S0039: Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
Security context for executives and security teams
Net is a built-in Windows command-line utility for managing users, groups, services, and network connections. Its business significance is that legitimate administration and adversary activity can look very similar: the same utility used by IT can support discovery, service interaction, and lateral movement via SMB/Windows Admin Shares using commands such as net use. Because many ATT&CK-listed groups and one campaign are related to use of this tool, organizations should treat Net activity as a coverage validation problem, not as inherently malicious by itself.
Executive priority
Prioritize visibility and governance around Windows administrative command execution. Net matters because it can affect identity administration, service control, and network connections—areas tied directly to operational resilience and incident scoping. Leaders should ask whether SOC and IR teams can distinguish expected administrator use from unusual use across endpoints, accounts, and network shares, and whether that evidence is retained well enough for investigations and audit support.
Technical view
For Windows environments, validate monitoring of net.exe and net1.exe execution, including command-line arguments, parent process, user context, host role, and remote share or service interaction where available. ATT&CK provides no official detection guidance for this object, so detections should be environment-driven: baseline normal administrative use, then alert on unusual account, host, timing, parent process, or target patterns. Relationship context shows use by numerous groups and campaign C0026, so detections should focus on behavior and context rather than attribution.
Likely telemetry
- Windows process creation events for net.exe and net1.exe
- Command-line arguments, including user, group, service, and net use activity
- Parent process and initiating user/account context
- Endpoint and host role context for administrative workstations, servers, and domain systems
- Authentication and network connection evidence associated with SMB/Windows Admin Shares
Detection direction
- Do not alert on Net execution alone; it is a legitimate Windows utility and likely common in administration.
- Baseline expected administrator, helpdesk, service account, and automation usage before tuning high-severity alerts.
- Prioritize anomalous net use activity involving unusual source hosts, destination systems, credentials, or administrative shares.
- Correlate Net execution with authentication events, SMB connections, service changes, and other discovery activity when available.
- Include net1.exe in detection logic because the official description notes it may be executed by net.exe and can be used directly.
Mitigation priorities
- Establish least-privilege administrative practices for Windows accounts that can manage users, groups, services, and remote connections.
- Limit and monitor administrative share and SMB access according to business need.
- Separate routine administration from user workstations where practical, so Net activity from unexpected endpoints is easier to triage.
- Ensure endpoint logging or EDR captures command-line execution for both net.exe and net1.exe.
- Document approved administrative use cases to support SOC tuning, IR scoping, and compliance evidence.
Additional notes and limits
This object is a tool entry, not a technique, and ATT&CK does not specify tactics for the object field even though the official description cites Discovery, SMB/Windows Admin Shares lateral movement via net use, and service interaction as adversary-relevant uses. The many related groups and campaign demonstrate broad historical reporting around Net use, but local detection should remain behavior-based.
No official ATT&CK detection text is provided. The supplied fields do not support claims of current exploitation, guaranteed detectability, non-Windows platforms, or specific vendor controls. Local baselines, logging configuration, and administrative workflows are required to determine what is suspicious.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1201 | Password Policy Discovery | |
| Enterprise | T1069.002 | Domain GroupsSub-technique | |
| Enterprise | T1124 | System Time Discovery | |
| Enterprise | T1087.002 | Domain AccountSub-technique | |
| Enterprise | T1087.001 | Local AccountSub-technique | |
| Enterprise | T1007 | System Service Discovery | |
| Enterprise | T1018 | Remote System Discovery | |
| Enterprise | T1135 | Network Share Discovery | |
| Enterprise | T1049 | System Network Connections Discovery | |
| Enterprise | T1070.005 | Network Share Connection RemovalSub-technique | |
| Enterprise | T1569.002 | Service ExecutionSub-technique | |
| Enterprise | T1136.001 | Local AccountSub-technique | |
| Enterprise | T1098.007 | Additional Local or Domain GroupsSub-technique | |
| Enterprise | T1069.001 | Local GroupsSub-technique | |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | |
| Enterprise | T1136.002 | Domain AccountSub-technique |
Groups, software, and campaigns
G1054: MirrorFace
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]
G0019: Naikon
Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).[1] Active since at least 2010, Naikon has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).[1][2]
While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.[3]
G0059: Magic Hound
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.[1][2][3][4][5]
G0082: APT38
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
G0035: Dragonfly
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.[1][2] Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.[3][4][5][6][7][8][9]
G0009: Deep Panda
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. [1] The intrusion into healthcare company Anthem has been attributed to Deep Panda. [2] This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. [3] Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. [4] Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same. [5]
G0027: Threat Group-3390
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]
G0049: OilRig
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]
G0028: Threat Group-1314
Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure. [1]
G0007: APT28
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]
APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
G0096: APT41
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]
G0045: menuPass
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.[1][2]
menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.[3][4][5][6][7][1][2]
C0026: C0026
C0026 was a campaign identified in September 2022 that included the selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine through re-registered ANDROMEDA C2 domains. Several tools and tactics used during C0026 were consistent with historic Turla operations.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 2.8 | Current bundle | c98a12b750b7… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Microsoft Net Utility
Microsoft. (2006, October 18). Net.exe Utility. Retrieved September 22, 2015.
Open source URL - [2]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [3]JPCERT MirrorFace JUL 2024
Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
Open source URL - [4]Baumgartner Naikon 2015
Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.
Open source URL - [5]Bitdefender Naikon April 2021
Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.
Open source URL - [6]TechNet Net Time
Microsoft. (n.d.). Net time. Retrieved November 25, 2016.
Open source URL - [7]Microsoft Net
Microsoft. (2017, February 14). Net Commands On Windows Operating Systems. Retrieved March 19, 2020.
Open source URL - [8]DFIR Report APT35 ProxyShell March 2022
DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.
Open source URL - [9]DFIR Phosphorus November 2021
DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.
Open source URL - [10]FireEye APT38 Oct 2018
FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.
Open source URL - [11]US-CERT TA18-074A
US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.
Open source URL - [12]Alperovitch 2014
Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.
Open source URL - [13]SecureWorks BRONZE UNION June 2017
Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.
Open source URL - [14]Mandiant Suspected Turla Campaign February 2023
Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.
Open source URL - [15]Palo Alto OilRig May 2016
Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.
- [16]FireEye APT34 Dec 2017
Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.
Open source URL - [17]Symantec Crambus OCT 2023
Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.
Open source URL - [18]Dell TG-1314
Dell SecureWorks Counter Threat Unit Special Operations Team. (2015, May 28). Living off the Land. Retrieved January 26, 2016.
Open source URL - [19]Cybersecurity Advisory GRU Brute Force Campaign July 2021
NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.
Open source URL - [20]Technet Net Use
Microsoft. (n.d.). Net Use. Retrieved November 25, 2016.
Open source URL - [21]FireEye APT41 Aug 2019
Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.
Open source URL - [22]PWC Cloud Hopper Technical Annex April 2017
PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.
Open source URL - [23]Microsoft Net Localgroup
Microsoft. (2016, August 31). Net Localgroup. Retrieved August 5, 2024.
Open source URL - [24]Microsoft Net Group
Microsoft. (2016, August 31). Net group. Retrieved August 5, 2024.
Open source URL - [25]Mandiant Operation Ke3chang November 2014
Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.
Open source URL - [26]NCC Group APT15 Alive and Strong
Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.
Open source URL - [27]FireEye APT40 March 2019
Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.
Open source URL - [28]Mandiant Pulse Secure Update May 2021
Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.
Open source URL - [29]Symantec Orangeworm April 2018
Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.
Open source URL - [30]Cybereason Soft Cell June 2019
Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.
Open source URL - [31]FireEye admin@338
FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.
Open source URL - [32]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [33]NCC Group Chimera January 2021
Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.
Open source URL - [34]Mandiant APT1
Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
Open source URL - [35]FireEye Know Your Enemy FIN8 Aug 2016
Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.
Open source URL - [36]Trend Micro TA505 June 2019
Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.
Open source URL - [37]Kaspersky ToddyCat Check Logs October 2023
Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.
Open source URL - [38]Kaspersky Turla
Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.
Open source URL - [39]Symantec Elfin Mar 2019
Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.
Open source URL - [40]CrowdStrike Ryuk January 2019
Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
Open source URL - [41]Red Canary Hospital Thwarted Ryuk October 2020
Brian Donohue, Katie Nickels, Paul Michaud, Adina Bodkins, Taylor Chapman, Tony Lambert, Jeff Felling, Kyle Rainey, Mike Haag, Matt Graeber, Aaron Didier.. (2020, October 29). A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak. Retrieved October 30, 2020.
Open source URL - [42]FireEye KEGTAP SINGLEMALT October 2020
Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.
Open source URL - [43]DFIR Ryuk's Return October 2020
The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.
Open source URL - [44]DFIR Ryuk 2 Hour Speed Run November 2020
The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.
Open source URL - [45]DFIR Ryuk in 5 Hours October 2020
The DFIR Report. (2020, October 18). Ryuk in 5 Hours. Retrieved October 19, 2020.
Open source URL - [46]Sophos New Ryuk Attack October 2020
Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.
Open source URL - [47]Mandiant FIN12 Oct 2021
Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.
Open source URL - [48]Dragos Crashoverride 2018
Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.
Open source URL - [49]CISA SoreFang July 2016
CISA. (2020, July 16). MAR-10296782-1.v1 – SOREFANG. Retrieved September 29, 2020.
Open source URL - [50]Cybereason Cobalt Kitty 2017
Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.
Open source URL - [51]Secureworks BRONZE SILHOUETTE May 2023
Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.
Open source URL - [52]CISA AA24-038A PRC Critical Infrastructure February 2024
CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.
Open source URL - [53]Microsoft Storm-501 Sabbath Ransomware Embargo September 2024
Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.
Open source URL - [54]Microsoft Storm-0501 Embargo Ransomware August 2025
Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.
Open source URL - [55]Secureworks BRONZE BUTLER Oct 2017
Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.
Open source URL - [56]Microsoft Net Utility
Microsoft. (2006, October 18). Net.exe Utility. Retrieved September 22, 2015.
Open source URL - [57]Microsoft Net Utility
Microsoft. (2006, October 18). Net.exe Utility. Retrieved September 22, 2015.
Open source URL - [58]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [59]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [60]mitre-attackS0039Open source URL
- [61]mitre-attackS0039Open source URL
- [62]mitre-attackS0039Open source URL
- [63]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [64]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [65]JPCERT MirrorFace JUL 2024
Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
Open source URL - [66]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [67]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [68]Baumgartner Naikon 2015
Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.
Open source URL - [69]Bitdefender Naikon April 2021
Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.
Open source URL - [70]TechNet Net Time
Microsoft. (n.d.). Net time. Retrieved November 25, 2016.
Open source URL - [71]Microsoft Net
Microsoft. (2017, February 14). Net Commands On Windows Operating Systems. Retrieved March 19, 2020.
Open source URL - [72]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [73]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [74]DFIR Phosphorus November 2021
DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.
Open source URL - [75]DFIR Report APT35 ProxyShell March 2022
DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.
Open source URL - [76]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [77]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [78]FireEye APT38 Oct 2018
FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.
Open source URL - [79]US-CERT TA18-074A
US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.
Open source URL - [80]Alperovitch 2014
Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.
Open source URL - [81]SecureWorks BRONZE UNION June 2017
Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.
Open source URL - [82]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [83]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [84]Mandiant Suspected Turla Campaign February 2023
Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.
Open source URL - [85]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [86]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [87]FireEye APT34 Dec 2017
Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.
Open source URL - [88]Palo Alto OilRig May 2016
Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.
- [89]Symantec Crambus OCT 2023
Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.
Open source URL - [90]Dell TG-1314
Dell SecureWorks Counter Threat Unit Special Operations Team. (2015, May 28). Living off the Land. Retrieved January 26, 2016.
Open source URL - [91]Cybersecurity Advisory GRU Brute Force Campaign July 2021
NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.
Open source URL - [92]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [93]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [94]Technet Net Use
Microsoft. (n.d.). Net Use. Retrieved November 25, 2016.
Open source URL - [95]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [96]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [97]FireEye APT41 Aug 2019
Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.
Open source URL - [98]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [99]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [100]PWC Cloud Hopper Technical Annex April 2017
PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.
Open source URL - [101]Microsoft Net Group
Microsoft. (2016, August 31). Net group. Retrieved August 5, 2024.
Open source URL - [102]Microsoft Net Localgroup
Microsoft. (2016, August 31). Net Localgroup. Retrieved August 5, 2024.
Open source URL - [103]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [104]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [105]Mandiant Operation Ke3chang November 2014
Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.
Open source URL - [106]NCC Group APT15 Alive and Strong
Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.
Open source URL - [107]FireEye APT40 March 2019
Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.
Open source URL - [108]Mandiant Pulse Secure Update May 2021
Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.
Open source URL - [109]Symantec Orangeworm April 2018
Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.
Open source URL - [110]Cybereason Soft Cell June 2019
Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.
Open source URL - [111]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [112]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [113]FireEye admin@338
FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.
Open source URL - [114]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [115]NCC Group Chimera January 2021
Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.
Open source URL - [116]Mandiant APT1
Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
Open source URL - [117]FireEye Know Your Enemy FIN8 Aug 2016
Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.
Open source URL - [118]Trend Micro TA505 June 2019
Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.
Open source URL - [119]Kaspersky ToddyCat Check Logs October 2023
Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.
Open source URL - [120]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [121]Savill 1999
Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.
Open source URL - [122]Kaspersky Turla
Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.
Open source URL - [123]Symantec Elfin Mar 2019
Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.
Open source URL - [124]CrowdStrike Ryuk January 2019
Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
Open source URL - [125]DFIR Ryuk 2 Hour Speed Run November 2020
The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.
Open source URL - [126]DFIR Ryuk in 5 Hours October 2020
The DFIR Report. (2020, October 18). Ryuk in 5 Hours. Retrieved October 19, 2020.
Open source URL - [127]DFIR Ryuk's Return October 2020
The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.
Open source URL - [128]FireEye KEGTAP SINGLEMALT October 2020
Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.
Open source URL - [129]Mandiant FIN12 Oct 2021
Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.
Open source URL - [130]Red Canary Hospital Thwarted Ryuk October 2020
Brian Donohue, Katie Nickels, Paul Michaud, Adina Bodkins, Taylor Chapman, Tony Lambert, Jeff Felling, Kyle Rainey, Mike Haag, Matt Graeber, Aaron Didier.. (2020, October 29). A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak. Retrieved October 30, 2020.
Open source URL - [131]Sophos New Ryuk Attack October 2020
Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.
Open source URL - [132]Dragos Crashoverride 2018
Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
