LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0357: Impacket

MITRE ATT&CK S0357: Impacket Tool details for Linux, macOS, Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS0357ToolObject v1.8Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Impacket matters because it is not a single malware family; it is an open-source Python toolkit for manipulating network protocols with capabilities that can support remote service execution, Kerberos activity, Windows credential dumping, packet sniffing, and relay attacks. That makes it relevant to identity security, lateral movement investigations, and incident response readiness across Linux, macOS, and Windows environments.

Executive priority

Treat Impacket coverage as a practical test of whether the organization can see abuse of administrative protocols and credentials, not just known malware. The relationship context shows use by many ATT&CK-tracked campaigns and groups, including espionage, financially motivated, disruptive, ransomware-linked, and critical-infrastructure-relevant activity. Leaders should ask whether SOC, identity, endpoint, and network teams can correlate suspicious protocol use with account, host, and administrative context.

Technical view

ATT&CK provides no official detection guidance for S0357, so defenders should validate behavior-based visibility around the capabilities MITRE lists: remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks. Because the tool is open source and may be present in security testing or administration contexts, detections should focus on unauthorized execution, unusual source hosts, abnormal authentication patterns, credential access indicators, and protocol activity inconsistent with normal operations.

Likely telemetry

  • Endpoint process execution and command-line telemetry on Linux, macOS, and Windows, especially where Python-based tooling may run
  • Authentication and identity logs related to Windows accounts, Kerberos activity, and remote access attempts
  • Windows host and server logs from systems receiving remote service execution or credential access attempts
  • Network traffic metadata or packet inspection for protocol manipulation, relay behavior, packet sniffing, and unusual east-west connections
  • EDR, NDR, SIEM, and privileged access logs that can correlate account, source host, destination host, and protocol usage

Detection direction

  • Build detections around behaviors and telemetry correlations rather than only tool names, since ATT&CK does not provide an official detection method for this object.
  • Tune for suspicious administrative-protocol use from non-admin workstations, unusual jump points, unexpected operating systems, or accounts outside normal maintenance windows.
  • Correlate Kerberos anomalies, relay-like authentication patterns, and remote service execution with endpoint process evidence and account privilege context.
  • Account for false positives from red teams, penetration testers, incident responders, and administrators who may use open-source protocol tooling legitimately.
  • Use the relationship context as threat-intelligence prioritization: organizations in government, MSP, aviation, energy, finance, healthcare, telecom, BPO, defense, critical infrastructure, retail, hospitality, and related sectors should verify coverage against this class of tooling.

Mitigation priorities

  • Inventory and govern authorized use of Impacket or similar protocol tooling; require documented approval for testing and administrative use.
  • Reduce credential exposure by tightening privileged account use, monitoring credential-dumping indicators, and enforcing least privilege for administrative access.
  • Harden remote administration paths and restrict which hosts and accounts can perform remote service execution.
  • Strengthen Kerberos and identity monitoring so suspicious authentication, delegation, or relay-like behavior is investigated quickly.
  • Segment sensitive systems and critical services to limit the operational impact of credential abuse and lateral movement.
Additional notes and limits

This take is based on the official ATT&CK description, platforms, external references, and relationships. The strongest decision value is not that Impacket is inherently malicious, but that its listed capabilities overlap with high-impact identity and lateral movement behaviors. The many campaign and group relationships make it useful for prioritizing defensive validation, but local telemetry is required to determine whether use is authorized or suspicious.

ATT&CK lists no tactics and provides no official detection text for this object. The supplied relationship descriptions are partial and do not prove current activity in any specific environment. No vendor-specific detections, indicators, or guaranteed coverage should be inferred from this object alone.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Impacket

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

11 rows
DomainIDNameRelationship / procedure
EnterpriseT1557.001Name Resolution Poisoning and SMB RelaySub-techniqueThis object uses Name Resolution Poisoning and SMB Relay.
EnterpriseT1040Network SniffingThis object uses Network Sniffing.
EnterpriseT1558.003KerberoastingSub-techniqueThis object uses Kerberoasting.
EnterpriseT1558.005Ccache FilesSub-techniqueThis object uses Ccache Files.
EnterpriseT1003.003NTDSSub-techniqueThis object uses NTDS.
EnterpriseT1569.002Service ExecutionSub-techniqueThis object uses Service Execution.
EnterpriseT1003.001LSASS MemorySub-techniqueThis object uses LSASS Memory.
EnterpriseT1047Windows Management InstrumentationThis object uses Windows Management Instrumentation.
EnterpriseT1003.002Security Account ManagerSub-techniqueThis object uses Security Account Manager.
EnterpriseT1570Lateral Tool TransferThis object uses Lateral Tool Transfer.
EnterpriseT1003.004LSA SecretsSub-techniqueThis object uses LSA Secrets.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G1053: Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.CitationAvertium Storm-0501 Sabbath Ransomware Arcane January 2022CitationMicrosoft Storm-501 Sabbath Ransomware Embargo September 2024CitationMicrosoft Storm-0501 Embargo Ransomware August 2025CitationGoogle Mandiant Storm-0501 Sabbath Ransomware November 2021

GroupEnterprise

G1016: FIN13

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.CitationMandiant FIN13 Aug 2022CitationSygnia Elephant Beetle Jan 2022

GroupEnterprise

G0059: Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.CitationFireEye APT35 2018CitationClearSky Kittens Back 3 August 2020CitationCertfa Charming Kitten January 2021CitationSecureworks COBALT ILLUSION Threat ProfileCitationProofpoint TA453 July2021

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.Citationapt41_mandiant Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.CitationFireEye APT41 Aug 2019CitationGroup IB APT 41 June 2021

GroupEnterprise

G0125: HAFNIUM

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.CitationMicrosoft HAFNIUM March 2020CitationVolexity Exchange Marauder March 2021CitationMicrosoft Silk Typhoon MAR 2025

GroupEnterprise

G0030: Lotus Blossom

Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.CitationLotus Blossom Jun 2015CitationSymantec Bilbug 2022CitationCisco LotusBlossom 2025

GroupEnterprise

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.CitationDell TG-3390 The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.CitationSecureWorks BRONZE UNION June 2017CitationSecurelist LuckyMouse June 2018CitationTrend Micro DRBControl February 2020

GroupEnterprise

G0129: Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. CitationBlackBerry MUSTANG PANDA October 2022CitationEset PlugX Korplug Mustang Panda March 2022CitationAnomali MUSTANG PANDA October 2019CitationCisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022CitationSecureworks BRONZE PRESIDENT December 2019CitationDOJ Affidavit Search and Seizure PlugX December 2024CitationEclecticIQ Mustang Panda PlugXCitationATTACKIQ MUSTANG PANDA TONESHELL March 2023CitationCrowdstrike MUSTANG PANDA June 2018CitationPalo Alto Networks, Unit 42CitationSophos PlugX September 2022CitationSophos Mustang Panda PLUGXCitationZscaler

GroupEnterprise

G0035: Dragonfly

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.CitationDOJ Russia Targeting Critical Infrastructure March 2022CitationUK GOV FSB Factsheet April 2022 Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.CitationSymantec DragonflyCitationSecureworks IRON LIBERTY July 2019CitationSymantec Dragonfly Sept 2017CitationFortune Dragonfly 2.0 Sept 2017CitationGigamon Berserk Bear October 2021CitationCISA AA20-296A Berserk Bear December 2020CitationSymantec Dragonfly 2.0 October 2017

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.CitationMicrosoft Storm-1811 2024Citationrapid7-email-bombingCitationRedCanary Storm-1811 2024CitationRedCanary June Insights 2024

GroupEnterprise

G1021: Cinnamon Tempest

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.CitationMicrosoft Ransomware as a ServiceCitationMicrosoft Threat Actor Naming July 2023CitationTrend Micro Cheerscrypt May 2022CitationSecureWorks BRONZE STARLIGHT Ransomware Operations June 2022

GroupEnterprise

G1017: Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.CitationCISA AA24-038A PRC Critical Infrastructure February 2024CitationMicrosoft Volt Typhoon May 2023CitationJoint Cybersecurity Advisory Volt Typhoon June 2023CitationSecureworks BRONZE SILHOUETTE May 2023. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.CitationDOJ KVBotnet 2024.

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. CitationDragos 2025 Year in Review

CampaignEnterprise

C0038: HomeLand Justice

HomeLand Justice was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for HomeLand Justice was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including HEXANE who probed victim infrastructure.CitationMandiant ROADSWEEP August 2022CitationMicrosoft Albanian Government Attacks September 2022CitationCISA Iran Albanian Attacks September 2022 A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.CitationCISA Iran Albanian Attacks September 2022

CampaignEnterprise

C0027: C0027

C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During C0027 Scattered Spider used various forms of social engineering, performed SIM swapping, and attempted to leverage access from victim environments to mobile carrier networks.CitationCrowdstrike TELCO BPO Campaign December 2022

CampaignEnterprise

C0058: SharePoint ToolShell Exploitation

The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.CitationMicrosoft SharePoint Exploit JUL 2025CitationPalo Alto SharePoint Vulnerabilities JUL 2025CitationEye Research ToolShell JUL 2025CitationESET ToolShell JUL 2025CitationTrend Micro SharePoint Attacks JUL 2025

CampaignEnterprise

C0014: Operation Wocao

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.CitationFoxIT Wocao December 2019

Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.CitationFoxIT Wocao December 2019

CampaignEnterprise

C0063: 2025 Poland Wiper Attacks

2025 Poland Wiper Attacks is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025. Targets included more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, and a manufacturing sector company. The attacks on the distributed energy resources (DER) disrupted communications between affected facilities and the distribution system operator, but did not impact electricity generation or heat supply. Across the campaign, threat actors deployed two previously undocumented wiper tools, DynoWiper, a Windows-based wiper and LazyWiper, a PowerShell wiper, distributed via malicious Group Policy Objects. At the CHP plant, threat actors had maintained access since at least March 2025, using that foothold to obtain credentials and move laterally before attempting wiper deployment. Some reporting has assessed the activity to be consistent with Russian Federal Security Service (FSB) threat activity group Dragonfly, also tracked as STATIC TUNDRA, while other reporting attributes the destructive wiper activities to the Russian General Staff Main Intelligence Directorate (GRU) threat activity group ELECTRUM, also tracked as Sandworm Team.CitationCERT PolskaCitationDragos ELECTRUM JAN 2026CitationESET DynoWiper JAN 2026CitationESET DynoWiper Update JAN 2026

CampaignEnterprise

C0029: Cutting Edge

Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.CitationMandiant Cutting Edge January 2024CitationVolexity Ivanti Zero-Day Exploitation January 2024CitationVolexity Ivanti Global Exploitation January 2024CitationMandiant Cutting Edge Part 2 January 2024CitationMandiant Cutting Edge Part 3 February 2024

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.8
Created
Modified
Raw hash
da6af34bb85dba0e...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.8Current bundleda6af34bb85d…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  2. [2]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  3. [3]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  4. [4]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  5. [5]
    apt41_dcsocytec_dec2022

    DCSO CyTec Blog. (2022, December 24). APT41 — The spy who failed to encrypt me. Retrieved June 13, 2024.

    Open source URL
  6. [6]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  7. [7]
    Crowdstrike TELCO BPO Campaign December 2022

    Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.

    Open source URL
  8. [8]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  9. [9]
    Cisco LotusBlossom 2025

    Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.

    Open source URL
  10. [10]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  11. [11]
    Kerberos GNU/Linux

    Adepts of 0xCC. (2021, January 28). The Kerberos Credential Thievery Compendium (GNU/Linux). Retrieved September 17, 2024.

    Open source URL
  12. [12]
    on security kerberos linux

    Boal, Calum. (2020, January 28). Abusing Kerberos From Linux - An Overview of Available Tools. Retrieved September 17, 2024.

    Open source URL
  13. [13]
    Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023

    Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.

    Open source URL
  14. [14]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  15. [15]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  16. [16]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  17. [17]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  18. [18]
    Microsoft Ransomware as a Service

    Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.

    Open source URL
  19. [19]
    Sygnia Emperor Dragonfly October 2022

    Biderman, O. et al. (2022, October 3). REVEALING EMPEROR DRAGONFLY: NIGHT SKY AND CHEERSCRYPT - A SINGLE RANSOMWARE GROUP. Retrieved December 6, 2023.

    Open source URL
  20. [20]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  21. [21]
    Microsoft Volt Typhoon May 2023

    Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.

    Open source URL
  22. [22]
    Joint Cybersecurity Advisory Volt Typhoon June 2023

    NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.

    Open source URL
  23. [23]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  24. [24]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  25. [25]
    Mandiant APT29 Eye Spy Email Nov 22

    Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

    Open source URL
  26. [26]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  27. [27]
    CERT Polska

    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

    Open source URL
  28. [28]
    Microsoft Prestige ransomware October 2022

    MSTIC. (2022, October 14). New “Prestige” ransomware impacts organizations in Ukraine and Poland. Retrieved January 19, 2023.

    Open source URL
  29. [29]
    Cadet Blizzard emerges as novel threat actor

    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.

    Open source URL
  30. [30]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  31. [31]
    Mandiant Cutting Edge Part 2 January 2024

    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  32. [32]
    Bitdefender FIN8 July 2021

    Martin Zugec. (2021, July 27). Deep Dive Into a FIN8 Attack - A Forensic Investigation. Retrieved September 1, 2021.

    Open source URL
  33. [33]
    Bitdefender Sardonic Aug 2021

    Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.

    Open source URL
  34. [34]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  35. [35]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  36. [36]
    mitre-attackS0357
    Open source URL
  37. [37]
    mitre-attackS0357
    Open source URL
  38. [38]
    mitre-attackS0357
    Open source URL
  39. [39]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  40. [40]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  41. [41]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  42. [42]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  43. [43]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  44. [44]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  45. [45]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  46. [46]
    apt41_dcsocytec_dec2022

    DCSO CyTec Blog. (2022, December 24). APT41 — The spy who failed to encrypt me. Retrieved June 13, 2024.

    Open source URL
  47. [47]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  48. [48]
    Crowdstrike TELCO BPO Campaign December 2022

    Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.

    Open source URL
  49. [49]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  50. [50]
    Cisco LotusBlossom 2025

    Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.

    Open source URL
  51. [51]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  52. [52]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  53. [53]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  54. [54]
    Kerberos GNU/Linux

    Adepts of 0xCC. (2021, January 28). The Kerberos Credential Thievery Compendium (GNU/Linux). Retrieved September 17, 2024.

    Open source URL
  55. [55]
    on security kerberos linux

    Boal, Calum. (2020, January 28). Abusing Kerberos From Linux - An Overview of Available Tools. Retrieved September 17, 2024.

    Open source URL
  56. [56]
    Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023

    Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.

    Open source URL
  57. [57]
    Core Security Impacket

    Core Security. (n.d.). Impacket. Retrieved November 2, 2017.

    Open source URL
  58. [58]
    US-CERT TA18-074A

    US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018.

    Open source URL
  59. [59]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  60. [60]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  61. [61]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  62. [62]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  63. [63]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  64. [64]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  65. [65]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  66. [66]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  67. [67]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  68. [68]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  69. [69]
    Microsoft Ransomware as a Service

    Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.

    Open source URL
  70. [70]
    Sygnia Emperor Dragonfly October 2022

    Biderman, O. et al. (2022, October 3). REVEALING EMPEROR DRAGONFLY: NIGHT SKY AND CHEERSCRYPT - A SINGLE RANSOMWARE GROUP. Retrieved December 6, 2023.

    Open source URL
  71. [71]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  72. [72]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  73. [73]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  74. [74]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  75. [75]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  76. [76]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  77. [77]
    Joint Cybersecurity Advisory Volt Typhoon June 2023

    NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.

    Open source URL
  78. [78]
    Microsoft Volt Typhoon May 2023

    Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.

    Open source URL
  79. [79]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  80. [80]
    Mandiant APT29 Eye Spy Email Nov 22

    Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

    Open source URL
  81. [81]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  82. [82]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  83. [83]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.