Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Turla and APT26 share the same synonym #942

Closed
frenkiesp opened this issue Mar 5, 2024 · 4 comments
Closed

Turla and APT26 share the same synonym #942

frenkiesp opened this issue Mar 5, 2024 · 4 comments
Assignees

Comments

@frenkiesp
Copy link

Hello,
We noticed that the threat actors Turla and APT26 share the same alias/synonym "Hippo Team". How is this possible? Is this a mistake?
Thanks.
Francesco

@adulau
Copy link
Member

adulau commented Mar 8, 2024

Interesting. I’ll do a review. Thanks for the notification.

@adulau adulau self-assigned this Mar 8, 2024
@adulau adulau closed this as completed in 3f039b5 Mar 11, 2024
@adulau
Copy link
Member

adulau commented Mar 11, 2024

Thanks for the notification, it's now fixed.

@frenkiesp
Copy link
Author

Hi Alexandre,
thanks for the fix. We found other six cases that have this issue. I attached a CSV file
misp_shared_aliases.csv

Tanks a lot,
Francesco

@adulau
Copy link
Member

adulau commented Mar 11, 2024

Thanks for the CSV and I just quickly reviewed those:

  • PLA Navy is more the sponsoring organisation. We should move it in a meta on the three clusters like sponsor-organisation
  • Grizzly Steppe is correct to be a synonym for APT28 and APT29
  • Andariel is a sub-group of Lazarous group
  • Cobalt Gypsy seems to be correct as it's historical with a discovery of multiple IR-sponsored groups
  • Golden Chickens seems to be a generic group to describe group 01 and 02 globally

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants