{
  "type": "bundle",
  "id": "bundle--4a6df89d-16d0-5898-8246-f16def01b776",
  "objects": [
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
      "created": "2017-01-20T00:00:00.000Z",
      "definition_type": "tlp",
      "name": "TLP:WHITE",
      "definition": {
        "tlp": "white"
      }
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-07T00:00:00.000Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "name": "skopnix",
      "identity_class": "organization",
      "description": "skopnix — open threat intelligence. Aggregated and published, not authored: cite the external_references, not us.",
      "contact_information": "https://skopnix.com"
    },
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-15T11:55:05.370Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "id": "intrusion-set--7d86f75e-80ae-52c8-91a7-24f079986d32",
      "name": "TiltedTemple",
      "aliases": [
        "TiltedTemple",
        "DEV-0322",
        "Circle Typhoon"
      ],
      "description": "One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activities have been linked to the exploitation of vulnerabilities in Zoho ManageEngine ADSelfService Plus and ServiceDesk Plus.",
      "external_references": [
        {
          "source_name": "skopnix",
          "external_id": "tiltedtemple",
          "url": "https://skopnix.com/actors/tiltedtemple"
        },
        {
          "source_name": "unit42.paloaltonetworks.com",
          "url": "https://unit42.paloaltonetworks.com/sockdetour/"
        },
        {
          "source_name": "blog.fox-it.com",
          "url": "https://blog.fox-it.com/2021/11/08/ta505-exploits-solarwinds-serv-u-vulnerability-cve-2021-35211-for-initial-access/"
        },
        {
          "source_name": "microsoft.com",
          "url": "https://www.microsoft.com/en-us/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/"
        }
      ]
    }
  ]
}