{
	"id": "1c015936-d411-47ac-961e-34f157d0d354",
	"created_at": "2026-04-06T00:12:14.472999Z",
	"updated_at": "2026-04-10T13:12:29.034304Z",
	"deleted_at": null,
	"sha1_hash": "67a5b8284b3a337d7f4807d876b01dc19754b9c4",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 45619,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\r\nArchived: 2026-04-05 13:22:54 UTC\r\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool MEGAsync\r\n Tool: MEGAsync\r\nNames MEGAsync\r\nCategory Tools\r\nType Exfiltration\r\nDescription\r\nMEGASync is the official MEGA client for Windows. You can use it to synchronize your files\r\nto the cloud, and upload any file to your personal MEGA account.\r\nInformation \u003chttps://megasync.en.uptodown.com/windows\u003e\r\nLast change to this tool card: 25 April 2021\r\nDownload this tool card in JSON format\r\nAll groups using tool MEGAsync\r\nChanged Name Country Observed\r\nAPT groups\r\n  ALPHV, BlackCat Gang [Unknown] 2021-Mar 2024\r\n  Indrik Spider 2007-Oct 2024\r\n  Traveling Spider [Unknown] 2019-Mar 2021  \r\n3 groups listed (3 APT, 0 other, 0 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=13674826-8ee9-4c1b-8700-6e238a481eb2\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=13674826-8ee9-4c1b-8700-6e238a481eb2\r\nPage 1 of 1",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=13674826-8ee9-4c1b-8700-6e238a481eb2"
	],
	"report_names": [
		"listgroups.cgi?u=13674826-8ee9-4c1b-8700-6e238a481eb2"
	],
	"threat_actors": [
		{
			"id": "8b7faa58-947b-4530-ab1f-250a0370aabf",
			"created_at": "2022-10-25T16:07:24.34248Z",
			"updated_at": "2026-04-10T02:00:04.945921Z",
			"deleted_at": null,
			"main_name": "Traveling Spider",
			"aliases": [
				"Gold Mansard"
			],
			"source_name": "ETDA:Traveling Spider",
			"tools": [
				"7-Zip",
				"AdFind",
				"LaZagne",
				"MEGAsync",
				"Mimikatz",
				"Nefilim",
				"Nemty",
				"Nephilim",
				"Network Password Recovery",
				"PsExec",
				"smbtool"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "1c76f1b6-a05b-4dba-82ea-07011b47c6cd",
			"created_at": "2023-01-06T13:46:39.201507Z",
			"updated_at": "2026-04-10T02:00:03.244851Z",
			"deleted_at": null,
			"main_name": "TRAVELING SPIDER",
			"aliases": [],
			"source_name": "MISPGALAXY:TRAVELING SPIDER",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "50068c14-343c-4491-b568-df41dd59551c",
			"created_at": "2022-10-25T15:50:23.253218Z",
			"updated_at": "2026-04-10T02:00:05.234464Z",
			"deleted_at": null,
			"main_name": "Indrik Spider",
			"aliases": [
				"Indrik Spider",
				"Evil Corp",
				"Manatee Tempest",
				"DEV-0243",
				"UNC2165"
			],
			"source_name": "MITRE:Indrik Spider",
			"tools": [
				"Mimikatz",
				"PsExec",
				"Dridex",
				"WastedLocker",
				"BitPaymer",
				"Cobalt Strike"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "b296f34c-c424-41da-98bf-90312a5df8ef",
			"created_at": "2024-06-19T02:03:08.027585Z",
			"updated_at": "2026-04-10T02:00:03.621193Z",
			"deleted_at": null,
			"main_name": "GOLD DRAKE",
			"aliases": [
				"Evil Corp",
				"Indrik Spider ",
				"Manatee Tempest "
			],
			"source_name": "Secureworks:GOLD DRAKE",
			"tools": [
				"BitPaymer",
				"Cobalt Strike",
				"Covenant",
				"Donut",
				"Dridex",
				"Hades",
				"Koadic",
				"LockBit",
				"Macaw Locker",
				"Mimikatz",
				"Payload.Bin",
				"Phoenix CryptoLocker",
				"PowerShell Empire",
				"PowerSploit",
				"SocGholish",
				"WastedLocker"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "d706edf6-cb86-4611-99e1-4b464e9dc5b9",
			"created_at": "2023-01-06T13:46:38.839083Z",
			"updated_at": "2026-04-10T02:00:03.117987Z",
			"deleted_at": null,
			"main_name": "INDRIK SPIDER",
			"aliases": [
				"Manatee Tempest"
			],
			"source_name": "MISPGALAXY:INDRIK SPIDER",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "6e23ce43-e1ab-46e3-9f80-76fccf77682b",
			"created_at": "2022-10-25T16:07:23.303713Z",
			"updated_at": "2026-04-10T02:00:04.530417Z",
			"deleted_at": null,
			"main_name": "ALPHV",
			"aliases": [
				"ALPHV",
				"ALPHVM",
				"Ambitious Scorpius",
				"BlackCat Gang",
				"UNC4466"
			],
			"source_name": "ETDA:ALPHV",
			"tools": [
				"ALPHV",
				"ALPHVM",
				"BlackCat",
				"GO Simple Tunnel",
				"GOST",
				"Impacket",
				"LaZagne",
				"MEGAsync",
				"Mimikatz",
				"Munchkin",
				"Noberus",
				"PsExec",
				"Remcom",
				"RemoteCommandExecution",
				"WebBrowserPassView"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "9806f226-935f-48eb-b138-6616c9bb9d69",
			"created_at": "2022-10-25T16:07:23.73153Z",
			"updated_at": "2026-04-10T02:00:04.729977Z",
			"deleted_at": null,
			"main_name": "Indrik Spider",
			"aliases": [
				"Blue Lelantos",
				"DEV-0243",
				"Evil Corp",
				"G0119",
				"Gold Drake",
				"Gold Winter",
				"Manatee Tempest",
				"Mustard Tempest",
				"UNC2165"
			],
			"source_name": "ETDA:Indrik Spider",
			"tools": [
				"Advanced Port Scanner",
				"Agentemis",
				"Babuk",
				"Babuk Locker",
				"Babyk",
				"BitPaymer",
				"Bugat",
				"Bugat v5",
				"Cobalt Strike",
				"CobaltStrike",
				"Cridex",
				"Dridex",
				"EmPyre",
				"EmpireProject",
				"FAKEUPDATES",
				"FakeUpdate",
				"Feodo",
				"FriedEx",
				"Hades",
				"IEncrypt",
				"LINK_MSIEXEC",
				"MEGAsync",
				"Macaw Locker",
				"Metasploit",
				"Mimikatz",
				"PayloadBIN",
				"Phoenix Locker",
				"PowerShell Empire",
				"PowerSploit",
				"PsExec",
				"QNAP-Worm",
				"Raspberry Robin",
				"RaspberryRobin",
				"SocGholish",
				"Vasa Locker",
				"WastedLoader",
				"WastedLocker",
				"cobeacon",
				"wp_encrypt"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775434334,
	"ts_updated_at": 1775826749,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/67a5b8284b3a337d7f4807d876b01dc19754b9c4.pdf",
		"text": "https://archive.orkl.eu/67a5b8284b3a337d7f4807d876b01dc19754b9c4.txt",
		"img": "https://archive.orkl.eu/67a5b8284b3a337d7f4807d876b01dc19754b9c4.jpg"
	}
}