{
	"id": "76caaeb3-c9e1-4468-9b5f-4373a90de84f",
	"created_at": "2026-04-06T00:15:55.362709Z",
	"updated_at": "2026-04-10T03:36:07.158387Z",
	"deleted_at": null,
	"sha1_hash": "45208a0175abef27623bce644c83ec5447cb9a70",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 49662,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 13:36:46 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool Bookworm\n Tool: Bookworm\nNames Bookworm\nCategory Malware\nType Backdoor, Keylogger, Info stealer\nDescription\n(Palo Alto) Bookworm’s functional code is radically different from PlugX and has a rather\nunique modular architecture that warranted additional analysis by Unit 42. Bookworm has\nlittle malicious functionality built-in, with its only core ability involving stealing keystrokes\nand clipboard contents. However, Bookworm expands on its capabilities through its ability to\nload additional modules directly from its command and control (C2) server.\nInformation Malpedia Last change to this tool card: 27 December 2022\nDownload this tool card in JSON format\nAll groups using tool Bookworm\nChanged Name Country Observed\nAPT groups\n Bookworm 2015\n1 group listed (1 APT, 0 other, 0 unknown)\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f4215b2e-bc7d-4294-a842-9bfb0fa34414\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f4215b2e-bc7d-4294-a842-9bfb0fa34414\nPage 1 of 1",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f4215b2e-bc7d-4294-a842-9bfb0fa34414"
	],
	"report_names": [
		"listgroups.cgi?u=f4215b2e-bc7d-4294-a842-9bfb0fa34414"
	],
	"threat_actors": [
		{
			"id": "8386d4af-5cca-40bb-91d7-aca5d1a0ec99",
			"created_at": "2022-10-25T16:07:23.414558Z",
			"updated_at": "2026-04-10T02:00:04.588816Z",
			"deleted_at": null,
			"main_name": "Bookworm",
			"aliases": [],
			"source_name": "ETDA:Bookworm",
			"tools": [
				"Agent.dhwf",
				"Chymine",
				"Darkmoon",
				"Destroy RAT",
				"DestroyRAT",
				"FF-RAT",
				"FormerFirstRAT",
				"Gen:Trojan.Heur.PT",
				"Kaba",
				"Korplug",
				"PlugX",
				"Poison Ivy",
				"RedDelta",
				"SPIVY",
				"Scieron",
				"Sogu",
				"TIGERPLUG",
				"TVT",
				"Thoper",
				"Xamtrav",
				"ffrat",
				"pivy",
				"poisonivy"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775434555,
	"ts_updated_at": 1775792167,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/45208a0175abef27623bce644c83ec5447cb9a70.pdf",
		"text": "https://archive.orkl.eu/45208a0175abef27623bce644c83ec5447cb9a70.txt",
		"img": "https://archive.orkl.eu/45208a0175abef27623bce644c83ec5447cb9a70.jpg"
	}
}