Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:07:06 UTC Home > List all groups > List all tools > List all groups using tool Bourbon Tool: Bourbon Names Bourbon Category Malware Type Info stealer Description (Citizen Lab) During our analysis, we were able to acquire two plugin packages, named “Bourbon.jar” and “IceCube.jar” which added functionality including exfiltrating SMS text messages, address books, and call logs, and spying on the target through their phone’s camera, microphone, and GPS. Information Last change to this tool card: 20 April 2020 Download this tool card in JSON format All groups using tool Bourbon Changed Name Country Observed APT groups Poison Carp, Evil Eye 2018-Jun 2023 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6833be25-8f66-46cf-9747-96cc3ee48a5a https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6833be25-8f66-46cf-9747-96cc3ee48a5a Page 1 of 1