LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0100: Inception

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.[1][2][3]

EnterpriseG0100GroupObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Inception is an ATT&CK group entry for a cyber espionage actor active since at least 2014, with reporting tied to targeting of government and multiple industries across Russia and other global regions. The defensive value is not the group name alone; it is the pattern of behaviors ATT&CK associates with it: targeted attachment-based entry, client-side exploitation, script-based execution, discovery, credential collection from browsers, persistence through Windows startup mechanisms, and command-and-control that may blend into web traffic or proxy chains.

Executive priority

Treat this as a readiness benchmark for espionage-style intrusions rather than as proof of current exposure. Leaders should ask whether email security, endpoint visibility, identity monitoring, browser credential controls, PowerShell/VBScript governance, and outbound web traffic review are producing usable evidence for investigations. The ATT&CK relationships also support vulnerability-management focus on client application exposure, because exploitation for client execution and malicious files are part of the mapped behavior set.

Technical view

The group object has no ATT&CK-provided detection text and no platform listed on the intrusion-set record, so validation should be driven by the related software and techniques. Related software includes PowerShower, a Windows PowerShell backdoor used for reconnaissance and second-stage payload execution; VBShower, a Windows backdoor/downloader; and LaZagne, a post-exploitation password recovery tool with Windows, Linux, and macOS modules. SOC and IR teams should validate visibility across suspicious Office/document execution chains, PowerShell and Visual Basic activity, mshta.exe and regsvr32.exe proxy execution, Run key or Startup folder persistence, browser credential access, host discovery commands, local file collection, and outbound HTTP/S or web-service-based C2 patterns, including traffic obscured by proxies or encryption.

Likely telemetry

  • Email gateway and mailbox telemetry for spearphishing attachments and malicious file delivery
  • Endpoint process creation telemetry for PowerShell, Visual Basic-related interpreters, mshta.exe, regsvr32.exe, discovery commands, and downloader behavior
  • PowerShell logging where available, including script block, module, and command-line evidence
  • Windows registry and startup folder change events for Run key or logon persistence
  • File system telemetry for document template references, encoded or encrypted payload files, local data staging, and file/directory enumeration

Detection direction

  • Do not rely on a single group signature; build coverage around the mapped behaviors and software relationships.
  • Tune detections for suspicious parent-child process chains from email clients, document viewers, archive tools, scripting engines, mshta.exe, and regsvr32.exe.
  • Validate PowerShell monitoring for reconnaissance, download, and second-stage execution patterns associated with PowerShower-like behavior, while accounting for legitimate administration noise.
  • Monitor VBScript/Visual Basic execution paths and downloader behavior consistent with VBShower-like staging, especially when followed by PowerShell execution.
  • Correlate discovery activity, browser credential access, and outbound web traffic rather than treating each signal independently.

Mitigation priorities

  • Prioritize patching and exposure reduction for client applications that can be reached through user-opened files or attachments.
  • Harden email and attachment handling with detonation, file-type controls, and user-reporting workflows where appropriate.
  • Restrict and monitor scripting and living-off-the-land utilities such as PowerShell, mshta.exe, and regsvr32.exe based on business need.
  • Reduce stored browser credential risk through credential management policy, browser hardening, and monitoring for credential store access.
  • Limit persistence opportunities by monitoring and controlling Run keys, Startup folders, and user-writable autostart locations.
Additional notes and limits

ATT&CK identifies Inception aliases as Inception, Inception Framework, and Cloud Atlas. The related behavior set emphasizes espionage tradecraft: targeted attachment delivery, client-side execution, script-based backdoors/downloaders, discovery, credential access, local data collection, persistence, and web-based C2. The Unit 42 reference title specifically mentions targeting Europe with a year-old Office vulnerability, supporting vulnerability-management relevance without asserting current exploitation.

The official group object does not provide detection guidance, tactics, or platforms directly. Platform and tactic context in this take comes from the supplied relationships to software and techniques, not from the intrusion-set platform field. Local telemetry, asset mix, email architecture, identity controls, and endpoint logging maturity are required to determine actual coverage or risk.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Inception

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

22 rows
DomainIDNameRelationship / procedure
EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption.[3]

EnterpriseT1588.002ToolSub-technique

Inception has obtained and used open-source tools such as LaZagne.[4]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Inception has maintained persistence by modifying Registry run key value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\.[3]

EnterpriseT1102Web Service

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.[3][2]

EnterpriseT1090.003Multi-hop ProxySub-technique

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.[2]

EnterpriseT1518Software Discovery

Inception has enumerated installed software on compromised systems.[2]

EnterpriseT1083File and Directory Discovery

Inception used a file listing plugin to collect information about file and directories both on local and remote drives.[2]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise.[3][2][1][4]

EnterpriseT1082System Information Discovery

Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host.[2]

EnterpriseT1059.001PowerShellSub-technique

Inception has used PowerShell to execute malicious commands and payloads.[1][3]

EnterpriseT1204.002Malicious FileSub-technique

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.[3][4][2][1]

EnterpriseT1071.001Web ProtocolsSub-technique

Inception has used HTTP, HTTPS, and WebDav in network communications.[3][1]

EnterpriseT1005Data from Local System

Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.[4]

EnterpriseT1218.005MshtaSub-technique

Inception has used malicious HTA files to drop and execute malware.[4]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex.[2]

EnterpriseT1203Exploitation for Client Execution

Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.[4][3][2][1]

EnterpriseT1069.002Domain GroupsSub-technique

Inception has used specific malware modules to gather domain membership.[2]

EnterpriseT1059.005Visual BasicSub-technique

Inception has used VBScript to execute malicious commands and payloads.[1][3]

EnterpriseT1221Template Injection

Inception has used decoy documents to load malicious remote payloads via HTTP.[1]

EnterpriseT1218.010Regsvr32Sub-technique

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.[3]

EnterpriseT1573.001Symmetric CryptographySub-technique

Inception has encrypted network communications with AES.[3]

EnterpriseT1057Process Discovery

Inception has used a reconnaissance module to identify active processes and other associated loaded modules.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0349: LaZagne

LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.[1]

LinuxmacOSWindows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
95cfebfb6178911e...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle95cfebfb6178…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  2. [2]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  3. [3]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  4. [4]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  5. [5]
    Cloud Atlas

    (Citation: Kaspersky Cloud Atlas December 2014)

  6. [6]
    Cloud Atlas

    (Citation: Kaspersky Cloud Atlas December 2014)

  7. [7]
    Cloud Atlas

    (Citation: Kaspersky Cloud Atlas December 2014)

  8. [8]
    Inception

    (Citation: Symantec Inception Framework March 2018)

  9. [9]
    Inception

    (Citation: Symantec Inception Framework March 2018)

  10. [10]
    Inception

    (Citation: Symantec Inception Framework March 2018)

  11. [11]
    Inception Framework

    (Citation: Symantec Inception Framework March 2018)

  12. [12]
    Inception Framework

    (Citation: Symantec Inception Framework March 2018)

  13. [13]
    Inception Framework

    (Citation: Symantec Inception Framework March 2018)

  14. [14]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  15. [15]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  16. [16]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  17. [17]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  18. [18]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  19. [19]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  20. [20]
    mitre-attackG0100
    Open source URL
  21. [21]
    mitre-attackG0100
    Open source URL
  22. [22]
    mitre-attackG0100
    Open source URL
  23. [23]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  24. [24]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  25. [25]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  26. [26]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  27. [27]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  28. [28]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  29. [29]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  30. [30]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  31. [31]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  32. [32]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  33. [33]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  34. [34]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  35. [35]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  36. [36]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  37. [37]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  38. [38]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  39. [39]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  40. [40]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  41. [41]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  42. [42]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  43. [43]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  44. [44]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  45. [45]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  46. [46]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  47. [47]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  48. [48]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  49. [49]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  50. [50]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  51. [51]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  52. [52]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  53. [53]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  54. [54]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  55. [55]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  56. [56]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  57. [57]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  58. [58]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  59. [59]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  60. [60]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  61. [61]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  62. [62]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  63. [63]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  64. [64]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  65. [65]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  66. [66]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  67. [67]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  68. [68]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  69. [69]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  70. [70]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  71. [71]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  72. [72]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  73. [73]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  74. [74]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  75. [75]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  76. [76]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  77. [77]
    Kaspersky Cloud Atlas August 2019

    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.

    Open source URL
  78. [78]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  79. [79]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  80. [80]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  81. [81]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  82. [82]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  83. [83]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  84. [84]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  85. [85]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  86. [86]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  87. [87]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  88. [88]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  89. [89]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  90. [90]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  91. [91]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  92. [92]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  93. [93]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  94. [94]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  95. [95]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  96. [96]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
  97. [97]
    Symantec Inception Framework March 2018

    Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.