{
	"id": "c325ff92-cb08-4601-ae7a-86fbe81ecfb8",
	"created_at": "2026-04-06T00:19:26.732702Z",
	"updated_at": "2026-04-10T13:13:10.203225Z",
	"deleted_at": null,
	"sha1_hash": "176a604293228a1104443309390fa648500f3f68",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 56625,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 22:25:42 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool Egregor\n Tool: Egregor\nNames Egregor\nCategory Malware\nType Ransomware, Big Game Hunting\nDescription\n(Malwarebytes) Egregor ransomware is a relatively new ransomware (first spotted in\nSeptember 2020) that seems intent on making its way to the top right now. Egregor is\nconsidered a variant of Ransom.Sekhmet based on similarities in obfuscation, API-calls,\nand the ransom note.\nAs we’ve reported in the past, affiliates that were using Maze ransomware started\nmoving over to Egregor even before the Maze gang officially announced they were\ncalling it quits.\nInformation\nMITRE ATT\u0026CK Malpedia AlienVault OTX https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833\nPage 1 of 2\n\nPlaybook\nLast change to this tool card: 30 December 2022\nDownload this tool card in JSON format\nAll groups using tool Egregor\nChanged Name Country Observed\nAPT groups\n Mallard Spider [Unknown] 2008-Dec 2020\n TA2101, Maze Team [Unknown] 2019-Feb 2024\n2 groups listed (2 APT, 0 other, 0 unknown)\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833"
	],
	"report_names": [
		"listgroups.cgi?u=4e65ee26-1493-4c96-a38d-441224e8f833"
	],
	"threat_actors": [
		{
			"id": "aa5b200f-a6c6-4d17-bc65-911d9a7bf4ef",
			"created_at": "2022-10-25T16:07:23.866039Z",
			"updated_at": "2026-04-10T02:00:04.765416Z",
			"deleted_at": null,
			"main_name": "Mallard Spider",
			"aliases": [
				"Gold Lagoon"
			],
			"source_name": "ETDA:Mallard Spider",
			"tools": [
				"Egregor",
				"Mimikatz",
				"Oakboat",
				"PinkSlip",
				"Pinkslipbot",
				"ProLock",
				"PwndLocker",
				"QakBot",
				"Qbot",
				"QuackBot",
				"QuakBot"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "d5cb8d20-b5b9-4ec6-9660-3dded9bd3c89",
			"created_at": "2023-01-06T13:46:39.204681Z",
			"updated_at": "2026-04-10T02:00:03.245695Z",
			"deleted_at": null,
			"main_name": "MALLARD SPIDER",
			"aliases": [
				"GOLD LAGOON"
			],
			"source_name": "MISPGALAXY:MALLARD SPIDER",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "e9f85280-337c-4321-b872-0919f8ef64a6",
			"created_at": "2022-10-25T16:07:24.261761Z",
			"updated_at": "2026-04-10T02:00:04.914455Z",
			"deleted_at": null,
			"main_name": "TA2101",
			"aliases": [
				"Gold Village",
				"Maze Team",
				"TA2101",
				"Twisted Spider"
			],
			"source_name": "ETDA:TA2101",
			"tools": [
				"7-Zip",
				"Agentemis",
				"BokBot",
				"Buran",
				"ChaCha",
				"Cobalt Strike",
				"CobaltStrike",
				"Egregor",
				"IceID",
				"IcedID",
				"Mimikatz",
				"PsExec",
				"SharpHound",
				"VegaLocker",
				"WinSCP",
				"cobeacon",
				"nmap"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "c3c864b3-fac9-4d56-8500-7c06c829fbf8",
			"created_at": "2023-01-06T13:46:39.071873Z",
			"updated_at": "2026-04-10T02:00:03.203749Z",
			"deleted_at": null,
			"main_name": "TA2101",
			"aliases": [
				"GOLD VILLAGE",
				"Storm-0216",
				"DEV-0216",
				"UNC2198",
				"TUNNEL SPIDER",
				"Maze Team",
				"TWISTED SPIDER"
			],
			"source_name": "MISPGALAXY:TA2101",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		}
	],
	"ts_created_at": 1775434766,
	"ts_updated_at": 1775826790,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/176a604293228a1104443309390fa648500f3f68.pdf",
		"text": "https://archive.orkl.eu/176a604293228a1104443309390fa648500f3f68.txt",
		"img": "https://archive.orkl.eu/176a604293228a1104443309390fa648500f3f68.jpg"
	}
}