #699 from nyx0/main. [Alexandre Dulaunoy] upd: [clusters] add ref and synonyms for Energetic Bear. * Upd: [cluster] add ref and synonyms for Energetic Bear. [Thomas Dupuy] * Merge pull request #694 from AgatheMgt/main. [Alexandre Dulaunoy] Handicap * Poatate. [AgatheMgt] * Update handicap.json. [AgatheMgt] * Update handicap.json. [AgatheMgt] * Update handicap.json. [AgatheMgt] * Create handicap.json. [AgatheMgt] * Update handicap.json. [AgatheMgt] * Create handicap.json. [AgatheMgt] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #698 from r0ny123/revert-697-main. [Alexandre Dulaunoy] Revert "update threat actors meta" * Add Avivore & HAZY TIGER/Bitter. [Rony] * Revert "update threat actors meta" [Rony] * Merge pull request #697 from Delta-Sierra/main. [Alexandre Dulaunoy] update threat actors meta * Dup. [Delta-Sierra] * Dup. [Delta-Sierra] * Duplicate. [Delta-Sierra] * Fix duplicate. [Delta-Sierra] * Fix duplicate. [Delta-Sierra] * Merge. [Delta-Sierra] * Merge pull request #695 from Mathieu4141/scarab-threat-actor. [Alexandre Dulaunoy] Add threat actor group Scarab * Add threat actor group Scarab. [Mathieu Beligon] * Update threat actors meta. [Delta-Sierra] * Update threat actors meta. [Delta-Sierra] * Merge pull request #687 from Badis-dev/main. [Alexandre Dulaunoy] Add galaxy and cluster cancer * Add galaxy and cluster cancer. [Badis-dev] * Add cancer.json. [Badis-dev] * Delete cancer.json. [Badis-dev] * Add cancer cluster. [Badis-dev] * Add cancer galaxy. [Badis-dev] * Adding threat actor group LAPSUS$ / DEV-0537. [Daniel Plohmann] * Merge pull request #692 from botlabsDev/patch-1. [Alexandre Dulaunoy] Added some Ransomware and Botnet names * Add Rook Ransomware, Pandora Ranomsware, Astro Locker, Mount Locker, Ripprbot, Abcbot Cyclops Blink and Elknot. [botlabsDev] ## v2.4.156 (2022-03-18) ### Other * Merge pull request #688 from botlabsDev/patch-0. [Alexandre Dulaunoy] Add tool 'BadPotato' to clusters/tool.json * Add tool 'BadPotato' to clusters/tool.json. [botlabsDev] * Merge pull request #691 from r0ny123/indian-adversaries. [Alexandre Dulaunoy] Update to Indian Adversaries * [threat-actor] merging viceroy tiger and donot team & adding SectorE02 as an alias of Donot team. [Rony] * Merge pull request #690 from r0ny123/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Fix. [Rony] * Update threat-actor.json. [Rony] * Merge pull request #686 from Delta-Sierra/main. [Alexandre Dulaunoy] update threat actors meta * Fix array. [Delta-Sierra] * Merge. [Delta-Sierra] * Merge pull request #685 from danielplohmann/patch-14. [Alexandre Dulaunoy] adding threat actor "Moses Staff" * Fixed with linted JSON. [Daniel Plohmann] * Adding threat actor "Moses Staff" [Daniel Plohmann] * Merge pull request #684 from Mathieu4141/actors-targeting-ukraine. [Alexandre Dulaunoy] Actors targeting ukraine * Version bump -> 213. [Mathieu Beligon] * Update Gamaredon target. [Mathieu Beligon] * Update GhostWriter. [Mathieu Beligon] * Update threat actors meta. [Delta-Sierra] ## v2.4.154 (2022-03-02) ### Other * Merge pull request #683 from Delta-Sierra/main. [Alexandre Dulaunoy] add TA2541 * Merge https://github.com/MISP/misp-galaxy into main. [Delta-Sierra] * Merge pull request #682 from danielplohmann/patch-13. [Alexandre Dulaunoy] adding ACTINIUM as MSFT name for Gamaredon * Another Gamaredon ref and version bump. [Daniel Plohmann] * Adding ACTINIUM as MSFT name for Gamaredon. [Daniel Plohmann] * Merge pull request #681 from Delta-Sierra/main. [Alexandre Dulaunoy] add DDG botnet and more * Jq. [Delta-Sierra] * Add TA2541. [Delta-Sierra] * Fix duplicate. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy into main. [Delta-Sierra] * Merge pull request #680 from richardweiss80/antlion. [Alexandre Dulaunoy] added antlion APT group * Added antlion APT group. [rwe] * Add DDG botnet and more. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy into main. [Delta-Sierra] * Merge. [Delta-Sierra] * Add Milan Rat, Shark tool and Lyceum synonyms. [Delta-Sierra] * Add Lyceum synonyms/sources. [Delta-Sierra] ## v2.4.153 (2022-02-04) ### New * [surveillance] Cytrox added. [Alexandre Dulaunoy] * [doc] screenshot added with galaxy 2.0 in MISP. [Alexandre Dulaunoy] * [tools] Generate markdown index. [Alexandre Dulaunoy] ### Changes * [ransomware] set encryption only. [Alexandre Dulaunoy] * [tools] updated for the new website. [Alexandre Dulaunoy] * [threat-actor] Add SideCopy. [Sami Tainio] * [doc] add new screenshot of MISP galaxy 2.0. [Alexandre Dulaunoy] * [doc] README clean-up - list automatically generated. [Alexandre Dulaunoy] * [tools] add a reference to the relationship graph. [Alexandre Dulaunoy] ### Fix * [ransomware] array end missing. [Alexandre Dulaunoy] * [tools] Generate index Markdown layout updated. [Alexandre Dulaunoy] ### Other * Merge branch 'digihash-patch-1' into main. [Alexandre Dulaunoy] * Forgot comma between JSON entries. [Kevin Holvoet] * Update ransomware.json with URL fix. [Kevin Holvoet] Fixed URL for AlphaLocker * Update ransomware.json: add BlackCat (ALPHV) [Kevin Holvoet] * Merge pull request #678 from danielplohmann/patch-12. [Alexandre Dulaunoy] adding Gamaredon alias Shuckworm used by Symantec * Updated URLs for Gamaredon with Shuckworm alias reference. [Daniel Plohmann] * Adding Gamaredon alias Shuckworm used by Symantec. [Daniel Plohmann] * Merge pull request #677 from jloehel/whispergate. [Alexandre Dulaunoy] Adds WhisperGate * Adds WhisperGate. [Jürgen Löhel] * Merge pull request #676 from jloehel/upaskit. [Alexandre Dulaunoy] Adds UPAS-Kit * Adds UPAS-Kit. [Jürgen Löhel] * Merge pull request #675 from nyx0/main. [Alexandre Dulaunoy] Add Motnug tool. * Add AQUATIC PANDA threat actor. [Thomas Dupuy] * Add Motnug tool. [Thomas Dupuy] * Merge pull request #674 from jloehel/ragnatela. [Alexandre Dulaunoy] Adds Ragnatela RAT * Adds Ragnatela RAT. [Jürgen Löhel] * Merge pull request #673 from samitainio/main. [Alexandre Dulaunoy] chg: [threat-actor] Add SideCopy * Merge pull request #672 from danielplohmann/patch-11. [Alexandre Dulaunoy] adding Mandiant's FIN13. * Adding Mandiant's FIN13. [Daniel Plohmann] ## v2.4.152 (2021-12-22) ### New * [CMTMF] fix the galaxy definition. [Alexandre Dulaunoy] ### Changes * Use pytest instead of nose. [Raphaël Vinot] * [concordia] CMTMF killchain typo fixed. [Alexandre Dulaunoy] * [concordia] fix name inconsistencies. [Alexandre Dulaunoy] * [concordia] set a mobile icon. [Alexandre Dulaunoy] * [concordia] duplicate removed. [Alexandre Dulaunoy] * [concordia] duplicate removed. [Alexandre Dulaunoy] * [concordia] duplicate techniques removed. [Alexandre Dulaunoy] * [concordia] typo fixed. [Alexandre Dulaunoy] * [misp-galaxy] duplicate modify trusted environment and also different technique ID? [Alexandre Dulaunoy] * [concordia] duplicates removed. [Alexandre Dulaunoy] * [cmtmf-attack-pattern] update. [Alexandre Dulaunoy] * [cmtmf-attack-pattern] various fixes to make JSON ok. [Alexandre Dulaunoy] ### Fix * Cmtmf-attack-pattern had multiple duplicate UUIDs. [Raphaël Vinot] ### Other * Merge pull request #671 from MISP/BennSaturn-concordia_mtmf. [Alexandre Dulaunoy] Benn saturn concordia mtmf * Merge branch 'concordia_mtmf' of https://github.com/BennSaturn/misp-galaxy into BennSaturn-concordia_mtmf. [Alexandre Dulaunoy] * Update cmtmf-attack-pattern.json. [Bernardo Santos] - update version * Update cmtmf-attack-pattern.json. [Bernardo Santos] - Changes to cluster type - Fix typo for privilege escalation tactic * CONCORDIA MTMF - Initial version. [Bernardo Santos] Initial version of the CONCORDIA Mobile Threat Modelling Framework for the CONCORDIA Project: https://www.concordia-h2020.eu/ * CONCORDIA MTMF - Initial version. [Bernardo Santos] Initial version of the CONCORDIA Mobile Threat Modelling Framework for the CONCORDIA Project: https://www.concordia-h2020.eu/ * Merge pull request #670 from jloehel/darkwatchman. [Alexandre Dulaunoy] Adds DarkWatchman RAT * Adds DarkWatchman RAT. [Jürgen Löhel] * Merge pull request #669 from Delta-Sierra/main. [Alexandre Dulaunoy] add ESPecter Bootkit * Add ESPecter Bootkit. [Delta-Sierra] * Add ESPecter bootkit. [Delta-Sierra] ## v2.4.151 (2021-11-19) ### Changes * [att&ck] update to ATT&CK v10. [Christophe Vandeplas] * [malpedia] remove duplicate. [Alexandre Dulaunoy] * [malpedia] duplicates removed. [Alexandre Dulaunoy] * [malpedia] updated. [Alexandre Dulaunoy] * [threat-actor] add origin country to UNC2452 & HAFNIUM. [Rony] addressed https://github.com/MISP/misp-galaxy/pull/660#issuecomment-884475015 ### Fix * [malpedia] remove duplicate urls. [Alexandre Dulaunoy] ### Other * Merge branch 'marjatech-main' into main. [Alexandre Dulaunoy] * Update malpedia. [marjatech] * Merge pull request #666 from Wachizungu/add-common-raven. [Alexandre Dulaunoy] Add threat actor common raven * Add threat actor common raven. [Jeroen Pinoy] * Merge pull request #665 from thomaspatzke/main. [Alexandre Dulaunoy] Added O365 techniques * Added O365 techniques. [Thomas Patzke] Source: https://www.inversecos.com/2021/09/office365-attacks-bypassing-mfa.html * Merge pull request #664 from nyx0/main. [Alexandre Dulaunoy] Adding TA and Tool * Add BLUELIGHT tool. [Thomas Dupuy] * Add InkySquid synonym. [Thomas Dupuy] * Merge pull request #663 from danielplohmann/patch-10. [Alexandre Dulaunoy] fixed typo in actor name (CLOCKWORD -> CLOCKWORK SPIDER) * Fixed typo in actor name (CLOCKWORD -> CLOCKWORK SPIDER) [Daniel Plohmann] * Merge pull request #662 from r0ny123/patch-1. [Alexandre Dulaunoy] Add origin country to UNC2452 & HAFNIUM ## v2.4.147 (2021-07-27) ### Other * Merge pull request #660 from r0ny123/patch-1. [Alexandre Dulaunoy] References for APT40, APT31 & HAFNIUM * Update threat-actor.json. [Rony] * Another fix. [Rony] * Fix. [Rony] * Multiple updates to apt40, apt31 & hafnium. [Rony] * From Gov Canada & MFA Japan. [Rony] * Adding references for APT40 & APT31. [Rony] * Merge pull request #658 from jasperla/oilrig. [Alexandre Dulaunoy] merge APT34 with OilRig * Merge APT34 with OilRig. [Jasper Lievisse Adriaanse] OilRig already has "APT 34" and "APT34" as synonyms. Additionally MITRE has since combined them due to overlap in activity: https://attack.mitre.org/groups/G0049/ * Merge pull request #659 from Delta-Sierra/master. [Alexandre Dulaunoy] Add NOBELIUM and related * Merge branch 'main' into master. [Deborah Servili] * Add NOBELIUM and related. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Remove more duplicates. [Delta-Sierra] * Version fix. [Delta-Sierra] ## v2.4.145 (2021-06-28) ### Other * Merge pull request #657 from jloehel/add_matanbuchus. [Alexandre Dulaunoy] [cluster][tool] Adds Matanbuchus * [cluster][tool] Adds Matanbuchus. [Jürgen Löhel] + threat actor: BelialDemon * Merge pull request #656 from jloehel/add_hackboss. [Alexandre Dulaunoy] [cluster][stealer] Adds HackBoss * [cluster][stealer] Adds HackBoss. [Jürgen Löhel] * Merge pull request #654 from nyx0/main. [Alexandre Dulaunoy] Added BackdoorDiplomacy and Gelsemium. * Added BackdoorDiplomacy and Gelsemium. [Thomas Dupuy] ## v2.4.144 (2021-06-07) ### Changes * [threat-actor] added cybercrime threat group profiles from Crowdstrike & Secureworks. [Rony] ### Other * Merge pull request #653 from r0ny123/cybercrime. [Alexandre Dulaunoy] Adding CyberCrime actor profiles from Crowdstrike & Secureworks * More ta544 references. [Rony] * Merge pull request #652 from danielplohmann/patch-9. [Alexandre Dulaunoy] adding Twisted Spider as alias for TA2101 (Maze) * Twisted Spider -> TWISTED SPIDER. [Daniel Plohmann] fair point * Adding Twisted Spider as alias for TA2101 (Maze) [Daniel Plohmann] * Merge pull request #650 from Still34/patches/alias-tick-1. [Alexandre Dulaunoy] Add alias for Tick * Add Nian alias. [Still Hsu] * Merge pull request #649 from Still34/patches/country-blacktech-1. [Alexandre Dulaunoy] Add country origin for BlackTech * Add country origin for BlackTech. [Still Hsu] * Merge pull request #648 from danielplohmann/patch-8. [Andras Iklody] fixing broken/dead links * Fixing broken/dead links. [Daniel Plohmann] ## v2.4.143 (2021-05-14) ### New * [ransomware] Ragnarok added. [Alexandre Dulaunoy] ### Changes * [ransomware] COLT (Compromise to Leak Time) added on Darkside and Pysa. [Alexandre Dulaunoy] "COLT – Compromise to Leak Time" - new meta colt-median/colt-average. For reference: https://vulnerability.ch/2021/05/colt-compromise-to-leak-time/ * [att&ck] bump to latest ATT&CK version from MITRE. [Christophe Vandeplas] ### Fix * [ransomware] Related key should be outside metas. [mokaddem] ### Other * Merge pull request #646 from r0ny123/update. [Alexandre Dulaunoy] Updates to APT27 & Tick * Merge branch 'update' of https://github.com/r0ny123/misp-galaxy into update. [Rony] * FlatChestWare duplicate removed. [Rony] * FlatChestWare duplicate removed. [Rony] * Merged STALKER PANDA to Tick. [Rony] * Several updates to apt27. [Rony] ## v2.4.142 (2021-04-26) ### New * [att&ck] support for subtechniques. [Christophe Vandeplas] * [dev] fix empty strings, lists. [VVX7] * [dev] add ASPI's China Defence University Tracker. [VVX7] Thanks to Cormac Doherty for writing the web scraper! To update the galaxy run the included gen_defence_university.py script. "The China Defence Universities Tracker is a database of Chinese institutions engaged in military or security-related science and technology research. It was created by ASPI’s International Cyber Policy Centre. It includes entries on nearly 100 civilian universities, 50 People’s Liberation Army institutions, China’s nuclear weapons program, three Ministry of State Security institutions, four Ministry of Public Security universities, and 12 state-owned defence industry conglomerates. The Tracker is a tool to inform universities, governments and scholars as they engage with the entities from the People’s Republic of China. It aims to build understanding of the expansion of military-civil fusion—the Chinese government’s policy of integrating military and civilian efforts—into the education sector. The Tracker should be used to inform due diligence of Chinese institutions. However, the fact that an institution is not included here does not indicate that it should not raise risks or is not involved in defence research. Similarly, entries in the database may not reflect the full range and nature of an institution’s defence and security links." - ASPI (https://unitracker.aspi.org.au/about/) * Added Bhadra framework for mobile attacks. [iglocska] - based on the paper published here: https://arxiv.org/pdf/2005.05110.pdf - thanks to the ATT&CK EU community conference speakers highlighting this framework! * [country] galaxy added. [iglocska] * [galaxy] AMITT (Adversarial Misinformation and Influence Tactics and Techniques) framework for describing disinformation incidents. AMITT is part of misinfosec - work on adapting information security practices to help track and counter misinformation - and is designed as far as possible to fit existing infosec practices and tools. [VVX7] * Added draft of the election guildelines galaxy. [mokaddem] * Add entries from Bambenek Consulting. [Raphaël Vinot] ### Changes * [ransomware] duplicate removed. [Alexandre Dulaunoy] * [ransomware] duplicate removed. [Alexandre Dulaunoy] * [ransomware] duplicates removed. [Alexandre Dulaunoy] * [ransomware] Flyper removed. [Alexandre Dulaunoy] * [ransomware] first duplicate removed. [Alexandre Dulaunoy] * [ransomware] remove duplicate "File-Locker" [Alexandre Dulaunoy] * [malpedia] jq all the file and removed ref duplicates. [Alexandre Dulaunoy] * [clusters] fixing broken UUID fix #628. [Alexandre Dulaunoy] * [ransomware] fix the broken UUID fix #628. [Alexandre Dulaunoy] * [microsoft activity group] HAFNIUM added. [Alexandre Dulaunoy] * [tool] SUNSPOT added. [Alexandre Dulaunoy] * [rsit] rsit as galaxy name. [Alexandre Dulaunoy] * [threat-actor] UNC2452/DarkHalo added - ref. #614. [Alexandre Dulaunoy] * [ransomware] Babuk Ransomware added. [Alexandre Dulaunoy] * [ransomware] RegretLocker added. [Alexandre Dulaunoy] * Fix gh actions. [Raphaël Vinot] * Add PR to GH actions. [Raphaël Vinot] * [doc] Travis is dead, GH Action is alive. [Alexandre Dulaunoy] * [att&ck] update to latest MITRE ATT&CK version. [Christophe Vandeplas] * [cryptominer] updated. [Alexandre Dulaunoy] * [rename] tea matrix. [Alexandre Dulaunoy] * [tea] matrix updated to include brewing time and the milk attack technique. [Alexandre Dulaunoy] * [tea] first version. [Alexandre Dulaunoy] * [att&ck] no tag for subtechnique. [Christophe Vandeplas] * [botnet] Katura mess added. [Alexandre Dulaunoy] * [galaxy] fix the name to China Defence Universities Tracker. [Alexandre Dulaunoy] * [dev] jq. [VVX7] * [dev] gen_defence_university.py no longer outputs empty strings, lists. [VVX7] * [threat-actor] remove duplicate references. [Alexandre Dulaunoy] * [threat-actor] fix #561 by using new meta to classify as a campaign only. [Alexandre Dulaunoy] Based on https://github.com/MISP/misp-galaxy/issues/469 There is an old and persistence issue in attribution world and basically no-one really agrees on this. So we decided to start a specific metadata `threat-actor-classification` on the threat-actor to define the various types per cluster entry: - _operation_: - _A military operation is the coordinated military actions of a state, or a non-state actor, in response to a developing situation. These actions are designed as a military plan to resolve the situation in the state or actor's favor. Operations may be of a combat or non-combat nature and may be referred to by a code name for the purpose of national security. Military operations are often known for their more generally accepted common usage names than their actual operational objectives._ from Wikipedia - **In the context of MISP threat-actor name, it's a single specific operation.** - _campaign_: - _The term military campaign applies to large scale, long duration, significant military strategy plans incorporating a series of inter-related military operations or battles forming a distinct part of a larger conflict often called a war. The term derives from the plain of Campania, a place of annual wartime operations by the armies of the Roman Republic._ from Wikipedia - **In the context of MISP threat-actor-name, it's long-term activity which might be composed of one or more operations.** - threat-actor - **In the context of MISP threat-actor-name, it's an agreed name by a set of organisations.** - activity group - **In the context of MISP threat-actor-name, it's a group defined by its set of common techniques or activities.** - unknown - **In the context of MISP threat-actor-name, it's still not clear if it's an operation, campaign, threat-actor or activity group** The meta field is an array to allow specific cluster of threat-actor to show the current disagreement between different organisations about the type (threat actor, activity group, campaign and operation). * Bump travis. [Raphaël Vinot] * [jq] all the things. [Alexandre Dulaunoy] * [preventive-measure] packet filtering added. [Alexandre Dulaunoy] * [threat-actor] remove the non-unique elements. [Alexandre Dulaunoy] * [ta] fix the JSON. [Alexandre Dulaunoy] * [jq] JSON fixed. [Alexandre Dulaunoy] * [json] add missing comma. [Alexandre Dulaunoy] * [country] jq all. [Alexandre Dulaunoy] * [malpedia] fixes. [Alexandre Dulaunoy] * [threat-actor] JSON fixed. [Alexandre Dulaunoy] * [travis] pip3. [Alexandre Dulaunoy] * [ransomware] Nodera ransomware added. [Alexandre Dulaunoy] * [threat-actor] typo fixed. [Alexandre Dulaunoy] * [threat-actor] format fixed. [Alexandre Dulaunoy] * [threat-actor] fix order. [Alexandre Dulaunoy] * [threat-actor] Budminer APT added based on document from "Soesanto, Stefan" [Alexandre Dulaunoy] * [threat-actor] SideWinder APT group added. [Alexandre Dulaunoy] * [threat-actor] jq. [Alexandre Dulaunoy] * [dark-pattern] namespace: misp. [Jean-Louis Huynen] * [ransomware] jq ;-) [Alexandre Dulaunoy] * [clean-up] jq all the things. [Alexandre Dulaunoy] * [threat-actor] Lucky Mouse synonym added. [Alexandre Dulaunoy] * [threat-actor] Calypso group added. [Alexandre Dulaunoy] Ref: https://www.ptsecurity.com/upload/corporate/ru-ru/analytics/calypso-apt-2019-rus.pdf MISP UUID: 5ca4718b-7f38-4822-83b7-0a1a0a00b412 * [threat-actor] threat-actor-classification updated. [Alexandre Dulaunoy] * [threat-actor] jq is jq. [Alexandre Dulaunoy] * [threat-actor] Operation WizardOpium added. [Alexandre Dulaunoy] ref: https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/ * [attack] update to latest ATT&CK data. [Christophe Vandeplas] * [attck4fraud] jq all the things. [Alexandre Dulaunoy] * [attck4fraud] updates based on issue #466. [Alexandre Dulaunoy] * [galaxy] added AMITT galaxy/cluster generator script. [VVX7] * [galaxy] version number to int. [VVX7] * [misp-galaxy] jq all the things. [Alexandre Dulaunoy] * [tool] COMPfun - Reductor added. [Alexandre Dulaunoy] * [threat-actor] new LookBack (Malware?Campaign?TA?) [Alexandre Dulaunoy] * [threat-actor] Evil Eye and POISON CARP. [Alexandre Dulaunoy] * [threat-actor] add machete-apt synonyms as reported in #445. [Alexandre Dulaunoy] * [threat-actor] jq all. [Alexandre Dulaunoy] * [threat-actor] LYCEUM added - 443 #fixed. [Alexandre Dulaunoy] * [threat-actor] rollback as discussed by chat with Andras until version 2.0. [Alexandre Dulaunoy] * [att&ck] July ATT&CK release included in MISP galaxy. [Alexandre Dulaunoy] * [threat-actor] version updated. [Alexandre Dulaunoy] * [threat-actor] duplicated refs removed. [Alexandre Dulaunoy] * [threat-actor] synonyms fixed. [Alexandre Dulaunoy] * [threat-actor] jq everything. [Alexandre Dulaunoy] * [branded_vulnerability] version updated. [Alexandre Dulaunoy] * Add PyMISPGalaxies test. [Raphaël Vinot] * [attack-pattern] Sync kill-chain with data from MITRE. [mokaddem] * [o365-exchange-techniques] Actions on Intent added (finalized) [Alexandre Dulaunoy] * [o365-exchange-techniques] Expansion added (WiP) [Alexandre Dulaunoy] * [o365-exchange-techniques] Persistence kill-chain added (WiP) [Alexandre Dulaunoy] * [o365-exchange-techniques] Compromise row added (WiP) [Alexandre Dulaunoy] * [o365-exchange-techniques] [WiP] based on John Lambert matrix techniques. [Alexandre Dulaunoy] * [malpedia] duplicates fixed. [Alexandre Dulaunoy] * [malpedia] jq all the things. [Alexandre Dulaunoy] * [malpedia] updated to the latest version. [Rintaro KOIKE] * [threat-actor] FIN4 updates. [Alexandre Dulaunoy] * [ATT&CK] updated to the latest version. [Alexandre Dulaunoy] * [exploit-kit] jq all the things. [Alexandre Dulaunoy] * [tool] Cowboy and KimJongRAT (Sorry Paul, we forgot ;-) [Alexandre Dulaunoy] ref: https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/ * [tool] jq all the things. [Alexandre Dulaunoy] * [tool] Karkoff tool added. [Alexandre Dulaunoy] * [ransomware] various fixes. [Alexandre Dulaunoy] * [ransomware] jq all the things(tm) [Alexandre Dulaunoy] * [ransomware] fix the meta to payment-method. [Alexandre Dulaunoy] * [mitre att&ck] updated with new version. [Alexandre Dulaunoy] * [threat-actor] change attribution confidence to be a string by default. [Alexandre Dulaunoy] * [tools] fix the attribution confidence level. [Alexandre Dulaunoy] * [attck4fraud] updated. [Alexandre Dulaunoy] * [attck4fraud] completed. [Alexandre Dulaunoy] * [attck4fraud] Assets Transfer added. [Alexandre Dulaunoy] * [attck4fraud] Obtain Fraudulent Assets added. [Alexandre Dulaunoy] * [attck4fraud] Perform fraud added. [Alexandre Dulaunoy] * [attck4fraud] Target compromise updated. [Alexandre Dulaunoy] * [attck4fraud] more techniques. [Alexandre Dulaunoy] * [threat-actor] BRONZE UNION is also uppercase. [Alexandre Dulaunoy] * [threat-actor] updated the version to avoid the past issue with 0 value for integer values. [Alexandre Dulaunoy] * [sector] typo fixed - reported in #364. [Alexandre Dulaunoy] * [attck4fraud] fix the type issue. [Alexandre Dulaunoy] * [attck4fraud] uuid fixed. [Alexandre Dulaunoy] * [attck4fraud] ATM Shimming added. [Alexandre Dulaunoy] * [attck4fraud] description fixed for FT1003. [Alexandre Dulaunoy] * [threat-actor] SandCat added. [Alexandre Dulaunoy] * [threat-actor] new attribution-confidence level introduced. [Alexandre Dulaunoy] * [threat-actor] jq all the things. [Alexandre Dulaunoy] * [threat-actor] IRIDIUM added. [Alexandre Dulaunoy] * [tools] jq all the things. [Alexandre Dulaunoy] * [tool] SLUB Backdoor added. [Alexandre Dulaunoy] * [tool] Xbash description updated. [Alexandre Dulaunoy] * [threat-actor] format fixed. [Alexandre Dulaunoy] * [threat-actor] jq all the things late in the night. [Alexandre Dulaunoy] * [threat-actor] uuid fixed. [Alexandre Dulaunoy] * [tool] BabyShark added. [Alexandre Dulaunoy] * [threat-actor] STOLEN PENCIL added. [Alexandre Dulaunoy] * [cert-eu-govsector] version fixed. [Alexandre Dulaunoy] * [threat-actor] version fixed. [Alexandre Dulaunoy] * [ransomware] no related object in meta. [Alexandre Dulaunoy] * [mitre-attack-pattern] jq. [Alexandre Dulaunoy] * [mitre-attack-pattern] bumped version number. [mokaddem] * [mitre-attack-pattern] Added kill_chain_order. [mokaddem] * [election-guidelines] sorting is important ;-) [Alexandre Dulaunoy] * [schema] optional kill_chain_order field added. [Alexandre Dulaunoy] * [election-guidelines] jq. [Alexandre Dulaunoy] * [mitre] Deprecated pre/enterprise/mobile separate galaxies. [Christophe Vandeplas] * [tool] jq jq jq jq jq jq jq jq. [Alexandre Dulaunoy] * [doc] new year copyright fun. [Alexandre Dulaunoy] * [mitre] bump to latest MITRE ATT&CK dataset. [Christophe Vandeplas] * [mitre] re-generated galaxies and values using the MITRE sources. [Christophe Vandeplas] and also using the MISP version to keep manually created relationships and such * [malpedia] updated to the latest version. [Alexandre Dulaunoy] * [licensing] 2-clause BSD added in addition to CC0. [Alexandre Dulaunoy] To remove ambiguity of licensing and allowing users to select the license they would like to use CC0 or 2-clause BSD. Related to: https://github.com/MISP/misp-taxonomies/issues/126 * [doc] move how to contribute to the CONTRIBUTE file. [Alexandre Dulaunoy] * [doc] Added some dependency pointers. [Steve Clement] * Uuid fixed. [Alexandre Dulaunoy] * [threat-actor] INDRIK SPIDER added. [Alexandre Dulaunoy] * [ransomware] duplicate removed. [Alexandre Dulaunoy] * Further categorization of galaxies. [Christophe Vandeplas] * Categorization of galaxies. [Christophe Vandeplas] This allows relationships to be created. * Removal of older unused relationships. [Christophe Vandeplas] * MITRE relationships included in the respective cluster. [Christophe Vandeplas] * Mappings are now in the generated adoc. [Christophe Vandeplas] plus massive performance improvement * Magical mapping with malpedia. [Christophe Vandeplas] * [malpedia] duplicate urls removed. [Alexandre Dulaunoy] * [tool] NOKKI added. [Alexandre Dulaunoy] ref: https://researchcenter.paloaltonetworks.com/2018/09/unit42-new-konni-malware-attacking-eurasia-southeast-asia/ * [botnet] Torii added. [Alexandre Dulaunoy] * [threat-actor] Iron Group added. [Alexandre Dulaunoy] ref: https://www.intezer.com/iron-cybercrime-group-under-the-scope-2/ * [tool] Xbash added. [Alexandre Dulaunoy] ref: https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/ * [tool] biscuit biscvt tool BISKVIT. [Alexandre Dulaunoy] ref: https://www.fortinet.com/blog/threat-research/russian-army-exhibition-decoy-leads-to-new-biskvit-malware.html * [threat-actor] APT-C-35 actor added. [Alexandre Dulaunoy] ref: https://ti.360.net/blog/articles/latest-activity-of-apt-c-35/ * [mapping] Generated automatic mapping between clusters. [Christophe Vandeplas] * [tool] KEYMARBLE malware added. [Alexandre Dulaunoy] ref: https://www.us-cert.gov/ncas/analysis-reports/AR18-221A * [threat-actor] jq document. [Alexandre Dulaunoy] * [schema clusters] fix the JSON indentation. [Alexandre Dulaunoy] * [threat-actor] The Gordon Group added. [Alexandre Dulaunoy] ref: https://researchcenter.paloaltonetworks.com/2018/08/unit42-gorgon-group-slithering-nation-state-cybercrime/ * [rat] Hallaj PRO Rat added. [Alexandre Dulaunoy] ref: https://securelist.com/attacks-on-industrial-enterprises-using-rms-and-teamviewer/87104/ misp-event: 5b63f5e4-bf24-4f46-8340-48fc02de0b81 * [threat-actor] leafminer - RASPITE added. [Alexandre Dulaunoy] * [tool] added based on Carbanak tooling description from Crowdstrike. [Alexandre Dulaunoy] ref: https://www.crowdstrike.com/blog/arrests-put-new-focus-on-carbon-spider-adversary-group/ * [threat-actor] new reference to CARBON SPIDER/Carbanak. [Alexandre Dulaunoy] * [tool] Bisonal malware added (new variant with encryption capabilities) [Alexandre Dulaunoy] * [threat-actor] The Big Bang campaign/group added. [Alexandre Dulaunoy] * [botnet] Xor DDoS added. [Alexandre Dulaunoy] * RANCOR group added. [Alexandre Dulaunoy] * Stalker Panda description added. [Alexandre Dulaunoy] * Old MITRE ATT&CK (2017) is moving to deprecated namespace. [Alexandre Dulaunoy] * Namespace mitre-attack added for version 2 of the MITRE ATT&CK after 2018. [Alexandre Dulaunoy] * [misp-galaxy] namespace misp added. [Alexandre Dulaunoy] ### Fix * Cryptominers type. [Jakub Onderka] * Rename "Innitial Access" to "Initial Access" [Thijsvanede] Renamed mitre-ics-tactics "Innitial Access" to "Initial Access". Original was a minor spelling mistake. The fixed naming corresponds to the original ATT&CK framework description https://collaborate.mitre.org/attackics/index.php/Initial_Access * Reorganize GH actions. [Raphaël Vinot] * Sort keys, fix tests. [Raphaël Vinot] * Remove comma. [Thomas Dupuy] * Name of SoD Matrix cluster to match galaxy. [Raphaël Vinot] Fix #566 * Small fixes to the bhadra framework. [iglocska] * JQ all the things. [Raphaël Vinot] * [attack] fixes old MITRE relationships not being removed. [Christophe Vandeplas] * [adoc] ignore deprecated galaxies. [Christophe Vandeplas] * [region] inconsistent type. [Christophe Vandeplas] * [misinfosec] fixes inconsistent filename. [Christophe Vandeplas] * [misinfosec] fixed kill_chain fields. [mokaddem] * Make tests happy. [Raphaël Vinot] * O365-exchange-techniques (duplicate values, duplicate UUIDs) [Raphaël Vinot] * UUID issues. [Raphaël Vinot] * Duplicate values, typos. [Raphaël Vinot] * Make validate all happy. [Raphaël Vinot] * Wrong (duplicate) value. [Raphaël Vinot] * [tool] MITRE conversion script. [Christophe Vandeplas] * [ransomware] more duplicates removed. [Alexandre Dulaunoy] * [ransomware] removed duplicate values. [Alexandre Dulaunoy] * [ransomware] duplicate removed. [Alexandre Dulaunoy] * [graph.py] small fix to make it work. [Alexandre Dulaunoy] * [malpedia] version. [Alexandre Dulaunoy] * [malpedia] broken reference has been fixed. [Alexandre Dulaunoy] * Add missing relations from commit 78c1f073590c4ae1822c8508f62934ffb215fab2. [Christophe Vandeplas] * Add missing relations from commit b857be9cabb02fb24aa5ef7db8e0c209a630189b. [Christophe Vandeplas] * Add missing relations from commit a81bbe288f91298fad0028e0f3c940c41c8d27fa. [Christophe Vandeplas] * Add missing relations from commit 29beb01dc3ed0067db6ccc33f41456147d38d2d7. [Christophe Vandeplas] * Intrusion is an actor and not a tool. [Christophe Vandeplas] * Jq all the things. [Christophe Vandeplas] * Minor newline difference after jq_all_the. [Christophe Vandeplas] * Automatically fix missing uuids. [Christophe Vandeplas] * Array in synonyms (MISP accepts it but not the schema ;-) [Alexandre Dulaunoy] * [threat-actor] added missing uuids. [Christophe Vandeplas] * [threat-actor] related is an array of JSON objects. [Alexandre Dulaunoy] * [JSON schema] related element is an array of JSON objects. [Alexandre Dulaunoy] * Jq all the things(tm) [Alexandre Dulaunoy] * [threat-actor] synonyms are always arraus. [Alexandre Dulaunoy] * Cleanup the link generation based on type instead of title (Thanks to Juan Rocha for the report) [Alexandre Dulaunoy] * Duplicate ELECTRUM entry. [Raphaël Vinot] Fix #212 * Duplicate UUID in tools. [Raphaël Vinot] * JSON format. [Alexandre Dulaunoy] * PureMasuta added to Masuta. [Alexandre Dulaunoy] * Typo in meta field. [Alexandre Dulaunoy] * Updated description to clearly states that only branded vulnerabilities. [Alexandre Dulaunoy] * Dedication page (CEF) and update overall structure of the document generated. [Alexandre Dulaunoy] * BARIUM and LEAD added. [Alexandre Dulaunoy] * Preventive measures added. [Alexandre Dulaunoy] * Naming normalisation. [Iglocska] ### Other * Merge pull request #647 from Delta-Sierra/master. [Alexandre Dulaunoy] Remove duplicate * Fix duplicates and add relations. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #645 from Delta-Sierra/master. [Alexandre Dulaunoy] Adding ransomware names [WIP 2/3] * Merge pull request #644 from danielplohmann/patch-7. [Alexandre Dulaunoy] adding Yanbian Gang as threat actor * Adding Yanbian Gang as threat actor. [Daniel Plohmann] * Merge pull request #643 from Delta-Sierra/master. [Alexandre Dulaunoy] Adding ransomware names[WIP] * Removing duplicate. [Delta-Sierra] * Removing unexpected line. [Delta-Sierra] * Adding ransomware names [WIP 3] [Delta-Sierra] * Adding ransomware names [WIP 2] [Delta-Sierra] * Fix version. [Delta-Sierra] * Adding ransomwares WIP. [Delta-Sierra] * Merge pull request #642 from danielplohmann/patch-6. [Alexandre Dulaunoy] Symantec uses Palmerworm as alias for BlackTech * Symantec uses Palmerworm as alias for BlackTech. [Daniel Plohmann] Adding Palmerworm as Symantec alias for BlackTech (with reference). * Merge pull request #641 from nyx0/main. [Alexandre Dulaunoy] Add Ghostwriter. * Add Ghostwriter. [Thomas Dupuy] * Merge pull request #639 from r0ny123/patch-1. [Alexandre Dulaunoy] remove turbine panda synonyms from hafnium * Reverted changes made into 52ae97718d520ad800cc2fa8631e44cfbf44dab5. [Rony] * Merge pull request #638 from sebdraven/main. [Alexandre Dulaunoy] add Turbinia Panda to Haffnium * Validation jsons. [sebdraven] * Update threat-actor.json. [Sebdraven] add a synonym to Haffnium * Merge pull request #637 from sebdraven/main. [Alexandre Dulaunoy] Add RedEcho Threat Actor * Validation ok. [sebdraven] * Update threat-actor.json. [Sebdraven] format json * Update threat-actor.json. [Sebdraven] add redecho threat actor * Merge pull request #2 from MISP/main. [sebdraven] Sync Forks * Merge pull request #636 from JakubOnderka/cryptominers-type. [Alexandre Dulaunoy] fix: Cryptominers type * Merge branch 'marjatech-main' into main. [Alexandre Dulaunoy] * Update to latest Ref: https://malpedia.caad.fkie.fraunhofer.de/api/get/misp. [Jakob M] * Merge pull request #634 from Delta-Sierra/master. [Alexandre Dulaunoy] Serveral updates and additions * Fix progress. [Delta-Sierra] * Fix merge & jq. [Delta-Sierra] * Merge. [Delta-Sierra] * Merge pull request #633 from r0ny123/patch-1. [Alexandre Dulaunoy] add more HAFNIUM references * From Nextron. [Rony] * More! [Rony] * More references. [Rony] From Crowdstrike MSRC and kql hunting query from James Quinn * Add HAFNIUM detection refs. [Rony] * Fix. [Rony] * Add more HAFNIUM references. [Rony] * Merge pull request #632 from r0ny123/patch-1. [Alexandre Dulaunoy] Adding alias NOBELIUM * Adding alias NOBELIUM. [Rony] * Merge pull request #631 from r0ny123/Enhancement. [Alexandre Dulaunoy] Add HAFNIUM * Added HAFNIUM. [Rony] Updates: Tonto Team UNC2452 * Add relationships between Maze, Rgnar, Egregor and Sekhmet. [Delta-Sierra] * Add Sekhmet ransomware. [Delta-Sierra] * Add TeamTNT ref. [Delta-Sierra] * Add Ragnar Locker and update accordingly. [Delta-Sierra] * Add Covidloc and tycoon ransomware + small updates on some ransomwares. [Delta-Sierra] * Add TeamTNT. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Fix merge. [Delta-Sierra] * Update sidewinder threat actor. [Delta-Sierra] * Merge pull request #1 from MISP/main. [sebdraven] merge * Merge pull request #630 from sebdraven/main. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Sebdraven] update Sidewinder card * Merge pull request #629 from nyx0/main. [Alexandre Dulaunoy] Update Infy TA. * Update Infy TA. [Thomas Dupuy] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #627 from r0ny123/patch-2. [Alexandre Dulaunoy] removing DePrimon * Removing DePrimon. [Rony] DePrimon is not a TA, added malfamily (waiting for approval) to Malpedia to better reflect that. * Merge pull request #626 from nyx0/main. [Alexandre Dulaunoy] Add RDAT backdoor * Add RDAT backdoor. [Thomas Dupuy] * Merge pull request #625 from Thijsvanede/patch-1. [Alexandre Dulaunoy] * Merge pull request #624 from nyx0/main. [Alexandre Dulaunoy] Add Exaramel and P.A.S. webshell tool. * Remove empty values. [Thomas Dupuy] * Add Exaramel and P.A.S. webshell tool. [Thomas Dupuy] * Merge pull request #623 from nyx0/main. [Alexandre Dulaunoy] Add Caterpillar WebShell. * Add Caterpillar WebShell. [Thomas Dupuy] * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #622 from danielplohmann/patch-5. [Alexandre Dulaunoy] adding ClearSky alias for Volatile Cedar * Adding ClearSky alias for Volatile Cedar. [Daniel Plohmann] adding ClearSky report as source and alias to the VolatileCedar entry. As proof from the report: "We attributed the operation to Lebanese Cedar (also known as Volatile Cedar), mainly based on the code overlaps between the 2015 variants of Explosive RAT and Caterpillar WebShell, to the 2020 variants of these malicious files." * Merge pull request #621 from cudeso/main. [Alexandre Dulaunoy] RSIT Galaxy/Cluster * Move cfr-type-of-incident to meta. [Koen Van Impe] * RSIT Galaxy/Cluster. [Koen Van Impe] * Merge pull request #620 from StefanKelm/main. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Lazarus * Merge pull request #619 from nyx0/main. [Alexandre Dulaunoy] Update tool cluster * Add HyperBro in tools. [Thomas Dupuy] * Update ZxShell tool. [Thomas Dupuy] * Merge pull request #618 from StefanKelm/main. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Lazarus * Merge pull request #617 from danielplohmann/patch-4. [Alexandre Dulaunoy] merge COVELLITE into Lazarus Group * Merge COVELLITE into Lazarus Group. [Daniel Plohmann] I would propose to move COVELLITE as tracked by Dragos as an alias into Lazarus Group and merge the references. Dragos' own description states that it refers to the same group as "Lazarus" and "Hidden Cobra" in that infrastructure and tools are the same: https://www.dragos.com/threat-activity-groups/ - the entry in MISP's threat actor library also reflects that. * Merge pull request #616 from r0ny123/patch-2. [Alexandre Dulaunoy] removing Starcruft * Update threat-actor.json. [Rony] Don't know how StarCraft * Merge pull request #615 from danielplohmann/patch-3. [Alexandre Dulaunoy] merging ScarCruft->APT37 * Merging ScarCruft->APT37. [Daniel Plohmann] I would like to propose merging entry "ScarCruft" into "APT37". It really just seems like a redundancy, as both its aliases "Operation Daybreak" and "Operation Erebus" are already present for "APT37", along alias "StarCruft", which just seems to be a less popular variation of the name ("StarCruft" 3.2k google hits vs "ScarCruft" 31.5k google hits). The references of the entry can be fully merged as well - they do not overlap so far. * Merge pull request #612 from r0ny123/patch-1. [Alexandre Dulaunoy] BISMUTH * Update threat-actor.json. [Rony] * BISMUTH. [Rony] * Merge pull request #609 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] DeathStalker, Mabna * Merge pull request #610 from Delta-Sierra/master. [Alexandre Dulaunoy] Add new clusters * Add BazarBackdoor. [Delta-Sierra] * Add RansomEXX. [Delta-Sierra] * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #608 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Turla * Merge pull request #607 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] OceanLotus * Merge branch 'main' of github.com:MISP/misp-galaxy into main. [Alexandre Dulaunoy] * Merge pull request #606 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] APT27 * Merge https://github.com/MISP/misp-galaxy. [Delta-Sierra] * Merge pull request #604 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] * Merge pull request #603 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Lazarus * Add Darkside ransomware. [Delta-Sierra] * Merge pull request #602 from snurilov/patch-1. [Alexandre Dulaunoy] Add ConfuserEx and Beds Protector .NET packers to tools.json cluster * Add ConfuserEx and Beds Protector .NET packers to tools.json cluster. [snurilov] Add ConfuserEx and Beds Protector .NET packers to tools.json cluster * Merge pull request #601 from snurilov/patch-1. [Alexandre Dulaunoy] Update rat.json to include Iperius Remote * Update rat.json to include Iperius Remote. [snurilov] Add Iperius Remote to the rat.json cluster. * Merge pull request #600 from StefanKelm/master. [Christophe Vandeplas] Update threat-actor.json * Update threat-actor.json. [StefanKelm] OceanLotus * Merge pull request #598 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Kimsuky * Merge pull request #596 from r0ny123/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Remove duplicate! [Rony] * Update threat-actor.json. [Rony] Added TRACER KITTEN, FIN11, UNC1878, Operation Skeleton Key * Merge pull request #594 from Delta-Sierra/master. [Alexandre Dulaunoy] update microsoft activity groups * Merge branch 'main' into master. [Deborah Servili] * Merge branch 'enhanced-master' into main. [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/enhanced/misp-galaxy into enhanced-master. [Alexandre Dulaunoy] * Added a new cryptominer galaxy and additional missing recent families to various clusters. [JJ Cummings] * Merge pull request #591 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Kimsuky * Merge pull request #588 from danielplohmann/patch-2. [Alexandre Dulaunoy] adding PowerPool alias IAmTheKing (Kaspersky) * Adding PowerPool alias IAmTheKing (Kaspersky) [Daniel Plohmann] after a quick search I haven't found a nice source except for costin's tweet. * Merge pull request #587 from StefanKelm/master. [Christophe Vandeplas] Update threat-actor.json * Update threat-actor.json. [StefanKelm] TA505 * Update threat-actor.json. [StefanKelm] XDSpy * Clarify error messages in validate_all.sh. [Christophe Vandeplas] * Fixes issues in attack-ics. [Christophe Vandeplas] * Added MITRE ICS to readme. [Christophe Vandeplas] * MITRE ATT&CK for ICS fixes #586. [Christophe Vandeplas] fixed issues in pull request #586 * Merge pull request #586 from tw010101/main. [Christophe Vandeplas] Mitre ATT&CK for ICS Galaxies/Clusters * Revert "Merge pull request #586 from tw010101/main" [Christophe Vandeplas] This reverts commit a416987d4052221eb80a92169616a5af86f54bd8. * Merge pull request #586 from tw010101/main. [Christophe Vandeplas] Mitre ATT&CK for ICS Galaxies/Clusters * Add files via upload. [tw010101] * Add files via upload. [tw010101] Mitre ATT&CK for ICS Galaxy + Cluster files Mitre ATT&CK for ICS - Assets Galaxy + Cluster files Mitre ATT&CK for ICS - Groups Galaxy and Cluster files Mitre ATT&CK for ICS - Levels Galaxy + Cluster files for Mitre ATT&CK for ICS - Software Galaxy + Cluster files for Mitre ATT&CK for ICS - Tactics Galaxy + Cluster files for Mitre ATT&CK for ICS - Techniques Galaxy + Cluster files for Mitre ATT&CK for ICS - Technique Matrix * Merge pull request #585 from StefanKelm/master. [Alexandre Dulaunoy] Lazarus * Lazarus. [StefanKelm] * Merge pull request #584 from bartblaze/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Bart] Add Machete alias * Merge pull request #583 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] GADOLINIUM * Merge pull request #582 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] APT28 * Jq. [Delta-Sierra] * Update microsoft activity groups. [Delta-Sierra] * Add Sepulcher RAT. [Deborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #581 from r0ny123/patch-3. [Alexandre Dulaunoy] FBI FLASH AC-000133-TT * FBI FLASH AC-000133-TT. [Rony] * Merge pull request #580 from r0ny123/patch-2. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] Adding Fox-Kitten and cleaned (or improved) winnti * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #579 from danielplohmann/ta413-evilnum. [Alexandre Dulaunoy] Adding TA413 and Evilnum * Adding TA413 and Evilnum. [Daniel Plohmann (jupiter)] * Merge pull request #578 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] APT33 * Merge pull request #577 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] STRONTIUM * Merge pull request #576 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Lazarus, FIN7 * Merge pull request #575 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] TA542 * Merge pull request #574 from VVX7/main. [Alexandre Dulaunoy] new: [dev] add ASPI's China Defence University Tracker. * Merge pull request #573 from rmkml/master. [Alexandre Dulaunoy] add Conti Ransomware * Add Conti Ransomware. [rmkml] * Merge pull request #572 from nyx0/main. [Alexandre Dulaunoy] Few updates * Update Tonto Team/CactusPete threat actor. [Thomas Dupuy] * Add Drovorub tool. [Thomas Dupuy] * Update TA APT40. [Thomas Dupuy] * Merge pull request #571 from danielplohmann/patch-30. [Alexandre Dulaunoy] adding Kaspersky's name for Microcin. * Update threat-actor.json. [Daniel Plohmann] adding Kaspersky's name for Microcin. * Merge pull request #570 from nyx0/master. [Alexandre Dulaunoy] Add WellMess and WellMail * Add WellMess and WellMail. [Thomas Dupuy] * Merge pull request #569 from rmkml/master. [Alexandre Dulaunoy] add Ragnarok Ransomware * Merge branch 'master' of https://github.com/rmkml/misp-galaxy. [rmkml] * Add Ragnarok Ransomware. [rmkml] * Add Ragnarok Ransomware. [rmkml] * Merge pull request #568 from Vasileios-Mavroeidis/patch-1. [Alexandre Dulaunoy] Motive correction based on the EU Cert motive taxonomy * Motive correction based on the EU Cert motive taxonomy. [Vasileios Mavroeidis] Changed the motive in object 29af2812-f7fb-4edb-8cc4-86d0d9e3644b from Hactivism-Nationalist to Hacktivists-Nationalists * Merge branch 'StefanKelm-master' into main. [Alexandre Dulaunoy] * Update threat-actor.json. [StefanKelm] OilRig * Merge pull request #563 from r0ny123/patch-1. [Steve Clement] * Update threat-actor.json. [Rony] Moved the JUDGMENT PANDA references to APT31 following the previous commit. Off note, Crowdstrike quietly removed the JUDGMENT PANDA section from its GTR-2019 report. However if anyone wants to grab the unchanged report, they can get it [here](https://b-ok.asia/book/3697424/2ab30a). * Update threat-actor.json. [Rony] * Merge pull request #564 from StefanKelm/master. [Christophe Vandeplas] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Turla * Merge pull request #562 from cudeso/main. [Alexandre Dulaunoy] SoD Matrix * SoD Matrix. [Koen Van Impe] Described at https://github.com/cudeso/SoD-Matrix * Add refs. [Deborah Servili] * Merge. [Deborah Servili] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #559 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] APT31 * Merge pull request #558 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] APT30 * Merge pull request #556 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] TA505 * Merge pull request #557 from r0ny123/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] * Merge branch 'r0ny123-master' [Alexandre Dulaunoy] * Fixed typo! [Rony] * Adding GALLIUM Threat Actor. [Rony] * Merge pull request #1 from MISP/master. [Rony] update * Merge pull request #554 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Higaisa * Commit. [Deborah Servili] * Merge pull request #553 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Cycldek * Merge pull request #552 from danielplohmann/reference-fixes. [Alexandre Dulaunoy] Reference fixes * Fixing deadlinks where possible. [Daniel Plohmann (jupiter)] * Default to HTTPS to be consistent with other links to same page. [Daniel Plohmann (jupiter)] * Merge pull request #551 from nyx0/master. [Alexandre Dulaunoy] Add CrackMapExec, metasploit, Cobalt Strike and Covenant * Remove duplicate TA (Chafer), fix symantec link, add synonyme for DarkHotel. [Thomas Dupuy] * Add CrackMapExec, metasploit, Cobalt Strike and Covenant. [Thomas Dupuy] * Merge pull request #550 from r0ny123/patch-1. [Alexandre Dulaunoy] fix * Update threat-actor.json. [Rony] * Fix. [Rony] * Merge branch '3c7-secureworks_profiles' [Alexandre Dulaunoy] * Merged (most) SecureWorks threat actor profiles && jq. [Nils Kuhnert] * Merge pull request #547 from Delta-Sierra/master. [Alexandre Dulaunoy] add Snake Ransomware * Fix missing description. [Deborah Servili] * Add Snake Ransomware. [Deborah Servili] * Merge pull request #546 from danielplohmann/patch-29. [Alexandre Dulaunoy] msft name: BORON for APT3 * Msft name: BORON for APT3. [Daniel Plohmann] as per tweet: https://twitter.com/bkMSFT/status/1259578051962306562 * Merge branch 'nyx0-master' [Alexandre Dulaunoy] * Add Sednit's Exploit-kit Sedkit. [Thomas Dupuy] * Add Higaisa Threat Actor. [Thomas Dupuy] * Merge pull request #542 from Delta-Sierra/master. [Alexandre Dulaunoy] add speculoos bakdoor * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #541 from nyx0/master. [Alexandre Dulaunoy] Add DenesRAT/METALJACK * Add DenesRAT/METALJACK. [Thomas Dupuy] * Merge branch 'intezer-fix/reports' [Alexandre Dulaunoy] * Added misp info. [de Rosen] * Merge pull request #539 from r0ny123/MergingTA. [Alexandre Dulaunoy] Adding alias Thallium and merging STOLEN PENCIL * Adding alias Thallium and merging STOLEN PENCIL. [Rony] Pretty much confirmed from the crowdstrike talk at ATT&CKon 2.0. And also Netscout named the campaign as STOLEN PENCIL. * Merge branch 'rvs1st-patch-1' [Alexandre Dulaunoy] * Update threat-actor.json. [rvs1st] Added on line 1403: Trident per campaign malicious RTF documents to exploit CVE-2017-11882 and CVE-2012-0158 * Merge pull request #537 from danielplohmann/patch-28. [Alexandre Dulaunoy] Adding Nazar APT as described by JAGS in his OPCDE talk yesterday. * Adding Nazar APT as described by JAGS in his OPCDE talk yesterday. [Daniel Plohmann] * Merge pull request #536 from danielplohmann/patch-27. [Alexandre Dulaunoy] adding VOYEUR as alias (used by NSA) for MAGIC KITTEN (source referen… * Adding VOYEUR as alias (used by NSA) for MAGIC KITTEN (source reference included) [Daniel Plohmann] * Merge pull request #535 from ITAYC0HEN/feature/AddDarkUniverseActor. [Alexandre Dulaunoy] Add ItaDuke/DarkUniverse actor * Add ItaDuke/DarkUniverse actor. [itayc0hen] * Add speculoos bakdoor. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #534 from danielplohmann/fin1. [Alexandre Dulaunoy] adding FIN1 * Adding FIN1. [pnx@pyrite] * Merge pull request #533 from r0ny123/MergingTA. [Alexandre Dulaunoy] fix * Typo. [Rony] thanks to @patricksvgr * Update threat-actor.json. [Rony] * More fix. [Rony] * Fix broken links. [Rony] * Dead link. [Rony] * Add link. [Rony] * Merging APT23 & Tropic Trooper. [Rony] * Merge pull request #531 from r0ny123/patch-3. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #529 from danielplohmann/patch-26. [Alexandre Dulaunoy] fixing/removing some more dead links * Removed duplicate entry. [Daniel Plohmann] * Fixing/removing some more dead links. [Daniel Plohmann] * Merge pull request #528 from Delta-Sierra/master. [Alexandre Dulaunoy] UPdate Ransomware Galaxy * Add Operation Shadow Forece. [Deborah Servili] * Add coronavirus ransomware. [Deborah Servili] * Add Pyta ransomnotes. [Deborah Servili] * Add pyza ransomware. [Deborah Servili] * Merge pull request #526 from Delta-Sierra/master. [Alexandre Dulaunoy] PARINACOTA group * PARINACOTA group. [Deborah Servili] * Merge pull request #523 from danielplohmann/patch-24. [Alexandre Dulaunoy] adding aliases MERCURY, HOLMIUM * Adding aliases MERCURY, HOLMIUM. [Daniel Plohmann] Muddywater->MERCURY: https://twitter.com/moranned/status/1234071210822184960 APT33->HOLMIUM: https://www.zdnet.com/article/microsoft-notified-10000-victims-of-nation-state-attacks/ * Merge pull request #524 from danielplohmann/patch-25. [Alexandre Dulaunoy] Kimsuki -> Black Banshee * Kimsuki -> Black Banshee. [Daniel Plohmann] PWC refers to Kimsuki as Black Banshee (https://www.pwc.co.uk/issues/cyber-security-data-privacy/research/tracking-kimsuky-north-korea-based-cyber-espionage-group-part-2.html) * Merge pull request #522 from Delta-Sierra/master. [Alexandre Dulaunoy] add sdbbot * Add SdBbot. [Deborah Servili] * Add clop ransomware extension. [Deborah Servili] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #519 from danielplohmann/crowdstrike2020report. [Alexandre Dulaunoy] adding new/updated threat actor names from CrowdStrike 2020 report * While we are at it, we can also do Longhorn = APT-C-39. [Daniel Plohmann (jupiter)] * IMPERIAL KITTEN as alias for Tortoiseshell. [Daniel Plohmann (jupiter)] * Adding new/updated threat actor names from CrowdStrike 2020 report. [pnx@pyrite] * Merge branch 'cocaman-patch-1' [Alexandre Dulaunoy] * Fixing a comma error. [Corsin Camichel] * Adding Raccoon (win.raccoon) [Corsin Camichel] * Merge pull request #518 from danielplohmann/patch-21. [Alexandre Dulaunoy] Accenture calls APT32 - "POND LOACH" * Accenture calls APT32 - "POND LOACH" [Daniel Plohmann] * Merge branch 'nyx0-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/nyx0/misp-galaxy into nyx0-master. [Alexandre Dulaunoy] * Add InvisiMole cluster. [Thomas Dupuy] * Merge pull request #517 from Delta-Sierra/master. [Alexandre Dulaunoy] update ransomware galaxy * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #516 from rmkml/master. [Alexandre Dulaunoy] add MedusaLocker ransomware * Add MedusaLocker ransomware. [rmkml] * Add extension to clop ransomware. [Deborah Servili] * Add razor ransomware. [Deborah Servili] * Merge pull request #513 from danielplohmann/patch-20. [Alexandre Dulaunoy] adding APT-C-12 * Adding APT-C-12. [Daniel Plohmann] * Merge pull request #512 from Delta-Sierra/master. [Alexandre Dulaunoy] Add several tools * Add tools used by TA505 + others. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Add warzone RAT. [Deborah Servili] * Merge pull request #510 from Delta-Sierra/master. [Alexandre Dulaunoy] add ransomwares * Add ransomwares. [Deborah Servili] * Merge pull request #509 from r0ny123/patch-3. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] those are the name of aliases of the same malware family sykipot. so removing it. * Merge pull request #508 from Delta-Sierra/master. [Alexandre Dulaunoy] add Operation Wocao * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #507 from nyx0/master. [Alexandre Dulaunoy] Add Attor and DePriMon * Add Attor and DePriMon. [Thomas Dupuy] * Merge pull request #506 from danielplohmann/patch-19. [Alexandre Dulaunoy] removing and fixing deadlinks in the best possible way * Removing and fixing deadlinks in the best possible way. [Daniel Plohmann] Hi! While migrating Malpedia to our new reference data format, we noticed a few potentially dead/moved references in your cluster. This pull request should fix most of them, for some I was not able to find an appropriate replacement. * Merge pull request #505 from danielplohmann/patch-18. [Alexandre Dulaunoy] adding references and TEMP.MixMaster as alias for WIZARD SPIDER * Adding references and TEMP.MixMaster as alias for WIZARD SPIDER. [Daniel Plohmann] with kudos to @tbarabosch * Merge pull request #504 from Delta-Sierra/master. [Alexandre Dulaunoy] update target location galaxy * Merge pull request #503 from StefanKelm/master. [Alexandre Dulaunoy] Update ransomware.json * Update ransomware.json. [StefanKelm] * Update ransomware.json. [StefanKelm] 5ss5c * Merge pull request #502 from Delta-Sierra/master. [Alexandre Dulaunoy] update tool galaxy * Jq. [Deborah Servili] * Add Operation Wocao. [Deborah Servili] * Complete Zimbabwe cluster. [Deborah Servili] * Update target location galaxy. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #500 from Delta-Sierra/master. [Alexandre Dulaunoy] update target information * Merge pull request #501 from StefanKelm/master. [Alexandre Dulaunoy] Update tool.json * Update tool.json. [StefanKelm] LiquorBot * Merge pull request #499 from StefanKelm/master. [Alexandre Dulaunoy] Update tool.json * Update tool.json. [StefanKelm] Lampion * Add Autochk Rootkit as tool. [Deborah Servili] * Add two wipers to tools. [Deborah Servili] * Update target information. [Deborah Servili] * Merge pull request #498 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] * Update threat-actor.json. [StefanKelm] BRONZE PRESIDENT * Merge pull request #497 from r0ny123/patch-2. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] * Merge pull request #496 from bartblaze/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Bart] Adds Operation Wocao.. * Merge pull request #495 from Delta-Sierra/master. [Alexandre Dulaunoy] add clop ransomware * Add clop ransomware. [Deborah Servili] * Merge pull request #494 from Delta-Sierra/master. [Alexandre Dulaunoy] add BitPaymer Synonyms * Jq. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #493 from Delta-Sierra/master. [Deborah Servili] add tools used by GALLIUM * Merge pull request #492 from Delta-Sierra/master. [Alexandre Dulaunoy] Operation Soft Cell ralated Updates * Merge pull request #491 from wagner-certat/threat-actor-syn-sofacy. [Alexandre Dulaunoy] sofacy: add apt_sofacy as synonym * Sofacy: add apt_sofacy as synonym. [Sebastian Wagner] * Merge pull request #490 from Delta-Sierra/master. [Alexandre Dulaunoy] Update threat actor galaxy * Add BitPaymer Synonsyms. [Deborah Servili] * Add tools used by GALLIUM. [Deborah Servili] * Add GALLIUM as microsoft activities group and similar to Operation Soft Cell. [Deborah Servili] * Update threat actor version. [Deborah Servili] * Add relation suspected link between operation soft cell and apt10. [Deborah Servili] * ##COMMA## [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #489 from danielplohmann/patch-16. [Alexandre Dulaunoy] added APT-C-34 / Golden Falcon * Added APT-C-34 / Golden Falcon. [Daniel Plohmann] * Merge pull request #488 from Delta-Sierra/master. [Alexandre Dulaunoy] create new galaxy - surveillance-vendor * Merge pull request #487 from gallypette/patch-1. [Alexandre Dulaunoy] add: [dark-pattern] updates the README * Add: [dark-pattern] updates the README. [Jean-Louis Huynen] * Merge pull request #486 from gallypette/master. [Alexandre Dulaunoy] chg: [dark-pattern] namespace: misp * Merge pull request #485 from danielplohmann/patch-15. [Alexandre Dulaunoy] added TA2101 * Added TA2101. [Daniel Plohmann] * Merge pull request #484 from gallypette/master. [Alexandre Dulaunoy] add: [dark-pattern] galaxy to tag dark patterns * Add: [dark-pattern] add a source. [Jean-Louis Huynen] * Add: [dark-pattern] galaxy to tag dark patterns. [Jean-Louis Huynen] * Add Axiom synonym. [Deborah Servili] * Add Sofacy ref. [Deborah Servili] * Add clusters to surveillance-vendor galaxy. [Deborah Servili] * Fix surveillance-vendor galaxy. [Deborah Servili] * Fix-tentative. [Deborah Servili] * Fix. [Deborah Servili] * Jq. [Deborah Servili] * Update schema_cluster. [Deborah Servili] * Add FlexiSPY + jq. [Deborah Servili] * Add new galaxy - surveillance-vendor. [Deborah Servili] * Add Private Internet Access as Tool. [Deborah Servili] * Merge branch 'rmkml-master' [Alexandre Dulaunoy] * Merge branch 'master' into master. [rmkml] * Merge pull request #482 from Delta-Sierra/master. [Alexandre Dulaunoy] add DePriMon malicious downloader & Cyborg ransomware * Jq. [Deborah Servili] * Add cyborg ransomnote refs. [Deborah Servili] * Add cyborg ransomnote filename. [Deborah Servili] * Add cyborg ranspmware extension. [Deborah Servili] * Jq. [Deborah Servili] * Add DePriMon malicious downloader & Cyborg ransomware. [Deborah Servili] * Merge pull request #481 from Delta-Sierra/master. [Andras Iklody] add silence synonym & new meta field spoken-language * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Merge. [Deborah Servili] * Merge pull request #480 from rmkml/master. [Alexandre Dulaunoy] Add Maze Ransomware * Merge pull request #477 from rmkml/master. [Alexandre Dulaunoy] Add Desync Ransomware * Merge pull request #476 from StefanKelm/master. [Alexandre Dulaunoy] new refs for APT33 * New refs for APT33. [StefanKelm] * Merge pull request #475 from Delta-Sierra/master. [Alexandre Dulaunoy] target information update [WIP] * Merge pull request #473 from Delta-Sierra/master. [Alexandre Dulaunoy] update target location WIP * Merge. [Deborah Servili] * Add silence synonym & new meta field spoken-language. [Deborah Servili] * Traget information update [WIP] [Deborah Servili] * Jq. [Deborah Servili] * Traget information update [WIP] [Deborah Servili] * Add Palestine PPound. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #472 from rmkml/master. [Alexandre Dulaunoy] Add DoppelPaymer Ransomware * Merge pull request #471 from rmkml/master. [Alexandre Dulaunoy] Add FreeMe Ransomware * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #468 from Delta-Sierra/master. [Alexandre Dulaunoy] add Turla Group Symonym variant * Merge pull request #467 from Delta-Sierra/master. [Deborah Servili] Few updates * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #465 from r0ny123/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] * Jq. [Deborah Servili] * Update target location WIP. [Deborah Servili] * Add Turla Group Symonym variant. [Deborah Servili] * Jq. [Deborah Servili] * Add Winnti related tools etc. [Deborah Servili] * Add operation soft cell. [Deborah Servili] * Merge pull request #464 from MISP/fix-misinfosec. [Sami Mokaddem] fix: [misinfosec] fixed kill_chain fields * Merge pull request #463 from VVX7/master. [Alexandre Dulaunoy] new: [galaxy] AMITT (Adversarial Misinformation and Influence Tactics… * Merge pull request #462 from Delta-Sierra/master. [Alexandre Dulaunoy] add synonyms * Jq. [Deborah Servili] * Add legitimate tools. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #461 from Delta-Sierra/target-location-galaxy. [Alexandre Dulaunoy] Target location galaxy * Fix empty string. [Deborah Servili] * Jq. [Deborah Servili] * Add TVSPY tool. [Deborah Servili] * WIP update target info. [Deborah Servili] * Try to please CodeFactor. [Deborah Servili] * Add script used to create region galaxy (Not optimised or anything) [Deborah Servili] * New galaxy - Region based on UN M49. [Deborah Servili] * WIP update target info. [Deborah Servili] * Merge pull request #459 from Delta-Sierra/target-location-galaxy. [Alexandre Dulaunoy] Target location galaxy * Jq. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy into target-location-galaxy. [Deborah Servili] * Merge pull request #458 from Delta-Sierra/master. [Alexandre Dulaunoy] Add Tortoiseshell thrat actor * WIP update target info - fix empty string. [Deborah Servili] * WIP update target info. [Deborah Servili] * WIP update target info. [Deborah Servili] * Moar clusters. [Deborah Servili] * Update target information [draft] [Deborah Servili] * Update target information. [Deborah Servili] * Update target information. [Deborah Servili] * Improve target-information. [Deborah Servili] * Update version. [Deborah Servili] * Add PlugX rat sysnonyms. [Deborah Servili] * Add Sodinokibi synonym. [Deborah Servili] * Version update. [Deborah Servili] * Add Tortoiseshell thrat actor. [Deborah Servili] * Merge pull request #457 from rmkml/master. [Alexandre Dulaunoy] Add Mr.Dec Ransomware * Merge pull request #456 from rmkml/master. [Alexandre Dulaunoy] Add Hildacrypt Ransomware * Merge pull request #455 from rmkml/master. [Alexandre Dulaunoy] Add InnfiRAT * Merge pull request #454 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Silent Librarian * Merge pull request #453 from rmkml/master. [Alexandre Dulaunoy] Add AsyncRAT * Fix Add FTCode Ransomware. [rmkml] * Add FTCode Ransomware. [rmkml] * Add Maze Ransomware. [rmkml] * Revert "Add Maze Ransomware" [rmkml] This reverts commit cfc6e2802cf8760e1389e77d3f1452f3eda7fb8f. * Add Maze Ransomware. [rmkml] * Add Desync Ransomware. [rmkml] * Add DoppelPaymer Ransomware. [rmkml] * Add FreeMe Ransomware. [rmkml] * Add Mr.Dec Ransomware. [rmkml] * Add Hildacrypt Ransomware. [rmkml] * Add InnfiRAT. [rmkml] * Merge branch 'master' into master. [rmkml] * Merge pull request #452 from Delta-Sierra/master. [Deborah Servili] aff SectorJ04 group * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #450 from rmkml/master. [Alexandre Dulaunoy] Add Buran Ransomware * Merge pull request #449 from danielplohmann/patch-14. [Alexandre Dulaunoy] 'SectorJ04 Group' as alias introduced by NSHC for TA505 * 'SectorJ04 Group' as alias introduced by NSHC for TA505. [Daniel Plohmann] Not explicitly mentioned in the blog post but it looks like we just got an alias for TA505... https://threatrecon.nshc.net/2019/08/29/sectorj04-groups-increased-activity-in-2019/ * Merge pull request #448 from rmkml/master. [Alexandre Dulaunoy] Add Nemty Ransomware * Merge pull request #447 from Delta-Sierra/target-location-galaxy. [Alexandre Dulaunoy] improve more clusters * Improve more clusters. [Deborah Servili] * Merge pull request #446 from wagner-certat/tool-empty-strings. [Alexandre Dulaunoy] Add test for empty strings * Target-information: fix territory-type for China. [Sebastian Wagner] * Add test for empty strings. [Sebastian Wagner] Should prevent MISP/misp-galaxy#438 * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #441 from Delta-Sierra/target-location-galaxy. [Deborah Servili] More clusters improved * More clusters improved. [Deborah Servili] * Merge pull request #444 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Add ITG08 as synonym for FIN6 * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge branch 'Delta-Sierra-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master. [Alexandre Dulaunoy] * Aff SectorJ04 group. [Deborah Servili] * Add Asruex Backdoor. [Deborah Servili] * Add ref for Gamaredon. [Deborah Servili] * Merge pull request #440 from Delta-Sierra/target-location-galaxy. [Alexandre Dulaunoy] Target location galaxy * More clusters improved. [Deborah Servili] * More clusters improved. [Deborah Servili] * Merge pull request #439 from Delta-Sierra/target-location-galaxy. [Alexandre Dulaunoy] Target location galaxy * More clusters improved. [Deborah Servili] * More clusters improved. [Deborah Servili] * More countries. [Deborah Servili] * Merge pull request #438 from wagner-certat/empty-strings. [Alexandre Dulaunoy] Remove some empty strings * Remove empty strings. [Sebastian Wagner] * Merge pull request #437 from Delta-Sierra/target-location-galaxy. [Deborah Servili] Target location galaxy * Complete more cluster + country is now an array. [Deborah Servili] * Target-informatione - add membership member-of attribute - Example:member-of NATO. [Deborah Servili] * Merge pull request #436 from Delta-Sierra/target-location-galaxy. [Alexandre Dulaunoy] Target location galaxy * Jq. [Deborah Servili] * Change attribute name. [Deborah Servili] * Jq. [Deborah Servili] * Complete some clusters. [Deborah Servili] * Fix building mistakes. [Deborah Servili] * Add tld. [Deborah Servili] * Add target-information galaxy file. [Deborah Servili] * Rename galaxy target-location -> target-information. [Deborah Servili] * New galaxy target-location [DRAFT] [Deborah Servili] * Merge pull request #435 from hackunagi/master. [Alexandre Dulaunoy] Adding Amavaldo Banking Trojan * Adding Amavaldo Banking Trojan. [Carlos Borges] * Merge pull request #434 from r0ny123/patch-1. [Alexandre Dulaunoy] added microsoft naming for the groups * Added microsoft naming for the groups. [Rony] * Merge pull request #433 from nyx0/master. [Alexandre Dulaunoy] add APT41 * Add synonyme for Turla. [Thomas Dupuy] * Update victims. [Thomas Dupuy] * Add APT41. [Thomas Dupuy] * Merge pull request #431 from Delta-Sierra/master. [Alexandre Dulaunoy] add Amavaldo * Jq. [Deborah Servili] * Update version. [Deborah Servili] * Add Amavaldo. [Deborah Servili] * Merge pull request #430 from 3c7/patch-2. [Alexandre Dulaunoy] [threat-actor] Remove local file reference in threat actor galaxy * Remove local file link :) [Nils Kuhnert] * Lowercased value field for DarkHotel. [Andras Iklody] * Merge pull request #429 from danielplohmann/patch-13. [Alexandre Dulaunoy] adding secureworks actor names for energetic bear and teamspy * Merge branch 'master' into patch-13. [Alexandre Dulaunoy] * Merge pull request #428 from danielplohmann/patch-12. [Alexandre Dulaunoy] adding Proofpoint's TA428 * Adding Proofpoint's TA428. [Daniel Plohmann] * Adding secureworks actor names for energetic bear and teamspy. [Daniel Plohmann] * Merge pull request #426 from mokaddem/patch-2. [Alexandre Dulaunoy] Update mitre-course-of-action.json * Update mitre-course-of-action.json. [Sami Mokaddem] Changed icon * Merge pull request #425 from mokaddem/patch-1. [Alexandre Dulaunoy] Update banker.json * Update banker.json. [Sami Mokaddem] Changed icon name * Merge pull request #424 from mokaddem/patch-3. [Alexandre Dulaunoy] Update mitre-enterprise-attack-course-of-action.json * Update mitre-enterprise-attack-course-of-action.json. [Sami Mokaddem] Changed icon * Merge pull request #423 from mokaddem/patch-4. [Alexandre Dulaunoy] Update mitre-mobile-attack-course-of-action.json * Update mitre-mobile-attack-course-of-action.json. [Sami Mokaddem] Changed icon * Merge pull request #422 from Delta-Sierra/master. [Alexandre Dulaunoy] add SWEED threat actor * Jq. [Deborah Servili] * Add SWEED threat actor. [Deborah Servili] * Merge pull request #420 from Delta-Sierra/master. [Deborah Servili] add Felipe Trojan * Jq. [Deborah Servili] * Add Felipe Trojan. [Deborah Servili] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy. [Alexandre Dulaunoy] * Fix duplicate. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * ##COMMA## [Deborah Servili] * Fix duplicate. [Deborah Servili] * Update version. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Merge pull request #419 from r0ny123/patch-6. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] * Merge pull request #415 from Delta-Sierra/master. [Alexandre Dulaunoy] update threat actor galaxy * Fix duplicate and links update (APT34) [Deborah Servili] * Fix duplicate. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Tryto fix duplicate. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Merge pull request #414 from Delta-Sierra/master. [Alexandre Dulaunoy] update threat actor galaxy * Fix duplicate. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #413 from Delta-Sierra/master. [Alexandre Dulaunoy] update threat actor galaxy * Merge pull request #412 from Delta-Sierra/master. [Alexandre Dulaunoy] update threat actors and tools * Merge pull request #411 from Delta-Sierra/master. [Alexandre Dulaunoy] update threat-actor galaxy * Merge pull request #409 from rmkml/master. [Alexandre Dulaunoy] Add GetCrypt Ransomware * Merge pull request #408 from rmkml/master. [Alexandre Dulaunoy] Add Phobos Ransomware * Merge pull request #407 from Delta-Sierra/master. [Alexandre Dulaunoy] add BlueKeep vulnerability * Update threat actor galaxy. [Deborah Servili] * Jq. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Update Threat actor galaxy. [Deborah Servili] * Update threat actor. [Deborah Servili] * Update threat actor darkhotel (nemim might be a typo) [Deborah Servili] * Update threat actor. [Deborah Servili] * FlawedAmmy RAT. [Deborah Servili] * Fix multiple refs. [Deborah Servili] * Update threat actors. [Deborah Servili] * Update threat actors. [Deborah Servili] * Update threat actors and tools. [Deborah Servili] * Fix merge mistakes. [Deborah Servili] * Update threat actor. [Deborah Servili] * Update threat actor. [Deborah Servili] * Update threat-actor galaxy. [Deborah Servili] * Update Anchor Panda Threat Actor. [Deborah Servili] * Add BlueKeep. [Deborah Servili] * Add AsyncRAT. [rmkml] * Add Buran Ransomware. [rmkml] * Add Nemty Ransomware. [rmkml] * Add GetCrypt Ransomware. [rmkml] * Merge branch 'master' into master. [rmkml] * Merge pull request #406 from Delta-Sierra/master. [Alexandre Dulaunoy] Rework of ransomware galaxy * Fix ransomware ransomnotes. [Deborah Servili] * Jq. [Deborah Servili] * Rework of ransomware galaxy. [Deborah Servili] * Merge pull request #405 from danielplohmann/patch-11. [Alexandre Dulaunoy] adding TA542 to MUMMY SPIDER (emotet) * Adding TA542 to MUMMY SPIDER (emotet) [Daniel Plohmann] * Merge pull request #404 from r0ny123/patch-5. [Alexandre Dulaunoy] merging Pacifier & Turla * Merging Pacifier & Turla. [Rony] * Merge pull request #403 from Delta-Sierra/master. [Alexandre Dulaunoy] add Reaver and probably related tools * Add Reaver and probably related tools. [Deborah Servili] * Merge pull request #402 from danielplohmann/patch-9. [Alexandre Dulaunoy] adding APT31/ZIRCONIUM * Adding APT31/ZIRCONIUM. [Daniel Plohmann] * Merge pull request #401 from mokaddem/bump-attack-pattern. [Alexandre Dulaunoy] chg: [attack-pattern] Sync kill-chain with data from MITRE. * Merge pull request #400 from Delta-Sierra/master. [Deborah Servili] add Sodinokibi * Add Sodinokibi. [Deborah Servili] * Merge pull request #399 from r0ny123/patch-4. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] * Merge pull request #395 from Delta-Sierra/master. [Alexandre Dulaunoy] add Scranos * Add Scarnos. [Deborah Servili] * Merge pull request #394 from StefanKelm/master. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [StefanKelm] Silent Librarian / COBALT DICKENS * Merge pull request #393 from Delta-Sierra/master. [Alexandre Dulaunoy] add AESDDoS Botnet and JasperLoader * Add JasperLoader. [Deborah Servili] * Add AESDDoS Botnet. [Deborah Servili] * Merge branch 'nao-sec-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/nao-sec/misp-galaxy into nao-sec-master. [Alexandre Dulaunoy] * Merge branch 'r0ny123-patch-2' [Alexandre Dulaunoy] * Update threat-actor.json. [Rony] * Update threat-actor.json. [Rony] * Update threat-actor.json. [Rony] * Updated FIN4. [Rony] * Merge branch 'Kafeine-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Kafeine/misp-galaxy into Kafeine-master. [Alexandre Dulaunoy] * += Spelevo. [Kafeine] * ZTDS. [Kafeine] * Novidade,taurus. [Kafeine] * Merge pull request #387 from r0ny123/patch-1. [Alexandre Dulaunoy] more report on APT36 * More report on APT36. [Rony] * Merge pull request #386 from Delta-Sierra/master. [Alexandre Dulaunoy] ad Sea Turtle Campaign * Add Sea Turtle campaign. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Chg; [threat-actor] validate + version bump. [Christophe Vandeplas] * Merge pull request #385 from bartblaze/master. [Christophe Vandeplas] Add Whitefly * Add Whitefly. [Bart] * Merge. [Deborah Servili] * Merge pull request #384 from r0ny123/patch-3. [Deborah Servili] fixed the broken link * Fixed the broken link. [Rony] * Merge pull request #383 from rmkml/master. [Deborah Servili] Add BigBobRoss Ransomware * Merge pull request #382 from rmkml/master. [Alexandre Dulaunoy] Add Caesar RAT * Merge pull request #381 from rmkml/master. [Alexandre Dulaunoy] Add Tellyouthepass Ransomware * Merge pull request #380 from bartblaze/master. [Alexandre Dulaunoy] Add DoNot team references * Add DoNot team references. [Bart] * Merge pull request #379 from rmkml/master. [Alexandre Dulaunoy] Add BlackWorm Ransomware * Merge branch 'danielplohmann-patch-8' [Alexandre Dulaunoy] * Merge branch 'patch-8' of https://github.com/danielplohmann/misp-galaxy into danielplohmann-patch-8. [Alexandre Dulaunoy] * Based on additional research, APT36 can actually be merged into Mythic Leopard. [Daniel Plohmann] * Merge pull request #377 from r0ny123/patch-2. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Rony] * Merge pull request #376 from r0ny123/patch-1. [Alexandre Dulaunoy] adding additional resources for APT36 * Update threat-actor.json. [Rony] * Adding additional resources for APT36. [Rony] * Merge pull request #375 from rmkml/master. [Alexandre Dulaunoy] Add Globe Imposter Ransomware * Merge pull request #374 from rmkml/master. [Alexandre Dulaunoy] Add Parasite HTTP RAT * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Add ref for Ryuk and LockerGoga ransomwares. [Deborah Servili] * Add Phobos Ransomware. [rmkml] * Add Cr1ptt0r Ransomware. [rmkml] * Add SpelevoEK. [rmkml] * Add Planetary Ransomware. [rmkml] * Add BigBobRoss Ransomware. [rmkml] * Add Caesar RAT. [rmkml] * Add Ave Maria Stealer. [rmkml] * Add Tellyouthepass Ransomware. [rmkml] * Add Vidar Stealer. [rmkml] * Add Brushaloader Malware. [rmkml] * Add BlackWorm Ransomware. [rmkml] * Add Globe Imposter Ransomware. [rmkml] * Add Parasite HTTP RAT. [rmkml] * Merge pull request #373 from danielplohmann/patch-7. [Alexandre Dulaunoy] adding FireEye's TMP.Lapis / APT36 * Adding FireEye's TMP.Lapis / APT36. [Daniel Plohmann] * Merge branch 'ismasma-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/ismasma/misp-galaxy into ismasma-master. [Alexandre Dulaunoy] * Add payment method and price. [ismasma] * Merge pull request #371 from Delta-Sierra/master. [Alexandre Dulaunoy] Add Operation ShadowHammer * Add Operation ShadowHammer. [Deborah Servili] * Add relationship between Cardinal RAT and EVILNUM. [Deborah Servili] * Merge branch 'Delta-Sierra-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master. [Alexandre Dulaunoy] * Jq. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Add Cardinal RAT ref. [Deborah Servili] * Add AOT-C-27 Goldmouse. [Deborah Servili] * Add SPOILER vulnerability + other minor changes. [Deborah Servili] * Remove mitre-relationships from readme. [Deborah Servili] * Merge pull request #370 from danielplohmann/patch-6. [Alexandre Dulaunoy] added APT-C-27 / GoldMouse * Added APT-C-27 / GoldMouse. [Daniel Plohmann] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #363 from Delta-Sierra/master. [Alexandre Dulaunoy] add H-worm RAT * Add H-worm RAT. [Deborah Servili] * Add: [attck4fraud] initial attck-like matrix for fraud from https://github.com/burritoblue/attck4fraud (WiP) [Alexandre Dulaunoy] * Merge pull request #362 from bartblaze/master. [Alexandre Dulaunoy] Update preventive-measure.json * Update preventive-measure.json. [Bart] Add ACL * Merge pull request #361 from Delta-Sierra/master. [Alexandre Dulaunoy] add Operation Comando - hit version 100 * Add Operation Comando - hit version 100. [Deborah Servili] * Merge pull request #359 from nyx0/master. [Alexandre Dulaunoy] add synonym, no need for uppercase in the name :) * Add synonym, no need for uppercase in the name :) [Thomas Dupuy] * Merge pull request #358 from Delta-Sierra/master. [Alexandre Dulaunoy] add attribution-confidence attribute to threat-actor * Add attribution-confidence attribute to threat-actor. [Deborah Servili] * Merge pull request #357 from Delta-Sierra/master. [Alexandre Dulaunoy] New clusters * Relations between SLUB Backdoor. [Deborah Servili] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #356 from danielplohmann/patch-5. [Alexandre Dulaunoy] another actor described by 360TIC. * Update threat-actor.json. [Daniel Plohmann] another actor described by 360TIC. * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #355 from danielplohmann/patch-4. [Alexandre Dulaunoy] FireEye upgraded TEMP.Periscope to APT40 * FireEye upgraded TEMP.Periscope to APT40. [Daniel Plohmann] * Add StealthWorker malware. [Deborah Servili] * Add SLUB backdoor. [Deborah Servili] * Add Jokeroo RaaS. [Deborah Servili] * Add operation Kabar Cobra. [Deborah Servili] * Add ref for garrantydecrypt. [Deborah Servili] * Add relation between Lazarus Group and Operation SharpShooter. [Deborah Servili] * Add Rising Sun Backdoor. [Deborah Servili] * Add Razdel. [Deborah Servili] * Merge pull request #350 from bartblaze/master. [Alexandre Dulaunoy] Add more info on Lotus Blossom * Add more info on Lotus Blossom. [Bart] Add 2 more references, fix typo - Trend calls it "Esile", not "Eslie" as mistakenly stated by CFR. The backdoor itself is commonly referred to as Elise. * Merge pull request #347 from bartblaze/master. [Alexandre Dulaunoy] Update cert-eu-motive.json * Update cert-eu-motive.json. [Bart] Fix typo * Merge pull request #346 from danielplohmann/patch-3. [Alexandre Dulaunoy] Two more actor names from GTR2019 * Two more actor names from GTR2019. [Daniel Plohmann] I found two more actor names while going again over the crowdstrike's report and updating the cross-references to malpedia. * Merge pull request #345 from danielplohmann/patch-2. [Alexandre Dulaunoy] Added missing actors from CrowdStrike GTR2019 * Added missing actors from CrowdStrike GTR2019. [Daniel Plohmann] * Merge pull request #344 from ITAYC0HEN/patch-1. [Alexandre Dulaunoy] Fix 404'd reference of BuhTrap * Fix 404'd reference of BuhTrap. [Itay Cohen] * Merge pull request #343 from mokaddem/newMitre. [Alexandre Dulaunoy] Added kill_chain_order in mitre-attack-pattern * Merge branch 'master' of https://github.com/MISP/misp-galaxy into newMitre. [mokaddem] * Merge pull request #342 from mokaddem/electionGuidelines. [Alexandre Dulaunoy] new: Added draft of the election guildelines galaxy * Merge pull request #320 from cvandeplas/mitre_attack. [Alexandre Dulaunoy] chg: [mitre] Deprecated pre/enterprise/mobile separate galaxies * Merge pull request #341 from Delta-Sierra/master. [Alexandre Dulaunoy] Add several clusters * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #340 from nyx0/master. [Alexandre Dulaunoy] add ANEL/UPPERCUT in tool cluster * Add ANEL/UPPERCUT in tool cluster. [Thomas Dupuy] * Merge pull request #338 from netjinho/patch-1. [Alexandre Dulaunoy] Updated "Iran" name * Updated "Iran" name. [João Neto] This extra space leads to an unnecessary key error when parsing the json file * Merge pull request #337 from 3c7/synonym/velvet-chollima. [Alexandre Dulaunoy] Added Velvet Chollima as synonym to Kimsuki * Added Velvet Chollima as synonym to Kimsuki. [Nils Kuhnert] * Merge pull request #336 from 3c7/synonym/static-kitten. [Christophe Vandeplas] Added static kitten as synonym for MuddyWater * Added static kitten as synonym for MuddyWater. [Nils Kuhnert] * Merge pull request #334 from 3c7/synonym/cobalt-spider. [Alexandre Dulaunoy] Added Cobalt Spider as Synonym for Cobalt * Added Cobalt Spider reference. [Nils Kuhnert] * Added Cobalt Spider as Synonym for Cobalt. [Nils Kuhnert] * Merge pull request #335 from 3c7/synonym/turbine-panda. [Alexandre Dulaunoy] Added Turbine Panda as synonym for APT 26 * Added Turbine Panda as synonym for APT 26. [Nils Kuhnert] * Merge pull request #333 from 3c7/synonym/oceanbuffalo. [Alexandre Dulaunoy] Added Ocean Buffalo synonym for Ocean Lotus * Added Ocean Buffalo synonym for Ocean Lotus. [Nils Kuhnert] * Merge pull request #332 from Delta-Sierra/master. [Alexandre Dulaunoy] Add APT39 & LockerGoga * Merge pull request #331 from 3c7/synonym/quilted_tiger. [Alexandre Dulaunoy] Added Quilted Tiger as Synonym for Patchwork/Dropping Elephant. * Added Quilted Tiger as Synonym for Patchwork/Dropping Elephant. [Nils Kuhnert] * Merge pull request #330 from 3c7/synonym/shadow_crane. [Alexandre Dulaunoy] Added Shadow Crane as synonym for Dark Hotel. * Added Shadow Crane as synonym for Dark Hotel. [Nils Kuhnert] * Add Gallmaker and other clusters. [Deborah Servili] * Add OSX/Shlayer and some refs. [Deborah Servili] * Add Siesta campaign. [Deborah Servili] * Add APT39. [Deborah Servili] * Add LockerGoga ransomware. [Deborah Servili] * Merge pull request #329 from 3c7/synonym/stardustchollima. [Alexandre Dulaunoy] Added "Stardust Chollima" as synonym for Lazarus. * Added "Stardust Chollima" as synonym for Lazarus. [Nils Kuhnert] * Merge pull request #328 from Delta-Sierra/master. [Alexandre Dulaunoy] add Silence Group * Add Silence Group. [Deborah Servili] * Merge pull request #327 from nyx0/master. [Alexandre Dulaunoy] add alternative name for DarkHydrus * Add alternative name for DarkHydrus. [Thomas Dupuy] * Merge pull request #326 from Delta-Sierra/master. [Alexandre Dulaunoy] add Cold River Threat actor * Add LoJax ref. [Deborah Servili] * Add Cold River Threat actor. [Deborah Servili] * Merge pull request #325 from Delta-Sierra/master. [Alexandre Dulaunoy] add several ransomware and threat actors * Fix versions. [Deborah Servili] * Add several ransomware and threat actors. [Deborah Servili] * Merge pull request #324 from Delta-Sierra/master. [Alexandre Dulaunoy] TA505 threat actorand affiliates malwares * Add drakhydrus ref. [Deborah Servili] * TA505 threat actorand affiliates malwares. [Deborah Servili] * Merge pull request #322 from Delta-Sierra/master. [Alexandre Dulaunoy] add Cryptomix variants refs * Add hidenad synonym. [Deborah Servili] * Add Cryptomix variants refs. [Deborah Servili] * Merge pull request #321 from Delta-Sierra/master. [Alexandre Dulaunoy] add AndroidOS_HidenAd * Update version. [Deborah Servili] * Add AndroidOS_HidenAd. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #319 from cvandeplas/master. [Christophe Vandeplas] chg: [mitre] bump to latest MITRE ATT&CK dataset * MITRE galaxy regeneration + updated migration script. [Christophe Vandeplas] * MITRE sorted. [Christophe Vandeplas] While dicts were sorted, lists were not yet sorted. This current sort algo is not yet the best, but is a good start. A good sort is needed for better comparison afterwards with automated tools. In a next stage tt will also be needed in the validate_all scripts. * MITRE galaxy - initial conversion and migration script. [Christophe Vandeplas] this is not fully working yet ! * Merge pull request #318 from 3c7/feature/helixkitten. [Alexandre Dulaunoy] Added OilRig synonym "Helix Kitten". * Added OilRig synonym "Helix Kitten". [Nils Kuhnert] * Merge pull request #316 from danielplohmann/master. [Alexandre Dulaunoy] New name SNAKEMACKEREL for APT28 by Accenture * Microsoft alias for apt29 is YTTRIUM. [Daniel Plohmann] * New name SNAKEMACKEREL for APT28 by Accenture. [Daniel Plohmann] * Removed Puplishing industry. [Gerard Wagener] * Merge pull request #315 from Delta-Sierra/master. [Alexandre Dulaunoy] add OSX malwares * Merge pull request #314 from Delta-Sierra/master. [Alexandre Dulaunoy] New clusters * Add ransomwares. [Deborah Servili] * Add OSX malwares. [Deborah Servili] * Add operation sharpshooter. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #313 from Delta-Sierra/master. [Alexandre Dulaunoy] add some clusters or info * Merge pull request #310 from Delta-Sierra/master. [Alexandre Dulaunoy] add several clusters * Update toll version. [Deborah Servili] * Add shamoon synonym. [Deborah Servili] * Fix tool version. [Deborah Servili] * Fix exploit-kit version. [Deborah Servili] * Add some clusters or info. [Deborah Servili] * Add Goden Chickens and affiliates. [Deborah Servili] * Add ransomwares. [Deborah Servili] * Add Operation Poison Needles. [Deborah Servili] * Add clusters. [Deborah Servili] * Add several clusters. [Deborah Servili] * Merge branch 'Delta-Sierra-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master. [Alexandre Dulaunoy] * Add DNSpionage cluster. [Deborah Servili] * Add everbe rasomnotes. [Deborah Servili] * Add ransomwares. [Deborah Servili] * Add ransomwares. [Deborah Servili] * Merge pull request #309 from cvandeplas/master. [Alexandre Dulaunoy] pep8, include the misp-galaxy tag in the output * Pep8, include the misp-galaxy tag in the output. [Christophe Vandeplas] * Add: [doc] contribution doc added. [Alexandre Dulaunoy] * Merge pull request #306 from SteveClement/master. [Steve Clement] chg: [doc] Added some dependency pointers. * Merge pull request #305 from Delta-Sierra/master. [Alexandre Dulaunoy] Add Rotexy * Add Aurora Ransomware metadata. [Deborah Servili] * Add Aurora Ransomware synonym. [Deborah Servili] * Fix version. [Deborah Servili] * Add Rotexy. [Deborah Servili] * Merge pull request #304 from Delta-Sierra/master. [Alexandre Dulaunoy] add PNG Dropper * Update version. [Deborah Servili] * Add PNG Dropper. [Deborah Servili] * Merge pull request #303 from Delta-Sierra/master. [Deborah Servili] add several references for Emotet and others * Add reference for Emotet/Geodo. [Deborah Servili] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy. [Deborah Servili] * Add several references for Emotet and others. [Deborah Servili] * Merge pull request #302 from Delta-Sierra/master. [Alexandre Dulaunoy] update oilrig related clusters + others * Merge branch 'master' into master. [Deborah Servili] * Merge branch 'Delta-Sierra-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master. [Alexandre Dulaunoy] * Merge pull request #300 from Delta-Sierra/master. [Deborah Servili] add several rqansomware and HookAds campaign * Update oilrig related clusters + others. [Deborah Servili] * Fix rat galaxy version. [Deborah Servili] * Jq and add ref in tool galaxy -hit version 100- [Deborah Servili] * Add TheOneSpy. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #299 from b3n7s/patch-1. [Alexandre Dulaunoy] Update threat-actor.json * Update threat-actor.json. [Benoit Sevens] Add LuckyMouse link * Merge pull request #297 from danielplohmann/patch-1. [Alexandre Dulaunoy] added APT38 as (FireEye) alias for Lazarus * Added APT38 as (FireEye) alias for Lazarus. [Daniel Plohmann] cross-references in https://content.fireeye.com/apt/rpt-apt38 suggest the link to Lazarus. * Merge branch 'Delta-Sierra-master' [Alexandre Dulaunoy] * Add several rqansomware and HookAds campaign. [Deborah Servili] * Add/update ransomawares. [Deborah Servili] * Add several tools and refs. [Deborah Servili] * Merge pull request #296 from Delta-Sierra/master. [Deborah Servili] update ransomware galaxy * Update ransomware galaxy. [Deborah Servili] * Merge pull request #295 from Delta-Sierra/master. [Alexandre Dulaunoy] update Red Alert 2 Android Banking Trojan * Jq fix. [Deborah Servili] * Update version. [Deborah Servili] * Update Red Alert 2 Android Banking Trojan. [Deborah Servili] * Merge pull request #294 from Delta-Sierra/master. [Deborah Servili] add ransomwares * Add ransomwares. [Deborah Servili] * Merge pull request #293 from Delta-Sierra/master. [Alexandre Dulaunoy] add Operation EvilTraffic * Add Chalubo botnet (+ jqallthethings) [Deborah Servili] * Add Operation EvilTraffic. [Deborah Servili] * Add Operation EvilTraffic. [Deborah Servili] * Merge pull request #292 from 3c7/master. [Alexandre Dulaunoy] Corrected DarkHotel threat actor entry * Corrected DarkHotel threat actor entry. [Nils Kuhnert] * Merge pull request #291 from Delta-Sierra/master. [Deborah Servili] Clusters & references * Fix duplicate ref. [Deborah Servili] * Add August Stealer. [Deborah Servili] * Add NukeSped reference. [Deborah Servili] * Add GhostMiner. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #290 from cvandeplas/master. [Alexandre Dulaunoy] tool: experimental graphing tool * Tool: experimental graphing tool. [Christophe Vandeplas] * Merge pull request #289 from cvandeplas/master. [Alexandre Dulaunoy] chg: further categorization of galaxies * Merge pull request #288 from cvandeplas/master. [Alexandre Dulaunoy] categorization of galaxies * Jq. [Christophe Vandeplas] * Merge remote-tracking branch 'MISP/master' [Christophe Vandeplas] * Merge pull request #287 from cvandeplas/master. [Alexandre Dulaunoy] fixes an important bug in the gen_relations * Some minor fixes. [Andras Iklody] * Merge remote-tracking branch 'MISP/master' [Christophe Vandeplas] * Merge pull request #286 from Delta-Sierra/master. [Alexandre Dulaunoy] Several clusters, refs, others. * Merge pull request #285 from cvandeplas/master. [Alexandre Dulaunoy] MITRE relationships included in the respective cluster * Merge pull request #284 from cvandeplas/master. [Alexandre Dulaunoy] chg: mappings are now in the generated adoc * Add tools from https://github.com/misterch0c/shadowbroker. [Deborah Servili] * Add DarkPulsar and affiliates + update some refs. [Deborah Servili] * Add GreyEnergy. [Deborah Servili] * Add refs & synonyms. [Deborah Servili] * Add several refs. [Deborah Servili] * Add several refs. [Deborah Servili] * Add roaming mantis group. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #283 from cvandeplas/master. [Alexandre Dulaunoy] fixes + relations with malpedia * Jq sort keys. [Christophe Vandeplas] Allows automation to edit the files * Merge branch 'steffenenders-patch-1' [Alexandre Dulaunoy] * Jq all the things. [Alexandre Dulaunoy] * Updated malpedia.json to the current state. [Steffen Enders] Fetched the new malpedia galaxy cluster from https://malpedia.caad.fkie.fraunhofer.de/api/get/misp - this includes an additional ~120 new families. * Merge pull request #281 from Delta-Sierra/master. [Deborah Servili] add SAVEfiles ransomware * Merge pull request #280 from Delta-Sierra/master. [Deborah Servili] update matrix ransomware * Add magecart ref. [Deborah Servili] * Add SAVEfiles ransomware. [Deborah Servili] * Update version. [Deborah Servili] * Update matrix ransomware. [Deborah Servili] * Merge pull request #279 from Delta-Sierra/master. [Alexandre Dulaunoy] add Triout Android Malware * Add Triout Android Malware. [Deborah Servili] * Merge pull request #278 from Delta-Sierra/master. [Alexandre Dulaunoy] fix failed copy-paste * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #276 from Delta-Sierra/master. [Alexandre Dulaunoy] add CoalaBot + Kraken Cryptor Ransmware + refs * Merge pull request #277 from dadokkio/master. [Alexandre Dulaunoy] Added Malpedia Galaxy * Added Malpedia Galaxy. [Davide Arcuri] based on malpedia git repo * Merge pull request #274 from Delta-Sierra/master. [Alexandre Dulaunoy] Refs updates * Merge pull request #273 from Delta-Sierra/master. [Alexandre Dulaunoy] update synonyms & attributions * Merge pull request #272 from Delta-Sierra/master. [Deborah Servili] New clusters based on CIG Circular 66 – FASTCash ATM Cash Out Campaign * Merge pull request #271 from Delta-Sierra/master. [Alexandre Dulaunoy] Several updates * Fix failed copy-paste. [Deborah Servili] * Jq. [Deborah Servili] * Add CoalaBot + Kraken Cryptor Ransmware + refs. [Deborah Servili] * Add CoalaBot + Kraken Cryptor Ransmware + refs. [Deborah Servili] * Add Persirai botnet. [Deborah Servili] * Update Torii botnet. [Deborah Servili] * Add ref for Torii botnet. [Deborah Servili] * Add refs. [Deborah Servili] * Add ZEBROCY tool. [Deborah Servili] * Update regarding https://twitter.com/adulau/status/1047764090410737664. [Deborah Servili] * Update synonyms & attributions. [Deborah Servili] * Add NukeSped. [Deborah Servili] * Add FASTCash. [Deborah Servili] * Add ref for magecart. [Deborah Servili] * New threat actors & tools. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #270 from Delta-Sierra/master. [Alexandre Dulaunoy] new clusters, relations and information * Merge pull request #268 from botherder/master. [Alexandre Dulaunoy] Added missing country values * Added missing country values. [Nex] * Merge pull request #267 from Delta-Sierra/master. [Alexandre Dulaunoy] New clusters * Merge pull request #266 from Delta-Sierra/master. [Alexandre Dulaunoy] small updates * Merge pull request #265 from Delta-Sierra/master. [Alexandre Dulaunoy] new threat actors * Merge pull request #264 from Delta-Sierra/master. [Alexandre Dulaunoy] more clusters~ * Add synonym. [Deborah Servili] * Add refs. [Deborah Servili] * Jq. [Deborah Servili] * New clusters and informtion. [Deborah Servili] * New ransomware and relations. [Deborah Servili] * Add relationships on Mirai. [Deborah Servili] * Add references. [Deborah Servili] * Add BusyGasper android spyware. [Deborah Servili] * Add Cobalt Dickensthreat actor. [Deborah Servili] * Add remcos ref. [Deborah Servili] * Update version. [Deborah Servili] * Fix field mistake. [Deborah Servili] * Update Lazarus group cluster. [Deborah Servili] * New unnamedthreat actor. [Deborah Servili] * New threat actors. [Deborah Servili] * Merge. [Deborah Servili] * Merge pull request #263 from botherder/bahamut. [Alexandre Dulaunoy] Added Bahamut to threat actors list * Added Bahamut to threat actors list. [Nex] * Merge pull request #262 from botherder/mythic-leopard. [Alexandre Dulaunoy] Added additional name to C-Major * Added additional name to C-Major. [Nex] * Merge pull request #261 from botherder/dedup. [Alexandre Dulaunoy] Removed duplicates * Removed duplicates. [Nex] * Merge pull request #259 from botherder/country-sync. [Alexandre Dulaunoy] Synced country codes with suspected state sponsor * Synced country codes with suspected state sponsor. [Nex] * Merge pull request #258 from botherder/transparent-tribe. [Alexandre Dulaunoy] Merged Transparent Tribe in C-Major * Merged Transparent Tribe in C-Major. [Nex] * Merge pull request #257 from Delta-Sierra/master. [Alexandre Dulaunoy] adding and updating clusters * Merge pull request #256 from Delta-Sierra/master. [Alexandre Dulaunoy] add ref for operation Applejeus * Merge pull request #255 from Delta-Sierra/master. [Alexandre Dulaunoy] Schema update * Merge pull request #254 from Delta-Sierra/master. [Alexandre Dulaunoy] add ransomwares * Add notpetya and update jadeRAT. [Deborah Servili] * Add references. [Deborah Servili] * Add magentocore malware. [Deborah Servili] * Add blacknurse logo. [Deborah Servili] * Add blacknurse. [Deborah Servili] * Add Crypt0saur ransomware. [Deborah Servili] * Adding and updating clusters. [Deborah Servili] * Add description for sigma ransomware. [Deborah Servili] * Fix versions. [Deborah Servili] * Add ref for operation Applejeus. [Deborah Servili] * Fix version. [Deborah Servili] * Add Operation AppleJeus. [Deborah Servili] * Fix schema. [Deborah Servili] * Fix some relations. [Deborah Servili] * Clusters. [Deborah Servili] * More clusters~ [Deborah Servili] * Add CamuBot Banker Trojan. [Deborah Servili] * Jq~ [Deborah Servili] * Add ransomwares. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * "jq all the thing (tm)" [Alexandre Dulaunoy] * Merge branch 'Kafeine-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Kafeine/misp-galaxy into Kafeine-master. [Alexandre Dulaunoy] * + Fallout. [Kafeine] * Hunter EK > Active. [Kafeine] * Adding Underminer EK. [Kafeine] * Status from Terror, Bingo and Astrum. [Kafeine] * Adapting to modification from Misp repository. [Kafeine] * Merge pull request #250 from Delta-Sierra/master. [Alexandre Dulaunoy] add cfr data * Add ransomware. [Deborah Servili] * Add cfr data. [Deborah Servili] * Update microsoft-activity-group.json version. [Deborah Servili] * Merge pull request #249 from Delta-Sierra/master. [Alexandre Dulaunoy] Update and add threat actors * More clusters. [Deborah Servili] * Add APT28/STRONTIUM refs. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #248 from Delta-Sierra/master. [Deborah Servili] merge black ruby duplicate (delete the newer) * Merge pull request #247 from Delta-Sierra/master. [Alexandre Dulaunoy] New clusters * Update Dharma Ransomware. [Deborah Servili] * Version update. [Deborah Servili] * Merge black ruby duplicate (delete the newer) [Deborah Servili] * Merge. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Fix. [Deborah Servili] * Resolve merge confilct -I hope- [Deborah Servili] * Cosmetic change. [Christophe Vandeplas] * No change: dump files with sort_keys=True. [Christophe Vandeplas] This is needed to keep better track of the changes when other tools load and save the json files. * Merge pull request #246 from Delta-Sierra/master. [Deborah Servili] add Skygofree android spyware * Merge pull request #245 from Delta-Sierra/master. [Alexandre Dulaunoy] add tools used by SamSam * Merge pull request #244 from Delta-Sierra/master. [Deborah Servili] add ransomwares * Fix typo and missing uuid. [Deborah Servili] * Add Rosenbridge backdoor. [Deborah Servili] * Add KEYPASS ransomware. [Deborah Servili] * Add Skygofree android spyware. [Deborah Servili] * Add tools used by SamSam. [Deborah Servili] * Add ransomwares. [Deborah Servili] * Merge branch 'Delta-Sierra-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master. [Alexandre Dulaunoy] * Update schema. [Deborah Servili] * Update schema. [Deborah Servili] * Tags is an array. [Deborah Servili] * Relationship system - v2. [Deborah Servili] * Update some clusters and try to add a relationship system. [Deborah Servili] * Merge pull request #242 from Delta-Sierra/master. [Deborah Servili] add RedAlpha campaigns * Add RedAlpha campaigns. [Deborah Servili] * Merge pull request #239 from Delta-Sierra/master. [Alexandre Dulaunoy] more clusters * Delete forgotten conflict marker. [Deborah Servili] * Resolve merge conflict. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Resolve merge conflict. [Deborah Servili] * Merge pull request #241 from 3c7/threat-actor/darkhydrus. [Andras Iklody] Added DarkHydrus * Added DarkHydrus. [Nils Kuhnert] * Merge pull request #240 from 3c7/fix/typos. [Alexandre Dulaunoy] Two small typos * Two small typos. [Nils Kuhnert] * Merge pull request #238 from Delta-Sierra/master. [Alexandre Dulaunoy] add Kronos Banking Trojan * Merge pull request #237 from Delta-Sierra/master. [Deborah Servili] Add CFR.org metadata into the galaxy - part 2 * Delete duplicate gorgon group. [Deborah Servili] * More clusters. [Deborah Servili] * Add Kronos Banking Trojan. [Deborah Servili] * Add CFR.org metadata into the galaxy - part 2. [Deborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #236 from raw-data/master. [Alexandre Dulaunoy] [add] new cluster + galaxy * [add] new backdoor cluster. [raw-data] * [add] new backdoor galaxy and cluster. [raw-data] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Raphaël Vinot] * Merge pull request #235 from raw-data/master. [Alexandre Dulaunoy] [add] x1 new entry in stealer.json - AZORult * [add] x1 new entry in stealer.json - AZORult. [raw-data] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #234 from Delta-Sierra/master. [Alexandre Dulaunoy] cfr update -in progress- + add clusters associated to RANCOR * Merging attempt. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #233 from Delta-Sierra/master. [Alexandre Dulaunoy] Add CFR.org metadata into the galaxy - Test * Merge pull request #231 from raw-data/master. [Alexandre Dulaunoy] [ADD] new entries in banker, rat and tool * [ADD] x1 new entry in tool.json - Koadic. [raw-data] * [ADD] x2 new rat - Sisfader, SocketPlayer. [raw-data] * [ADD] banker.json version bump. [raw-data] * [ADD] x2 new banker - Backswap, Karius. [raw-data] * Merge pull request #230 from 3c7/patch-1. [Alexandre Dulaunoy] Updated APT1 report link * Updated APT1 report link. [Nils Kuhnert] * Update cert-eu-govsector.json. [Deborah Servili] * Update cert-eu-govsector.json. [Deborah Servili] * Fix typo in type. [Deborah Servili] * Merge pull request #229 from iglocska/patch-1. [Andras Iklody] Fixed typo * Fixed typo. [Andras Iklody] * Merge pull request #228 from Delta-Sierra/master. [Alexandre Dulaunoy] add Thrip as threat actor * Merge pull request #227 from Delta-Sierra/master. [Andras Iklody] Ransomwares and Olympic Destroyer * Merge pull request #226 from Delta-Sierra/master. [Alexandre Dulaunoy] Even more clusters * Merge pull request #225 from Delta-Sierra/master. [Alexandre Dulaunoy] More ransomwares and other clusters * Add cfr related informations -still in progress- [Deborah Servili] * Cfr update -in progress + add clusters associated to RANCOR. [Deborah Servili] * Add cfr prefix for cfr data - test. [Deborah Servili] * Add CFR.org metadata into the galaxy - Test. [Deborah Servili] * Some updates. [Deborah Servili] * Update verion. [Deborah Servili] * Add Thrip as threat actor. [Deborah Servili] * Add olympic destroyer. [Deborah Servili] * Add severals ransomware. [Deborah Servili] * More clusters. [Deborah Servili] * Add cluster in threat actor. [Deborah Servili] * Add ClipboardWalletHijacker. [Deborah Servili] * Add MysteryBot in android galaxy. [Deborah Servili] * Add some ransomwares. [Deborah Servili] * Merge pull request #224 from Delta-Sierra/master. [Alexandre Dulaunoy] add some clusters * Add some tools. [Deborah Servili] * Update version. [Deborah Servili] * Add some clusters. [Deborah Servili] * Minor layout corrections - validate_all. [Christophe Vandeplas] * Merge pull request #222 from Kafeine/master. [Christophe Vandeplas] * Merge pull request 222. [Christophe Vandeplas] * Fix. [Kafeine] * + Glazunov. [Kafeine] * Guuid & + VenomKit. [Kafeine] * +ThreadKit. [Kafeine] * +Glazunov. [Kafeine] * Merge pull request #223 from Delta-Sierra/master. [Deborah Servili] Add tools * Add BabaYaga Malware. [Deborah Servili] * Add PLEAD. [Deborah Servili] * Merge pull request #221 from Delta-Sierra/master. [Alexandre Dulaunoy] New clusters * Add sigrun ransomware's ransomnotes. [Deborah Servili] * Add Sigrun ransomwaremeta data. [Deborah Servili] * Add Sigrun ransomware. [Deborah Servili] * Add another cryptomix variant. [Deborah Servili] * Add Brambul worm. [Deborah Servili] * Add Joanap RAT. [Deborah Servili] * Add: Iron Backdoor. [Alexandre Dulaunoy] * Merge pull request #220 from raw-data/master. [Alexandre Dulaunoy] [ADD] New Stealer galaxy and cluster * [FIX] botnet file link. [raw-data] * [ADD] Stealer galaxy definition. [raw-data] * [ADD] x2 new info/pwd stealers - Nocturnal Stealer, TeleGrab. [raw-data] * [ADD] Introduced stealer cluster. [raw-data] * Merge pull request #219 from raw-data/master. [Alexandre Dulaunoy] [ADD] x2 new entries for banker.json and rat.json * [ADD] NavRAT. [raw-data] * [ADD] DanaBot. [raw-data] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #218 from Delta-Sierra/master. [Alexandre Dulaunoy] fix typo in pre-attack-relationship script - thanks @Terrtia * Fix typo in pre-attack-relationship script - thanks @Terrtia. [Deborah Servili] * Merge pull request #217 from Terrtia/master. [Alexandre Dulaunoy] fix typo mitre-pre-attack-relationship * Fix typo mitre-pre-attack-relationship. [Thirion Aurélien] * Merge pull request #216 from raw-data/master. [Alexandre Dulaunoy] [ADD] VPNFilter in tool.json cluster * [ADD] VPNFilter in tool.json cluster. [raw-data] * Merge pull request #215 from raw-data/master. [Alexandre Dulaunoy] [ADD] Pontoeb, WICKED and Brain Food into botnet.json cluster * [ADD] Pontoeb, WICKED and Brain Food into botnet.json cluster. [raw-data] * Add: mitre-attack namespace for all the ATT&CK galaxies. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Raphaël Vinot] * Merge pull request #214 from Delta-Sierra/master. [Deborah Servili] update mitre galaxies - add external id and killchain * Jq. [Deborah Servili] * Fix scripts for nobile and pre attack attack pattern. [Deborah Servili] * Jq. [Deborah Servili] * Update mitre galaxies - add external id and killchain. [Deborah Servili] * Merge pull request #213 from Delta-Sierra/master. [Alexandre Dulaunoy] update mitre 2.0 scripts to add external_id in meta * Update mitre 2.0 scripts to add external_id in meta (still need to be tested) [Deborah Servili] * Schema updated to have namespace key at galaxy level. [Alexandre Dulaunoy] * Merge pull request #211 from eCrimeLabs/master. [Alexandre Dulaunoy] Added links in relation to Threat-actor info from Dragos * Added data related to Dragos Adverseries. [Dennis Rand] * Merge pull request #2 from MISP/master. [eCrimeLabs] Updated from Core * Merge pull request #209 from raw-data/master. [Alexandre Dulaunoy] [ADD] RadRAT, ARS VBS Loader and FlawedAmmyy into rat.json cluster * [ADD] RadRAT, ARS VBS Loader and FlawedAmmyy into rat.json cluster. [raw-data] * Merge pull request #210 from Delta-Sierra/master. [Deborah Servili] update/add some clusters * Add Stalinlocker. [Deborah Servili] * Add Mettle botnet. [Deborah Servili] * Update some clusters. [Deborah Servili] * Merge pull request #208 from Delta-Sierra/master. [Deborah Servili] add maikspy * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #207 from Delta-Sierra/master. [Deborah Servili] New clusters * Merge pull request #206 from Delta-Sierra/master. [Alexandre Dulaunoy] update ransomware version * Merge pull request #205 from Delta-Sierra/master. [Deborah Servili] update - GandCrab v3 * Merge pull request #204 from Delta-Sierra/master. [Alexandre Dulaunoy] New clusters~ * Merge pull request #203 from Delta-Sierra/master. [Deborah Servili] add ZooPark campaign * Add maikspy. [Deborah Servili] * Jq~ [Deborah Servili] * Add reference for HNS botnet. [Deborah Servili] * Add HNS bot net & HPE iLO 4 Ransomware/Wiper. [Deborah Servili] * Add Kitty malware. [Deborah Servili] * Update version -oops- [Deborah Servili] * Update - GandCrab v3. [Deborah Servili] * Add an unnamed ransomware. [Deborah Servili] * Add spymaster pro as rat. [Deborah Servili] * Add ZooPark campaign. [Deborah Servili] * Add: threat actors from Dragos Inc. (based on https://dragos.com/adversaries.html) [Alexandre Dulaunoy] * Merge pull request #202 from Delta-Sierra/master. [Alexandre Dulaunoy] MOAR & MOAR Clusters * Jq. [Deborah Servili] * Add Rubella Macro Builder. [Deborah Servili] * Add GravityRAT. [Deborah Servili] * Add HOGFISH as APT10 synonym. [Deborah Servili] * Merge pull request #201 from Delta-Sierra/master. [Alexandre Dulaunoy] add Henbox * Add Henbox. [Deborah Servili] * Merge pull request #200 from Delta-Sierra/master. [Alexandre Dulaunoy] MOAR CLUSTERS * Add Orangeworm, Kwampirs, Iron ransomware and Ton ransomware. [Deborah Servili] * Add Muhstik botnet. [Deborah Servili] * Merge pull request #199 from StefanKelm/master. [Alexandre Dulaunoy] add NMCRYPT ransomware * NMCRYPT ransomware. [Stefan Kelm] * Merge pull request #198 from Delta-Sierra/master. [Deborah Servili] add Xiaoba * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy. [Deborah Servili] * Update Ransomware galaxy version. [Deborah Servili] * Jq. [Deborah Servili] * Add Xiaoba. [Deborah Servili] * Merge pull request #197 from Delta-Sierra/master. [Deborah Servili] add some ransomwares * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #195 from droe/master. [Alexandre Dulaunoy] Add Comnie RAT * Add Comnie RAT. [Daniel Roethlisberger] * Merge pull request #194 from StefanKelm/master. [Alexandre Dulaunoy] Update to 'Chthonic' galaxy * Added 'Chtonic' synonym. [StefanKelm] * Remove Chthonic since it's a duplicate (banker.json) [StefanKelm] * Merge pull request #192 from Delta-Sierra/master. [Deborah Servili] add some ransomwares & threat actors * Merge pull request #191 from Delta-Sierra/master. [Deborah Servili] add Rovnix * Merge pull request #190 from Delta-Sierra/master. [Deborah Servili] add LockCrypt ransomware & GoScanSSH tool * Merge pull request #189 from Delta-Sierra/master. [Deborah Servili] add PUBG ransomware * Merge pull request #188 from Delta-Sierra/master. [Deborah Servili] update matrix ransomware * Merge pull request #187 from Delta-Sierra/master. [Deborah Servili] update threat actor galaxy based on https://www.fireeye.com/content/d… * Add some ransomwares. [Deborah Servili] * Add some ransomwares & threat actors. [Deborah Servili] * Add Rovnix. [Deborah Servili] * Add IcedID reference. [Deborah Servili] * Add GoScanSSH tool. [Deborah Servili] * Add LockCrypt ransomware. [Deborah Servili] * Jq. [Deborah Servili] * Add PUBG ransomware. [Deborah Servili] * Update matrix ransomware. [Deborah Servili] * Update version. [Deborah Servili] * Update matrix ransomware. [Deborah Servili] * Update threat actor galaxy based on https://www.fireeye.com/content/dam/collateral/en/mtrends-2018.pdf. [Deborah Servili] * Merge pull request #186 from Delta-Sierra/master. [Deborah Servili] add BlackRuby& WhiteRose ransomwares (+some fix) * Add BlackRuby& WhiteRose ransomwares (+some fix) [Deborah Servili] * Merge pull request #185 from Delta-Sierra/master. [Deborah Servili] merge the two Igexin clusters - fix #183 * Merge the two Igexin clusters - fix #183. [Deborah Servili] * Merge pull request #184 from Delta-Sierra/master. [Deborah Servili] add 2 -supposed- wipers * Add 2 -supposed- wipers. [Deborah Servili] * Merge pull request #182 from Delta-Sierra/master. [Deborah Servili] Add hajime botnet + update cryptomix (new variant) * Update ransomware galaxy versionC. [Deborah Servili] * Update cryptomix. [Deborah Servili] * Update botnet version. [Deborah Servili] * Complete hajime botnet. [Deborah Servili] * Add hajime botnet. [Deborah Servili] * Merge pull request #181 from Delta-Sierra/master. [Deborah Servili] add external_id to values (MITRE galaxies) * Jq. [Deborah Servili] * Add external_id to values. [Deborah Servili] * Add: SHARPKNOT. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Raphaël Vinot] * Merge pull request #179 from Delta-Sierra/master. [Alexandre Dulaunoy] add several tools * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Add several tools. [Deborah Servili] * Merge pull request #176 from StefanKelm/master. [Alexandre Dulaunoy] Cosmetic changes only * Update mitre-enterprise-attack-intrusion-set.json. [StefanKelm] * Update create_mitre-enterprise-attack-tool_galaxy.py. [StefanKelm] * Update create_mitre-enterprise-attack-relationship_galaxy.py. [StefanKelm] * Update create_mitre-enterprise-attack-malware_galaxy.py. [StefanKelm] * Update create_mitre-enterprise-attack-intrusion-set_galaxy.py. [StefanKelm] * Update create_mitre-enterprise-attack-course-of-action_galaxy.py. [StefanKelm] * Update create_mitre-enterprise-attack-attack-pattern_galaxy.py. [StefanKelm] * Update mitre-enterprise-attack-intrusion-set.json. [StefanKelm] * Update README.md. [StefanKelm] * Update and rename mitre-entreprise-attack-tool.json to mitre-enterprise-attack-tool.json. [StefanKelm] * Rename mitre-entreprise-attack-relationship.json to mitre-enterprise-attack-relationship.json. [StefanKelm] * Update mitre-entreprise-attack-relationship.json. [StefanKelm] * Update and rename mitre-entreprise-attack-malware.json to mitre-enterprise-attack-malware.json. [StefanKelm] * Update and rename mitre-entreprise-attack-intrusion-set.json to mitre-enterprise-attack-intrusion-set.json. [StefanKelm] * Update and rename mitre-entreprise-attack-course-of-action.json to mitre-enterprise-attack-course-of-action.json. [StefanKelm] * Update and rename mitre-entreprise-attack-attack-pattern.json to mitre-enterprise-attack-attack-pattern.json. [StefanKelm] * Update and rename mitre-entreprise-attack-tool.json to mitre-enterprise-attack-tool.json. [StefanKelm] * Update and rename mitre-entreprise-attack-relationship.json to mitre-enterprise-attack-relationship.json. [StefanKelm] * Update and rename mitre-entreprise-attack-malware.json to mitre-enterprise-attack-malware.json. [StefanKelm] * Update and rename mitre-entreprise-attack-intrusion-set.json to mitre-enterprise-attack-intrusion-set.json. [StefanKelm] * Update mitre-enterprise-attack-course-of-action.json. [StefanKelm] * Update and rename mitre-entreprise-attack-course-of-action.json to mitre-enterprise-attack-course-of-action.json. [StefanKelm] * Update and rename mitre-entreprise-attack-attack-pattern.json to mitre-enterprise-attack-attack-pattern.json. [StefanKelm] * Merge pull request #175 from Delta-Sierra/master. [Deborah Servili] add Zenis ransomware * Update Android galaxy based on: https://source.android.com/security/reports/Google_Android_Security_2017_Report_Final.pdf - possible duplicates! [Deborah Servili] * Add Zenis ransomware. [Deborah Servili] * Merge pull request #174 from Delta-Sierra/master. [Deborah Servili] add gamut botnet * Merge branch 'master' into master. [Deborah Servili] * Merge pull request #173 from danielplohmann/leviathan. [Alexandre Dulaunoy] adding Leviathan / TEMP.Periscope * Added leviathan. [Daniel Plohmann (jupiter)] * Merge pull request #172 from eCrimeLabs/master. [Alexandre Dulaunoy] Added RoyalCli and RoyalDNS related to APT15 based on information from NCC Group * Added RoyalCli and RoyalDNS related to APT15 based on information from NCC Group. [Dennis Rand] * Merge pull request #1 from MISP/master. [eCrimeLabs] Syncing Fork * Merge pull request #171 from Delta-Sierra/master. [Alexandre Dulaunoy] add qwerty ransomware * Merge pull request #170 from eCrimeLabs/master. [Alexandre Dulaunoy] Malware Used by APT37 * Malware Used by APT37. [eCrimeLabs] Malware Used by APT37 * Added tools from APT37. [eCrimeLabs] Malware Used by APT37 * Merge pull request #167 from Delta-Sierra/master. [Alexandre Dulaunoy] update some clusters * Merge pull request #166 from Delta-Sierra/master. [Alexandre Dulaunoy] add Nautilus, Neuron and update GandCrab * Merge pull request #165 from Delta-Sierra/master. [Alexandre Dulaunoy] add some tools * Merge pull request #164 from Delta-Sierra/master. [Alexandre Dulaunoy] add RSAUtil and Coldroot * Merge pull request #163 from Delta-Sierra/master. [Alexandre Dulaunoy] Add TSCookie Malware and RAT * Add gamut botnet. [Deborah Servili] * Jq. [Deborah Servili] * Add qwertyransomware. [Deborah Servili] * Update version. [Deborah Servili] * Jq. [Deborah Servili] * Add missing uuid. [Deborah Servili] * Add ref for BS2005. [Deborah Servili] * Update Mirage Threat actor. [Deborah Servili] * Add Nautilus, Neuron and update GandCrab. [Deborah Servili] * Update GandCrab. [Deborah Servili] * Jq all the things. [Deborah Servili] * Add missing uuid. [Deborah Servili] * Add Shipup. [Deborah Servili] * Add ghotex. [Deborah Servili] * Add miniflame. [Deborah Servili] * Add Downloader-FGO. [Deborah Servili] * Add Cheshire Cat -hack.lu video as reference! [Deborah Servili] * Add Aurora/Hydraq. [Deborah Servili] * Add Rotinom. [Deborah Servili] * Add Exforel. [Deborah Servili] * Add RSAUtil and Coldroot. [Deborah Servili] * Add TSCookie Malware and RAT. [Deborah Servili] * Merge pull request #162 from Delta-Sierra/master. [Alexandre Dulaunoy] add uuid to every cluster * Jq. [Deborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Fix #161. [Alexandre Dulaunoy] * Merge pull request #160 from Delta-Sierra/master. [Alexandre Dulaunoy] add botnets to galaxy * Merge pull request #159 from Delta-Sierra/master. [Alexandre Dulaunoy] add MITRE Galaxies V2.0 * Modify argument in add_missing_uuid script. [Deborah Servili] * Jq ftw. [Deborah Servili] * Add uuid to every cluster. [Deborah Servili] * Add extension for Thanatos ransomware. [Deborah Servili] * Add botnets to galaxy. [Deborah Servili] * Add Thanatos ransomware. [Deborah Servili] * Removing duplicates refs - 2. [Deborah Servili] * Manage duplicate refs - first try. [Deborah Servili] * Clean version. [Deborah Servili] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Deborah Servili] * Add: UUID also at value level. [Alexandre Dulaunoy] * Merge pull request #157 from Delta-Sierra/master. [Alexandre Dulaunoy] add botnet galaxy and other stuffs * Merge pull request #156 from Delta-Sierra/master. [Alexandre Dulaunoy] complete gandcrab - add ransomnotes * Merge pull request #155 from Delta-Sierra/master. [Alexandre Dulaunoy] add gandcrap ransomware + update references * Jq all the things. [Deborah Servili] * Add uuid as a field. [Deborah Servili] * Fix empty meta field. [Deborah Servili] * Add MITRE Galaxies V2.0. [Deborah Servili] * Add botnet galaxy to readme. [Deborah Servili] * Create botnet galaxy. [Deborah Servili] * Add ShurL0ckr ransomware. [Deborah Servili] * Add synonym and ref for Emissary Panda (Iron Tiger APT) [Deborah Servili] * Jq. [Deborah Servili] * Complete gandcrab. [Deborah Servili] * Add gandcrap ransomware + update references. [Deborah Servili] * Merge branch 'Kafeine-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Kafeine/misp-galaxy into Kafeine-master. [Alexandre Dulaunoy] * ~Sakura description. [Kafeine] * +SPL Exploit Kit, ~Grandsoft. [Kafeine] * BlackTDS added. [Kafeine] * Merge pull request #153 from Delta-Sierra/master. [Alexandre Dulaunoy] add Smominru * Add Smominru. [Deborah Servili] * Merge pull request #152 from Delta-Sierra/master. [Alexandre Dulaunoy] add CrossRat * Add CrossRat. [Deborah Servili] * Add ref to Nexus Zeta. [Alexandre Dulaunoy] * Add: Nexus Zeta is no stranger when it comes to implementing SOAP relatedrelated exploit ;-) [Alexandre Dulaunoy] * Add: Matsuta IoT botnet added. [Alexandre Dulaunoy] * Merge pull request #151 from danielplohmann/dark-caracal. [Alexandre Dulaunoy] adding dark caracal * Adding dark caracal. [Daniel Plohmann] * Merge pull request #150 from Delta-Sierra/master. [Alexandre Dulaunoy] add Digmine * Add Digmine. [Deborah Servili] * Merge pull request #149 from Delta-Sierra/master. [Alexandre Dulaunoy] add downAndExec * Add downAndExec. [Deborah Servili] * Merge pull request #148 from Delta-Sierra/master. [Deborah Servili] add travle/PYLOT * Add travle/PYLOT. [Deborah Servili] * Merge pull request #147 from Delta-Sierra/master. [Deborah Servili] fix forgotten value Microcin * Fix forgotten value Microcin. [Deborah Servili] * Merge pull request #146 from Delta-Sierra/master. [Alexandre Dulaunoy] add macOS malwares * Add macOS malwares. [Deborah Servili] * Merge pull request #145 from Delta-Sierra/master. [Alexandre Dulaunoy] add monero miner * Add monero miner. [Deborah Servili] * Merge pull request #144 from Delta-Sierra/master. [Alexandre Dulaunoy] rename files + update README.md * Rename files + update README.md. [Deborah Servili] * Merge pull request #143 from Delta-Sierra/master. [Alexandre Dulaunoy] New galaxy Branded Vulnerability * New galaxy Branded Vulnerability. [Deborah Servili] * Add in preventive measures: blacklisting phone numbers. [Alexandre Dulaunoy] * Merge pull request #142 from Delta-Sierra/master. [Alexandre Dulaunoy] add SedKit * Jqallthethings. [Deborah Servili] * Update Sofacy tools. [Deborah Servili] * Modify SedKit description. [Deborah Servili] * Add SedKit. [Deborah Servili] * Merge pull request #141 from Delta-Sierra/master. [Alexandre Dulaunoy] add "Power"tools * Add "Power"tools. [Deborah Servili] * Merge pull request #140 from Delta-Sierra/master. [Alexandre Dulaunoy] add satori (Mirai Variant) * Add satori (Mirai Variant) [Deborah Servili] * Merge pull request #139 from Delta-Sierra/master. [Alexandre Dulaunoy] update Android galaxy * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #138 from Delta-Sierra/master. [Alexandre Dulaunoy] add source for NewCore RAT * Merge pull request #137 from Delta-Sierra/master. [Alexandre Dulaunoy] update OilRig threat actor * Merge pull request #136 from Delta-Sierra/master. [Alexandre Dulaunoy] add OSX.Pirrit * Add PRILEX & CUTLET MAKER. [Deborah Servili] * Add GratefulPOS. [Deborah Servili] * Update Android galaxy. [Deborah Servili] * Add source for NewCore RAT. [Deborah Servili] * Update OilRig threat actor. [Deborah Servili] * Add file spider ransomware. [Deborah Servili] * Add OSX.Pirrit. [Deborah Servili] * TRISIS is the main name of TRITON as discussed in https://twitter.com/DragosInc/status/941355602512613381. [Alexandre Dulaunoy] * TRITON added. [Alexandre Dulaunoy] * Merge pull request #135 from Delta-Sierra/master. [Alexandre Dulaunoy] add Quant Loader * Add SSHDoor. [Deborah Servili] * Add cryptomix variant. [Deborah Servili] * Add Quant Loader. [Deborah Servili] * Merge pull request #134 from Delta-Sierra/master. [Deborah Servili] Add MoneyTaker * Add MoneyTaker. [Deborah Servili] * Update threat actor galaxy. [Deborah Servili] * Merge pull request #133 from Delta-Sierra/master. [Deborah Servili] add source for BankBot * Add source for BankBot. [Deborah Servili] * Merge branch 'Delta-Sierra-master' [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master. [Alexandre Dulaunoy] * Jq. [Deborah Servili] * Add malware/ransomwares. [Deborah Servili] * Merge conflict solved - wp-vcd added. [Alexandre Dulaunoy] * StrongPity2 added. [Alexandre Dulaunoy] * Merge pull request #131 from Delta-Sierra/master. [Deborah Servili] add SLocker * Add SLocker. [Deborah Servili] * Merge pull request #130 from Delta-Sierra/master. [Deborah Servili] add HC7 ransomware * Add HC7 ransomware. [Deborah Servili] * Merge pull request #129 from Delta-Sierra/master. [Deborah Servili] add StorageCrypt Ransomware * Add StorageCrypt Ransomware. [Deborah Servili] * Merge pull request #128 from Delta-Sierra/master. [Deborah Servili] add Halloware ransomware * Add Halloware ransomware. [Deborah Servili] * Merge pull request #127 from Delta-Sierra/master. [Deborah Servili] update cryptomix * Update cryptomix. [Deborah Servili] * Add: Tizi malware added. [Alexandre Dulaunoy] * Merge pull request #126 from Delta-Sierra/master. [Alexandre Dulaunoy] add UBoatRAT * Add UBoatRAT. [Deborah Servili] * Merge pull request #125 from Delta-Sierra/master. [Raphaël Vinot] update ROKRAT * Update ROKRAT. [Deborah Servili] * Merge pull request #124 from Delta-Sierra/master. [Deborah Servili] cryptomix - update * Cryptomix - update. [Deborah Servili] * Merge pull request #123 from Delta-Sierra/master. [Alexandre Dulaunoy] add IcedID banker * Add IcedID banker. [Deborah Servili] * Merge pull request #122 from Delta-Sierra/master. [Deborah Servili] cryptomix - merge duplicates and update * Cryptomix - add ransomnotes. [Deborah Servili] * Cryptomix - merge duplicates and update. [Deborah Servili] * Merge pull request #121 from Delta-Sierra/master. [Alexandre Dulaunoy] add Ordinypt * Add Ordinypt. [Deborah Servili] * Merge pull request #120 from Delta-Sierra/master. [Alexandre Dulaunoy] update tool galaxy * Jq. [Deborah Servili] * Update tool galaxy. [Deborah Servili] * Merge pull request #119 from steffenenders/patch-1. [Alexandre Dulaunoy] Fixed mixed up description/value for MuddyWater * Fixed mixed up description/value for MuddyWater. [steffenenders] * Merge pull request #118 from Delta-Sierra/master. [Alexandre Dulaunoy] add MuddyWater + Update HIDDEN COBRA and update its tools * Add MuddyWater + Update HIDDEN COBRA and update its tools. [Deborah Servili] * Merge pull request #117 from Delta-Sierra/master. [Alexandre Dulaunoy] add Silence Trojan * Add Silence Trojan. [Deborah Servili] * Merge pull request #116 from Delta-Sierra/master. [Alexandre Dulaunoy] Fix typo * Update version number. [Deborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #115 from Delta-Sierra/master. [Alexandre Dulaunoy] add ALMA Communicator * Merge pull request #114 from Delta-Sierra/master. [Alexandre Dulaunoy] add Sowbug group * Merge pull request #113 from Delta-Sierra/master. [Alexandre Dulaunoy] add sector vocabulary * Merge pull request #112 from Delta-Sierra/master. [Deborah Servili] update Felismus RAT * Merge pull request #111 from Delta-Sierra/master. [Alexandre Dulaunoy] Fix README.md AGAIN * Fix typo - Spaaaace~ [Deborah Servili] * Add ALMA Communicator. [Deborah Servili] * Add Sowbug group. [Deborah Servili] * Add sector vocabulary. [Deborah Servili] * Update Falismus RAT. [Deborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #110 from Delta-Sierra/master. [Alexandre Dulaunoy] Fix README.md * ##comma## AGAIN. [Deborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #108 from sbrom/master. [Alexandre Dulaunoy] Updated with data from APT Groups and Operations * Merge pull request #4 from frbor/fix-iso-code-3. [sbrom] Fix iso codes * Fix-iso-code-3. [Fredrik Borg] * Fix iso codes. [Fredrik Borg] * Merge pull request #2 from frbor/master. [sbrom] Remove duplicate references * Merge branch 'fix-duplicates' [Fredrik Borg] * Remove duplicate references. [Fredrik Borg] * Merge pull request #1 from frbor/master. [sbrom] Replace tab with space and add newline at end of file * Replace tab with space and add newline at end of file. [Fredrik Borg] * Updated with data from APT Groups and Operations. [Siri Bromander] * Merge pull request #109 from Delta-Sierra/master. [Alexandre Dulaunoy] update README * ##comma## [Deborah Servili] * Update README. [Deborah Servili] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #107 from frbor/iso-codes. [Raphaël Vinot] Use standard (2 digits) ISO codes for all countries * Bump version number. [Fredrik Borg] * Use standard (2 digits) ISO codes for all countries. [Fredrik Borg] * Update banker galaxy. [Raphaël Vinot] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Raphaël Vinot] * Merge pull request #106 from Delta-Sierra/master. [Deborah Servili] add htpRAT * Add htpRAT. [Deborah Servili] * Merge pull request #105 from Delta-Sierra/master. [Alexandre Dulaunoy] add dimnie * Add dimnie. [Deborah Servili] * Merge pull request #104 from Delta-Sierra/master. [Alexandre Dulaunoy] add ttp-categories descriptions * Add ttp-categories descripiions. [Deborah Servili] * Merge pull request #103 from Delta-Sierra/master. [Deborah Servili] add Formbook * Fix typo. [Deborah Servili] * Add Formbook. [Deborah Servili] * Cosmetic updates. [Raphaël Vinot] * Deduplicate Android cluster. [Raphaël Vinot] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Raphaël Vinot] * Merge pull request #102 from Delta-Sierra/master. [Alexandre Dulaunoy] delete x_ prefix from mitre_attack_pattern * Jq. [Deborah Servili] * Add galaxy icon to mitre-cti tools & regenerate galaxies. [Deborah Servili] * Delete x_ prefix from mitre_attack_pattern. [Deborah Servili] * Add android and banker galaxies. [Raphaël Vinot] * Remove the executable flag from the json files, again. [Raphaël Vinot] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Raphaël Vinot] * Merge pull request #101 from Delta-Sierra/master. [Deborah Servili] add BadRabbit ransomware * Add BadRabbit ransomware. [Deborah Servili] * Merge pull request #100 from Delta-Sierra/master. [Alexandre Dulaunoy] add cert EU govsectors galaxy * Update README.md. [Deborah Servili] * Add cert EU govsectors galaxy. [Deborah Servili] * Merge pull request #99 from Delta-Sierra/master. [Deborah Servili] typo * Typo. [Deborah Servili] * SOCKET23 RAT added. [Alexandre Dulaunoy] * JadeRAT added. [Alexandre Dulaunoy] * Merge pull request #98 from Delta-Sierra/master. [Alexandre Dulaunoy] add cert-eu based vocabularies * Jq. [Deborah Servili] * Add IoT_reaper. [Deborah Servili] * Delete duplicate. [Deborah Servili] * Add cert-eu based vocabularies. [Deborah Servili] * Jq all the things. [Alexandre Dulaunoy] * Merge pull request #97 from Delta-Sierra/master. [Alexandre Dulaunoy] add synonym in tool galaxy * Add synonym in tool galaxy. [Deborah Servili] * Merge pull request #96 from Delta-Sierra/master. [Alexandre Dulaunoy] add cert EU's motive vocabulary * ##comma## [Deborah Servili] * Add cert EU's motive vocabulary. [Deborah Servili] * Merge pull request #95 from Delta-Sierra/master. [Alexandre Dulaunoy] add sectors galaxy * Add sectors galaxy. [Deborah Servili] * Merge pull request #94 from Delta-Sierra/master. [Alexandre Dulaunoy] add lukitus extension to Locky * Add lukitus ransomnote to Locky. [Deborah Servili] * Add lukitus extension to Locky. [Deborah Servili] * Merge pull request #93 from Delta-Sierra/master. [Alexandre Dulaunoy] add year of apparition for Rats + fixing some typos * Fix typo. [Deborah Servili] * Add year of apparition for Rats + fixing some typos. [Deborah Servili] * Merge pull request #92 from Delta-Sierra/master. [Alexandre Dulaunoy] add Remote Access/Administration Tools * Jq. [Deborah Servili] * Add Remote Access/Administration Tools. [Deborah Servili] * Merge pull request #91 from danielplohmann/apt33. [Alexandre Dulaunoy] add APT33 as identified by FireEye * Add APT33 as identified by FireEye. [Daniel Plohmann] * Schema updated to include icon field. [Alexandre Dulaunoy] * As now everything is in the Blockchain, ransomware are too. [Alexandre Dulaunoy] * Icons for the grand Master who is redesigning the overall graphical view. [Alexandre Dulaunoy] * Merge pull request #90 from Delta-Sierra/master. [Deborah Servili] add Adwind RAT synonyms * Add Adwind RAT synonyms. [Deborah Servili] * Fix typo. [Deborah Servili] * Merge pull request #89 from Delta-Sierra/master. [Deborah Servili] add SyncCrypt Ransomwar * Add SyncCrypt Ransomwar. [Deborah Servili] * Merge pull request #88 from Delta-Sierra/master. [Deborah Servili] add SynAck Ransomware * Add SynAck Ransomware ransomnote's name. [Deborah Servili] * Add SynAck Ransomware. [Deborah Servili] * Merge pull request #87 from Delta-Sierra/master. [Alexandre Dulaunoy] add tools and rat * Fix typo~ [Deborah Servili] * Add tools and rat. [Deborah Servili] * Remove the executable flag from the json files. [Raphaël Vinot] * JQ all the things. [Raphaël Vinot] * Fixed with jq ;-) [Alexandre Dulaunoy] * Merge pull request #86 from Kafeine/master. [Alexandre Dulaunoy] Up EK and TDS * Merge branch 'master' into master. [Kafeine] * Merge pull request #85 from Delta-Sierra/master. [Deborah Servili] add ransomwares * Add ransomwares. [Deborah Servili] * Merge pull request #84 from Delta-Sierra/master. [Alexandre Dulaunoy] add fireball malware * Add fireball malware. [Deborah Servili] * Merge pull request #83 from Delta-Sierra/master. [Alexandre Dulaunoy] add Joao malware * Add Joao malware. [Deborah Servili] * EngineBox malware added. [Alexandre Dulaunoy] * Adversarial Tactics, Techniques & Common Knowledge from MITRE ATT&CK added. [Alexandre Dulaunoy] * Merge pull request #82 from Delta-Sierra/master. [Alexandre Dulaunoy] update mitre galaxies and scripts * Jq. [Deborah Servili] * Update mitre galaxies. [Deborah Servili] * Script mitre - version given as an input + renaming. [Deborah Servili] * Merge pull request #81 from Delta-Sierra/master. [Alexandre Dulaunoy] Fixed some issues with a misnamed galaxy - script * Fixed some issues with a misnamed galaxy - script. [Deborah Servili] * Fixed some issues with a misnamed galaxy. [iglocska] * Merge pull request #80 from Delta-Sierra/master. [Alexandre Dulaunoy] add mitre based galaxies * Version is integer. [Deborah Servili] * Put uuid as meta. [Deborah Servili] * New generation of mitre galaxies. [Deborah Servili] * Fix mitre-cti script - replace 'name' by 'value' [Deborah Servili] * Add mitre based galaxies. [Deborah Servili] * Asciidoctor-pdf is now stable. [Alexandre Dulaunoy] * Documentation generator added. [Alexandre Dulaunoy] * Merge pull request #79 from Delta-Sierra/master. [Alexandre Dulaunoy] add scripts to create galaxy from https://github.com/mitre/cti/tree/master/ATTACK * Add scripts to create galaxy from https://github.com/mitre/cti/tree/master/ATTACK - still under testing. [Deborah Servili] * Fix space typo. [Deborah Servili] * Merge pull request #78 from Delta-Sierra/master. [Alexandre Dulaunoy] add GlobeImposter synonym * Type is array -shh I'm bad with the format, I know. [Deborah Servili] * Type is meta. [Deborah Servili] * Jq~ [Deborah Servili] * Add/update tool galaxy. [Deborah Servili] * Add GlobeImposter synonym. [Deborah Servili] * Merge pull request #75 from Delta-Sierra/master. [Raphaël Vinot] add svpeng tool * Jq. [Deborah Servili] * Merge branch 'master' into master. [Deborah Servili] * Try to merge 'CowerSnail added' [Deborah Servili] * Add svpeng tool. [Deborah Servili] * Merge pull request #77 from danielplohmann/fin7. [Raphaël Vinot] added FIN7 as alias for anunak * Added FIN7 as alias for anunak. [Daniel Plohmann] * Merge pull request #76 from danielplohmann/axiom-merge. [Raphaël Vinot] merged barium into axiom (only one redundant reference given) * Merged barium into axiom (only one redundant reference given) [Daniel Plohmann] * CowerSnail added. [Alexandre Dulaunoy] * Remove duplicates. [Raphaël Vinot] * Merge pull request #74 from Delta-Sierra/master. [Raphaël Vinot] adding clusters based on MISP data * Clean tool.json. [Deborah Servili] * Update Spring Dragon threat actor. [Deborah Servili] * Adding clusters based on MISP data. [Deborah Servili] * Add missing name XtremeRAT. [Raphaël Vinot] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Raphaël Vinot] * Add validators for vocabularies and misp. [Raphaël Vinot] * Remove empty string. [Raphaël Vinot] * Add new entries in meta key. [Raphaël Vinot] * Remove duplicates. [Raphaël Vinot] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #73 from Delta-Sierra/master. [Alexandre Dulaunoy] add cerber synonym * Add cerber synonym. [Deborah Servili] * Cobalt gang added. [Alexandre Dulaunoy] * El Machete added. [Alexandre Dulaunoy] * Merge pull request #72 from Delta-Sierra/master. [Alexandre Dulaunoy] add synonym for ammyyadmin * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #71 from Delta-Sierra/master. [Alexandre Dulaunoy] Add SOREBRECT ransomware * Add synonym for ammyyadmin. [Deborah Servili] * Add SOREBRECT ransomware. [Deborah Servili] * Jq all ;-) [Alexandre Dulaunoy] * Merge pull request #70 from jaimeblasco/master. [Alexandre Dulaunoy] Added FIN8 actor * Added FIN8 actor. [Jaime] * Merge pull request #69 from Delta-Sierra/master. [Alexandre Dulaunoy] alwaaays moooore RAT * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #68 from Delta-Sierra/master. [Alexandre Dulaunoy] add rats * Alwaaays moooore RAT. [Deborah Servili] * Add rats from https://www.lifewire.com/free-remote-access-software-tools-2625161. [Deborah Servili] * Add rats. [Deborah Servili] * Validation added. [Alexandre Dulaunoy] * Jq. [Alexandre Dulaunoy] * Merge pull request #67 from Delta-Sierra/master. [Alexandre Dulaunoy] add some rats and tools * Add some rats sand tools. [Deborah Servili] * Merge pull request #66 from elhoim/patch-2. [Alexandre Dulaunoy] Added Symantec alias for sofacy * Added Symantec alias for sofacy. [David André] * Merge pull request #65 from danielplohmann/hidden-cobra-lazarus. [Alexandre Dulaunoy] added Hidden Cobra as alias for Lazarus Group * Merge branch 'master' into hidden-cobra-lazarus. [danielplohmann] * Merge pull request #64 from danielplohmann/threat-actor-electrum. [Alexandre Dulaunoy] Threat actor electrum * Added ELECTRUM to threat-actor.json (afaik not confirmed as an alias atm) [Daniel Plohmann] * Added PLATINUM to threat-actor.json (afaik not confirmed as an alias atm) [Daniel Plohmann] * Added Hidden Cobra as alias for Lazarus Group. [Daniel Plohmann (jupiter)] * Merge pull request #62 from Delta-Sierra/master. [Raphaël Vinot] update rat galaxy * Merge https://github.com/MISP/misp-galaxy. [Deborah Servili] * Merge pull request #58 from danielplohmann/wildneutron. [Alexandre Dulaunoy] added WildNeutron (Morph, Butterfly, Sphinx Moth) * Added WildNeutron (Morph, Butterfly, Sphinx Moth) [Daniel Plohmann (jupiter)] * Merge pull request #61 from Delta-Sierra/master. [Alexandre Dulaunoy] edit threat actor - should fix #59 and #60 * Update rat. [Deborah Servili] * Edit threat actor - should fix #59 and #60. [Deborah Servili] * Merge pull request #56 from elhoim/patch-1. [Alexandre Dulaunoy] Added synonyms for APT10 and one for APT1 * Added synonyms for APT10 and one for APT1. [David André] * RAT added. [Alexandre Dulaunoy] * Merge pull request #57 from Delta-Sierra/master. [Alexandre Dulaunoy] add rat galaxy * Jq. [Deborah Servili] * Add RAT listed in https://github.com/kevthehermit/RATDecoders. [Deborah Servili] * Add rat galaxy. [Deborah Servili] * SilverTerrier added. [Alexandre Dulaunoy] * Jq all. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #54 from Delta-Sierra/master. [Alexandre Dulaunoy] add Uiwik ransomware * Jq 'n ##COMMA## [Deborah Servili] * Add Uiwik ransomware. [Deborah Servili] * Merge pull request #53 from Delta-Sierra/master. [Alexandre Dulaunoy] add synonym - half done * Add synonym and cleaning. [Deborah Servili] * Merge hiddentear & cryptear data. [Deborah Servili] * Add synonym - half done. [Deborah Servili] * Add synonym - step 1. [Deborah Servili] * Merge pull request #52 from Delta-Sierra/master. [Alexandre Dulaunoy] add synonym to hancitor * Add synonym to hancitor. [Deborah Servili] * Merge pull request #51 from Delta-Sierra/master. [Alexandre Dulaunoy] add jaff Ransomware * Add jaff Ransomwarejq-ed. [Deborah Servili] * Add jaff Ransomware. [Deborah Servili] * Emotet/Geodo added. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #50 from Delta-Sierra/master. [Alexandre Dulaunoy] Update ransomware galaxy - possible duplicate * Property requirement updated. [Deborah Servili] * Update Wannacry ransomware. [Deborah Servili] * Make it mergable (try to) [Deborah Servili] * Update ransomware galaxy - possible duplicate. [Déborah Servili] * Remove duplicate ref. [Alexandre Dulaunoy] * Input from Deborah incorporated. [Alexandre Dulaunoy] * APT32 added. [Alexandre Dulaunoy] * WannaCry added. [Alexandre Dulaunoy] * PDF added. [Alexandre Dulaunoy] * Fixed the double trailing dot. [Alexandre Dulaunoy] * Add meaningful infobox. [Alexandre Dulaunoy] * A tool to convert MISP Galaxy Cluster into an asciidoctor document. [Alexandre Dulaunoy] * Kazuar: Multiplatform Espionage Backdoor with API Access added. [Alexandre Dulaunoy] * Duplicate references removed. [Alexandre Dulaunoy] * Merge pull request #49 from Delta-Sierra/master. [Alexandre Dulaunoy] reformat ransomware galaxy * Add source to please the schema~ [Déborah Servili] * Change sources for authors. [Déborah Servili] * Jq on ransomware. [Déborah Servili] * Managing duplicate. [Déborah Servili] * Managing duplicate. [Déborah Servili] * Reformat ransomware galaxy - including http://pastebin.com/raw/GHgpWjar. [Déborah Servili] * Reformat ransomware galaxy. [Déborah Servili] * Additional properties allowed on the meta part. [Alexandre Dulaunoy] * REDLEAVES malware added. [Alexandre Dulaunoy] * Merge pull request #48 from Delta-Sierra/master. [Raphaël Vinot] add Cardinal RAT * Update tools. [Déborah Servili] * Feodo added. [Alexandre Dulaunoy] * FlexiSpy. [Alexandre Dulaunoy] * Shadow broker leak of NSA tools from https://github.com/misterch0c/shadowbroker. [Alexandre Dulaunoy] * First batch of shadow broker leak (NSA name of exploit and tools) from https://github.com/misterch0c/shadowbroker. [Alexandre Dulaunoy] * Jq all. [Alexandre Dulaunoy] * Merge pull request #40 from Kafeine/master. [Alexandre Dulaunoy] Updated. * Merge pull request #47 from Delta-Sierra/master. [Alexandre Dulaunoy] add synonyms for Da Vinci RCS * Merge pull request #46 from Delta-Sierra/master. [Alexandre Dulaunoy] Add some tools/threat actor * Add Cardinal RAT. [Déborah Servili] * Add synonyms for Da Vinci RCS. [Déborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Déborah Servili] * Merge pull request #45 from Delta-Sierra/master. [Alexandre Dulaunoy] add tools from https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html * ##comma## [Déborah Servili] * Add some tools/threat actor. [Déborah Servili] * Correct copypasta mistake. [Déborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Déborah Servili] * Merge pull request #44 from Delta-Sierra/master. [Alexandre Dulaunoy] Update tool's galaxy * Add tools from https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html. [Déborah Servili] * Update tool. [Déborah Servili] * Json fix. [Déborah Servili] * Update tool's galaxy using http://contagiodump.blogspot.lu/2013/03/mandiant-apt1-samples-categorized-by.html. [Déborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Déborah Servili] * Longhorn (CIA) added. [Alexandre Dulaunoy] * Sathurbot added. [Alexandre Dulaunoy] * The product from NSO Group Technologies added to the list of tools. [Alexandre Dulaunoy] The Pegasus name is used as synonym of Chrysaor ;-) * The mysterious ZIRCONIUM activity group added. [Alexandre Dulaunoy] * Merge pull request #43 from nyx0/master. [Alexandre Dulaunoy] Add new Sednit name * Add new Sednit name according to https://www.secureworks.com/research/iron-twilight-supports-active-measures. [nyx0] * Trochilus and MoonWind RATs added. [Alexandre Dulaunoy] * KHRAT added. [Alexandre Dulaunoy] * Merge pull request #42 from chrisdoman/master. [Alexandre Dulaunoy] Added descriptions and reference to threat-actor json * Added descriptions and reference to threat-actor json. [chrisdoman] * JQ all. [Alexandre Dulaunoy] * Merge https://github.com/MISP/misp-galaxy. [Déborah Servili] * +WhiteHole +ref for Disdain. [Kafeine] * +disdain+captainblack-Neutrino. [Kafeine] * Update exploit-kit.json. [Kafeine] * Fix. [Kafeine] * +Bingo -- Hunter > Retired. [Kafeine] * Update tds.json. [Kafeine] * Fix. [Kafeine] * Update Terror. [Kafeine] * Updated. [Kafeine] Blaze <-> Terror - Updated Sundown and Nebula status * Merge branch 'master' into master. [Raphaël Vinot] * JQ all the things. [Raphaël Vinot] * Merge pull request #41 from CERT-Bund/patch-1. [Raphaël Vinot] Added groups, joined groups, added synonyms (see extended description) * Fix typo. [Raphaël Vinot] * Added groups, joined groups, added synonyms (see extended description) [CERT-Bund] * IMEIJ added. [Alexandre Dulaunoy] * Missing \n at the end of the file. [Alexandre Dulaunoy] * Merge pull request #38 from chrisdoman/master. [Alexandre Dulaunoy] Added references * Ran jq. [Chris Doman] * Added references. [Chris Doman] Mostly added references to existing groups Capitalised DarkHotel, put a space in APT30 default name (the others had that) * Add: Gamaredon Group added. [Alexandre Dulaunoy] * Merge pull request #37 from cvandeplas/master. [Christophe Vandeplas] minor correction * Minor correction. [Christophe Vandeplas] * Merge pull request #36 from Th4nat0s/gutembergII. [Alexandre Dulaunoy] Gutemberg II * Remove duplicate of ratdecode import. [Thanat0s] * Add a bunch of rat from ratdecoder list. [Thanat0s] * Pimp Epic turla. [Thanat0s] * Pimp and agreggate turla. [Thanat0s] * Somes alias fetch from : https://attack.mitre.org/wiki/Groups. [Thanat0s] * Pimp comrat. [Thanat0s] * Pimp xneteagle. [Thanat0s] * Pimp xscontrol. [Thanat0s] * Update Xagent from aptnote Bitdefender-Whitepaper-APT-Mac-A4-en-EN-web(02-23-2017) [Thanat0s] * Pimp lecna/Backspace. [Thanat0s] * Pimp lecna/Backspace. [Thanat0s] * Pimp RarStone. [Thanat0s] * Pimp Pirpi. Hard to say:) [Thanat0s] * Pimp webc2. [Thanat0s] * Pimp winnti. [Thanat0s] * Pimp nettraveler. [Thanat0s] * Cleanup zeus duplicate in alias and name. [Thanat0s] * Update apt28 tools. [Thanat0s] * Remove duplicate AlienSpy. [Thanat0s] * Merge pull request #32 from Th4nat0s/donokilljson. [Alexandre Dulaunoy] modify validators to check json an format, stop on any error * Block by default, but usable anyway with param. [Thanat0s] * Modify validators to check json an format, stop on any error. [Thanat0s] * Merge pull request #30 from Th4nat0s/gutemberg. [Alexandre Dulaunoy] Gutemberg work.. * Add info to the famous mimikatz. [Thanat0s] * Add moudor info. [Thanat0s] * Add Tinba banking. [Thanat0s] * Udpate trojan.main. [Thanat0s] * Update evilgrab. [Thanat0s] * Remove coreshell duplicate. [Thanat0s] * Add derusbi. [Thanat0s] * Merge IEchecker et sasfi. [Thanat0s] * Go for caro, add hi-zor. [Thanat0s] * Fix side victims of schemaupdate. [Thanat0s] * Update 2 array. [Thanat0s] * Go 4 string. [Thanat0s] * Follow the format. [Thanat0s] * Json typo. [Thanat0s] * Locky removed > ransomware. [Thanat0s] * Json issue. [Thanat0s] * Generic plugx names. [Thanat0s] * Update. [Thanat0s] * Remove JOYRat -> team -> https://www.crowdstrike.com/blog/whois-numbered-panda/ [Thanat0s] * Remove Lstudio (group using elise) , add info to PWOBOT. [Thanat0s] * Remove EK and Ransomwares. [Thanat0s] * Gutemberg on first 10. [Thanat0s] * Merge pull request #33 from Th4nat0s/checkdup. [Alexandre Dulaunoy] Tool to find duplicate * Add tool to find duplicate. [Thanat0s] * PupyRAT added. [Alexandre Dulaunoy] * Strict schema, update clusters accordingly. [Raphaël Vinot] * Add validator for galaxies. [Raphaël Vinot] * Fix validation, remove duplicate. [Raphaël Vinot] * Initial Json schema. [Raphaël Vinot] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #29 from Delta-Sierra/master. [Alexandre Dulaunoy] add Erebus ransomware * Add Erebus ransomware. [Déborah Servili] * Merge pull request #28 from Kafeine/master. [Alexandre Dulaunoy] Added Microsoft Naming * StreamEX added. [Alexandre Dulaunoy] * ZeroT added. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #26 from Delta-Sierra/master. [Alexandre Dulaunoy] Change author name to 'Various' * Merge https://github.com/MISP/misp-galaxy. [Déborah Servili] * Change author name to 'Various' [Déborah Servili] * Flokibot added. [Alexandre Dulaunoy] * Merge pull request #25 from Delta-Sierra/master. [Alexandre Dulaunoy] ransomware galaxy * Fix galaxy ##comma## [Déborah Servili] * Ransomware galaxy. [Déborah Servili] * Merge pull request #24 from Delta-Sierra/master. [Alexandre Dulaunoy] add ransomware galaxy * Merge https://github.com/MISP/misp-galaxy. [Déborah Servili] * Merge pull request #23 from Delta-Sierra/master. [Alexandre Dulaunoy] improve csv_to_galaxy * Merge pull request #22 from Delta-Sierra/master. [Alexandre Dulaunoy] add csv to galaxy converter * Add ransomware galaxy. [Déborah Servili] * Improve csv_to_galaxy 2. [Déborah Servili] * Improve csv_to_galaxy. [Déborah Servili] * Merge https://github.com/MISP/misp-galaxy. [Déborah Servili] * Merge pull request #20 from cgi1/master. [Alexandre Dulaunoy] Adding Zeus to tools * Adding Zeus to tools. [cgi] * Greenbug added. [Alexandre Dulaunoy] * Tavdig was missing. [Alexandre Dulaunoy] * LuminosityLink RAT added. [Alexandre Dulaunoy] * EyePyramid added. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #18 from Delta-Sierra/master. [Alexandre Dulaunoy] add APT28's tools * GhostAdmin added. [Alexandre Dulaunoy] * Add csv to galaxy converter. [Déborah Servili] * Add APT28's tools. [Déborah Servili] * Equation Group added. [Alexandre Dulaunoy] * "the shoemaker's son always goes barefoot" Regin added. [Alexandre Dulaunoy] * Merge pull request #17 from Delta-Sierra/master. [Alexandre Dulaunoy] begin preventive-measure galaxy * Complete preventive-measure. [Déborah Servili] * Begin preventive-measure galaxy. [Déborah Servili] * Shamoon added. [Alexandre Dulaunoy] * Import manually cert-eu contribution. [Alexandre Dulaunoy] - Fix the meta attributes (like the motive field ) to be within meta and not outside - Remove some "null" values that seems to come from previous tests - Pretty-print the Javascript (better for diffing) * MM Core added. [Alexandre Dulaunoy] * Shiz Trojan + Shifu. [Alexandre Dulaunoy] * GeminiDuke added. [Alexandre Dulaunoy] * Separate APT30 from Naikon group. [Alexandre Dulaunoy] * PassCV group added. [Alexandre Dulaunoy] * Cadelle and Chafer groups added. [Alexandre Dulaunoy] * Exploit-kit and TDS added. [Alexandre Dulaunoy] * Merge pull request #15 from Kafeine/master. [Alexandre Dulaunoy] Exploit Kit and TDS Galaxies * Empire status, Nebula, Blaze/Terror. [Kafeine] * +Pangimop, alias Microsoft for magnitude. [Kafeine] * Fix. [Kafeine] * +Derbit alias for Sundown. [Kafeine] * Indent. [Kafeine] * Added Microsoft Naming. [root] * TDS Cluster: EOF. [root] * EK and TDS clusters : several minor fixes. [root] * EK and TDS clusters : Removed empty entries. [root] * TDS Cluster: json fix. [root] * EK Cluster : several fixes. [root] * EK Cluster typo fix. [root] * EK Cluster update. [root] * EK galaxie. [root] * Mwi added. [root] * Init. [root] * Clarification regarding the contribution and the different models. [Alexandre Dulaunoy] * Various updates including the addition of Chthonic Banking Trojan. [Alexandre Dulaunoy] * Packrat added. [Alexandre Dulaunoy] * DownRage added. [Alexandre Dulaunoy] * Java RAT updated. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #14 from Delta-Sierra/master. [Alexandre Dulaunoy] update readme * Update readme. [Déborah Servili] * Merge pull request #13 from Delta-Sierra/master. [Alexandre Dulaunoy] Add microsoft-activity-group cluster * ##comma## [Déborah Servili] * Add microsoft-activity-group cluster. [Déborah Servili] * Seaduke added. [Alexandre Dulaunoy] * MISP integration added. [Alexandre Dulaunoy] * MISP galaxy screenshot. [Alexandre Dulaunoy] * Operation Iron Tiger added as synonym. [Alexandre Dulaunoy] * Molerats, PROMETHIUM and NEODYMIUM added. [Alexandre Dulaunoy] * BlackEnergy malware family added. [Alexandre Dulaunoy] * TeleBots group added. [Alexandre Dulaunoy] * TERBIUM added. [Alexandre Dulaunoy] * Mirai and BASHLITE added. [Alexandre Dulaunoy] * Links fixed. [Alexandre Dulaunoy] * Added missing file. [Iglocska] * Threat-actor fixed. [Alexandre Dulaunoy] * Singular everywhere. [Alexandre Dulaunoy] * Singular everywhere. [Alexandre Dulaunoy] * Singular everywhere. [Alexandre Dulaunoy] * Singular everywhere. [Alexandre Dulaunoy] * Structure ready for MISP 2.4.56. [Alexandre Dulaunoy] * Fixed to merge PR #11. [Alexandre Dulaunoy] * Meta added as required by MISP 2.4.56. [Alexandre Dulaunoy] * Source added as required by MISP 2.4.56. [Alexandre Dulaunoy] * Source field added as required to MISP 2.4.56. [Alexandre Dulaunoy] * Add a source field for the clusters (required for MISP 2.4.56) [Alexandre Dulaunoy] * Merge pull request #10 from cvandeplas/master. [Alexandre Dulaunoy] Metushy, Uroburos, Pfinet synonyms added * Metushy, Uroburos, Pfinet synonyms added. [Christophe Vandeplas] * Yahoyah added. [Alexandre Dulaunoy] * Tropic Trooper added. [Alexandre Dulaunoy] * KeyBoy malware added. [Alexandre Dulaunoy] * Merge pull request #9 from cvandeplas/master. [Alexandre Dulaunoy] added Callisto threat actor, and removed duplicates * Added Callisto. [Christophe Vandeplas] * Removed duplicates. [Christophe Vandeplas] * Merge pull request #7 from cvandeplas/master. [Alexandre Dulaunoy] Added Rocket Kitten * Added Rocket Kitten. [Christophe Vandeplas] * Description added for Volatile Cedar. [Alexandre Dulaunoy] * Explosive malware added. [Alexandre Dulaunoy] * Volatile Cedar added. [Alexandre Dulaunoy] * OilRig added. [Alexandre Dulaunoy] * Merge branch 'master' of https://github.com/MISP/misp-galaxy. [Iglocska] * Empire post-exploitation tool added. [Alexandre Dulaunoy] * Some small fixes. [Iglocska] - more uniform pluralisation - Added display name fields * Plural it's plural (tm) [Alexandre Dulaunoy] * README updated to reflect the new structure. [Alexandre Dulaunoy] * Threat actors simplified (no more groups) it's already in the value field. [Alexandre Dulaunoy] * Tools added. [Alexandre Dulaunoy] * Merge pull request #6 from MISP/restructure. [Alexandre Dulaunoy] Restructure * Typo fixed. [Alexandre Dulaunoy] * Typo fixed. [Alexandre Dulaunoy] * Some small fixes. [Iglocska] * Some small changes. [Iglocska] * Moving things around. [Iglocska] * Merge pull request #5 from cvandeplas/master. [Alexandre Dulaunoy] adding additional threat-actor-tools * Minor correction. [Christophe Vandeplas] * Added additional threat-actor-tools. [Christophe Vandeplas] * Merged branch master into master. [Christophe Vandeplas] * Houdini added. [Alexandre Dulaunoy] * Corrected typo in njRAT synonym. [Christophe Vandeplas] * Removed empty synonym. [Christophe Vandeplas] * Odinaff added. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #4 from cvandeplas/master. [Alexandre Dulaunoy] additional adversary groups * Additional adversary groups. [Christophe Vandeplas] Using as a source https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit * TeamXRat added. [Alexandre Dulaunoy] * StrongPity added (more refs required) [Alexandre Dulaunoy] * Libyan Scorpions added. [Alexandre Dulaunoy] * FIN6 added. [Alexandre Dulaunoy] * Suckfly added. [Alexandre Dulaunoy] * GCMAN added. [Alexandre Dulaunoy] * More synonyms. [Alexandre Dulaunoy] * TA530 added. [Alexandre Dulaunoy] * Dust storm added. [Alexandre Dulaunoy] * More synonyms added. [Alexandre Dulaunoy] * Lazagne tools added. [Alexandre Dulaunoy] * Pirpi reference added. [Alexandre Dulaunoy] * Buckeye added. [Alexandre Dulaunoy] * Gothic Panda updated. [Alexandre Dulaunoy] * Sauron versus Project Sauron (Kasperksy used both) [Alexandre Dulaunoy] * License (PD) added. [Alexandre Dulaunoy] * Umbreon added. [Alexandre Dulaunoy] * Turla synonym added. [Alexandre Dulaunoy] * Ozone RAT added. [Alexandre Dulaunoy] * Typo fixed. [Alexandre Dulaunoy] * UUID added. [Alexandre Dulaunoy] * UUID added. [Alexandre Dulaunoy] * Mapping triples/machine tags with galaxy, clusters and so on. [Alexandre Dulaunoy] * Revert "Machine tags/triple tags mapping" [Alexandre Dulaunoy] This reverts commit 06e2372d6674f86e32c10216fcbf5e4ea3ee03f1. * Machine tags/triple tags mapping. [Alexandre Dulaunoy] * Make JSON key values inline with the other elements. [Alexandre Dulaunoy] * ProjectSauron added. [Alexandre Dulaunoy] * Badnews added. [Alexandre Dulaunoy] * Moonsoon added. [Alexandre Dulaunoy] * NANHAISHU added. [Alexandre Dulaunoy] * Threat Group-3390 added. [Alexandre Dulaunoy] * Moafee added. [Alexandre Dulaunoy] * DragonOK added. [Alexandre Dulaunoy] * Quedagh added. [Alexandre Dulaunoy] * Poseidon Group added. [Alexandre Dulaunoy] * Scarlet Mimic added. [Alexandre Dulaunoy] * Admin338 updated. [Alexandre Dulaunoy] * Turla is also known as Waterbug. [Alexandre Dulaunoy] * Prikormka malware added. [Alexandre Dulaunoy] * Operation Transparent Tribe added. [Alexandre Dulaunoy] * Crimson malwre added. [Alexandre Dulaunoy] * Mad Max malware added. [Alexandre Dulaunoy] * More references. [Alexandre Dulaunoy] * Chinastrats added. [Alexandre Dulaunoy] * HummingBad added. [Alexandre Dulaunoy] * Pacifier APT added. [Alexandre Dulaunoy] * More RU tools. [Alexandre Dulaunoy] * ScarCruft added. [Alexandre Dulaunoy] * ShimRAT added. [Alexandre Dulaunoy] * Darkhotel added. [Alexandre Dulaunoy] * IRONGATE added. [Alexandre Dulaunoy] * HDRoot added. [Alexandre Dulaunoy] * WINNTI reference updated. [Alexandre Dulaunoy] * Typo fixed. [Alexandre Dulaunoy] * HerHer Trojan and Helminth Backdoor added. [Alexandre Dulaunoy] * Stealth Falcon added. [Alexandre Dulaunoy] * Hancitor and Ruckguv added. [Alexandre Dulaunoy] * Pretty-print of the adversary groups. [Alexandre Dulaunoy] * Lazarus group (KP) added. [Alexandre Dulaunoy] * NanoCore RAT added. [Alexandre Dulaunoy] * Lost Door RAT added. [Alexandre Dulaunoy] * SPIVY added. [Alexandre Dulaunoy] * Laziok added. [Alexandre Dulaunoy] * PWOBot added. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Add Travis file (validate json files) [Raphaël Vinot] * Slempo added. [Alexandre Dulaunoy] * Timo Steffens contributed various refs, tools and actors. [Alexandre Dulaunoy] * PK actor added Operation C-Major. [Alexandre Dulaunoy] * Recommendation regarding the pull-request. [Alexandre Dulaunoy] * Backdoor.Dripion added. [Alexandre Dulaunoy] * Missing comma. [Christophe Vandeplas] * APT 4 synonyms added. [Alexandre Dulaunoy] * Snifula added. [Alexandre Dulaunoy] * More adversary tools. [Alexandre Dulaunoy] * More adversary tools added. [Alexandre Dulaunoy] * New synonyms and potential adversary groups. [Alexandre Dulaunoy] * More RATs added. [Alexandre Dulaunoy] * More RATs and description added. [Alexandre Dulaunoy] * Adversary tools added + some clarification. [Alexandre Dulaunoy] * Threat-actor tools added. [Alexandre Dulaunoy] * More adversaries tools. [Alexandre Dulaunoy] * First version of adversary tools. [Alexandre Dulaunoy] * Fix #3 - as black energy is sometimes mentioned as group (even if it seems to be more a campaign). [Alexandre Dulaunoy] * Nitro/CN added. [Alexandre Dulaunoy] * Codoso/CN added. [Alexandre Dulaunoy] * More IR. [Alexandre Dulaunoy] * More IR added. [Alexandre Dulaunoy] * Additional IR operation added. [Alexandre Dulaunoy] * SNOWGLOBE added. [Alexandre Dulaunoy] * New elements added. [Alexandre Dulaunoy] * Threat-actor-sophistication-vocabulary added. [Alexandre Dulaunoy] * The ThreatActorSophisticationVocab enumeration is used to define the default STIX vocabulary for expressing the subjective level of sophistication of a threat actor. [Alexandre Dulaunoy] * Threat actor type added. [Alexandre Dulaunoy] * Threat actor type vocabulary added. [Alexandre Dulaunoy] * Foxy Panda added. [Alexandre Dulaunoy] * Karma panda added. [Alexandre Dulaunoy] * New actors + refs added. [Alexandre Dulaunoy] * Planning-and-operational-support-vocabulary added. [Alexandre Dulaunoy] * The PlanningAndOperationalSupportVocab is the default STIX vocabulary for expressing the planning and operational support functions available to a threat actor. added. [Alexandre Dulaunoy] * Planning-and-operational-support-vocabulary added. [Alexandre Dulaunoy] * JSON beautified. [Alexandre Dulaunoy] * Description added. [Alexandre Dulaunoy] * More descriptions added. [Alexandre Dulaunoy] * Typo fixed. [Alexandre Dulaunoy] * More adversaries... [Alexandre Dulaunoy] * Thomas added. [Alexandre Dulaunoy] * More groups. [Alexandre Dulaunoy] * Synonyms updates. [Alexandre Dulaunoy] * RU and CN updates. [Alexandre Dulaunoy] * More actors CN,TN and RU + synonyms. [Alexandre Dulaunoy] * CN group updated. [Alexandre Dulaunoy] * IR group added. [Alexandre Dulaunoy] * RU synonym of TeamSpy. [Alexandre Dulaunoy] * AE group added. [Alexandre Dulaunoy] * CN synonyms added + IR group. [Alexandre Dulaunoy] * Merge branch 'master' of github.com:MISP/misp-galaxy. [Alexandre Dulaunoy] * Merge pull request #1 from rotanid/patch-1. [Andras Iklody] fix small grammatical errors in README.md * Fix small grammatical errors in README.md. [Andreas Ziegler] * Certainty level added. [Alexandre Dulaunoy] * Certainty-level added. [Alexandre Dulaunoy] * Certainty level of an associated element or cluster added. [Alexandre Dulaunoy] * Adversary groups added. [Alexandre Dulaunoy] * APT groups renamed to adversary groups. [Alexandre Dulaunoy] * Deleted old APT groups. [Alexandre Dulaunoy] * Adversary groups instead of APT. [Alexandre Dulaunoy] * Adversary groups instead of APT. [Alexandre Dulaunoy] * Motivation vocabulary added. [Alexandre Dulaunoy] * Motivation vocabulary added. [Alexandre Dulaunoy] * The MotivationVocab is the default STIX vocabulary for expressing the motivation of a threat actor. [Alexandre Dulaunoy] * More CN-based groups. [Alexandre Dulaunoy] * More CN-based groups. [Alexandre Dulaunoy] * Some more CN actors. [Alexandre Dulaunoy] * More CN groups. [Alexandre Dulaunoy] * MISP distribution to be applied on cluster objects. [Alexandre Dulaunoy] * First explanation. [Alexandre Dulaunoy] * Some more CN groups. [Alexandre Dulaunoy] * More CN groups. [Alexandre Dulaunoy] * Groups array updated. [Alexandre Dulaunoy] * Description added + stix version reference. [Alexandre Dulaunoy] * More groups from RU. [Alexandre Dulaunoy] * Example of galaxy including a cluster which is default type where you can add as much element as you want. [Alexandre Dulaunoy] The elements are the default values known by MISP but a local instance can add more or overwrite some elements.