{
	"id": "170a800b-13bc-4045-8580-9f7ae0d57b21",
	"created_at": "2026-04-06T00:21:42.491452Z",
	"updated_at": "2026-04-10T13:13:07.573078Z",
	"deleted_at": null,
	"sha1_hash": "7bfd68baa04f834c7f72e30ff66a297b351896fb",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 49120,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 20:04:03 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool DoubleZero\n Tool: DoubleZero\nNames\nDoubleZero\nFiberLake\nCategory Malware\nType Wiper\nDescription\n(Talos) The Computer Emergency Response Team of Ukraine released an advisory on March\n22, 2022 disclosing another wiper dubbed 'DoubleZero' targeting Ukrainian enterprises during\nRussia's invasion of the country. This wiper was detected as early as March 17, 2022.\nDoubleZero is yet another wiper discovered in addition to previously disclosed attacks we've\nseen in Ukraine over the past two months, such as 'CaddyWiper' 'HermeticWiper' and\n'WhisperGate.'\nDoubleZero is a .NET-based implant that destroys files, registry keys and trees on the infected\nendpoint.\nInformation\nMalpedia Last change to this tool card: 27 December 2022\nDownload this tool card in JSON format\nAll groups using tool DoubleZero\nChanged Name Country Observed\nUnknown groups\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=52b5ac80-4227-4351-8032-52ea1a878d6e\nPage 1 of 2\n\n_[ Interesting malware not linked to an actor yet ]_  \r\n1 group listed (0 APT, 0 other, 1 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=52b5ac80-4227-4351-8032-52ea1a878d6e\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=52b5ac80-4227-4351-8032-52ea1a878d6e\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=52b5ac80-4227-4351-8032-52ea1a878d6e"
	],
	"report_names": [
		"listgroups.cgi?u=52b5ac80-4227-4351-8032-52ea1a878d6e"
	],
	"threat_actors": [],
	"ts_created_at": 1775434902,
	"ts_updated_at": 1775826787,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/7bfd68baa04f834c7f72e30ff66a297b351896fb.pdf",
		"text": "https://archive.orkl.eu/7bfd68baa04f834c7f72e30ff66a297b351896fb.txt",
		"img": "https://archive.orkl.eu/7bfd68baa04f834c7f72e30ff66a297b351896fb.jpg"
	}
}