{
  "type": "bundle",
  "id": "bundle--ee193fd8-0c1d-5f50-9642-a54a468f8512",
  "objects": [
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
      "created": "2017-01-20T00:00:00.000Z",
      "definition_type": "tlp",
      "name": "TLP:WHITE",
      "definition": {
        "tlp": "white"
      }
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-07T00:00:00.000Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "name": "skopnix",
      "identity_class": "organization",
      "description": "skopnix — open threat intelligence. Aggregated and published, not authored: cite the external_references, not us.",
      "contact_information": "https://skopnix.com"
    },
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-08T11:29:40.332Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "id": "intrusion-set--caaae864-dab9-5f71-9184-3e8e9410f419",
      "name": "SongXY",
      "aliases": [
        "SongXY"
      ],
      "description": "SongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2018-0798 vulnerability in Microsoft Equation Editor. In one instance, they sent a document containing a link to an attacker-controlled server, which automatically triggered upon opening, allowing them to gather information about the target's system configuration.",
      "external_references": [
        {
          "source_name": "skopnix",
          "external_id": "songxy",
          "url": "https://skopnix.com/actors/songxy"
        },
        {
          "source_name": "ptsecurity.com",
          "url": "https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/covid-19-and-new-year-greetings-the-higaisa-group/"
        },
        {
          "source_name": "ptsecurity.com",
          "url": "http://www.ptsecurity.com/upload/corporate/ww-en/analytics/APT-Attacks-eng.pdf"
        }
      ]
    }
  ]
}