other
Threat group reported to have partnered with the SocGholish fake-update infrastructure, delivering malware via scareware and call centres.
No current published clusters are mapped here yet.