{
	"id": "ee765c05-cda0-4519-8cd2-038fa71d10cf",
	"created_at": "2026-04-06T00:20:02.27182Z",
	"updated_at": "2026-04-10T13:11:27.787791Z",
	"deleted_at": null,
	"sha1_hash": "deb689f5361281865715107dde7c3d38e5e970ef",
	"title": "Talks - BrightTALK",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 46979,
	"plain_text": "Talks - BrightTALK\r\nArchived: 2026-04-05 19:16:37 UTC\r\nRecent talks\r\nTransform the Software Development Lifecycle with Atlassian Teamwork Collection\r\nChannel Logo\r\nTransform the Software\r\nDevelopment Lifecycle …\r\nTeamwork Collection in\r\naction! In this\r\non-demand demo, see t…\r\n2 days ago| 19 mins\r\nInsights from Teamwork Labs\r\nChannel Logo\r\nInsights from Teamwork\r\nLabs\r\nHear top findings from\r\nthe latest AI collaboration\r\nreport and insights fro…\r\n2 days ago| 8 mins\r\nTeamwork in an AI Era\r\nChannel Logo\r\nTeamwork in an AI Era\r\nTeamwork Collection in\r\naction! In this\r\non-demand demo, see t…\r\n2 days ago| 119 mins\r\nHow to streamline complex quoting and order fulfillment with ServiceNow\r\nhttps://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east\r\nPage 1 of 5\n\nChannel Logo\r\nHow to streamline\r\ncomplex quoting and or…\r\nQuoting and fulfilling\r\ncomplex orders can slow\r\ndown sales cycles and fr…\r\n2 days ago| 33 mins\r\nCity of Vienna: Demonstrating the Power of WienKI (ViennaAI) The City’s AI Sovereignty\r\nChannel Logo\r\nCity of Vienna:\r\nDemonstrating the Pow…\r\nHow does a major\r\nEuropean capital harness\r\nthe speed of Generative…\r\n2 days ago| 29 mins\r\nCrush quotas with quotes that close\r\nChannel Logo\r\nCrush quotas with\r\nquotes that close\r\nLegacy CRMs promised to\r\nhelp sellers but ended up\r\nburying them in busywo…\r\n2 days ago| 21 mins\r\nFuture-Proofing Your Data Security in a World Rewritten by AI\r\nChannel Logo\r\nFuture-Proofing Your\r\nData Security in a World…\r\nAs generative AI\r\ntransforms the way we\r\nhttps://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east\r\nPage 2 of 5\n\nwork and innovate, the …\r\n2 days ago| 39 mins\r\nBeyond DLP: How DSPM and Unified Platforms Are Redefining Data Security\r\nChannel Logo\r\nBeyond DLP: How DSPM\r\nand Unified Platforms A…\r\nAs data expands across\r\nSaaS, cloud, on-prem,\r\nand AI environments, st…\r\n2 days ago| 23 mins\r\nComing up\r\nSecuring Your AI Agents To Embrace Their Full Potential\r\nChannel Logo\r\nSecuring Your AI Agents\r\nTo Embrace Their Full P…\r\nIn this session you will\r\nlearn about the state of\r\nAI adoption around the …\r\nApr 09 2026, 5:00am UTC\r\nUncover the Metrics That Make an Impact on Your Security Posture!\r\nChannel Logo\r\nUncover the Metrics That\r\nMake an Impact on You…\r\nAre you looking to\r\nimprove your security\r\nmetrics game? In our w…\r\nApr 06 2026, 1:00pm UTC\r\nUnlocking Municipal Success with Modern Project Portfolio Management (PPM) Tools\r\nhttps://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east\r\nPage 3 of 5\n\nChannel Logo\r\nUnlocking Municipal\r\nSuccess with Modern Pr…\r\nJoin Rego Consulting, a\r\nproud MISA Canada\r\nmember, for a practical,…\r\nApr 06 2026, 3:00pm UTC\r\nCrackArmor - How a Nearly Decade‑Old Flaw Opened the Door to Root Access\r\nChannel Logo\r\nCrackArmor - How a\r\nNearly Decade‑Old Flaw…\r\nA newly uncovered set of\r\nvulnerabilities in the\r\nLinux kernel has expose…\r\nApr 06 2026, 4:00pm UTC\r\nAdvanced Dashboard: See how purpose-built AI tools make your job (and outcomes) easier (APAC)\r\nChannel Logo\r\nAdvanced Dashboard:\r\nSee how purpose-built …\r\nToo often, teams have to\r\nchoose between\r\ndashboards that are fas…\r\nApr 07 2026, 12:00am UTC\r\nBeyond Tools - SMB Security that Works\r\nChannel Logo\r\nBeyond Tools - SMB\r\nSecurity that Works\r\nSMBs are surrounded by\r\nsecurity noise — new\r\nhttps://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east\r\nPage 4 of 5\n\ntools, new features, and…\r\nApr 07 2026, 4:30am UTC\r\nStop Threats Faster: Elevate Your Security from EDR to XDR Optimum\r\nChannel Logo\r\nStop Threats Faster:\r\nElevate Your Security fr…\r\nCybercriminals have\r\nevolved. Has your\r\nsecurity? With phishing,…\r\nApr 07 2026, 5:00am UTC\r\nBrowse content by topics\r\nDiscover the most popular and trending topics on BrightTALK.See all topics\r\nSource: https://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east\r\nhttps://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east\r\nPage 5 of 5",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"MITRE"
	],
	"origins": [
		"web"
	],
	"references": [
		"https://www.brighttalk.com/webcast/10703/296317/apt34-new-targeted-attack-in-the-middle-east"
	],
	"report_names": [
		"apt34-new-targeted-attack-in-the-middle-east"
	],
	"threat_actors": [
		{
			"id": "ce10c1bd-4467-45f9-af83-28fc88e35ca4",
			"created_at": "2022-10-25T15:50:23.458833Z",
			"updated_at": "2026-04-10T02:00:05.419537Z",
			"deleted_at": null,
			"main_name": "APT34",
			"aliases": null,
			"source_name": "MITRE:APT34",
			"tools": [
				"netstat",
				"Systeminfo",
				"PsExec",
				"SEASHARPEE",
				"Tasklist",
				"Mimikatz",
				"POWRUNER",
				"certutil"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "cffb3c01-038f-4527-9cfd-57ad5a035c22",
			"created_at": "2022-10-25T15:50:23.38055Z",
			"updated_at": "2026-04-10T02:00:05.258283Z",
			"deleted_at": null,
			"main_name": "OilRig",
			"aliases": [
				"COBALT GYPSY",
				"IRN2",
				"APT34",
				"Helix Kitten",
				"Evasive Serpens",
				"Hazel Sandstorm",
				"EUROPIUM",
				"ITG13",
				"Earth Simnavaz",
				"Crambus",
				"TA452"
			],
			"source_name": "MITRE:OilRig",
			"tools": [
				"ISMInjector",
				"ODAgent",
				"RDAT",
				"Systeminfo",
				"QUADAGENT",
				"OopsIE",
				"ngrok",
				"Tasklist",
				"certutil",
				"ZeroCleare",
				"POWRUNER",
				"netstat",
				"Solar",
				"ipconfig",
				"LaZagne",
				"BONDUPDATER",
				"SideTwist",
				"OilBooster",
				"SampleCheck5000",
				"PsExec",
				"SEASHARPEE",
				"Mimikatz",
				"PowerExchange",
				"OilCheck",
				"RGDoor",
				"ftp"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "67b2c161-5a04-4e3d-8ce7-cce457a4a17b",
			"created_at": "2025-08-07T02:03:24.722093Z",
			"updated_at": "2026-04-10T02:00:03.681914Z",
			"deleted_at": null,
			"main_name": "COBALT EDGEWATER",
			"aliases": [
				"APT34 ",
				"Cold River ",
				"DNSpionage "
			],
			"source_name": "Secureworks:COBALT EDGEWATER",
			"tools": [
				"AgentDrable",
				"DNSpionage",
				"Karkoff",
				"MailDropper",
				"SideTwist",
				"TWOTONE"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "c786e025-c267-40bd-9491-328da70811a5",
			"created_at": "2025-08-07T02:03:24.736817Z",
			"updated_at": "2026-04-10T02:00:03.752071Z",
			"deleted_at": null,
			"main_name": "COBALT GYPSY",
			"aliases": [
				"APT34 ",
				"CHRYSENE ",
				"Crambus ",
				"EUROPIUM ",
				"Hazel Sandstorm ",
				"Helix Kitten ",
				"ITG13 ",
				"OilRig ",
				"Yellow Maero "
			],
			"source_name": "Secureworks:COBALT GYPSY",
			"tools": [
				"Glimpse",
				"Helminth",
				"Jason",
				"MacDownloader",
				"PoisonFrog",
				"RGDoor",
				"ThreeDollars",
				"TinyZbot",
				"Toxocara",
				"Trichuris",
				"TwoFace"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "67709937-2186-4a32-b64c-a5693d40ac77",
			"created_at": "2023-01-06T13:46:38.495593Z",
			"updated_at": "2026-04-10T02:00:02.999196Z",
			"deleted_at": null,
			"main_name": "OilRig",
			"aliases": [
				"Crambus",
				"Helix Kitten",
				"APT34",
				"IRN2",
				"ATK40",
				"G0049",
				"EUROPIUM",
				"TA452",
				"Twisted Kitten",
				"Cobalt Gypsy",
				"APT 34",
				"Evasive Serpens",
				"Hazel Sandstorm",
				"Earth Simnavaz"
			],
			"source_name": "MISPGALAXY:OilRig",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		}
	],
	"ts_created_at": 1775434802,
	"ts_updated_at": 1775826687,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/deb689f5361281865715107dde7c3d38e5e970ef.pdf",
		"text": "https://archive.orkl.eu/deb689f5361281865715107dde7c3d38e5e970ef.txt",
		"img": "https://archive.orkl.eu/deb689f5361281865715107dde7c3d38e5e970ef.jpg"
	}
}