{
  "type": "bundle",
  "id": "bundle--0d6f2a11-8e1c-4c65-9a1f-3f0b7c2d4e51",
  "objects": [
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
      "created": "2017-01-20T00:00:00.000Z",
      "definition_type": "tlp",
      "name": "TLP:WHITE",
      "definition": {
        "tlp": "white"
      }
    },
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--7b2c9a48-1d3e-4f60-8a5b-6c9e0f1a2b34",
      "created": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "definition_type": "statement",
      "definition": {
        "statement": "SCOPE LIMITATION: this bundle establishes that ONE mailbox at airdroid.com was under adversary control on 2026-08-06 and nothing beyond that. It does NOT establish and Lifted Holdings LLC does NOT claim any breach of AirDroid or Sand Studio Pte. Ltd. products, systems, infrastructure, customer data or user accounts. Only Sand Studio's own Google Workspace admin audit logs can determine scope. The mailbox holder is a victim, not a perpetrator."
      }
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "name": "Lifted Holdings LLC",
      "description": "Payments and technology company, Tennessee, USA. Reporter and analyst of record for LH-IR-2026-0806-AIRDROID. Analyst: Daniel Wilson Kemp, Founder & CEO. Contact: will@liftedholdings.com / https://liftedholdings.com",
      "identity_class": "organization",
      "sectors": [
        "financial-services",
        "technology"
      ],
      "contact_information": "will@liftedholdings.com",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--5c8b3d92-7a61-4e0f-b2d4-9e1f6a7c8b90",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "name": "Sand Studio Pte. Ltd. (airdroid.com)",
      "description": "Singapore software vendor, maker of AirDroid and AirDroid Business. One business-development mailbox in this organisation's Google Workspace tenant was under adversary control on 2026-08-06 and was used to send the campaign. No compromise of this organisation's products, systems, customer data or user accounts is established or claimed.",
      "identity_class": "organization",
      "sectors": [
        "technology"
      ],
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
        "marking-definition--7b2c9a48-1d3e-4f60-8a5b-6c9e0f1a2b34"
      ]
    },
    {
      "type": "campaign",
      "spec_version": "2.1",
      "id": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "b4f61f2a - RFQ & Investment Partnership credential phishing",
      "description": "Two-stage credential-harvesting campaign delivered from a compromised vendor mailbox in a Google Workspace tenant. Stage 1 is a Microsoft-branded fake identity-verification gate on an abused ~7.7-year-old legitimate domain; it auto-extracts the victim email from query values, query keys, the URL fragment or $-delimited segments (plaintext, base64 or hex) and auto-redirects after 3.5 seconds. The victim identifier is handed to stage 2 in the URL fragment, which is not transmitted to servers and is not logged by most proxies, secure web gateways or mail-security URL rewriters; the effect is to keep the victim identifier out of server-side logs. Stage 2 is Cloudflare-fronted on a domain registered seven days before the campaign and served a visually faithful Google sign-in clone; it applies Turnstile-gated (HTTPS connection resets versus HTTP 200, first-fetch-then-reset per source address). Kit architecture is consistent with adversary-in-the-middle session-token relay that would capture a post-MFA session cookie; this is assessed at moderate confidence and was NOT observed end to end. No actor attribution is made.",
      "aliases": [
        "b4f61f2a",
        "LH-IR-2026-0806-AIRDROID"
      ],
      "first_seen": "2026-08-06T13:15:32.000Z",
      "objective": "Harvest identity-provider credentials, and plausibly post-authentication session tokens, from recipients of a vendor's business contact list using an RFQ / investment-partnership pretext.",
      "confidence": 85,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
        "marking-definition--7b2c9a48-1d3e-4f60-8a5b-6c9e0f1a2b34"
      ],
      "external_references": [
        {
          "source_name": "Lifted Holdings LLC",
          "description": "LH-IR-2026-0806-AIRDROID investigation report. Vendor notified 2026-08-06 14:51 UTC, 45 minutes after receipt; AirDroid support Ticket #74851; escalated to security@airdroid.com. No vendor response beyond automated acknowledgement as of publication.",
          "external_id": "LH-IR-2026-0806-AIRDROID"
        }
      ]
    },
    {
      "type": "note",
      "spec_version": "2.1",
      "id": "note--9f4a7c31-6b28-4d5e-8a90-2c3d4e5f6a71",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "abstract": "What we did not find - scope limitation and confidence statement",
      "content": "WHAT WE DID NOT FIND. (1) No evidence of any breach of AirDroid or Sand Studio products, systems, infrastructure, source code, customer data or user accounts. Scope beyond one mailbox is NOT established; only Sand Studio's own Google Workspace admin audit logs can determine it. (2) A valid DKIM signature on tenant mail is a DOMAIN-LEVEL assertion applied automatically by Google to all authenticated outbound mail. It proves the message came from an authenticated sender inside the tenant. It does NOT mean DKIM was cracked, broken or stolen, and it CANNOT distinguish one compromised mailbox from many. (3) HEADER VERIFICATION COMPLETE: the raw Authentication-Results header was read on 2026-08-06 and shows dkim=pass header.i=@airdroid.com header.s=google, spf=pass from Google relay 209.85.220.65, dmarc=pass (p=REJECT sp=REJECT dis=NONE), with two Received hops both internal to Google and no external origin hop. The send is observed, not inferred. Those headers do NOT establish how the session was obtained, and cannot distinguish one compromised mailbox from several. (4) Independent of headers, the 14:51:58 UTC interactive in-thread reply quoting the challenger's own text proves live human control of the mailbox; an external spoofing sender never receives the reply. This is the strongest single fact in the report. (5) MFA bypass via adversary-in-the-middle session-token relay is assessed at MODERATE confidence on architecture, and was not observed end to end. (6) No actor attribution is made. No claim of APT, nation-state involvement, sophistication or novel malware is made or supported. (7) No Lifted Holdings credentials were entered and no cardholder data exposure was identified.",
      "object_refs": [
        "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f",
        "identity--5c8b3d92-7a61-4e0f-b2d4-9e1f6a7c8b90"
      ],
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--1c7d8e94-3a52-4b16-9d08-4e5f6a7b8c92",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Phishing: Spearphishing Link",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1566.002",
          "url": "https://attack.mitre.org/techniques/T1566/002/"
        }
      ],
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--2d8e9f05-4b63-4c27-8e19-5f6a7b8c9d03",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Compromise Accounts: Email Accounts",
      "description": "The campaign was delivered from an authenticated session in a legitimate vendor's Google Workspace tenant, giving the mail full DMARC alignment against a p=reject domain.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1586.002",
          "url": "https://attack.mitre.org/techniques/T1586/002/"
        }
      ],
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--3e9f0a16-5c74-4d38-9f2a-6a7b8c9d0e14",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Multi-Factor Authentication Interception",
      "description": "MODERATE CONFIDENCE, ARCHITECTURE-BASED ONLY. Fragment handoff of the victim identifier plus identity-provider fingerprinting plus a visually faithful sign-in clone are the standard preconditions for adversary-in-the-middle session-token relay. Post-MFA session-cookie capture was not observed end to end.",
      "confidence": 50,
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1111",
          "url": "https://attack.mitre.org/techniques/T1111/"
        }
      ],
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--4f0a1b27-6d85-4e49-8a3b-7b8c9d0e1f25",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage Capabilities: Link Target",
      "description": "Stage-1 payload staged on an abused legitimate domain at 13:15:32 UTC, 50 minutes 31 seconds before the 14:06:03 UTC send.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1608.005",
          "url": "https://attack.mitre.org/techniques/T1608/005/"
        }
      ],
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--5a1b2c38-7e96-4f5a-9b4c-8c9d0e1f2a36",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Impersonation",
      "description": "Microsoft brand impersonation at stage 1, including retrieval of a genuine Microsoft CDN background asset for visual authenticity; Google sign-in impersonation at stage 2, selected by identity-provider fingerprinting.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1656",
          "url": "https://attack.mitre.org/techniques/T1656/"
        }
      ],
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b2c3d49-8f07-4a6b-8c5d-9d0e1f2a3b47",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage 1 - fake Microsoft identity-verification gate",
      "description": "Microsoft-branded gate on an abused legitimate domain. Written 2026-08-06T13:15:32Z per HTTP Last-Modified. 21,039 bytes. Footer misspelling '(c) 2026 Microsoft Corportation'. Posts nothing; classifies and forwards only.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[url:value = 'https://pulp2pack.com/bidaccess/rfp-notification.html']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T13:15:32.000Z",
      "confidence": 95,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f4a7b28-5c93-4e61-af02-6d7b8c9e0a13",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage-1 HTML payload file hash",
      "description": "rfp-notification.html, 21,039 bytes, retrieved 2026-08-06T16:42Z. SHA-256 aaf1470747fcb7bad9197fa92c2f5b028f1132ef0396646308623eb4059a86d2; SHA-1 288e5594263d3ce728cb7d5cc56d8ddd47a860f8; MD5 e7e20d67542713dd23f0fd287b649779.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[file:hashes.'SHA-256' = 'aaf1470747fcb7bad9197fa92c2f5b028f1132ef0396646308623eb4059a86d2']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T13:15:32.000Z",
      "confidence": 100,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c3d4e5a-9018-4b7c-9d6e-0e1f2a3b4c58",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage 2 - Turnstile-gated Google sign-in clone",
      "description": "Cloudflare-fronted credential-capture stage. Receives the victim email via URL fragment: /?b4f61f2a#<victim-email>. Turnstile-gated: HTTPS resets, HTTP 200. Origin host concealed.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[url:value = 'https://addendum-200notice-encryption-base.icu/?b4f61f2a']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T14:06:03.000Z",
      "confidence": 95,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8d4e5f6b-0129-4c8d-8e7f-1f2a3b4c5d69",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage-2 domain (attacker-registered)",
      "description": "Registered 2026-07-30 via Namecheap, Inc., seven days before the campaign. Nameservers lennon.ns.cloudflare.com / ophelia.ns.cloudflare.com. Zero prior urlscan.io records as of 2026-08-06.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'addendum-200notice-encryption-base.icu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-07-30T00:00:00.000Z",
      "confidence": 95,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e5f6a7c-123a-4d9e-9f80-2a3b4c5d6e7a",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage-1 host domain (ABUSED third party - handle with care)",
      "description": "ABUSED legitimate domain approximately 2,806 days (~7.7 years) old, NOT attacker-registered. Apex serves an unrelated Indonesian slot-gambling SEO link farm; urlscan.io also records unrelated abuse at sunriseprintstore.in.pulp2pack.com (2025-12-14). Consistent with a compromised shared-hosting account. Block at the URL/path level in preference to blanket-blocking the apex.",
      "indicator_types": [
        "compromised"
      ],
      "pattern": "[domain-name:value = 'pulp2pack.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T13:15:32.000Z",
      "confidence": 85,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f6a7b8d-234b-4e0f-8a91-3b4c5d6e7f8b",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage-1 origin IP (AS59253 Leaseweb Singapore)",
      "description": "PTR sgpr200.websitehostserver.net. Shared hosting - other legitimate sites are likely co-hosted; prefer URL-level blocking.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '23.106.55.199']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T13:15:32.000Z",
      "confidence": 85,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a7b8c9e-345c-4f1a-9b02-4c5d6e7f8a9c",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Stage-2 Cloudflare edge addresses - ATTRIBUTION ONLY, DO NOT BLOCK",
      "description": "AS13335 Cloudflare anycast addresses. Shared infrastructure serving vast numbers of legitimate sites. Recorded for attribution and correlation only. Blocking these will cause collateral outages.",
      "indicator_types": [
        "benign"
      ],
      "pattern": "[ipv4-addr:value = '104.21.86.28' OR ipv4-addr:value = '172.67.214.97']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T16:42:00.000Z",
      "confidence": 15,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b8c9d0f-456d-4a2b-8c13-5d6e7f8a9b0d",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Sending mailbox (VICTIM ACCOUNT under adversary control at time of send)",
      "description": "Listed for defensive hunting and mail-filter tuning only. This is a compromised legitimate mailbox belonging to a victim, NOT an attacker-registered or attacker-owned address, and the mailbox holder is not a perpetrator. Its presence here is not evidence of scope beyond this one account.",
      "indicator_types": [
        "compromised"
      ],
      "pattern": "[email-addr:value = 'debbie.hu@airdroid.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T14:06:03.000Z",
      "valid_until": "2026-08-06T23:59:59.000Z",
      "confidence": 95,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
        "marking-definition--7b2c9a48-1d3e-4f60-8a5b-6c9e0f1a2b34"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c9d0e1a-567e-4b3c-9d24-6e7f8a9b0c1e",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Campaign email subject",
      "description": "To: undisclosed-recipients:; with recipients BCC'd. Opens 'Dear Prospective Partner'. Lure is a 'REVIEW PROJECT' hyperlink. Sent 2026-08-06T14:06:03Z.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[email-message:subject = 'Sand Studio Pte. Ltd. - RFQ & Investment Partnership']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T14:06:03.000Z",
      "confidence": 90,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d0e1f2b-678f-4c4d-8e35-7f8a9b0c1d2f",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "name": "Kit content signature - footer misspelling",
      "description": "Highest-fidelity content hunt term in the kit. The stage-1 footer reads '(c) 2026 Microsoft Corportation' (sic), with the copyright character U+00A9. Hunt web-content and mail-body inspection for the token 'Microsoft Corportation'. Genuine Microsoft properties never contain it.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[artifact:payload_bin MATCHES 'Microsoft Corportation']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "valid_from": "2026-08-06T13:15:32.000Z",
      "confidence": 90,
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ]
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--5e1f2a3c-789a-4d5e-9f46-8a9b0c1d2e30",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "indicates",
      "source_ref": "indicator--6b2c3d49-8f07-4a6b-8c5d-9d0e1f2a3b47",
      "target_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--6f2a3b4d-89ab-4e6f-8a57-9b0c1d2e3f41",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "indicates",
      "source_ref": "indicator--7c3d4e5a-9018-4b7c-9d6e-0e1f2a3b4c58",
      "target_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--7a3b4c5e-9abc-4f7a-9b68-0c1d2e3f4a52",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "indicates",
      "source_ref": "indicator--8d4e5f6b-0129-4c8d-8e7f-1f2a3b4c5d69",
      "target_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8b4c5d6f-abcd-4a8b-8c79-1d2e3f4a5b63",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "indicates",
      "source_ref": "indicator--3c9d0e1a-567e-4b3c-9d24-6e7f8a9b0c1e",
      "target_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--9c5d6e7a-bcde-4b9c-9d8a-2e3f4a5b6c74",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "uses",
      "source_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f",
      "target_ref": "attack-pattern--1c7d8e94-3a52-4b16-9d08-4e5f6a7b8c92"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--0d6e7f8b-cdef-4c0d-8e9b-3f4a5b6c7d85",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "uses",
      "source_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f",
      "target_ref": "attack-pattern--2d8e9f05-4b63-4c27-8e19-5f6a7b8c9d03"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--1e7f8a9c-def0-4d1e-9f0c-4a5b6c7d8e96",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "uses",
      "source_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f",
      "target_ref": "attack-pattern--4f0a1b27-6d85-4e49-8a3b-7b8c9d0e1f25"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--2f8a9b0d-ef01-4e2f-8a1d-5b6c7d8e9f07",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "uses",
      "source_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f",
      "target_ref": "attack-pattern--5a1b2c38-7e96-4f5a-9b4c-8c9d0e1f2a36"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--3a9b0c1e-f012-4f3a-9b2e-6c7d8e9f0a18",
      "created": "2026-08-06T16:42:00.000Z",
      "modified": "2026-08-06T16:42:00.000Z",
      "created_by_ref": "identity--3a9c1f70-2b48-4d19-9e6c-5f8a0b1c2d3e",
      "relationship_type": "uses",
      "source_ref": "campaign--b4f61f2a-0000-4a00-9c00-1a2b3c4d5e6f",
      "target_ref": "attack-pattern--3e9f0a16-5c74-4d38-9f2a-6a7b8c9d0e14",
      "description": "MODERATE CONFIDENCE, architecture-based only. Not observed end to end.",
      "confidence": 50
    }
  ]
}
