{
	"id": "d5af2675-27a9-4c6c-902f-8fd80bfbfe88",
	"created_at": "2026-04-06T00:14:53.61303Z",
	"updated_at": "2026-04-10T13:12:10.679177Z",
	"deleted_at": null,
	"sha1_hash": "6825bcb519019f5aad0642129fc5142edcdddcbc",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 47383,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 23:46:30 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool PoSlurp\n Tool: PoSlurp\nNames\nPoSlurp\nPUNCHTRACK\nPSVC\nCategory Malware\nType POS malware, Backdoor, Info stealer\nDescription\n(Trend Micro) PoSlurp scrapes credit card data processed by the PoS devices, including\nstored and encrypted card data prior to malware infection. Once the information is\nextracted from the infected system, the attackers can check and verify the validity of the\ndata offline. PoSlurp also allows the attackers to inject other commands, access files,\ncopy log files back to the server, and delete log files, among others.\nInformation\nMITRE ATT\u0026CK Malpedia AlienVault OTX Last change to this tool card: 22 April 2020\nDownload this tool card in JSON format\nAll groups using tool PoSlurp\nChanged Name Country Observed\nAPT groups\n FIN8 [Unknown] 2016-Dec 2022\n1 group listed (1 APT, 0 other, 0 unknown)\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=40074bfa-a8db-4cd2-89d4-200c99d717f2\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=40074bfa-a8db-4cd2-89d4-200c99d717f2\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=40074bfa-a8db-4cd2-89d4-200c99d717f2\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=40074bfa-a8db-4cd2-89d4-200c99d717f2"
	],
	"report_names": [
		"listgroups.cgi?u=40074bfa-a8db-4cd2-89d4-200c99d717f2"
	],
	"threat_actors": [
		{
			"id": "3150bf4f-288a-44b8-ab48-0ced9b052a0c",
			"created_at": "2025-08-07T02:03:24.910023Z",
			"updated_at": "2026-04-10T02:00:03.713077Z",
			"deleted_at": null,
			"main_name": "GOLD HUXLEY",
			"aliases": [
				"CTG-6969 ",
				"FIN8 "
			],
			"source_name": "Secureworks:GOLD HUXLEY",
			"tools": [
				"Gozi ISFB",
				"Powersniff"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "5bdde906-0416-42ee-9100-5ebd95dda77a",
			"created_at": "2023-01-06T13:46:38.601977Z",
			"updated_at": "2026-04-10T02:00:03.035842Z",
			"deleted_at": null,
			"main_name": "FIN8",
			"aliases": [
				"ATK113",
				"G0061"
			],
			"source_name": "MISPGALAXY:FIN8",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "72d09c17-e33e-4c2f-95db-f204848cc797",
			"created_at": "2022-10-25T15:50:23.832551Z",
			"updated_at": "2026-04-10T02:00:05.336787Z",
			"deleted_at": null,
			"main_name": "FIN8",
			"aliases": [
				"FIN8",
				"Syssphinx"
			],
			"source_name": "MITRE:FIN8",
			"tools": [
				"BADHATCH",
				"PUNCHBUGGY",
				"Ragnar Locker",
				"PUNCHTRACK",
				"dsquery",
				"Nltest",
				"Sardonic",
				"PsExec",
				"Impacket"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "fc80a724-e567-457c-82bb-70147435e129",
			"created_at": "2022-10-25T16:07:23.624289Z",
			"updated_at": "2026-04-10T02:00:04.691643Z",
			"deleted_at": null,
			"main_name": "FIN8",
			"aliases": [
				"ATK 113",
				"G0061",
				"Storm-0288",
				"Syssphinx"
			],
			"source_name": "ETDA:FIN8",
			"tools": [
				"ALPHV",
				"ALPHVM",
				"BadHatch",
				"BlackCat",
				"Noberus",
				"PSVC",
				"PUNCHTRACK",
				"PoSlurp",
				"Powersniff",
				"PunchBuggy",
				"Ragnar Loader",
				"Ragnar Locker",
				"RagnarLocker",
				"Sardonic",
				"ShellTea"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775434493,
	"ts_updated_at": 1775826730,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/6825bcb519019f5aad0642129fc5142edcdddcbc.pdf",
		"text": "https://archive.orkl.eu/6825bcb519019f5aad0642129fc5142edcdddcbc.txt",
		"img": "https://archive.orkl.eu/6825bcb519019f5aad0642129fc5142edcdddcbc.jpg"
	}
}