Codoso

Threat Actor updated 4 months ago (2024-05-04T20:50:02.546Z)
Download STIX
Preview STIX
Codoso, also known as C0d0so0 or the Sunshop Group, is a notable threat actor in the cybersecurity landscape. Originally identified by FireEye as the Sunshop Group in 2013, this adversary group has been on security research radars since 2010 due to its numerous targeted attacks exploiting zero-day vulnerabilities. The group's modus operandi includes using sophisticated malware like Derusbi, similar to another prominent threat actor, Deep Panda. Unit 42 recently discovered new malicious activity linked to Codoso while investigating unknown malware and attack campaigns through the AutoFocus threat intelligence platform. This discovery indicates that Codoso continues to be an active and significant threat in the cybersecurity world, constantly evolving and adapting their techniques to carry out their operations more effectively. In a recent incident, Codoso was implicated in a watering hole attack against Forbes and other targets in November of the previous year. This attack was attributed to Codoso by iSIGHT Partners and Invincea, confirming the group's ongoing activities and highlighting their ability to target high-profile entities. These incidents underscore the importance of robust cybersecurity measures and constant vigilance against persistent threat actors such as Codoso.
Description last updated: 2023-11-29T02:02:39.112Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Codoso Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
New Attacks Linked to C0d0so0 Group
MITRE
2 years ago
Chinese Hacking Group Codoso Team Uses Forbes.com As Watering Hole