This threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa, Europe, and the Middle East, for the purpose of espionage.
Also known as
Clean Ursa, Cloud Atlas, OXYGEN, G0100, ATK116, Blue Odin.
References
- cfr.org
- web.archive.org
- paper.seebug.org
- logrhythm.com
- paper.seebug.org
- securelist.com
- securelist.com
- securelist.com
- securelist.com
- securelist.com
- unit42.paloaltonetworks.com
- securelist.com
Actor metadata imported from Malpedia (Fraunhofer FKIE).