LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1010: Application Window Discovery

Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used.[1] For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade.[2]

Adversaries typically abuse system features for this type of enumeration. For example, they may gather information through native system features such as Command and Scripting Interpreter commands and Native API functions.

EnterpriseT1010TechniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Application Window Discovery is a low-noise discovery behavior where an intruder or malware checks what windows are open on a Linux, macOS, or Windows endpoint. The business value is not the window list itself; it is what that list can reveal: user activity, potential sensitive data to collect, and whether security tools are visible. For leaders, this technique matters because it can be an early sign that a compromised endpoint is being assessed for surveillance, data collection, or evasion decisions.

Executive priority

Treat this as a validation point for endpoint visibility and incident triage, not as a standalone high-severity event. Security leaders should ask whether SOC tooling can see script-based and API-based local discovery across managed workstations and servers, and whether IR playbooks correlate this behavior with other discovery, collection, or security software discovery activity. The relationship context includes multiple remote access tools and espionage-oriented software, plus groups listed by ATT&CK as using the technique, so coverage is useful evidence for managed detection readiness and audit discussions around endpoint monitoring.

Technical view

ATT&CK places T1010 under Discovery for Linux, macOS, and Windows. The description states adversaries may abuse native system features, including Command and Scripting Interpreter behavior and Native API functions, to list open application windows. Since official MITRE detection text is not provided, defenders should validate coverage through the related detection strategy DET0097, Detection of Application Window Enumeration via API or Scripting, and by testing whether endpoint telemetry captures suspicious enumeration performed by scripts, interpreters, or unusual processes. Correlate with T1518.001 Security Software Discovery where window names reveal security tooling, and with follow-on collection or evasion behaviors when present.

Likely telemetry

  • Endpoint process creation and command-line telemetry for shells, scripting interpreters, and unusual parent-child process chains
  • Script execution logs where available, including local enumeration commands or automation frameworks
  • EDR or endpoint sensor telemetry for native API calls associated with window enumeration
  • Process metadata and user-session context showing which process performed enumeration and under which user
  • Application/window title metadata if collected by approved endpoint monitoring tools

Detection direction

  • Validate DET0097-style coverage for API-based and scripting-based application window enumeration rather than relying only on command-line indicators.
  • Tune detections around context: user-driven accessibility tools, helpdesk utilities, window managers, and legitimate automation may enumerate windows, so suspicious parent process, execution path, user context, and timing matter.
  • Prioritize alerts when enumeration is performed by newly observed binaries, remote access tools, scripts launched from unusual locations, or processes already associated with other discovery activity.
  • Look for relationship-driven context: ATT&CK maps this technique to numerous RATs/backdoors such as PoisonIvy, NETWIRE, QuasarRAT, Remcos, njRAT, and others, but do not infer a specific family from T1010 alone.
  • Check cross-platform blind spots. Windows coverage may be stronger than Linux/macOS depending on endpoint sensor depth, while API-level enumeration may not be visible in basic operating system logs.

Mitigation priorities

  • Ensure managed endpoints on Linux, macOS, and Windows have process, script, and endpoint behavior telemetry sufficient to support discovery detection.
  • Restrict and monitor unnecessary scripting capability where business operations allow, especially for high-risk users and sensitive systems.
  • Harden endpoint controls so untrusted or newly introduced tools cannot freely execute reconnaissance behavior without inspection.
  • Use application control, least privilege, and endpoint protection policies to reduce abuse of remote access tools and unauthorized automation.
  • Include this behavior in IR triage runbooks as a correlation signal with broader discovery, security software discovery, collection, and remote access activity.
Additional notes and limits

This take is based on ATT&CK T1010 version 1.3 in enterprise-attack and the supplied relationship context. The most actionable relationship is DET0097, which frames detection around API or scripting enumeration. ATT&CK also lists multiple groups and software families as using this behavior, including Lazarus Group, HEXANE, Volt Typhoon, and many RAT/backdoor tools; those relationships support prioritizing detection engineering but should not be used as attribution by themselves.

MITRE provides no official detection text for this object in the supplied fields. Specific APIs, commands, event IDs, and vendor detections are not supplied, so local validation must be based on the organization’s endpoint sensor capabilities, logging policy, operating systems, and legitimate administrative tooling. T1010 alone is usually contextual rather than conclusive.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Application Window Discovery

Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used.[1] For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade.[2]

Adversaries typically abuse system features for this type of enumeration. For example, they may gather information through native system features such as Command and Scripting Interpreter commands and Native API functions.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0032: Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). [1] [2] Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.[3]

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.[4][5][6]

GroupEnterprise

G1017: Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]

GroupEnterprise

G1001: HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.[1][2][3][4]

MalwareEnterprise

S0438: Attor

Attor is a Windows-based espionage platform that has been seen in use since 2013. Attor has a loadable plugin architecture to customize functionality for specific targets.[1]

Windows
MalwareEnterprise

S0033: NetTraveler

NetTraveler is malware that has been used in multiple cyber espionage campaigns for basic surveillance of victims. The earliest known samples have timestamps back to 2005, and the largest number of observed samples were created between 2010 and 2013. [1]

Windows
MalwareEnterprise

S0696: Flagpro

Flagpro is a Windows-based, first-stage downloader that has been used by BlackTech since at least October 2020. It has primarily been used against defense, media, and communications companies in Japan.[1]

Windows
MalwareEnterprise

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

Windows
MalwareEnterprise

S1111: DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

Windows
MalwareEnterprise

S0139: PowerDuke

PowerDuke is a backdoor that was used by APT29 in 2016. It has primarily been delivered through Microsoft Word or Excel attachments containing malicious macros. [1]

Windows
MalwareEnterprise

S0260: InvisiMole

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.[1][2]

Windows
MalwareEnterprise

S0531: Grandoreiro

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.[1][2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
0d3ad4453e507f4a...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundle0d3ad4453e50…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  2. [2]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  3. [3]
    ESET Attor Oct 2019

    Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

    Open source URL
  4. [4]
    Kaspersky NetTraveler

    Kaspersky Lab's Global Research and Analysis Team. (n.d.). The NetTraveler (aka ‘Travnet’). Retrieved November 17, 2024.

    Open source URL
  5. [5]
    Symantec Chafer Dec 2015

    Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

    Open source URL
  6. [6]
    NTT Security Flagpro new December 2021

    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

    Open source URL
  7. [7]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  8. [8]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  9. [9]
    Novetta Blockbuster Loaders

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024.

    Open source URL
  10. [10]
    Novetta Blockbuster Tools

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Tools Report. Retrieved March 10, 2016.

    Open source URL
  11. [11]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  12. [12]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  13. [13]
    Volexity PowerDuke November 2016

    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

    Open source URL
  14. [14]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  15. [15]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  16. [16]
    CheckPoint Naikon May 2020

    CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.

    Open source URL
  17. [17]
    2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

    Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.

    Open source URL
  18. [18]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  19. [19]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  20. [20]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  21. [21]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  22. [22]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  23. [23]
    Securelist Remexi Jan 2019

    Legezo, D. (2019, January 30). Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities. Retrieved April 17, 2019.

    Open source URL
  24. [24]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  25. [25]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  26. [26]
    Symantec W32.Duqu

    Symantec Security Response. (2011, November). W32.Duqu: The precursor to the next Stuxnet. Retrieved September 17, 2015.

    Open source URL
  27. [27]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  28. [28]
    Carbon Black HotCroissant April 2020

    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

    Open source URL
  29. [29]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  30. [30]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  31. [31]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  32. [32]
    Talos ROKRAT

    Mercer, W., Rascagneres, P. (2017, April 03). Introducing ROKRAT. Retrieved May 21, 2018.

    Open source URL
  33. [33]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  34. [34]
    Symantec Catchamas April 2018

    Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.

    Open source URL
  35. [35]
    ATT QakBot April 2021

    Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.

    Open source URL
  36. [36]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  37. [37]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  38. [38]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
  39. [39]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  40. [40]
    Symantec Darkmoon Aug 2005

    Hayashi, K. (2005, August 18). Backdoor.Darkmoon. Retrieved February 23, 2018.

    Open source URL
  41. [41]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  42. [42]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  43. [43]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  44. [44]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  45. [45]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  46. [46]
    mitre-attackT1010
    Open source URL
  47. [47]
    mitre-attackT1010
    Open source URL
  48. [48]
    mitre-attackT1010
    Open source URL
  49. [49]
    ESET Attor Oct 2019

    Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

    Open source URL
  50. [50]
    Kaspersky NetTraveler

    Kaspersky Lab's Global Research and Analysis Team. (n.d.). The NetTraveler (aka ‘Travnet’). Retrieved November 17, 2024.

    Open source URL
  51. [51]
    Symantec Chafer Dec 2015

    Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

    Open source URL
  52. [52]
    NTT Security Flagpro new December 2021

    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

    Open source URL
  53. [53]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  54. [54]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  55. [55]
    Novetta Blockbuster Loaders

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024.

    Open source URL
  56. [56]
    Novetta Blockbuster Tools

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Tools Report. Retrieved March 10, 2016.

    Open source URL
  57. [57]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  58. [58]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  59. [59]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  60. [60]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  61. [61]
    Volexity PowerDuke November 2016

    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

    Open source URL
  62. [62]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  63. [63]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  64. [64]
    CheckPoint Naikon May 2020

    CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.

    Open source URL
  65. [65]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  66. [66]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  67. [67]
    2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

    Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.

    Open source URL
  68. [68]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  69. [69]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  70. [70]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  71. [71]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  72. [72]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  73. [73]
    Securelist Remexi Jan 2019

    Legezo, D. (2019, January 30). Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities. Retrieved April 17, 2019.

    Open source URL
  74. [74]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  75. [75]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  76. [76]
    Symantec W32.Duqu

    Symantec Security Response. (2011, November). W32.Duqu: The precursor to the next Stuxnet. Retrieved September 17, 2015.

    Open source URL
  77. [77]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  78. [78]
    Carbon Black HotCroissant April 2020

    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

    Open source URL
  79. [79]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  80. [80]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  81. [81]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  82. [82]
    Talos ROKRAT

    Mercer, W., Rascagneres, P. (2017, April 03). Introducing ROKRAT. Retrieved May 21, 2018.

    Open source URL
  83. [83]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  84. [84]
    Symantec Catchamas April 2018

    Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.

    Open source URL
  85. [85]
    TrendMicro BlackTech June 2017

    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.