{
	"id": "190216a4-d57c-477e-bf9d-8a2fdef6e1d1",
	"created_at": "2026-04-06T00:06:17.39698Z",
	"updated_at": "2026-04-10T03:37:19.37019Z",
	"deleted_at": null,
	"sha1_hash": "19307f79f0cee274a70c6a55d82a52ee8743b69d",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 50965,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 13:15:02 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool USBCulprit\n Tool: USBCulprit\nNames USBCulprit\nCategory Malware\nType Info stealer, Worm\nDescription\n(Kaspersky) One of the most notable examples in Cycldek’s toolset that demonstrates\nboth data stealing and lateral movement capabilities is a malware we discovered and\ndubbed USBCulrpit. This tool, which we saw downloaded by RedCore implants in several\ninstances, is capable of scanning various paths in victim machines, collecting documents\nwith particular extensions and passing them on to USB drives when they are connected to\nthe system. It can also selectively copy itself to a removable drive in the presence of a\nparticular file, suggesting it can be spread laterally by having designated drives infected\nand the executable in them opened manually.\nInformation Malpedia AlienVault OTX Last change to this tool card: 15 May 2021\nDownload this tool card in JSON format\nAll groups using tool USBCulprit\nChanged Name Country Observed\nAPT groups\n Goblin Panda, Cycldek, Conimes 2013-Jun 2020\n1 group listed (1 APT, 0 other, 0 unknown)\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2efd7c09-c2d3-4e8c-b48b-5cda7a3a80e8\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2efd7c09-c2d3-4e8c-b48b-5cda7a3a80e8\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2efd7c09-c2d3-4e8c-b48b-5cda7a3a80e8\r\nPage 2 of 2\n\nAPT groups Goblin Panda, Cycldek, Conimes 2013-Jun 2020 \n1 group listed (1 APT, 0 other, 0 unknown) \n   Page 1 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=2efd7c09-c2d3-4e8c-b48b-5cda7a3a80e8"
	],
	"report_names": [
		"listgroups.cgi?u=2efd7c09-c2d3-4e8c-b48b-5cda7a3a80e8"
	],
	"threat_actors": [
		{
			"id": "7d553b83-a7b2-431f-9bc9-08da59f3c4ea",
			"created_at": "2023-01-06T13:46:39.444946Z",
			"updated_at": "2026-04-10T02:00:03.331753Z",
			"deleted_at": null,
			"main_name": "GOBLIN PANDA",
			"aliases": [
				"Conimes",
				"Cycldek"
			],
			"source_name": "MISPGALAXY:GOBLIN PANDA",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "2c7ecb0e-337c-478f-95d4-7dbe9ba44c39",
			"created_at": "2022-10-25T16:07:23.690871Z",
			"updated_at": "2026-04-10T02:00:04.709966Z",
			"deleted_at": null,
			"main_name": "Goblin Panda",
			"aliases": [
				"1937CN",
				"Conimes",
				"Cycldek",
				"Goblin Panda"
			],
			"source_name": "ETDA:Goblin Panda",
			"tools": [
				"8.t Dropper",
				"8.t RTF exploit builder",
				"8t_dropper",
				"Agent.dhwf",
				"BackDoor-FBZT!52D84425CDF2",
				"BlueCore",
				"BrowsingHistoryView",
				"ChromePass",
				"CoreLoader",
				"Custom HDoor",
				"Destroy RAT",
				"DestroyRAT",
				"DropPhone",
				"FoundCore",
				"HDoor",
				"HTTPTunnel",
				"JsonCookies",
				"Kaba",
				"Korplug",
				"LOLBAS",
				"LOLBins",
				"Living off the Land",
				"NBTscan",
				"NewCore RAT",
				"PlugX",
				"ProcDump",
				"PsExec",
				"QCRat",
				"RainyDay",
				"RedCore",
				"RedDelta",
				"RoyalRoad",
				"Sisfader",
				"Sisfader RAT",
				"Sogu",
				"TIGERPLUG",
				"TVT",
				"Thoper",
				"Trojan.Win32.Staser.ytq",
				"USBCulprit",
				"Win32/Zegost.BW",
				"Xamtrav",
				"ZeGhost",
				"nbtscan"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775433977,
	"ts_updated_at": 1775792239,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/19307f79f0cee274a70c6a55d82a52ee8743b69d.pdf",
		"text": "https://archive.orkl.eu/19307f79f0cee274a70c6a55d82a52ee8743b69d.txt",
		"img": "https://archive.orkl.eu/19307f79f0cee274a70c6a55d82a52ee8743b69d.jpg"
	}
}