LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

EnterpriseS0039ToolObject v2.8Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Net is a built-in Windows command-line utility for managing users, groups, services, and network connections. Its business significance is that legitimate administration and adversary activity can look very similar: the same utility used by IT can support discovery, service interaction, and lateral movement via SMB/Windows Admin Shares using commands such as net use. Because many ATT&CK-listed groups and one campaign are related to use of this tool, organizations should treat Net activity as a coverage validation problem, not as inherently malicious by itself.

Executive priority

Prioritize visibility and governance around Windows administrative command execution. Net matters because it can affect identity administration, service control, and network connections—areas tied directly to operational resilience and incident scoping. Leaders should ask whether SOC and IR teams can distinguish expected administrator use from unusual use across endpoints, accounts, and network shares, and whether that evidence is retained well enough for investigations and audit support.

Technical view

For Windows environments, validate monitoring of net.exe and net1.exe execution, including command-line arguments, parent process, user context, host role, and remote share or service interaction where available. ATT&CK provides no official detection guidance for this object, so detections should be environment-driven: baseline normal administrative use, then alert on unusual account, host, timing, parent process, or target patterns. Relationship context shows use by numerous groups and campaign C0026, so detections should focus on behavior and context rather than attribution.

Likely telemetry

  • Windows process creation events for net.exe and net1.exe
  • Command-line arguments, including user, group, service, and net use activity
  • Parent process and initiating user/account context
  • Endpoint and host role context for administrative workstations, servers, and domain systems
  • Authentication and network connection evidence associated with SMB/Windows Admin Shares

Detection direction

  • Do not alert on Net execution alone; it is a legitimate Windows utility and likely common in administration.
  • Baseline expected administrator, helpdesk, service account, and automation usage before tuning high-severity alerts.
  • Prioritize anomalous net use activity involving unusual source hosts, destination systems, credentials, or administrative shares.
  • Correlate Net execution with authentication events, SMB connections, service changes, and other discovery activity when available.
  • Include net1.exe in detection logic because the official description notes it may be executed by net.exe and can be used directly.

Mitigation priorities

  • Establish least-privilege administrative practices for Windows accounts that can manage users, groups, services, and remote connections.
  • Limit and monitor administrative share and SMB access according to business need.
  • Separate routine administration from user workstations where practical, so Net activity from unexpected endpoints is easier to triage.
  • Ensure endpoint logging or EDR captures command-line execution for both net.exe and net1.exe.
  • Document approved administrative use cases to support SOC tuning, IR scoping, and compliance evidence.
Additional notes and limits

This object is a tool entry, not a technique, and ATT&CK does not specify tactics for the object field even though the official description cites Discovery, SMB/Windows Admin Shares lateral movement via net use, and service interaction as adversary-relevant uses. The many related groups and campaign demonstrate broad historical reporting around Net use, but local detection should remain behavior-based.

No official ATT&CK detection text is provided. The supplied fields do not support claims of current exploitation, guaranteed detectability, non-Windows platforms, or specific vendor controls. Local baselines, logging configuration, and administrative workflows are required to determine what is suspicious.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

16 rows
DomainIDNameRelationship / procedure
EnterpriseT1201Password Policy Discovery

The net accounts and net accounts /domain commands with Net can be used to obtain password policy information.[2]

EnterpriseT1069.002Domain GroupsSub-technique

Commands such as net group /domain can be used in Net to gather information about and manipulate groups.[2]

EnterpriseT1124System Time Discovery

The net time command can be used in Net to determine the local or remote system time.[6]

EnterpriseT1087.002Domain AccountSub-technique

Net commands used with the /domain flag can be used to gather information about and manipulate user accounts on the current domain.[7]

EnterpriseT1087.001Local AccountSub-technique

Commands under net user can be used in Net to gather information about and manipulate user accounts.[2]

EnterpriseT1007System Service Discovery

The net start command can be used in Net to find information about Windows services.[2]

EnterpriseT1018Remote System Discovery

Commands such as net view can be used in Net to gather information about available remote systems.[2]

EnterpriseT1135Network Share Discovery

The net view \\remotesystem and net share commands in Net can be used to find shared drives and directories on remote and local systems respectively.[2]

EnterpriseT1049System Network Connections Discovery

Commands such as net use and net session can be used in Net to gather information about network connections from a particular host.[2]

EnterpriseT1070.005Network Share Connection RemovalSub-technique

The net use \\system\share /delete command can be used in Net to remove an established connection to a network share.[20]

EnterpriseT1569.002Service ExecutionSub-technique

The net start and net stop commands can be used in Net to execute or stop Windows services.[2]

EnterpriseT1136.001Local AccountSub-technique

The net user username \password commands in Net can be used to create a local account.[2]

EnterpriseT1098.007Additional Local or Domain GroupsSub-technique

The `net localgroup` and `net group` commands in Net can be used to add existing users to local and domain groups.[23] [24]

EnterpriseT1069.001Local GroupsSub-technique

Commands such as net group and net localgroup can be used in Net to gather information about and manipulate groups.[2]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Lateral movement can be done with Net through net use commands to connect to the on remote systems.[2]

EnterpriseT1136.002Domain AccountSub-technique

The net user username \password \domain commands in Net can be used to create a domain account.[2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1054: MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]

GroupEnterprise

G0019: Naikon

Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).[1] Active since at least 2010, Naikon has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).[1][2]

While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.[3]

GroupEnterprise

G0059: Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.[1][2][3][4][5]

GroupEnterprise

G0082: APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

GroupEnterprise

G0035: Dragonfly

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.[1][2] Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.[3][4][5][6][7][8][9]

GroupEnterprise

G0009: Deep Panda

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. [1] The intrusion into healthcare company Anthem has been attributed to Deep Panda. [2] This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. [3] Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. [4] Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same. [5]

GroupEnterprise

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0045: menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.[1][2]

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.[3][4][5][6][7][1][2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.8
Created
Modified
Raw hash
c98a12b750b7d44f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.8Current bundlec98a12b750b7…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft Net Utility

    Microsoft. (2006, October 18). Net.exe Utility. Retrieved September 22, 2015.

    Open source URL
  2. [2]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  3. [3]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  4. [4]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  5. [5]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  6. [6]
    TechNet Net Time

    Microsoft. (n.d.). Net time. Retrieved November 25, 2016.

    Open source URL
  7. [7]
    Microsoft Net

    Microsoft. (2017, February 14). Net Commands On Windows Operating Systems. Retrieved March 19, 2020.

    Open source URL
  8. [8]
    DFIR Report APT35 ProxyShell March 2022

    DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.

    Open source URL
  9. [9]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  10. [10]
    FireEye APT38 Oct 2018

    FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.

    Open source URL
  11. [11]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  12. [12]
    Alperovitch 2014

    Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.

    Open source URL
  13. [13]
    SecureWorks BRONZE UNION June 2017

    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

    Open source URL
  14. [14]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  15. [15]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  16. [16]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  17. [17]
    Symantec Crambus OCT 2023

    Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

    Open source URL
  18. [18]
    Dell TG-1314

    Dell SecureWorks Counter Threat Unit Special Operations Team. (2015, May 28). Living off the Land. Retrieved January 26, 2016.

    Open source URL
  19. [19]
    Cybersecurity Advisory GRU Brute Force Campaign July 2021

    NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.

    Open source URL
  20. [20]
    Technet Net Use

    Microsoft. (n.d.). Net Use. Retrieved November 25, 2016.

    Open source URL
  21. [21]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  22. [22]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  23. [23]
    Microsoft Net Localgroup

    Microsoft. (2016, August 31). Net Localgroup. Retrieved August 5, 2024.

    Open source URL
  24. [24]
    Microsoft Net Group

    Microsoft. (2016, August 31). Net group. Retrieved August 5, 2024.

    Open source URL
  25. [25]
    Mandiant Operation Ke3chang November 2014

    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

    Open source URL
  26. [26]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  27. [27]
    FireEye APT40 March 2019

    Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.

    Open source URL
  28. [28]
    Mandiant Pulse Secure Update May 2021

    Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.

    Open source URL
  29. [29]
    Symantec Orangeworm April 2018

    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

    Open source URL
  30. [30]
    Cybereason Soft Cell June 2019

    Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.

    Open source URL
  31. [31]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  32. [32]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  33. [33]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  34. [34]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  35. [35]
    FireEye Know Your Enemy FIN8 Aug 2016

    Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.

    Open source URL
  36. [36]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  37. [37]
    Kaspersky ToddyCat Check Logs October 2023

    Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

    Open source URL
  38. [38]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  39. [39]
    Symantec Elfin Mar 2019

    Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.

    Open source URL
  40. [40]
    CrowdStrike Ryuk January 2019

    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.

    Open source URL
  41. [41]
    Red Canary Hospital Thwarted Ryuk October 2020

    Brian Donohue, Katie Nickels, Paul Michaud, Adina Bodkins, Taylor Chapman, Tony Lambert, Jeff Felling, Kyle Rainey, Mike Haag, Matt Graeber, Aaron Didier.. (2020, October 29). A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak. Retrieved October 30, 2020.

    Open source URL
  42. [42]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  43. [43]
    DFIR Ryuk's Return October 2020

    The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

    Open source URL
  44. [44]
    DFIR Ryuk 2 Hour Speed Run November 2020

    The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.

    Open source URL
  45. [45]
    DFIR Ryuk in 5 Hours October 2020

    The DFIR Report. (2020, October 18). Ryuk in 5 Hours. Retrieved October 19, 2020.

    Open source URL
  46. [46]
    Sophos New Ryuk Attack October 2020

    Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.

    Open source URL
  47. [47]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  48. [48]
    Dragos Crashoverride 2018

    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.

    Open source URL
  49. [49]
    CISA SoreFang July 2016

    CISA. (2020, July 16). MAR-10296782-1.v1 – SOREFANG. Retrieved September 29, 2020.

    Open source URL
  50. [50]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  51. [51]
    Secureworks BRONZE SILHOUETTE May 2023

    Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.

    Open source URL
  52. [52]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  53. [53]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  54. [54]
    Microsoft Storm-0501 Embargo Ransomware August 2025

    Microsoft Threat Intelligence. (2025, August 27). Storm-0501’s evolving techniques lead to cloud-based ransomware. Retrieved October 19, 2025.

    Open source URL
  55. [55]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  56. [56]
    Microsoft Net Utility

    Microsoft. (2006, October 18). Net.exe Utility. Retrieved September 22, 2015.

    Open source URL
  57. [57]
    Microsoft Net Utility

    Microsoft. (2006, October 18). Net.exe Utility. Retrieved September 22, 2015.

    Open source URL
  58. [58]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  59. [59]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  60. [60]
    mitre-attackS0039
    Open source URL
  61. [61]
    mitre-attackS0039
    Open source URL
  62. [62]
    mitre-attackS0039
    Open source URL
  63. [63]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  64. [64]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  65. [65]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  66. [66]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  67. [67]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  68. [68]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  69. [69]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  70. [70]
    TechNet Net Time

    Microsoft. (n.d.). Net time. Retrieved November 25, 2016.

    Open source URL
  71. [71]
    Microsoft Net

    Microsoft. (2017, February 14). Net Commands On Windows Operating Systems. Retrieved March 19, 2020.

    Open source URL
  72. [72]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  73. [73]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  74. [74]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  75. [75]
    DFIR Report APT35 ProxyShell March 2022

    DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.

    Open source URL
  76. [76]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  77. [77]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  78. [78]
    FireEye APT38 Oct 2018

    FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.

    Open source URL
  79. [79]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  80. [80]
    Alperovitch 2014

    Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.

    Open source URL
  81. [81]
    SecureWorks BRONZE UNION June 2017

    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

    Open source URL
  82. [82]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  83. [83]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  84. [84]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  85. [85]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  86. [86]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  87. [87]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  88. [88]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  89. [89]
    Symantec Crambus OCT 2023

    Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

    Open source URL
  90. [90]
    Dell TG-1314

    Dell SecureWorks Counter Threat Unit Special Operations Team. (2015, May 28). Living off the Land. Retrieved January 26, 2016.

    Open source URL
  91. [91]
    Cybersecurity Advisory GRU Brute Force Campaign July 2021

    NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.

    Open source URL
  92. [92]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  93. [93]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  94. [94]
    Technet Net Use

    Microsoft. (n.d.). Net Use. Retrieved November 25, 2016.

    Open source URL
  95. [95]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  96. [96]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  97. [97]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  98. [98]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  99. [99]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  100. [100]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  101. [101]
    Microsoft Net Group

    Microsoft. (2016, August 31). Net group. Retrieved August 5, 2024.

    Open source URL
  102. [102]
    Microsoft Net Localgroup

    Microsoft. (2016, August 31). Net Localgroup. Retrieved August 5, 2024.

    Open source URL
  103. [103]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  104. [104]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  105. [105]
    Mandiant Operation Ke3chang November 2014

    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

    Open source URL
  106. [106]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  107. [107]
    FireEye APT40 March 2019

    Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.

    Open source URL
  108. [108]
    Mandiant Pulse Secure Update May 2021

    Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.

    Open source URL
  109. [109]
    Symantec Orangeworm April 2018

    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

    Open source URL
  110. [110]
    Cybereason Soft Cell June 2019

    Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.

    Open source URL
  111. [111]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  112. [112]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  113. [113]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  114. [114]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  115. [115]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  116. [116]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  117. [117]
    FireEye Know Your Enemy FIN8 Aug 2016

    Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.

    Open source URL
  118. [118]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  119. [119]
    Kaspersky ToddyCat Check Logs October 2023

    Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

    Open source URL
  120. [120]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  121. [121]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  122. [122]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  123. [123]
    Symantec Elfin Mar 2019

    Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.

    Open source URL
  124. [124]
    CrowdStrike Ryuk January 2019

    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.

    Open source URL
  125. [125]
    DFIR Ryuk 2 Hour Speed Run November 2020

    The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.

    Open source URL
  126. [126]
    DFIR Ryuk in 5 Hours October 2020

    The DFIR Report. (2020, October 18). Ryuk in 5 Hours. Retrieved October 19, 2020.

    Open source URL
  127. [127]
    DFIR Ryuk's Return October 2020

    The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

    Open source URL
  128. [128]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  129. [129]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  130. [130]
    Red Canary Hospital Thwarted Ryuk October 2020

    Brian Donohue, Katie Nickels, Paul Michaud, Adina Bodkins, Taylor Chapman, Tony Lambert, Jeff Felling, Kyle Rainey, Mike Haag, Matt Graeber, Aaron Didier.. (2020, October 29). A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak. Retrieved October 30, 2020.

    Open source URL
  131. [131]
    Sophos New Ryuk Attack October 2020

    Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.

    Open source URL
  132. [132]
    Dragos Crashoverride 2018

    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.