{
	"id": "3a34aa8b-56de-42e8-b11e-b0bdd77a63e6",
	"created_at": "2026-04-06T00:10:52.554593Z",
	"updated_at": "2026-04-10T03:20:54.060699Z",
	"deleted_at": null,
	"sha1_hash": "e3602cb46ccd11458b14117d5e8009f6a57afde6",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 48119,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 12:41:13 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool AcidRain\n Tool: AcidRain\nNames AcidRain\nCategory Malware\nType Wiper\nDescription\n(SentinelOne) AcidRain’s functionality is relatively straightforward and takes a\nbruteforce attempt that possibly signifies that the attackers were either unfamiliar with\nthe particulars of the target firmware or wanted the tool to remain generic and reusable.\nThe binary performs an in-depth wipe of the filesystem and various known storage\ndevice files. If the code is running as root, AcidRain performs an initial recursive\noverwrite and delete of non-standard files in the filesystem.\nInformation\nMITRE ATT\u0026CK Malpedia Last change to this tool card: 19 June 2024\nDownload this tool card in JSON format\nAll groups using tool AcidRain\nChanged Name Country Observed\nUnknown groups\n _[ Interesting malware not linked to an actor yet ]_\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5402160-095e-43cf-a6bc-86671d5e10bb\nPage 1 of 2\n\n1 group listed (0 APT, 0 other, 1 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5402160-095e-43cf-a6bc-86671d5e10bb\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5402160-095e-43cf-a6bc-86671d5e10bb\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5402160-095e-43cf-a6bc-86671d5e10bb"
	],
	"report_names": [
		"listgroups.cgi?u=d5402160-095e-43cf-a6bc-86671d5e10bb"
	],
	"threat_actors": [],
	"ts_created_at": 1775434252,
	"ts_updated_at": 1775791254,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/e3602cb46ccd11458b14117d5e8009f6a57afde6.pdf",
		"text": "https://archive.orkl.eu/e3602cb46ccd11458b14117d5e8009f6a57afde6.txt",
		"img": "https://archive.orkl.eu/e3602cb46ccd11458b14117d5e8009f6a57afde6.jpg"
	}
}