Threat Actor Profiles

FSB Center

Active

1 briefing · first covered 7/19/2026 · last covered 7/19/2026

Exploitable Vulnerabilities, Prioritized

Sorted by CISA KEV status and EPSS exploit probability, same signals as the dashboard.

CVE-2018-0171CiscoCritical

Indicators of Compromise

Subscribe to unlock this actor's full IOC list

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Detection Rules

Generic Sigma rules matched to this actor's known behavior — see Detection Rules to filter across every actor.

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock this Sigma rule

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Attribution & Known Techniques

Not tracked in MITRE ATT&CK or MISP's open threat-actor/ransomware galaxies as of the last check — real absence, not a gap in our lookup. Both sources skew toward nation-state APTs and well-established ransomware brands; this one may simply not have a public group profile yet.

Coverage Timeline

Not yet tracked for this actor

  • CrowdStrike Falcon / SentinelOne Deep Visibility-specific query syntax — hunting queries above (if any) are Microsoft Defender/Sentinel KQL
  • File transfer and exfiltration services used
  • MITRE ATT&CK techniques and structured country/sector attribution — see the note above
FSB Center: Threat Actor Profile | Decryption Digest | Decryption Digest