BlueHornetBlueHornet

Also known as: APT49 · AgainstTheWest · BlueHornet

Known aliases
3

Profile

BlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked data from other APT groups like Kryptonite Panda and Lazarus Group. BlueHornet has been involved in campaigns such as Operation Renminbi, Operation Ruble, and Operation EUSec, focusing on exfiltrating region-specific data and selling it on the dark web. They have also been known to collaborate with different threat actors and have recently disclosed a zero-day exploit in NGINX 1.18.

Aliases· 3

APT49AgainstTheWestBlueHornet

References

  1. https://cyberint.com/blog/research/bluehornet-one-apt-to-terrorize-them-all/
  2. https://www.mandiant.com/resources/blog/killnet-new-capabilities-older-tactics
  3. https://www.csoonline.com/article/3684668/cyberattacks-against-governments-jumped-95-in-last-half-of-2022-cloudsek-says.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
NightEagle
Actor
APT41
Actor
Lazarus Group
Actor
APT37
Actor
APT4
Actor
BlueBottle
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.