LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1008: Fallback Channels

Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.

EnterpriseT1008TechniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Fallback Channels matter because they turn command-and-control disruption into a resilience problem for the defender: blocking or losing visibility on one C2 path may not end adversary control if alternate paths remain available. For leaders, the practical question is whether the organization can detect C2 behavior across Windows, Linux, macOS, and ESXi networks rather than relying on a single blocked indicator or one perimeter control.

Executive priority

Prioritize this technique where business continuity depends on fast containment and confidence that an intrusion is actually isolated. ATT&CK links this behavior to multiple groups, malware families, and the Night Dragon campaign, including activity involving energy, petrochemical, SCADA-related collection, financial services, cloud services, telecommunications, healthcare, retail, hospitality, utilities, and other sectors. The decision value is to validate whether incident response playbooks, network controls, and SOC monitoring can handle adversaries shifting channels after an initial C2 route is blocked or degraded.

Technical view

T1008 is an enterprise command-and-control technique for alternate or fallback communications across ESXi, Linux, macOS, and Windows. ATT&CK provides no native detection text for the technique, but the relationship to DET0499 indicates a behavioral detection strategy exists for fallback or alternate C2 channels. SOC and detection teams should validate whether detections look for changes in outbound C2 patterns, repeated attempts to reach alternate destinations, protocol or infrastructure shifts after blocking, and traffic that avoids expected data-transfer thresholds. IR teams should avoid treating one sinkholed, blocked, or remediated channel as proof of containment without checking for secondary communications from affected hosts.

Likely telemetry

  • Network boundary IDS/IPS alerts and block logs, consistent with mitigation M1031
  • Outbound connection metadata from endpoints and servers on Windows, Linux, macOS, and ESXi environments
  • DNS, proxy, firewall, and egress filtering logs showing alternate destinations or protocol changes
  • Endpoint network telemetry that can tie outbound connections to processes or services where available
  • Incident response timelines showing whether new network paths appear after a primary C2 path is disrupted

Detection direction

  • Use the DET0499 relationship as the main ATT&CK-supported detection direction: validate behavioral analytics for fallback or alternate C2 rather than relying only on fixed indicators.
  • Tune for sequences: primary C2 blocked or unavailable, followed by new outbound destinations, ports, protocols, or lower-volume transfer patterns from the same host or cluster of hosts.
  • Account for false positives from legitimate failover, software update mechanisms, VPN/proxy changes, and resilient cloud services; detections should combine network behavior with host and incident context.
  • Check platform coverage explicitly for ESXi, Linux, macOS, and Windows, since enterprise visibility is often uneven across virtualization, server, and workstation environments.
  • During incidents, hunt related software and campaign context from ATT&CK relationships, but do not assume a specific actor based only on fallback-channel behavior.

Mitigation priorities

  • Start with network intrusion prevention at boundaries as supported by M1031: use intrusion detection signatures to block known malicious traffic where reliable indicators exist.
  • Pair blocking with validation: confirm whether blocked systems attempt alternate outbound communications after the primary path is denied.
  • Strengthen egress monitoring and logging coverage across the listed platforms, especially systems with weaker endpoint visibility such as ESXi or non-Windows servers.
  • Update IR containment procedures so responders search for backup C2 paths before declaring eradication or containment complete.
  • Use ATT&CK relationship context to prioritize testing against malware and campaign patterns relevant to the organization’s sector, without treating those relationships as proof of current exposure.
Additional notes and limits

ATT&CK relationships show this technique used by Night Dragon, Lazarus Group, FIN7, OilRig, APT41, UNC3886, and numerous software families including BISCUIT, Derusbi, Uroburos, CHOPSTICK, NETEAGLE, JHUHUGIT, MiniDuke, SslMM, WinMM, DustySky, Mis-Type, S-Type, BlackEnergy, XTunnel, Linfo, and Kwampirs. This breadth makes the behavior strategically important, but the defensive takeaway is behavior-based resilience: can the SOC see C2 channel switching and can IR prove channels are exhausted?

The official ATT&CK detection field for T1008 is not provided, so detection recommendations are derived from the technique description, platforms, tactic, the DET0499 detection-strategy relationship, and M1031 mitigation relationship. Local network architecture, logging depth, approved failover behavior, and incident evidence are required to determine actual coverage or risk.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Fallback Channels

Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0032: Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). [1] [2] Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.[3]

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.[4][5][6]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G1048: UNC3886

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.[1][2]

MalwareEnterprise

S0023: CHOPSTICK

CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants. [1] [2] [3] [4] It is tracked separately from the X-Agent for Android.

WindowsLinux
MalwareEnterprise

S0260: InvisiMole

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.[1][2]

Windows
MalwareEnterprise

S0377: Ebury

Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.[1][2][3][4]

Linux
MalwareEnterprise

S0266: TrickBot

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.[1][2][3][4]

Windows
MalwareEnterprise

S0476: Valak

Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019 targeting enterprises in the US and Germany.[1][2]

Windows
CampaignEnterprise

C0002: Night Dragon

Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the United States. The unidentified threat actors searched for information related to oil and gas field production systems, financials, and collected data from SCADA systems. Based on the observed techniques, tools, and network activities, security researchers assessed the campaign involved a threat group based in China.[1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
681925ef80dd00fd...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle681925ef80dd…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ESET Sednit Part 1

    ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.

  2. [2]
    Symantec Linfo May 2012

    Zhou, R. (2012, May 15). Backdoor.Linfo. Retrieved February 23, 2018.

    Open source URL
  3. [3]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  4. [4]
    OilRig ISMAgent July 2017

    Falcone, R. and Lee, B. (2017, July 27). OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group. Retrieved January 8, 2018.

    Open source URL
  5. [5]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  6. [6]
    US-CERT HOPLIGHT Apr 2019

    US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019.

    Open source URL
  7. [7]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  8. [8]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  9. [9]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  10. [10]
    ESET Ebury Oct 2017

    Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021.

    Open source URL
  11. [11]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  12. [12]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  13. [13]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  14. [14]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  15. [15]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  16. [16]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  17. [17]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  18. [18]
    Mandiant APT29 Eye Spy Email Nov 22

    Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

    Open source URL
  19. [19]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  20. [20]
    Securelist MiniDuke Feb 2013

    Kaspersky Lab's Global Research & Analysis Team. (2013, February 27). The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor. Retrieved November 17, 2024.

    Open source URL
  21. [21]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  22. [22]
    ANSSI Sandworm January 2021

    ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

    Open source URL
  23. [23]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  24. [24]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  25. [25]
    Check Point APT35 CharmPower January 2022

    Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.

    Open source URL
  26. [26]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  27. [27]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  28. [28]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  29. [29]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  30. [30]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  31. [31]
    FOX-IT May 2016 Mofang

    Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

    Open source URL
  32. [32]
    Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023

    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.

    Open source URL
  33. [33]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  34. [34]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  35. [35]
    Novetta Blockbuster RATs

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Remote Administration Tools & Content Staging Malware Report. Retrieved March 16, 2016.

    Open source URL
  36. [36]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  37. [37]
    Koi Glassworm InvisibleCode October 2025

    Idan Dardikman. (2025, October 18). GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace. Retrieved April 10, 2026.

    Open source URL
  38. [38]
    Koi GlassWorm Rust December 2025

    Lotan Sery. (2025, December 10). GlassWorm Goes Native: Same Infrastructure, Hardened Delivery. Retrieved April 10, 2026.

    Open source URL
  39. [39]
    DustySky

    ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.

    Open source URL
  40. [40]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  41. [41]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  42. [42]
    Fidelis Turbo

    Fidelis Cybersecurity. (2016, February 29). The Turbo Campaign, Featuring Derusbi for 64-bit Linux. Retrieved March 2, 2016.

    Open source URL
  43. [43]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  44. [44]
    NCC Group Team9 June 2020

    Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.

    Open source URL
  45. [45]
    ESET Crutch December 2020

    Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020.

    Open source URL
  46. [46]
    CISA MAR-10288834-2.v1 TAINTEDSCRIBE MAY 2020

    USG. (2020, May 12). MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE. Retrieved March 5, 2021.

    Open source URL
  47. [47]
    PaloAlto CardinalRat Apr 2017

    Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018.

    Open source URL
  48. [48]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  49. [49]
    Unit 42 QUADAGENT July 2018

    Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.

    Open source URL
  50. [50]
    Crowdstrike GTR2020 Mar 2020

    Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.

    Open source URL
  51. [51]
    Symantec Orangeworm April 2018

    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

    Open source URL
  52. [52]
    ESET OilRig Downloaders DEC 2023

    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

    Open source URL
  53. [53]
    ESET PipeMon May 2020

    Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020.

    Open source URL
  54. [54]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  55. [55]
    Securelist BlackEnergy Nov 2014

    Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016.

    Open source URL
  56. [56]
    Google Cloud Mandiant UNC3886 2024

    Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024.

    Open source URL
  57. [57]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  58. [58]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  59. [59]
    mitre-attackT1008
    Open source URL
  60. [60]
    mitre-attackT1008
    Open source URL
  61. [61]
    mitre-attackT1008
    Open source URL
  62. [62]
    ESET Sednit Part 1

    ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.

  63. [63]
    Symantec Linfo May 2012

    Zhou, R. (2012, May 15). Backdoor.Linfo. Retrieved February 23, 2018.

    Open source URL
  64. [64]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  65. [65]
    OilRig ISMAgent July 2017

    Falcone, R. and Lee, B. (2017, July 27). OilRig Uses ISMDoor Variant; Possibly Linked to Greenbug Threat Group. Retrieved January 8, 2018.

    Open source URL
  66. [66]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  67. [67]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  68. [68]
    US-CERT HOPLIGHT Apr 2019

    US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019.

    Open source URL
  69. [69]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  70. [70]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  71. [71]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  72. [72]
    ESET Ebury Oct 2017

    Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021.

    Open source URL
  73. [73]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  74. [74]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  75. [75]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  76. [76]
    Unit 42 Valak July 2020

    Duncan, B. (2020, July 24). Evolution of Valak, from Its Beginnings to Mass Distribution. Retrieved August 31, 2020.

    Open source URL
  77. [77]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  78. [78]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  79. [79]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  80. [80]
    Mandiant APT29 Eye Spy Email Nov 22

    Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023.

    Open source URL
  81. [81]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  82. [82]
    Securelist MiniDuke Feb 2013

    Kaspersky Lab's Global Research & Analysis Team. (2013, February 27). The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor. Retrieved November 17, 2024.

    Open source URL
  83. [83]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  84. [84]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  85. [85]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  86. [86]
    ANSSI Sandworm January 2021

    ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

    Open source URL
  87. [87]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  88. [88]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  89. [89]
    Check Point APT35 CharmPower January 2022

    Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.

    Open source URL
  90. [90]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  91. [91]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  92. [92]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  93. [93]
    McAfee Night Dragon

    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

    Open source URL
  94. [94]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  95. [95]
    FOX-IT May 2016 Mofang

    Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

    Open source URL
  96. [96]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  97. [97]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  98. [98]
    Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023

    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.

    Open source URL
  99. [99]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  100. [100]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  101. [101]
    Novetta Blockbuster RATs

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Remote Administration Tools & Content Staging Malware Report. Retrieved March 16, 2016.

    Open source URL
  102. [102]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  103. [103]
    Koi GlassWorm Rust December 2025

    Lotan Sery. (2025, December 10). GlassWorm Goes Native: Same Infrastructure, Hardened Delivery. Retrieved April 10, 2026.

    Open source URL
  104. [104]
    Koi Glassworm InvisibleCode October 2025

    Idan Dardikman. (2025, October 18). GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace. Retrieved April 10, 2026.

    Open source URL
  105. [105]
    DustySky

    ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.

    Open source URL
  106. [106]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  107. [107]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  108. [108]
    Fidelis Turbo

    Fidelis Cybersecurity. (2016, February 29). The Turbo Campaign, Featuring Derusbi for 64-bit Linux. Retrieved March 2, 2016.

    Open source URL
  109. [109]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  110. [110]
    NCC Group Team9 June 2020

    Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.

    Open source URL
  111. [111]
    ESET Crutch December 2020

    Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020.

    Open source URL
  112. [112]
    CISA MAR-10288834-2.v1 TAINTEDSCRIBE MAY 2020

    USG. (2020, May 12). MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE. Retrieved March 5, 2021.

    Open source URL
  113. [113]
    PaloAlto CardinalRat Apr 2017

    Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018.

    Open source URL
  114. [114]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  115. [115]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  116. [116]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.