{
	"id": "375b8751-c768-46a9-acd4-46e521b8f62d",
	"created_at": "2026-04-06T00:14:09.178025Z",
	"updated_at": "2026-04-10T03:21:05.222862Z",
	"deleted_at": null,
	"sha1_hash": "a28452a02a6d4386f8df60477434433cdca27164",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 52237,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 23:19:42 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool FlokiBot\n Tool: FlokiBot\nNames FlokiBot\nCategory Malware\nType Banking trojan, POS malware, Backdoor, Info stealer, Credential stealer\nDescription\n(Talos) Floki Bot is another example of what happens when the source code of successful\nmalware kits gets leaked online. As we have seen several times since the Zeus source code\nbecame available, new malware variants based on this codebase continue to emerge. Floki\nBot is unique in that the authors of this malware have put effort into expanding upon the\nfunctionality that was present in Zeus and have implemented new functionality making\nFloki Bot very attractive to criminals.\nInformation\nMalpedia AlienVault OTX Last change to this tool card: 24 May 2020\nDownload this tool card in JSON format\nAll groups using tool FlokiBot\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0aa1adbc-f0d5-4945-9b35-30ae9c4f3772\nPage 1 of 2\n\nChanged Name Country Observed\r\nUnknown groups\r\n  _[ Interesting malware not linked to an actor yet ]_  \r\n1 group listed (0 APT, 0 other, 1 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0aa1adbc-f0d5-4945-9b35-30ae9c4f3772\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0aa1adbc-f0d5-4945-9b35-30ae9c4f3772\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0aa1adbc-f0d5-4945-9b35-30ae9c4f3772"
	],
	"report_names": [
		"listgroups.cgi?u=0aa1adbc-f0d5-4945-9b35-30ae9c4f3772"
	],
	"threat_actors": [],
	"ts_created_at": 1775434449,
	"ts_updated_at": 1775791265,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/a28452a02a6d4386f8df60477434433cdca27164.pdf",
		"text": "https://archive.orkl.eu/a28452a02a6d4386f8df60477434433cdca27164.txt",
		"img": "https://archive.orkl.eu/a28452a02a6d4386f8df60477434433cdca27164.jpg"
	}
}