Skip to content

Latest commit

 

History

History
202 lines (171 loc) · 15.1 KB

APT-Groups.md

File metadata and controls

202 lines (171 loc) · 15.1 KB

APT Group by Name (work in progress)

Classification based on Threat Group Cards: A Threat Actor Encyclopedia by ThaiCert and the Group pages of the MITRE ATT&CK team.

aka Comment Crew, Comment Group, Comment Panda, TG-8223, BrownFox, Group 3, Byzantine Hades, Byzantine Candor, Shangai Group, GIF89a

Title Year Month Source
Operation Oceansalt Attacks South Korea, U.S. and Canada with Source Code from Chinese Hacker Group 2018 Oct McAfee
Putter Panda 2014 Jun Crowdstrike
Apt1 Exposing One Of China's Cyber Espionage Units 2013 Feb Mandiant
APT1s GLASSES: Watching a Human Rights Organization 2013 Feb The Citizen Lab
Apt1: Technical Backstage 2013 Mar itrust

Other:

aka Gothic Panda, Pirpi, UPS Team, Buckeye, Threat Group-0110, TG-0110, Group 6

Title Year Month Source
APT3 Adversary Emulation Plan 2017 Sep MITRE

Other:

aka Sofacy, Pawn Storm, Sednit, Strontium, Fancy Bear, Group 74, TG-4127, Tsar Team, Swallowtail, SIG40, Snakemackerel, Grizzly Steppe

Title Year Month Source
Operation Roman Holiday Hunting the Russian APT28 group 2018 Jul CSE Zlab
LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group 2018 Oct ESET
APT28: A Window into Russias Cyber Espionage Operations 2017 Jan FireEye
APT28: At the center of the storm. Russia strategically evolves its cyber operations 2017 Jan FireEeye
APT28 Under the Scope A Journey into Exfiltrating Intelligence and Government Information 2017 Feb BitDefender
Dissecting the APT28 Mac OS X Payload 2017 Feb Bitdefender
Sednit adds two zero-day exploits using Trumps attack on Syria as a decoy 2017 May ESET
Two Years of Pawn Storm Examining an Increasingly Relevant Threat 2017 May Trend Micro
En Route with Sednit Part 1: Approaching the Target 2016 Oct ESET
En Route with Sednit Part 2: Observing the Comings and Goings 2016 Oct ESET
En Route with Sednit Part 3: A Mysterious Downloader 2016 Oct ESET
Use of Fancy Bear Android Malware tracking of Ukrainian Artillery Units 2016 Dec Crowdstrike
Sofacy II Same Sofacy, Different Day 2015 Apr PWC
APT28 Targets Financial Markets: Zero Day Hashes Released 2015 May Root9b
Operation Pawn Storm Using Decoys to Evade Detection 2014 Oct Trend Micro
Sofacy Phishing 2014 Oct PWC

Other:

aka Group 100, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, Iron Hemlock, Minidionis, CloudLook, Grizzly Steppe

Title Year Month Source
Enhanced Analysis of GRIZZLY STEPPE Activity 2017 Feb US-CERT
GRIZZLY STEPPE - Russian Malicious Cyber Activity 2016 Dec FBI
HAMMERTOSS: Stealthy Tactics Define a Russian Cyber Threat Group 2015 Jul FireEye
The Dukes: 7 years of Russian cyberespionage 2015 Dec F-Secure

Other:

aka Newscaster, NewsBeef, Group 83, Parastoo, APT35, Phosphorus

Title Year Month Source
The Kittens are back in town: Charming Kitten Campaign against Academic Researchers 2019 Sep ClearSky
Charming Kitten 2017 Dec ClearSky

Other:

Sometimes referred to as Carbanak Group, but these appear to be two groups using the same Carbanak malware

Title Year Month Source
Behind the CARBANAK Backdoor 2017 Jun FireEye
The CARBANAK/FIN7 Syndicate a historical overview of an evolving threat 2017 Nov RSA
The Shadows of Ghosts Inside the Response of a Unique CARBANAK Intrusion 2017 Nov RSA
CARBANAK APT THE GREAT BANK ROBBERY 2015 Feb Kaspersky
Anunak: Apt Against Financial Institutions 2014 Dec FoxIT

Others:

aka Hidden Cobra, Guardians of Peace, Zinc, Nickel Academy, Labyrinth Chollima, Group 77, Hastai Group, Whois Hacking Team, NewRomanic Cyber Army Team, APT-C-26

Title Year Month Source
Full Discloser of Andariel - A Subgroup of Lazarus Threat Group 2018 Jun AhnLab
Lazarus Under the Hood 2017 Apr Kaspersky
Lazarus: History of mysterious group behind infamous cyber attacks 2017 May Symantec
Lazarus Arisen - full report 2017 May Group IB
Lazarus Arisen - article 2017 May Group IB
North Korea Bitten by Bitcoin Bug 2017 Dec Proofpoint
Operation Blockbuster 2016 Feb Novetta

Other:

References