{
  "type": "bundle",
  "id": "bundle--f59974b1-ad57-533b-8b30-adb0a388ec6b",
  "objects": [
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
      "created": "2017-01-20T00:00:00.000Z",
      "definition_type": "tlp",
      "name": "TLP:WHITE",
      "definition": {
        "tlp": "white"
      }
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-07T00:00:00.000Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "name": "skopnix",
      "identity_class": "organization",
      "description": "skopnix — open threat intelligence. Aggregated and published, not authored: cite the external_references, not us.",
      "contact_information": "https://skopnix.com"
    },
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-08T11:29:40.332Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "id": "intrusion-set--dcc12a12-c9f1-5e4e-a725-0b2768f053e9",
      "name": "Teleboyi",
      "aliases": [
        "Teleboyi"
      ],
      "description": "Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a similar string decryption algorithm as seen in the McUtil.dll loader from Operation Harvest. While there are weak links to the dsqurey[.]com domain, the connection remains uncertain due to the domain's registration history.",
      "external_references": [
        {
          "source_name": "skopnix",
          "external_id": "teleboyi",
          "url": "https://skopnix.com/actors/teleboyi"
        },
        {
          "source_name": "trendmicro.com",
          "url": "https://www.trendmicro.com/en_us/research/25/b/updated-shadowpad-malware-leads-to-ransomware-deployment.html"
        }
      ]
    }
  ]
}