{
	"id": "0ebe059a-ebb4-4e03-aeb3-2b93bd7b271d",
	"created_at": "2026-04-06T00:18:43.563201Z",
	"updated_at": "2026-04-10T03:21:16.488861Z",
	"deleted_at": null,
	"sha1_hash": "e68a0d9ebf0f9597c5fd48662248c345111cf1e2",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 48126,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 21:50:04 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool Karius\n Tool: Karius\nNames Karius\nCategory Malware\nType Banking trojan, Info stealer, Credential stealer\nDescription\n(Check Point) The Check Point Research team recently came across one such banking Trojan\nunder development and already being distributed through the RIG Exploit Kit. Dubbed\n‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s\nlegitimate login page and send the inputted information to the attacker.\nWhile Karius is not yet in full infection mode, initial tests have already been made and our\nresearch below shows the evolution of how such malware takes place. Our analysis also shows\nhow banking trojans such as Karius are put together and makes use of code from other well-known bankers such as Ramnit, Vawtrak and TrickBot.\nInformation\nMalpedia Last change to this tool card: 23 May 2020\nDownload this tool card in JSON format\nAll groups using tool Karius\nChanged Name Country Observed\nUnknown groups\n _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown)\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028\nPage 1 of 2\n\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028\r\nPage 2 of 2\n\nUnknown groups _[ Interesting malware not linked to an actor yet ]_\n1 group listed (0 APT, 0 other, 1 unknown) \n   Page 1 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028"
	],
	"report_names": [
		"listgroups.cgi?u=a68618b6-5b31-43fd-a615-e48d35fae028"
	],
	"threat_actors": [],
	"ts_created_at": 1775434723,
	"ts_updated_at": 1775791276,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/e68a0d9ebf0f9597c5fd48662248c345111cf1e2.pdf",
		"text": "https://archive.orkl.eu/e68a0d9ebf0f9597c5fd48662248c345111cf1e2.txt",
		"img": "https://archive.orkl.eu/e68a0d9ebf0f9597c5fd48662248c345111cf1e2.jpg"
	}
}