consolidated_actor_descriptions_ng

The consolidated_actor_descriptions_ng search table is one of the data sources for the AI Actor Profile dashboard. It adds an AI description for every unique threat actor and its aliases on ThreatStream. The table is read-only and not subject to modification.

(Click the image to enlarge it)

Field Value Type Description Example
actor_ids string ID of the Actor 856269
actor_name string Name of the Actor Dragon Force Group
alias array of strings Other names associated with the Actor. [Apolog, Satacom]
modified_ts date

Time stamp of when the Actor was last updated in ThreatStream.

Date is specified in the following format:

MMM dd, yyyy HH:mm:ss.SSS Z where

  • MMM - month name

  • dd - day of the month

  • yyyy - year

  • HH - hour (24-clock, 2 digits)

  • mm - minutes

  • ss - seconds

  • .SSS - milliseconds (3 digits)

  • Z - timezone offset from UTC

Jun 30, 2025 13:50:52.000 -07

summary string Summary of the Actor Group. ## Actor Group: UNC2814, Alloytaurus, Gallium, Granite Typhoon, Phantom Panda, Winnti Area 6 UNC2814 is a suspected Chinese cyber espionage group confirmed by multiple cybersecurity firms including Palo Alto Networks, Microsoft, CrowdStrike, and ProtectWise. Active since at least 2011, the group primarily targets international governments and telecommunications organizations with motivations centered on espionage. UNC2814 has merged with UNC4512 as of September 2024. The group employs a wide range of malware such as CHINACHOP, COLDEYE (including a Linux variant), COLDNOSE, HALFSPOT, HTRAN, POISONIVY, TROCHILUS, and ZXSHELL, alongside tools like WHOAMI. Their operations originate from China, specifically the Asia region and East Asia subregion. UNC2814 utilizes diverse tactics and techniques mapped to MITRE ATT&CK, including resource development (compromise infrastructure, develop and obtain capabilities, install digital certificates), initial access (external remote services, exploit public-facing applications), execution (command and scripting interpreters), persistence (external remote services, server software components, web shells, boot or logon autostart execution), privilege escalation (process injection, hijack execution flow), defense evasion (rootkits, obfuscation, process injection, indicator removal, virtualization/sandbox evasion, code signing), credential access (OS credential dumping), discovery (system services, network configuration, process and file discovery), collection (archiving collected data), command and control (application layer protocols, web protocols, encrypted channels), ingress tool transfer, data encoding, and impact (system shutdown/reboot).'