{
	"id": "e823c78e-dd1a-48a3-9775-3e7bd06974ff",
	"created_at": "2026-04-06T03:35:58.092748Z",
	"updated_at": "2026-04-10T13:11:36.168732Z",
	"deleted_at": null,
	"sha1_hash": "547e247951940853063a1badc4c09ef84b720fe9",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 50963,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-06 03:09:07 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool TinyNuke\n Tool: TinyNuke\nNames\nTinyNuke\nNukeBot\nNuclear Bot\nMicroBankingTrojan\nXbot\nCategory Malware\nType Reconnaissance, Banking trojan, Backdoor, Credential stealer, Tunneling, Botnet\nDescription\n(Bitsight) Tinynuke, or Nukebot malware, is a trojan able to perform man in the browser\nattacks against modern web browsers and equipped with the most common features\nneeded by a bank trojan (e.g. Webinjects, Socks proxy, VNC, Remote command\nexecution). This malware was in the spotlight in 2017 after the complete bot source code\nwas leaked in March by someone claiming to be the author of the malware.\nInformation\nMalpedia AlienVault OTX Last change to this tool card: 27 December 2021\nDownload this tool card in JSON format\nAll groups using tool TinyNuke\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e8441890-a53f-4eb0-8cf9-4bfbd68ab527\nPage 1 of 2\n\nChanged Name Country Observed\r\nUnknown groups\r\n  _[ Interesting malware not linked to an actor yet ]_  \r\n1 group listed (0 APT, 0 other, 1 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e8441890-a53f-4eb0-8cf9-4bfbd68ab527\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e8441890-a53f-4eb0-8cf9-4bfbd68ab527\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e8441890-a53f-4eb0-8cf9-4bfbd68ab527"
	],
	"report_names": [
		"listgroups.cgi?u=e8441890-a53f-4eb0-8cf9-4bfbd68ab527"
	],
	"threat_actors": [],
	"ts_created_at": 1775446558,
	"ts_updated_at": 1775826696,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/547e247951940853063a1badc4c09ef84b720fe9.pdf",
		"text": "https://archive.orkl.eu/547e247951940853063a1badc4c09ef84b720fe9.txt",
		"img": "https://archive.orkl.eu/547e247951940853063a1badc4c09ef84b720fe9.jpg"
	}
}