98 lines
5.2 KiB
JSON
98 lines
5.2 KiB
JSON
{
|
|
"type": "bundle",
|
|
"id": "bundle--548292ac-ee7e-4ee9-ab36-d9286017fe7c",
|
|
"spec_version": "2.0",
|
|
"objects": [
|
|
{
|
|
"modified": "2024-11-17T20:01:55.806Z",
|
|
"name": "APT-C-23",
|
|
"description": "[APT-C-23](https://attack.mitre.org/groups/G1028) is a threat group that has been active since at least 2014.(Citation: symantec_mantis) [APT-C-23](https://attack.mitre.org/groups/G1028) has primarily focused its operations on the Middle East, including Israeli military assets. [APT-C-23](https://attack.mitre.org/groups/G1028) has developed mobile spyware targeting Android and iOS devices since 2017.(Citation: welivesecurity_apt-c-23)",
|
|
"aliases": [
|
|
"APT-C-23",
|
|
"Mantis",
|
|
"Arid Viper",
|
|
"Desert Falcon",
|
|
"TAG-63",
|
|
"Grey Karkadann",
|
|
"Big Bang APT",
|
|
"Two-tailed Scorpion"
|
|
],
|
|
"x_mitre_deprecated": false,
|
|
"x_mitre_version": "1.0",
|
|
"x_mitre_contributors": [
|
|
"Sittikorn Sangrattanapitak"
|
|
],
|
|
"type": "intrusion-set",
|
|
"spec_version": "2.1",
|
|
"id": "intrusion-set--8332952e-b86b-486b-acc3-1c2a85d39394",
|
|
"created": "2024-03-26T18:38:00.759Z",
|
|
"created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
|
|
"revoked": false,
|
|
"external_references": [
|
|
{
|
|
"source_name": "mitre-attack",
|
|
"url": "https://attack.mitre.org/groups/G1028",
|
|
"external_id": "G1028"
|
|
},
|
|
{
|
|
"source_name": "Big Bang APT",
|
|
"description": "(Citation: checkpoint_interactive_map_apt-c-23) "
|
|
},
|
|
{
|
|
"source_name": "Grey Karkadann",
|
|
"description": "(Citation: sentinelone_israel_hamas_war)"
|
|
},
|
|
{
|
|
"source_name": "Mantis",
|
|
"description": "(Citation: symantec_mantis)(Citation: sentinelone_israel_hamas_war)"
|
|
},
|
|
{
|
|
"source_name": "Two-tailed Scorpion",
|
|
"description": "(Citation: welivesecurity_apt-c-23)"
|
|
},
|
|
{
|
|
"source_name": "Arid Viper",
|
|
"description": "(Citation: welivesecurity_apt-c-23)(Citation: sentinelone_israel_hamas_war)(Citation: fb_arid_viper)"
|
|
},
|
|
{
|
|
"source_name": "Desert Falcon",
|
|
"description": "(Citation: welivesecurity_apt-c-23)(Citation: sentinelone_israel_hamas_war)(Citation: fb_arid_viper)"
|
|
},
|
|
{
|
|
"source_name": "fb_arid_viper",
|
|
"description": "Flossman, M., Scott, M. (2021, April). Technical Paper // Taking Action Against Arid Viper. Retrieved November 17, 2024.",
|
|
"url": "https://web.archive.org/web/20231126111812/https:/about.fb.com/wp-content/uploads/2021/04/Technical-threat-report-Arid-Viper-April-2021.pdf"
|
|
},
|
|
{
|
|
"source_name": "sentinelone_israel_hamas_war",
|
|
"description": "Hegel, T., Milenkoski, A. (2023, October 24). The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest. Retrieved March 4, 2024.",
|
|
"url": "https://web.archive.org/web/20240208234008/www.sentinelone.com/labs/the-israel-hamas-war-cyber-domain-state-sponsored-activity-of-interest/"
|
|
},
|
|
{
|
|
"source_name": "checkpoint_interactive_map_apt-c-23",
|
|
"description": "Kayal, A. (2018, August 26). Interactive Mapping of APT-C-23. Retrieved March 4, 2024.",
|
|
"url": "https://web.archive.org/web/20230604112435/https://research.checkpoint.com/2018/interactive-mapping-of-apt-c-23/"
|
|
},
|
|
{
|
|
"source_name": "welivesecurity_apt-c-23",
|
|
"description": "Stefanko, L. (2020, September 30). APT\u2011C\u201123 group evolves its Android spyware. Retrieved March 4, 2024.",
|
|
"url": "https://web.archive.org/web/20201123042131/www.welivesecurity.com/2020/09/30/aptc23-group-evolves-its-android-spyware/"
|
|
},
|
|
{
|
|
"source_name": "symantec_mantis",
|
|
"description": "Symantec Threat Hunter Team. (2023, April 4). Mantis: New Tooling Used in Attacks Against Palestinian Targets. Retrieved March 4, 2024.",
|
|
"url": "https://web.archive.org/web/20231227054130/https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mantis-palestinian-attacks"
|
|
}
|
|
],
|
|
"object_marking_refs": [
|
|
"marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
|
|
],
|
|
"x_mitre_attack_spec_version": "3.2.0",
|
|
"x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
|
|
"x_mitre_domains": [
|
|
"mobile-attack",
|
|
"enterprise-attack"
|
|
]
|
|
}
|
|
]
|
|
} |