{
	"id": "cfe863b9-c307-4e4a-ad52-2bcb8eab398a",
	"created_at": "2026-04-06T03:37:15.160654Z",
	"updated_at": "2026-04-10T03:22:08.664176Z",
	"deleted_at": null,
	"sha1_hash": "6128b03bd94dd68f1bd62f31cc5a4c28f0b392d9",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 47140,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\r\nArchived: 2026-04-06 03:14:34 UTC\r\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool ExoBotCompact\r\n Tool: ExoBotCompact\r\nNames\r\nExoBotCompact\r\nCoper\r\nOcto\r\nOcto2\r\nCategory Malware\r\nType Banking trojan, Info stealer, Credential stealer, Botnet\r\nDescription\r\n(ThreatFabric) On January 23, 2022, ThreatFabric analysts spotted a post on one of the darknet\r\nforums, in which a member was looking for Octo Android botnet. Further analysis, as it will be\r\nshown in this blog, uncovered a direct connection between Octo and ExobotCompact: in fact,\r\nExobotCompact was updated with several features and rebranded to Octo.\r\nInformation\r\n\u003chttps://threatfabric.com/blogs/octo-new-odf-banking-trojan.html\u003e\r\n\u003chttps://www.threatfabric.com/blogs/octo2-european-banks-already-under-attack-by-new-malware-variant\u003e\r\nMalpedia \u003chttps://malpedia.caad.fkie.fraunhofer.de/details/apk.coper\u003e\r\nLast change to this tool card: 23 October 2024\r\nDownload this tool card in JSON format\r\nAll groups using tool ExoBotCompact\r\nChanged Name Country Observed\r\nUnknown groups\r\n  _[ Interesting malware not linked to an actor yet ]_  \r\n1 group listed (0 APT, 0 other, 1 unknown)\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f63ac450-fcb3-421d-866a-1dccb2db15aa\r\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f63ac450-fcb3-421d-866a-1dccb2db15aa\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f63ac450-fcb3-421d-866a-1dccb2db15aa\r\nPage 2 of 2\n\nUnknown groups _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown) \n   Page 1 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f63ac450-fcb3-421d-866a-1dccb2db15aa"
	],
	"report_names": [
		"listgroups.cgi?u=f63ac450-fcb3-421d-866a-1dccb2db15aa"
	],
	"threat_actors": [],
	"ts_created_at": 1775446635,
	"ts_updated_at": 1775791328,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/6128b03bd94dd68f1bd62f31cc5a4c28f0b392d9.pdf",
		"text": "https://archive.orkl.eu/6128b03bd94dd68f1bd62f31cc5a4c28f0b392d9.txt",
		"img": "https://archive.orkl.eu/6128b03bd94dd68f1bd62f31cc5a4c28f0b392d9.jpg"
	}
}