[
  {
    "instruction": "Question: Answer which mitre campaign is related to the description: The campaign was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. The campaign initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign \"Honeybee\" after the author name discovered in malicious Word documents.\nA. C0027, B. Operation Honeybee, C. Operation Wocao, D. Operation Ghost\nAnswer:",
    "context": "",
    "output": "B. Operation Honeybee",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Answer which mitre campaign is related to the description: The campaign was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. The campaign initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign \"Honeybee\" after the author name discovered in malicious Word documents.",
      "options": "A. C0027, B. Operation Honeybee, C. Operation Wocao, D. Operation Ghost",
      "choice": "B. Operation Honeybee",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Q: Which MITRE ATT&CK campaign is described in the following:\nThe The campaign was a Sandworm Team campaign that used a combination of GOGETTER, Neo-REGEORG, CaddyWiper, and living of the land (LotL) techniques to gain access to a Ukrainian electric utility to send unauthorized commands from their SCADA system.\n\nOptions:\nA. C0026, B. Operation CuckooBees, C. C0011, D. 2022 Ukraine Electric Power Attack",
    "context": "",
    "output": "D. 2022 Ukraine Electric Power Attack",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Which MITRE ATT&CK campaign is described in the following:\nThe The campaign was a Sandworm Team campaign that used a combination of GOGETTER, Neo-REGEORG, CaddyWiper, and living of the land (LotL) techniques to gain access to a Ukrainian electric utility to send unauthorized commands from their SCADA system.",
      "options": "A. C0026, B. Operation CuckooBees, C. C0011, D. 2022 Ukraine Electric Power Attack",
      "choice": "D. 2022 Ukraine Electric Power Attack",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Q: Answer which mitre campaign is related to the description: The campaign was a PROMETHIUM campaign during which they used StrongPity to target Android users. The campaign was the first publicly documented mobile campaign for PROMETHIUM, who previously used Windows-based techniques.\n\nOptions:\nA. CostaRicto, B. C0033, C. Operation Honeybee, D. C0032",
    "context": "",
    "output": "B. C0033",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Answer which mitre campaign is related to the description: The campaign was a PROMETHIUM campaign during which they used StrongPity to target Android users. The campaign was the first publicly documented mobile campaign for PROMETHIUM, who previously used Windows-based techniques.",
      "options": "A. CostaRicto, B. C0033, C. Operation Honeybee, D. C0032",
      "choice": "B. C0033",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Answer which mitre campaign is related to the description: The campaign was a suspected hacker-for-hire cyber espionage campaign that targeted multiple industries worldwide, with a large number being financial institutions. The campaign actors targeted organizations in Europe, the Americas, Asia, Australia, and Africa, with a large concentration in South Asia (especially India, Bangladesh, and Singapore), using custom malware, open source tools, and a complex network of proxies and SSH tunnels.\n\nA. CostaRicto, B. SolarWinds Compromise, C. Cutting Edge, D. 2015 Ukraine Electric Power Attack\nAnswer:",
    "context": "",
    "output": "A. CostaRicto",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Answer which mitre campaign is related to the description: The campaign was a suspected hacker-for-hire cyber espionage campaign that targeted multiple industries worldwide, with a large number being financial institutions. The campaign actors targeted organizations in Europe, the Americas, Asia, Australia, and Africa, with a large concentration in South Asia (especially India, Bangladesh, and Singapore), using custom malware, open source tools, and a complex network of proxies and SSH tunnels.",
      "options": "A. CostaRicto, B. SolarWinds Compromise, C. Cutting Edge, D. 2015 Ukraine Electric Power Attack",
      "choice": "A. CostaRicto",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Question: Answer which mitre campaign is related to the description: The campaign was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During The campaign, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of The campaign are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).\nA. C0032, B. C0010, C. Operation Dust Storm, D. C0017\nAnswer:",
    "context": "",
    "output": "D. C0017",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Answer which mitre campaign is related to the description: The campaign was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During The campaign, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of The campaign are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).",
      "options": "A. C0032, B. C0010, C. Operation Dust Storm, D. C0017",
      "choice": "D. C0017",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Which MITRE ATT&CK campaign is described in the following:\nThe campaign was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between The campaign, Operation North Star, and Operation Interception; by 2022 security researchers described The campaign as an umbrella term covering both Operation Interception and Operation North Star.\nA. C0027, B. C0032, C. Operation Spalax, D. Operation Dream Job",
    "context": "",
    "output": "D. Operation Dream Job",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Which MITRE ATT&CK campaign is described in the following:\nThe campaign was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between The campaign, Operation North Star, and Operation Interception; by 2022 security researchers described The campaign as an umbrella term covering both Operation Interception and Operation North Star.",
      "options": "A. C0027, B. C0032, C. Operation Spalax, D. Operation Dream Job",
      "choice": "D. Operation Dream Job",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Q: Give the MITRE ATT&CK campaign relevant to the following:\nThe campaign was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries. The majority of targets were located in the US, particularly in and around Washington D.C., with other targets located in Europe, Hong Kong, India, and Canada. The campaign's technical artifacts, tactics, techniques, and procedures (TTPs), and targeting overlap with previous suspected APT29 activity.\n\nOptions:\nA. C0010, B. Operation Dust Storm, C. 2015 Ukraine Electric Power Attack, D. C0021",
    "context": "",
    "output": "D. C0021",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Give the MITRE ATT&CK campaign relevant to the following:\nThe campaign was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries. The majority of targets were located in the US, particularly in and around Washington D.C., with other targets located in Europe, Hong Kong, India, and Canada. The campaign's technical artifacts, tactics, techniques, and procedures (TTPs), and targeting overlap with previous suspected APT29 activity.",
      "options": "A. C0010, B. Operation Dust Storm, C. 2015 Ukraine Electric Power Attack, D. C0021",
      "choice": "D. C0021",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Tell me which MITRE campaign is referred to in the following description:\n\nThe campaign was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.\n\nA. SolarWinds Compromise, B. Operation Spalax, C. C0017, D. C0015\nAnswer:",
    "context": "",
    "output": "D. C0015",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Tell me which MITRE campaign is referred to in the following description:\n\nThe campaign was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.",
      "options": "A. SolarWinds Compromise, B. Operation Spalax, C. C0017, D. C0015",
      "choice": "D. C0015",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Answer which mitre campaign is related to the description: The campaign was a Sandworm Team campaign during which they used Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid. This campaign was the second major public attack conducted against Ukraine by Sandworm Team.\nA. 2022 Ukraine Electric Power Attack, B. 2016 Ukraine Electric Power Attack, C. C0027, D. Operation Wocao",
    "context": "",
    "output": "B. 2016 Ukraine Electric Power Attack",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Answer which mitre campaign is related to the description: The campaign was a Sandworm Team campaign during which they used Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid. This campaign was the second major public attack conducted against Ukraine by Sandworm Team.",
      "options": "A. 2022 Ukraine Electric Power Attack, B. 2016 Ukraine Electric Power Attack, C. C0027, D. Operation Wocao",
      "choice": "B. 2016 Ukraine Electric Power Attack",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  },
  {
    "instruction": "Tell me which MITRE campaign is referred to in the following description:\n\nThe campaign was a suspected Chinese cyber espionage campaign that targeted government and foreign organizations in Malaysia, the Philippines, Taiwan, Vietnam, and other parts of Southeast Asia. Security researchers linked the The campaign campaign to possible Chinese-speaking threat actors through the use of the Chinoxy backdoor and noted infrastructure overlap with the TAG-16 threat group.\nA. Operation Ghost, B. FunnyDream, C. C0018, D. C0033",
    "context": "",
    "output": "B. FunnyDream",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_campaign",
    "parsed_raw_data": {
      "question": "Tell me which MITRE campaign is referred to in the following description:\n\nThe campaign was a suspected Chinese cyber espionage campaign that targeted government and foreign organizations in Malaysia, the Philippines, Taiwan, Vietnam, and other parts of Southeast Asia. Security researchers linked the The campaign campaign to possible Chinese-speaking threat actors through the use of the Chinoxy backdoor and noted infrastructure overlap with the TAG-16 threat group.",
      "options": "A. Operation Ghost, B. FunnyDream, C. C0018, D. C0033",
      "choice": "B. FunnyDream",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_campaign"
    }
  }
]