LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1007: System Service Discovery

Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.[1][2][3][4]

Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

EnterpriseT1007TechniqueObject v1.6Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

System Service Discovery is adversary reconnaissance of local services and scheduled tasks across Windows, Linux, and macOS. Its business importance is that it often helps an intruder decide what to do next: whether to continue infection, choose a persistence path, avoid security tools, or tailor follow-on actions to the host. For leaders, this is a coverage-validation technique: can the organization see common service-enumeration activity before it becomes lateral movement, persistence, or broader compromise?

Executive priority

Prioritize this as a SOC and incident-response readiness check rather than a standalone high-severity event. The commands MITRE lists, such as sc query, tasklist /svc, systemctl --type=service, net start, schtasks, and crontab -l, are legitimate administration tools, so value comes from context, baselining, and correlation. This technique is documented in relationships with multiple campaigns, groups, and malware/software entries, including espionage and cloud/container-focused contexts, making it relevant to enterprise resilience, intellectual property protection, managed detection quality, and audit evidence that endpoint and command telemetry are actually being collected.

Technical view

For SOC and detection engineering, validate visibility for service and scheduled-task enumeration on Windows, Linux, and macOS. ATT&CK provides no official detection text for T1007, but the relationship to DET0483, “Detection of System Service Discovery Commands Across OS Platforms,” supports building detections around cross-platform command execution patterns. Focus on process creation, command-line arguments, parent/child process relationships, user context, remote execution context where available, and clustering with other discovery behaviors. Treat single commands carefully because administrators and management tooling commonly enumerate services; higher-confidence alerts should consider unusual user, host role, execution chain, time of day, repeated enumeration, or proximity to suspicious access or execution events.

Likely telemetry

  • Endpoint process creation events with full command line for Windows, Linux, and macOS
  • Windows command execution involving sc query, tasklist /svc, net start, and schtasks
  • Linux and macOS command execution involving systemctl --type=service and crontab -l
  • Parent process, user account, host role, and session context for service-enumeration commands
  • Scheduled task and cron listing/audit records where available

Detection direction

  • Validate DET0483-style coverage for service discovery commands across all supported platforms, not only Windows.
  • Tune detections against known administrative software, patching tools, monitoring agents, and standard operating procedures to reduce false positives.
  • Prioritize alerts when service discovery is launched by unusual parent processes, non-administrative users, newly observed accounts, or processes associated with suspicious execution.
  • Correlate service and scheduled-task enumeration with adjacent discovery activity and later attempts to establish persistence, move laterally, or alter services.
  • Check blind spots where command-line logging is disabled, EDR coverage is missing on servers, Linux/macOS telemetry is weaker than Windows telemetry, or scheduled-task/cron visibility is not centralized.

Mitigation priorities

  • Ensure endpoint logging and EDR coverage capture process command lines and process lineage across Windows, Linux, and macOS.
  • Limit routine administrative privileges and service-management permissions to appropriate roles, reducing the number of accounts that can legitimately perform broad service enumeration.
  • Standardize administrative tooling and document expected service-discovery behavior so SOC teams can distinguish normal operations from suspicious use.
  • Harden scheduled task and cron administration with access controls and monitoring, since ATT&CK includes scheduled-task discovery in this technique description.
  • Use incident-response playbooks that treat suspicious service discovery as a prompt to review surrounding activity, affected account scope, and possible follow-on behavior rather than as proof of compromise by itself.
Additional notes and limits

ATT&CK lists this as an enterprise discovery technique, not a sub-technique, with platforms Linux, macOS, and Windows. The supplied relationships show use by multiple groups, campaigns, and software, and one detection strategy relationship, but the official ATT&CK detection field is not provided. The practical defensive value is therefore in validating telemetry and correlation logic for legitimate OS utilities that can also support adversary decision-making.

This take is based only on the supplied ATT&CK object fields, external references, and relationships. It does not establish current exploitation, local exposure, actor attribution, or confirmed detection coverage in any environment. Local baselines, logging configuration, endpoint coverage, and administrative workflows are required to determine alert severity and response priority.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

System Service Discovery

Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.[1][2][3][4]

Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0060: BRONZE BUTLER

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.[1][2][3]

GroupEnterprise

G0139: TeamTNT

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.[1][2][3][4][5][6][7][8][9]

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G0010: Turla

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]

GroupEnterprise

G0143: Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]

GroupEnterprise

G0033: Poseidon Group

Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm. [1]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0114: Chimera

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.[1][2]

GroupEnterprise

G0004: Ke3chang

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.[1][2][3][4]

GroupEnterprise

G1054: MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]

GroupEnterprise

G1006: Earth Lusca

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.[1]

Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.[1]

MalwareEnterprise

S0386: Ursnif

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]

Windows
MalwareEnterprise

S0018: Sykipot

Sykipot is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily in the US. One variant of Sykipot hijacks smart cards on victims. [1] The group using this malware has also been referred to as Sykipot. [2]

Windows
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
MalwareEnterprise

S0081: Elise

Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.[1][2]

Windows
ToolEnterprise

S0378: PoshC2

PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.[1]

WindowsLinuxmacOS
MalwareEnterprise

S0533: SLOTHFULMEDIA

SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017.[1][2] It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.[3][4]

In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing".[4] ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".[5]

Windows
MalwareEnterprise

S1244: Medusa Ransomware

Medusa Ransomware has been utilized in attacks since at least 2021. Medusa Ransomware has been known to be utilized in conjunction with living off the land techniques and remote management software. Medusa Ransomware has been used in campaigns associated with “double extortion” ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Medusa Ransomware software was initially a closed ransomware variant which later evolved to a Ransomware as a Service (RaaS). Medusa Ransomware has impacted victims from a diverse range of sectors within a multitude of countries, and it is assessed Medusa Ransomware is used in an opportunistic manner.[1][2][3][4]

MalwareEnterprise

S0236: Kwampirs

Kwampirs is a backdoor Trojan used by Orangeworm. Kwampirs has been found on machines which had software installed for the use and control of high-tech imaging devices such as X-Ray and MRI machines.[1] Kwampirs has multiple technical overlaps with Shamoon based on reverse engineering analysis.[2]

Windows
ToolEnterprise

S0057: Tasklist

The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It is packaged with Windows operating systems and can be executed from the command-line interface. [1]

MalwareEnterprise

S0283: jRAT

jRAT is a cross-platform, Java-based backdoor originally available for purchase in 2012. Variants of jRAT have been distributed via a software-as-a-service platform, similar to an online subscription model.[1] [2]

LinuxWindowsmacOS
CampaignEnterprise

C0014: Operation Wocao

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.[1]

Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.[1]

CampaignEnterprise

C0012: Operation CuckooBees

Operation CuckooBees was a cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019. Security researchers noted the goal of Operation CuckooBees, which was still ongoing as of May 2022, was likely the theft of proprietary information, research and development documents, source code, and blueprints for various technologies. Researchers assessed Operation CuckooBees was conducted by actors affiliated with Winnti Group, APT41, and BARIUM.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.6
Created
Modified
Raw hash
2c30d9d549efcf8b...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.6Current bundle2c30d9d549ef…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Elastic Security Labs GOSAR 2024

    Jia Yu Chan, Salim Bitam, Daniel Stepanic, and Seth Goodwin. (2024, December 12). Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite. Retrieved May 22, 2025.

    Open source URL
  2. [2]
    SentinelLabs macOS Malware 2021

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved May 22, 2025.

    Open source URL
  3. [3]
    Splunk Linux Gormir 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, July 15). Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs. Retrieved May 22, 2025.

    Open source URL
  4. [4]
    Aquasec Kinsing 2020

    Gal Singer. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved May 22, 2025.

    Open source URL
  5. [5]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  6. [6]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  7. [7]
    AlienVault Sykipot 2011

    Blasco, J. (2011, December 12). Another Sykipot sample likely targeting US federal agencies. Retrieved March 28, 2016.

    Open source URL
  8. [8]
    Palo Alto Comnie

    Grunzweig, J. (2018, January 31). Comnie Continues to Target Organizations in East Asia. Retrieved June 7, 2018.

    Open source URL
  9. [9]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  10. [10]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  11. [11]
    Cisco Talos Intelligence Group

    Darin Smith. (2022, April 21). TeamTNT targeting AWS, Alibaba. Retrieved August 4, 2022.

    Open source URL
  12. [12]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  13. [13]
    GitHub PoshC2

    Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.

    Open source URL
  14. [14]
    Symantec WastedLocker June 2020

    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

    Open source URL
  15. [15]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  16. [16]
    Palo Alto Unit 42 Medusa Group Medusa Ransomware January 2024

    Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.

    Open source URL
  17. [17]
    Broadcom Medusa Ransomware Medusa Group March 2025

    Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.

    Open source URL
  18. [18]
    Security Scorecard Medusa Ransomware January 2024

    Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  19. [19]
    Symantec Orangeworm April 2018

    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

    Open source URL
  20. [20]
    Microsoft Tasklist

    Microsoft. (n.d.). Tasklist. Retrieved December 23, 2015.

    Open source URL
  21. [21]
    Kaspersky Adwind Feb 2016

    Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.

    Open source URL
  22. [22]
    RATANKBA

    Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.

    Open source URL
  23. [23]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  24. [24]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  25. [25]
    Palo Alto Networks BBSRAT

    Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

  26. [26]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  27. [27]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  28. [28]
    US-CERT Volgmer Nov 2017

    US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017.

    Open source URL
  29. [29]
    Proofpoint LookBack Malware Aug 2019

    Raggi, M. Schwarz, D.. (2019, August 1). LookBack Malware Targets the United States Utilities Sector with Phishing Attacks Impersonating Engineering Licensing Boards. Retrieved February 25, 2021.

    Open source URL
  30. [30]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  31. [31]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  32. [32]
    Trend Micro Agenda Ransomware AUG 2022

    Magdy, S. et al. (2022, August 25). New Golang Ransomware Agenda Customizes Attacks. Retrieved September 26, 2025.

    Open source URL
  33. [33]
    SentinelOne Qilin NOV 2022

    SentinelOne. (2022, November 30). Agenda (Qilin). Retrieved September 26, 2025.

    Open source URL
  34. [34]
    HC3 Qilin Threat Profile JUN 2024

    Health Sector Cybersecurity Coordination Center. (2024, June 18). Qilin, aka Agenda Ransomware. Retrieved September 26, 2025.

    Open source URL
  35. [35]
    Cisco Talos Qilin Ransomware OCT 2025

    Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

    Open source URL
  36. [36]
    Kaspersky Poseidon Group

    Kaspersky Lab's Global Research and Analysis Team. (2016, February 9). Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage. Retrieved March 16, 2016.

    Open source URL
  37. [37]
    Talos Kimsuky Nov 2021

    An, J and Malhotra, A. (2021, November 10). North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets. Retrieved December 29, 2021.

    Open source URL
  38. [38]
    ClearSky Lebanese Cedar Jan 2021

    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

    Open source URL
  39. [39]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  40. [40]
    Mandiant Operation Ke3chang November 2014

    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

    Open source URL
  41. [41]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  42. [42]
    ESET GreyEnergy Oct 2018

    Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.

    Open source URL
  43. [43]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  44. [44]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  45. [45]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  46. [46]
    Cyble Embargo Ransomware May 2024

    Cyble. (2024, May 24). The Rust Revolution: New Embargo Ransomware Steps In. Retrieved October 19, 2025.

    Open source URL
  47. [47]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  48. [48]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  49. [49]
    Talos GravityRAT

    Mercer, W., Rascagneres, P. (2018, April 26). GravityRAT - The Two-Year Evolution Of An APT Targeting India. Retrieved May 16, 2018.

    Open source URL
  50. [50]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  51. [51]
    McAfee Cuba April 2021

    Roccio, T., et al. (2021, April). Technical Analysis of Cuba Ransomware. Retrieved June 18, 2021.

    Open source URL
  52. [52]
    SecureList SynAck Doppelgänging May 2018

    Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.

    Open source URL
  53. [53]
    Kaspersky Lab SynAck May 2018

    Bettencourt, J. (2018, May 7). Kaspersky Lab finds new variant of SynAck ransomware using sophisticated Doppelgänging technique. Retrieved May 24, 2018.

    Open source URL
  54. [54]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  55. [55]
    Bitdefender Sardonic Aug 2021

    Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.

    Open source URL
  56. [56]
    Carbon Black HotCroissant April 2020

    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

    Open source URL
  57. [57]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  58. [58]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  59. [59]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  60. [60]
    F-Secure The Dukes

    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

    Open source URL
  61. [61]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  62. [62]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  63. [63]
    Emissary Trojan Feb 2016

    Falcone, R. and Miller-Osborn, J. (2016, February 3). Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?. Retrieved February 15, 2016.

  64. [64]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  65. [65]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  66. [66]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  67. [67]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  68. [68]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  69. [69]
    S2 Grupo TrickBot June 2017

    Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.

    Open source URL
  70. [70]
    Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024

    Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.

    Open source URL
  71. [71]
    Nov AI Threat Tracker

    Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.

    Open source URL
  72. [72]
    Cato LAMEHUG JUL 2025

    Simonovich, V. (2025, July 23). Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) . Retrieved April 21, 2026.

    Open source URL
  73. [73]
    Microsoft PLATINUM April 2016

    Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

    Open source URL
  74. [74]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  75. [75]
    Cybereason OperationCuckooBees May 2022

    Cybereason Nocturnus. (2022, May 4). Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques. Retrieved September 22, 2022.

    Open source URL
  76. [76]
    Malwarebytes Dyreza November 2015

    hasherezade. (2015, November 4). A Technical Look At Dyreza. Retrieved June 15, 2020.

    Open source URL
  77. [77]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  78. [78]
    Talos ZxShell Oct 2014

    Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019.

    Open source URL
  79. [79]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  80. [80]
    Aquasec Kinsing 2020

    Gal Singer. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved May 22, 2025.

    Open source URL
  81. [81]
    Aquasec Kinsing 2020

    Gal Singer. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved May 22, 2025.

    Open source URL
  82. [82]
    Elastic Security Labs GOSAR 2024

    Jia Yu Chan, Salim Bitam, Daniel Stepanic, and Seth Goodwin. (2024, December 12). Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite. Retrieved May 22, 2025.

    Open source URL
  83. [83]
    Elastic Security Labs GOSAR 2024

    Jia Yu Chan, Salim Bitam, Daniel Stepanic, and Seth Goodwin. (2024, December 12). Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite. Retrieved May 22, 2025.

    Open source URL
  84. [84]
    SentinelLabs macOS Malware 2021

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved May 22, 2025.

    Open source URL
  85. [85]
    SentinelLabs macOS Malware 2021

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved May 22, 2025.

    Open source URL
  86. [86]
    Splunk Linux Gormir 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, July 15). Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs. Retrieved May 22, 2025.

    Open source URL
  87. [87]
    Splunk Linux Gormir 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, July 15). Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs. Retrieved May 22, 2025.

    Open source URL
  88. [88]
    mitre-attackT1007
    Open source URL
  89. [89]
    mitre-attackT1007
    Open source URL
  90. [90]
    mitre-attackT1007
    Open source URL
  91. [91]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  92. [92]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  93. [93]
    AlienVault Sykipot 2011

    Blasco, J. (2011, December 12). Another Sykipot sample likely targeting US federal agencies. Retrieved March 28, 2016.

    Open source URL
  94. [94]
    Palo Alto Comnie

    Grunzweig, J. (2018, January 31). Comnie Continues to Target Organizations in East Asia. Retrieved June 7, 2018.

    Open source URL
  95. [95]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  96. [96]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  97. [97]
    Cisco Talos Intelligence Group

    Darin Smith. (2022, April 21). TeamTNT targeting AWS, Alibaba. Retrieved August 4, 2022.

    Open source URL
  98. [98]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  99. [99]
    GitHub PoshC2

    Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.

    Open source URL
  100. [100]
    Symantec WastedLocker June 2020

    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

    Open source URL
  101. [101]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  102. [102]
    Broadcom Medusa Ransomware Medusa Group March 2025

    Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.

    Open source URL
  103. [103]
    Palo Alto Unit 42 Medusa Group Medusa Ransomware January 2024

    Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.

    Open source URL
  104. [104]
    Security Scorecard Medusa Ransomware January 2024

    Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  105. [105]
    Symantec Orangeworm April 2018

    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

    Open source URL
  106. [106]
    Microsoft Tasklist

    Microsoft. (n.d.). Tasklist. Retrieved December 23, 2015.

    Open source URL
  107. [107]
    Kaspersky Adwind Feb 2016

    Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.

    Open source URL
  108. [108]
    RATANKBA

    Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.

    Open source URL
  109. [109]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  110. [110]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  111. [111]
    Palo Alto Networks BBSRAT

    Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

  112. [112]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  113. [113]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  114. [114]
    US-CERT Volgmer Nov 2017

    US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017.

    Open source URL
  115. [115]
    Proofpoint LookBack Malware Aug 2019

    Raggi, M. Schwarz, D.. (2019, August 1). LookBack Malware Targets the United States Utilities Sector with Phishing Attacks Impersonating Engineering Licensing Boards. Retrieved February 25, 2021.

    Open source URL
  116. [116]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  117. [117]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  118. [118]
    Cisco Talos Qilin Ransomware OCT 2025

    Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

    Open source URL
  119. [119]
    HC3 Qilin Threat Profile JUN 2024

    Health Sector Cybersecurity Coordination Center. (2024, June 18). Qilin, aka Agenda Ransomware. Retrieved September 26, 2025.

    Open source URL
  120. [120]
    SentinelOne Qilin NOV 2022

    SentinelOne. (2022, November 30). Agenda (Qilin). Retrieved September 26, 2025.

    Open source URL
  121. [121]
    Trend Micro Agenda Ransomware AUG 2022

    Magdy, S. et al. (2022, August 25). New Golang Ransomware Agenda Customizes Attacks. Retrieved September 26, 2025.

    Open source URL
  122. [122]
    Kaspersky Poseidon Group

    Kaspersky Lab's Global Research and Analysis Team. (2016, February 9). Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage. Retrieved March 16, 2016.

    Open source URL
  123. [123]
    Talos Kimsuky Nov 2021

    An, J and Malhotra, A. (2021, November 10). North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets. Retrieved December 29, 2021.

    Open source URL
  124. [124]
    ClearSky Lebanese Cedar Jan 2021

    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

    Open source URL
  125. [125]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  126. [126]
    Mandiant Operation Ke3chang November 2014

    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

    Open source URL
  127. [127]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  128. [128]
    ESET GreyEnergy Oct 2018

    Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.

    Open source URL
  129. [129]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  130. [130]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  131. [131]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  132. [132]
    Cyble Embargo Ransomware May 2024

    Cyble. (2024, May 24). The Rust Revolution: New Embargo Ransomware Steps In. Retrieved October 19, 2025.

    Open source URL
  133. [133]
    Symantec Hydraq Jan 2010

    Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.

    Open source URL
  134. [134]
    Symantec Trojan.Hydraq Jan 2010

    Symantec Security Response. (2010, January 18). The Trojan.Hydraq Incident. Retrieved February 20, 2018.

    Open source URL
  135. [135]
    Talos GravityRAT

    Mercer, W., Rascagneres, P. (2018, April 26). GravityRAT - The Two-Year Evolution Of An APT Targeting India. Retrieved May 16, 2018.

    Open source URL
  136. [136]
    Intel 471 REvil March 2020

    Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

    Open source URL
  137. [137]
    McAfee Cuba April 2021

    Roccio, T., et al. (2021, April). Technical Analysis of Cuba Ransomware. Retrieved June 18, 2021.

    Open source URL
  138. [138]
    Kaspersky Lab SynAck May 2018

    Bettencourt, J. (2018, May 7). Kaspersky Lab finds new variant of SynAck ransomware using sophisticated Doppelgänging technique. Retrieved May 24, 2018.

    Open source URL
  139. [139]
    SecureList SynAck Doppelgänging May 2018

    Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.

    Open source URL
  140. [140]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  141. [141]
    Bitdefender Sardonic Aug 2021

    Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.

    Open source URL
  142. [142]
    Carbon Black HotCroissant April 2020

    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

    Open source URL
  143. [143]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  144. [144]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  145. [145]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  146. [146]
    F-Secure The Dukes

    F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.

    Open source URL
  147. [147]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  148. [148]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  149. [149]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  150. [150]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  151. [151]
    Emissary Trojan Feb 2016

    Falcone, R. and Miller-Osborn, J. (2016, February 3). Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?. Retrieved February 15, 2016.

  152. [152]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  153. [153]
    Trend Micro IXESHE 2012

    Sancho, D., et al. (2012, May 22). IXESHE An APT Campaign. Retrieved June 7, 2019.

    Open source URL
  154. [154]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  155. [155]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  156. [156]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  157. [157]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  158. [158]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  159. [159]
    S2 Grupo TrickBot June 2017

    Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.

    Open source URL
  160. [160]
    Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024

    Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.

    Open source URL
  161. [161]
    Cato LAMEHUG JUL 2025

    Simonovich, V. (2025, July 23). Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) . Retrieved April 21, 2026.

    Open source URL
  162. [162]
    Nov AI Threat Tracker

    Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.