WIP: add :targeted_{countries,industries} to Actor#447
Draft
WIP: add :targeted_{countries,industries} to Actor#447
Conversation
| :tlp "green" | ||
| :aliases ["alias 1" "alias 2"]}) | ||
| :aliases ["alias 1" "alias 2"] | ||
| :targeted_countries ["840"] |
Contributor
There was a problem hiding this comment.
Let's us 3166-1 A2 codes, ie 2-letter country codes, see the following example:
"[APT38](https://attack.mitre.org/groups/G0082) is a North Korean state-sponsored
threat group that specializes in financial cyber operations; it has been attributed to
the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020)
Active since at least 2014, [APT38](https://attack.mitre.org/groups/G0082) has targeted
banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system
endpoints, and ATMs in at least 38 countries worldwide. Significant operations include
the 2016 Bank of Bangladesh heist, during which
[APT38](https://attack.mitre.org/groups/G0082) stole $81 million, as well as attacks
against Bancomext (2018) and Banco de Chile (2018); some of their attacks have been
destructive.(Citation: CISA AA20-239A BeagleBoyz August 2020)(Citation: FireEye APT38
Oct 2018)(Citation: DOJ North Korea Indictment Feb 2021)(Citation: Kaspersky Lazarus
Under The Hood Blog 2017)\n\nNorth Korean group definitions are known to have
significant overlap, and some security researchers report all North Korean
state-sponsored cyber activity under the name [Lazarus
Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or
subgroups.",
:aliases
["APT38"
"NICKEL GLADSTONE"
"BeagleBoyz"
"Bluenoroff"
"Stardust Chollima"],
:external_references
{:external_id "G0082",
:source_name "mitre-attack",
:url "https://attack.mitre.org/groups/G0082"},
:mitre_group_id "G0082",
:targeted_industries ["financial-services", "government"]
:targeted_countries ["BD", "MX", "CL"]}
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
XDR-2098