{
	"id": "762ce36c-625a-4cb3-8341-8958a310f2b7",
	"created_at": "2026-04-06T03:35:58.383622Z",
	"updated_at": "2026-04-10T13:12:35.516621Z",
	"deleted_at": null,
	"sha1_hash": "74ef9af2635298360c76bce693bd041414720db8",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 46969,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\r\nArchived: 2026-04-06 03:31:42 UTC\r\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool SUCEFUL\r\n Tool: SUCEFUL\r\nNames SUCEFUL\r\nCategory Malware\r\nType ATM malware\r\nDescription\r\n(FireEye) FireEye Labs discovered a new piece of ATM malware\r\n(4BDD67FF852C221112337FECD0681EAC) that we detect as Backdoor.ATM.Suceful\r\n(the name comes from a typo made by the malware authors), which targets cardholders\r\nand is able to retain debit cards on infected ATMs, disable alarms, or read the debit card\r\ntracks.\r\nInformation\r\n\u003chttps://www.fireeye.com/blog/threat-research/2015/09/suceful_next_genera.html\u003e\r\n\u003chttps://documents.trendmicro.com/assets/white_papers/wp-cashing-in-on-atm-malware.pdf\u003e\r\nMalpedia \u003chttps://malpedia.caad.fkie.fraunhofer.de/details/win.suceful\u003e\r\nAlienVault OTX \u003chttps://otx.alienvault.com/browse/pulses?q=tag:suceful\u003e\r\nLast change to this tool card: 24 April 2021\r\nDownload this tool card in JSON format\r\nAll groups using tool SUCEFUL\r\nChanged Name Country Observed\r\nUnknown groups\r\n  _[ Interesting malware not linked to an actor yet ]_  \r\n1 group listed (0 APT, 0 other, 1 unknown)\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=85aa5414-42c2-40ad-badd-64e3e16f5025\r\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=85aa5414-42c2-40ad-badd-64e3e16f5025\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=85aa5414-42c2-40ad-badd-64e3e16f5025\r\nPage 2 of 2\n\nUnknown groups _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown) \n   Page 1 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=85aa5414-42c2-40ad-badd-64e3e16f5025"
	],
	"report_names": [
		"listgroups.cgi?u=85aa5414-42c2-40ad-badd-64e3e16f5025"
	],
	"threat_actors": [],
	"ts_created_at": 1775446558,
	"ts_updated_at": 1775826755,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/74ef9af2635298360c76bce693bd041414720db8.pdf",
		"text": "https://archive.orkl.eu/74ef9af2635298360c76bce693bd041414720db8.txt",
		"img": "https://archive.orkl.eu/74ef9af2635298360c76bce693bd041414720db8.jpg"
	}
}