LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0160: certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

EnterpriseS0160ToolObject v1.6Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

certutil matters because it is a legitimate Windows command-line utility with ATT&CK relationships showing adversary use across file transfer, decoding, root certificate installation, and archiving behaviors. For leaders, the risk is not the tool’s existence; it is whether the organization can distinguish authorized certificate administration from suspicious use during intrusion activity.

Executive priority

Treat certutil coverage as a practical test of Windows endpoint visibility and administrative control governance. Because ATT&CK links this tool to multiple groups and campaigns, including espionage, ransomware, and critical-infrastructure-related contexts, security leaders should ask whether SOC teams can rapidly explain certutil execution, certificate trust changes, file creation, and any related network activity on important Windows systems.

Technical view

The object has no ATT&CK detection text and no tactic listed directly, so validation should be relationship-driven. Confirm monitoring for Windows certutil execution and command-line context, then map observed activity to the related techniques: Ingress Tool Transfer, Deobfuscate/Decode Files or Information, Install Root Certificate, and Archive via Utility. Prioritize high-value hosts, certificate services infrastructure, administrator workstations, and systems where unexpected certificate trust or file-staging behavior would materially affect incident scope.

Likely telemetry

  • Windows process creation events including executable path, command line, parent process, user, host, and timestamp
  • File creation or modification events associated with decoded, downloaded, or archived content
  • Network connection or proxy/DNS evidence when certutil activity coincides with external transfer behavior
  • Windows certificate store or root certificate change events
  • Authentication and privilege context for users running certutil

Detection direction

  • Build baselines for legitimate certificate administration and Certificate Services use before treating all certutil execution as malicious.
  • Tune for unusual parent processes, unexpected users, execution on non-administrative workstations or servers, rare command-line patterns, and certutil activity followed by new files or execution chains.
  • Correlate certutil with related ATT&CK behaviors rather than alerting on the binary alone: transfer, decoding, certificate trust modification, and archiving.
  • Investigate certificate store changes with special urgency because the related Install Root Certificate technique can affect trust decisions and visibility into secure communications.
  • Account for false positives from administrators, PKI operations, software deployment, and troubleshooting workflows.

Mitigation priorities

  • Inventory where certutil is legitimately required and who should use it.
  • Apply least privilege and administrative separation for Certificate Services and certificate trust management.
  • Use application control or execution restrictions where business workflows allow, especially on systems with no operational need for certutil.
  • Monitor and govern root certificate installation and certificate store changes as security-relevant configuration events.
  • Ensure egress controls, proxy logging, and endpoint telemetry can support investigations of file transfer or staging behavior.
Additional notes and limits

ATT&CK identifies certutil as a Windows command-line utility for certificate authority information and Certificate Services configuration. The key defensive value comes from its relationships to techniques and many groups/campaigns that use it, not from a supplied ATT&CK detection analytic. This should be handled as dual-use administrative behavior requiring context, not as inherently malicious execution.

The supplied ATT&CK object does not provide official detection guidance, direct tactics, aliases, labels, or detailed procedures. Local baselines, endpoint logging quality, PKI architecture, and administrator workflows are required to determine whether certutil activity is expected or suspicious.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

4 rows
DomainIDNameRelationship / procedure
EnterpriseT1560.001Archive via UtilitySub-technique

certutil may be used to Base64 encode collected data.[1][3]

EnterpriseT1553.004Install Root CertificateSub-technique

certutil can be used to install browser root certificates as a precursor to performing Adversary-in-the-Middle between connections to banking websites. Example command: certutil -addstore -f -user ROOT ProgramData\cert512121.der.[15]

EnterpriseT1140Deobfuscate/Decode Files or Information

certutil has been used to decode binaries hidden inside certificate files as Base64 information.[16]

EnterpriseT1105Ingress Tool Transfer

certutil can be used to download files from a given URL.[1][3]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0045: menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.[1][2]

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.[3][4][5][6][7][1][2]

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0010: Turla

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G1051: Medusa Group

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” [1] [2] Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. [3] For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. [4]

GroupEnterprise

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

GroupEnterprise

G0126: Higaisa

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.[1][2][3]

GroupEnterprise

G1016: FIN13

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.[1][2]

GroupEnterprise

G1006: Earth Lusca

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.[1]

Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.[1]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0075: Rancor

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. [1]

CampaignEnterprise

C0063: 2025 Poland Wiper Attacks

2025 Poland Wiper Attacks is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025. Targets included more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, and a manufacturing sector company. The attacks on the distributed energy resources (DER) disrupted communications between affected facilities and the distribution system operator, but did not impact electricity generation or heat supply. Across the campaign, threat actors deployed two previously undocumented wiper tools, DynoWiper, a Windows-based wiper and LazyWiper, a PowerShell wiper, distributed via malicious Group Policy Objects. At the CHP plant, threat actors had maintained access since at least March 2025, using that foothold to obtain credentials and move laterally before attempting wiper deployment. Some reporting has assessed the activity to be consistent with Russian Federal Security Service (FSB) threat activity group Dragonfly, also tracked as STATIC TUNDRA, while other reporting attributes the destructive wiper activities to the Russian General Staff Main Intelligence Directorate (GRU) threat activity group ELECTRUM, also tracked as Sandworm Team.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.6
Created
Modified
Raw hash
45bdba7c7746b7ad...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.6Current bundle45bdba7c7746…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    TechNet Certutil

    Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.

    Open source URL
  2. [2]
    CERT Polska

    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

    Open source URL
  3. [3]
    LOLBAS Certutil

    LOLBAS. (n.d.). Certutil.exe. Retrieved July 31, 2019.

    Open source URL
  4. [4]
    Accenture Hogfish April 2018

    Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018.

  5. [5]
    FireEye APT10 Sept 2018

    Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.

    Open source URL
  6. [6]
    Symantec Cicada November 2020

    Symantec. (2020, November 17). Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. Retrieved December 17, 2020.

    Open source URL
  7. [7]
    Unit 42 Sofacy Feb 2018

    Lee, B, et al. (2018, February 28). Sofacy Attacks Multiple Government Entities. Retrieved March 15, 2018.

    Open source URL
  8. [8]
    Cybersecurity Advisory GRU Brute Force Campaign July 2021

    NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.

    Open source URL
  9. [9]
    Aryaka Kimsuky July 2025

    Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026.

    Open source URL
  10. [10]
    Symantec Waterbug Jun 2019

    Symantec DeepSight Adversary Intelligence Team. (2019, June 20). Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments. Retrieved July 8, 2019.

    Open source URL
  11. [11]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  12. [12]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  13. [13]
    Symantec Crambus OCT 2023

    Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

    Open source URL
  14. [14]
    CISA Medusa Group Medusa Ransomware March 2025

    Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  15. [15]
    Palo Alto Retefe

    Levene, B., Falcone, R., Grunzweig, J., Lee, B., Olson, R. (2015, August 20). Retefe Banking Trojan Targets Sweden, Switzerland and Japan. Retrieved July 3, 2017.

    Open source URL
  16. [16]
    Malwarebytes Targeted Attack against Saudi Arabia

    Malwarebytes Labs. (2017, March 27). New targeted attack against Saudi Arabia Government. Retrieved July 3, 2017.

    Open source URL
  17. [17]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  18. [18]
    Malwarebytes Higaisa 2020

    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

    Open source URL
  19. [19]
    PTSecurity Higaisa 2020

    PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.

    Open source URL
  20. [20]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  21. [21]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  22. [22]
    FireEye APT41 March 2020

    Glyer, C, et al. (2020, March). This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved April 28, 2020.

    Open source URL
  23. [23]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  24. [24]
    Secureworks BRONZE SILHOUETTE May 2023

    Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.

    Open source URL
  25. [25]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  26. [26]
    Symantec Bilbug 2022

    Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.

    Open source URL
  27. [27]
    TechNet Certutil

    Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.

    Open source URL
  28. [28]
    TechNet Certutil

    Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.

    Open source URL
  29. [29]
    mitre-attackS0160
    Open source URL
  30. [30]
    mitre-attackS0160
    Open source URL
  31. [31]
    mitre-attackS0160
    Open source URL
  32. [32]
    CERT Polska

    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

    Open source URL
  33. [33]
    LOLBAS Certutil

    LOLBAS. (n.d.). Certutil.exe. Retrieved July 31, 2019.

    Open source URL
  34. [34]
    TechNet Certutil

    Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.

    Open source URL
  35. [35]
    TechNet Certutil

    Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.

    Open source URL
  36. [36]
    Accenture Hogfish April 2018

    Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018.

  37. [37]
    FireEye APT10 Sept 2018

    Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.

    Open source URL
  38. [38]
    Symantec Cicada November 2020

    Symantec. (2020, November 17). Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. Retrieved December 17, 2020.

    Open source URL
  39. [39]
    Cybersecurity Advisory GRU Brute Force Campaign July 2021

    NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.

    Open source URL
  40. [40]
    Unit 42 Sofacy Feb 2018

    Lee, B, et al. (2018, February 28). Sofacy Attacks Multiple Government Entities. Retrieved March 15, 2018.

    Open source URL
  41. [41]
    Aryaka Kimsuky July 2025

    Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026.

    Open source URL
  42. [42]
    Symantec Waterbug Jun 2019

    Symantec DeepSight Adversary Intelligence Team. (2019, June 20). Waterbug: Espionage Group Rolls Out Brand-New Toolset in Attacks Against Governments. Retrieved July 8, 2019.

    Open source URL
  43. [43]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  44. [44]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  45. [45]
    Symantec Crambus OCT 2023

    Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

    Open source URL
  46. [46]
    CISA Medusa Group Medusa Ransomware March 2025

    Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  47. [47]
    Palo Alto Retefe

    Levene, B., Falcone, R., Grunzweig, J., Lee, B., Olson, R. (2015, August 20). Retefe Banking Trojan Targets Sweden, Switzerland and Japan. Retrieved July 3, 2017.

    Open source URL
  48. [48]
    Malwarebytes Targeted Attack against Saudi Arabia

    Malwarebytes Labs. (2017, March 27). New targeted attack against Saudi Arabia Government. Retrieved July 3, 2017.

    Open source URL
  49. [49]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  50. [50]
    Malwarebytes Higaisa 2020

    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

    Open source URL
  51. [51]
    PTSecurity Higaisa 2020

    PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.

    Open source URL
  52. [52]
    LOLBAS Certutil

    LOLBAS. (n.d.). Certutil.exe. Retrieved July 31, 2019.

    Open source URL
  53. [53]
    LOLBAS Certutil

    LOLBAS. (n.d.). Certutil.exe. Retrieved July 31, 2019.

    Open source URL
  54. [54]
    TechNet Certutil

    Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.

    Open source URL
  55. [55]
    TechNet Certutil

    Microsoft. (2012, November 14). Certutil. Retrieved July 3, 2017.

    Open source URL
  56. [56]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  57. [57]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  58. [58]
    FireEye APT41 March 2020

    Glyer, C, et al. (2020, March). This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved April 28, 2020.

    Open source URL
  59. [59]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.