Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Threat actors/ghost emperor alias #1052

Closed

Conversation

jashdalvi
Copy link
Contributor

This PR adds Earth Estries as an alias of Ghost Emperor and removes it as an independent TA. Also adds reference articles where Earth Estries is mentioned as an alias of Ghost Emperor.

@r0ny123
Copy link
Contributor

r0ny123 commented Feb 6, 2025

Hi, thanks for the PR. However, the references you've added to support your assertion are primarily news media articles. I've already included them as overlapping activities, so I'd like to maintain the current version, as there aren't enough legitimate public references available on this topic.

@jashdalvi
Copy link
Contributor Author

jashdalvi commented Feb 7, 2025

Thank you for the prompt review @r0ny123. I have added another article to support my PR. It is written by threat analyst so should be more credible. Here is the article: https://www.trendmicro.com/en_us/research/24/k/earth-estries.html. Does this count as valid resource to support my PR? I have also added this article in the list of references for Ghost Emperor. Thanks!

@r0ny123
Copy link
Contributor

r0ny123 commented Feb 8, 2025

They are not sure that both are the same actor, they just mentioned TTP overlap. This fact is already captured in MISP. So, I would like to close this as for now. If you still want to use it, you can fork the branch and use it by yourself.

@jashdalvi
Copy link
Contributor Author

jashdalvi commented Feb 10, 2025

Thank you for the review @r0ny123. There is another research article which mentions the alias quite clearly: https://www.cyfirma.com/research/apt-profile-earth-estries/. Adding this alias is quite important for our downstream work. If you think it might not be convincing enough for Earth Estries to be an alias of Ghost Emperor, feel free to close this PR.

@r0ny123
Copy link
Contributor

r0ny123 commented Feb 10, 2025

Cyfirma compiles original research and just provides a summary of findings. Yeah, I will lean toward closing the PR. But thanks for your research.

@adulau, we can close this.

@adulau
Copy link
Member

adulau commented Feb 10, 2025

Thanks!

@adulau adulau closed this Feb 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants