LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1033: System Owner/User Discovery

MITRE ATT&CK T1033: System Owner/User Discovery Technique details for Linux, macOS, Network Devices, with detection guidance, relationships and mapped CVEs.

EnterpriseT1033TechniqueObject v1.6Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

System Owner/User Discovery is a basic but high-value discovery behavior: an intruder tries to learn who uses a machine or network device, whether someone is currently active, and which accounts are present. For leaders, this matters because that context helps an adversary decide what to do next—such as whether to continue, avoid user attention, or tailor follow-on actions around specific identities or systems.

Executive priority

Treat this as an early-warning discovery signal, not as a standalone impact event. It is relevant to SOC readiness, identity governance, incident triage, and network device administration because the same behavior can appear on Windows, Linux, macOS, and network devices. Executives should ask whether the organization can distinguish routine administrative user checks from unusual enumeration after initial access, especially on servers, privileged workstations, and infrastructure devices.

Technical view

ATT&CK lists this as an enterprise Discovery technique across Linux, macOS, Windows, and Network Devices. Examples include use of commands/utilities such as whoami, w, who, macOS dscl user listing, environment variables like %USERNAME% and $USER, and network device CLI commands such as show users and show ssh. MITRE provides no official detection text, but the relationship context includes DET0093, Behavioral Detection of User Discovery via Local and Remote Enumeration. SOC and IR teams should validate visibility into local command execution, process ownership, session state, account enumeration, and network device CLI activity, then correlate with surrounding discovery, credential access, lateral movement, or remote administration context.

Likely telemetry

  • Endpoint process creation and command-line telemetry for user/session discovery utilities
  • Shell history or command execution records where available on Linux and macOS
  • Windows environment variable usage and process context where captured by endpoint telemetry
  • Running process ownership metadata
  • File and directory ownership metadata when queried or enumerated

Detection direction

  • Baseline legitimate administrative, help desk, deployment, and monitoring use of user-discovery commands before alerting broadly.
  • Prioritize alerts when user discovery occurs from unusual parent processes, unexpected accounts, newly accessed hosts, remote sessions, or shortly after other discovery behavior.
  • For network devices, confirm CLI command accounting is enabled; otherwise show users/show ssh activity may not be visible to the SOC.
  • Tune for sequence and context rather than single commands alone, because utilities such as whoami, who, w, and account/session queries are common in normal operations.
  • Use relationship context from DET0093 as a validation direction for behavioral detection of local and remote user enumeration, while recognizing the supplied ATT&CK object does not include a detailed detection analytic.

Mitigation priorities

  • Ensure endpoint and network device logging is sufficient to reconstruct command execution, session state, and account context during investigations.
  • Restrict and monitor administrative access to network devices and high-value systems so user/session enumeration is attributable to known operators.
  • Apply least-privilege and identity hygiene so discovery of usernames or active users does not easily translate into privileged follow-on activity.
  • Harden remote administration paths and review whether service accounts or automation routinely perform user discovery in ways that obscure suspicious behavior.
  • Document detection and logging coverage as compliance and incident-response evidence, especially for privileged systems and critical infrastructure-facing network devices.
Additional notes and limits

ATT&CK maps this technique to many historical campaigns and groups, including examples across espionage, financially motivated, ransomware, and critical-infrastructure-relevant contexts. That breadth means the behavior is common tradecraft rather than a strong attribution indicator. Its defensive value is highest when correlated with timing, source account, host role, remote access method, and adjacent ATT&CK discovery or credential behaviors.

MITRE does not provide official detection guidance for this object, and the supplied relationship descriptions are not complete for every related campaign or group. This take does not establish active exploitation, customer exposure, or guaranteed detection coverage. Local baselines, logging configuration, and asset criticality are required to decide alert severity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

System Owner/User Discovery

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0082: APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

GroupEnterprise

G1036: Moonstone Sleet

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.[1]

GroupEnterprise

G0061: FIN8

FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.[1][2][3][4]

GroupEnterprise

G0004: Ke3chang

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.[1][2][3][4]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G0125: HAFNIUM

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.[1][2][3]

GroupEnterprise

G1035: Winter Vivern

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.[1][2][3][4][5]

GroupEnterprise

G0073: APT19

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. [1] Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same. [2] [3] [4]

GroupEnterprise

G0051: FIN10

FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations. [1]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.[1][2][3][4][5]

MalwareEnterprise

S0428: PoetRAT

PoetRAT is a remote access trojan (RAT) that was first identified in April 2020. PoetRAT has been used in multiple campaigns against the private and public sectors in Azerbaijan, including ICS and SCADA systems in the energy sector. The STIBNITE activity group has been observed using the malware. PoetRAT derived its name from references in the code to poet William Shakespeare. [1][2][3]

Windows
MalwareEnterprise

S0266: TrickBot

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.[1][2][3][4]

Windows
MalwareEnterprise

S0596: ShadowPad

ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups. [1][2][3]

Windows
MalwareEnterprise

S0367: Emotet

Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID. Emotet first emerged in June 2014, initially targeting the financial sector, and has expanded to multiple verticals over time.[1]

Windows
MalwareEnterprise

S0414: BabyShark

BabyShark is a Microsoft Visual Basic (VB) script-based malware family that is believed to be associated with several North Korean campaigns. [1]

Windows
CampaignEnterprise

C0058: SharePoint ToolShell Exploitation

The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.[1][2][3][4][5]

CampaignEnterprise

C0017: C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]

CampaignEnterprise

C0014: Operation Wocao

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.[1]

Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.6
Created
Modified
Raw hash
c5fa12e1809eef83...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.6Current bundlec5fa12e1809e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    show_ssh_users_cmd_cisco

    Cisco. (2023, March 7). Cisco IOS Security Command Reference: Commands S to Z . Retrieved July 13, 2022.

    Open source URL
  2. [2]
    US-CERT TA18-106A Network Infrastructure Devices 2018

    US-CERT. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

    Open source URL
  3. [3]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  4. [4]
    Talos PoetRAT April 2020

    Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.

    Open source URL
  5. [5]
    Cylance Shaheen Nov 2018

    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

    Open source URL
  6. [6]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  7. [7]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  8. [8]
    Kaspersky ShadowPad Aug 2017

    Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.

    Open source URL
  9. [9]
    ZScaler Squirrelwaffle Sep 2021

    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

    Open source URL
  10. [10]
    CISA AA20-239A BeagleBoyz August 2020

    DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.

    Open source URL
  11. [11]
    Debian nbtscan Nov 2019

    Bezroutchko, A. (2019, November 19). NBTscan man page. Retrieved March 17, 2021.

    Open source URL
  12. [12]
    SecTools nbtscan June 2003

    SecTools. (2003, June 11). NBTscan. Retrieved March 17, 2021.

    Open source URL
  13. [13]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  14. [14]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  15. [15]
    Unit42 BabyShark Feb 2019

    Unit 42. (2019, February 22). New BabyShark Malware Targets U.S. National Security Think Tanks. Retrieved October 7, 2019.

    Open source URL
  16. [16]
    CISA WellMess July 2020

    CISA. (2020, July 16). MAR-10296782-2.v1 – WELLMESS. Retrieved September 24, 2020.

    Open source URL
  17. [17]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  18. [18]
    ESET DazzleSpy Jan 2022

    M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.

    Open source URL
  19. [19]
    CloudSEK_RustyWater_Jan2026

    Awasthi, P. (2026, January 8). Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant. Retrieved March 19, 2026.

    Open source URL
  20. [20]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  21. [21]
    Volexity InkySquid BLUELIGHT August 2021

    Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.

    Open source URL
  22. [22]
    Symantec Daggerfly 2023

    Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.

    Open source URL
  23. [23]
    Cybereason StrifeWater Feb 2022

    Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022.

    Open source URL
  24. [24]
    Google EXOTIC LILY March 2022

    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

    Open source URL
  25. [25]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  26. [26]
    SentinelOne ToolShell JUL 2025

    Kenin, S. et al. (2025, July 21). SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers. Retrieved October 15, 2025.

    Open source URL
  27. [27]
    Kandji Cuckoo April 2024

    Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024.

    Open source URL
  28. [28]
    Malwarebytes Dyreza November 2015

    hasherezade. (2015, November 4). A Technical Look At Dyreza. Retrieved June 15, 2020.

    Open source URL
  29. [29]
    MalwareBytes WoodyRAT Aug 2022

    MalwareBytes Threat Intelligence Team. (2022, August 3). Woody RAT: A new feature-rich malware spotted in the wild. Retrieved December 6, 2022.

    Open source URL
  30. [30]
    Fortinet Diavol July 2021

    Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.

    Open source URL
  31. [31]
    Kaspersky Turla Aug 2014

    Kaspersky Lab's Global Research & Analysis Team. (2014, August 06). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroboros. Retrieved November 7, 2018.

    Open source URL
  32. [32]
    TrendMicro POWERSTATS V3 June 2019

    Lunghi, D. and Horejsi, J.. (2019, June 10). MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools. Retrieved May 14, 2020.

    Open source URL
  33. [33]
    Symantec FIN8 Jul 2023

    Symantec Threat Hunter Team. (2023, July 18). FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware. Retrieved August 9, 2023.

    Open source URL
  34. [34]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  35. [35]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  36. [36]
    Microsoft NICKEL December 2021

    MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.

    Open source URL
  37. [37]
    Zscaler Havoc FEB 2023

    Shivtarkar, N. and Jain, S. (2023, February 14). Havoc Across the Cyberspace. Retrieved August 4, 2025.

    Open source URL
  38. [38]
    Fortinet Havoc MAR 2025

    Wan, Y. (2025, March 3). Havoc: SharePoint with Microsoft Graph API turns into FUD C2. Retrieved August 4, 2025.

    Open source URL
  39. [39]
    ESET Turla Mosquito Jan 2018

    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

    Open source URL
  40. [40]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  41. [41]
    Unit42 Azorult Nov 2018

    Yan, T., et al. (2018, November 21). New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit. Retrieved November 29, 2018.

    Open source URL
  42. [42]
    S2W Racoon 2022

    S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.

    Open source URL
  43. [43]
    Sekoia Raccoon1 2022

    Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.

    Open source URL
  44. [44]
    Sekoia Raccoon2 2022

    Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.

    Open source URL
  45. [45]
    SentinelLabs Metador Technical Appendix Sept 2022

    SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

    Open source URL
  46. [46]
    Mandiant FIN7 Apr 2022

    Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

    Open source URL
  47. [47]
    MalwareBytes SideCopy Dec 2021

    Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

    Open source URL
  48. [48]
    Rapid7 HAFNIUM Mar 2021

    Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.

    Open source URL
  49. [49]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  50. [50]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  51. [51]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  52. [52]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  53. [53]
    2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

    Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.

    Open source URL
  54. [54]
    ANSSI Sandworm January 2021

    ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

    Open source URL
  55. [55]
    Proofpoint RedLine Stealer March 2020

    Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.

    Open source URL
  56. [56]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  57. [57]
    Veriti RedLine Stealer MAAS April 2023

    Yair Herling. (2023, April 4). From ChatGPT to RedLine Stealer: The Dark Side of OpenAI and Google Bard. Retrieved September 17, 2025.

    Open source URL
  58. [58]
    Splunk LAMEHUG SEP 2025

    Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

    Open source URL
  59. [59]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  60. [60]
    SentinelOne WinterVivern 2023

    Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.

    Open source URL
  61. [61]
    RATANKBA

    Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.

    Open source URL
  62. [62]
    Proofpoint TA505 Mar 2018

    Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019.

    Open source URL
  63. [63]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  64. [64]
    McAfee Sharpshooter December 2018

    Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020.

    Open source URL
  65. [65]
    FireEye APT10 Sept 2018

    Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.

    Open source URL
  66. [66]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  67. [67]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  68. [68]
    SecureList SynAck Doppelgänging May 2018

    Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.

    Open source URL
  69. [69]
    XAgentOSX 2017

    Robert Falcone. (2017, February 14). XAgentOSX: Sofacy's Xagent macOS Tool. Retrieved July 12, 2017.

    Open source URL
  70. [70]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  71. [71]
    Github Koadic

    Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.

    Open source URL
  72. [72]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  73. [73]
    Kaspersky WIRTE November 2021

    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

    Open source URL
  74. [74]
    Unit 42 C0d0so0 Jan 2016

    Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.

    Open source URL
  75. [75]
    Securelist Octopus Oct 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.

    Open source URL
  76. [76]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  77. [77]
    CheckPoint SpeakUp Feb 2019

    Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.

    Open source URL
  78. [78]
    Group IB GrimAgent July 2021

    Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

    Open source URL
  79. [79]
    PaloAlto CardinalRat Apr 2017

    Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018.

    Open source URL
  80. [80]
    GitHub Pupy

    Nicolas Verdier. (n.d.). Retrieved January 29, 2018.

    Open source URL
  81. [81]
    FSecure Lokibot November 2019

    Kazem, M. (2019, November 25). Trojan:W32/Lokibot. Retrieved May 15, 2020.

    Open source URL
  82. [82]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  83. [83]
    FireEye FIN10 June 2017

    FireEye iSIGHT Intelligence. (2017, June 16). FIN10: Anatomy of a Cyber Extortion Operation. Retrieved November 17, 2024.

    Open source URL
  84. [84]
    DigiTrust Agent Tesla Jan 2017

    The DigiTrust Group. (2017, January 12). The Rise of Agent Tesla. Retrieved November 5, 2018.

    Open source URL
  85. [85]
    Fortinet Agent Tesla April 2018

    Zhang, X. (2018, April 05). Analysis of New Agent Tesla Spyware Variant. Retrieved November 5, 2018.

    Open source URL
  86. [86]
    Malwarebytes Agent Tesla April 2020

    Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020.

    Open source URL
  87. [87]
    Unit 42 MechaFlounder March 2019

    Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020.

    Open source URL
  88. [88]
    FireEye APT32 April 2020

    Henderson, S., et al. (2020, April 22). Vietnamese Threat Actors APT32 Targeting Wuhan Government and Chinese Ministry of Emergency Management in Latest Example of COVID-19 Related Espionage. Retrieved April 28, 2020.

    Open source URL
  89. [89]
    ESET OceanLotus

    Foltýn, T. (2018, March 13). OceanLotus ships new backdoor using old tricks. Retrieved May 22, 2018.

    Open source URL
  90. [90]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  91. [91]
    Talos Konni May 2017

    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

    Open source URL
  92. [92]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  93. [93]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  94. [94]
    Unit 42 Lucifer June 2020

    Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.

    Open source URL
  95. [95]
    Forcepoint Felismus Mar 2017

    Somerville, L. and Toro, A. (2017, March 30). Playing Cat & Mouse: Introducing the Felismus Malware. Retrieved November 16, 2017.

    Open source URL
  96. [96]
    Symantec Chafer Dec 2015

    Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

    Open source URL
  97. [97]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  98. [98]
    US-CERT TA18-106A Network Infrastructure Devices 2018

    US-CERT. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

    Open source URL
  99. [99]
    US-CERT TA18-106A Network Infrastructure Devices 2018

    US-CERT. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

    Open source URL
  100. [100]
    mitre-attackT1033
    Open source URL
  101. [101]
    mitre-attackT1033
    Open source URL
  102. [102]
    mitre-attackT1033
    Open source URL
  103. [103]
    show_ssh_users_cmd_cisco

    Cisco. (2023, March 7). Cisco IOS Security Command Reference: Commands S to Z . Retrieved July 13, 2022.

    Open source URL
  104. [104]
    show_ssh_users_cmd_cisco

    Cisco. (2023, March 7). Cisco IOS Security Command Reference: Commands S to Z . Retrieved July 13, 2022.

    Open source URL
  105. [105]
    Secureworks Karagany July 2019

    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

    Open source URL
  106. [106]
    Talos PoetRAT April 2020

    Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.

    Open source URL
  107. [107]
    Cylance Shaheen Nov 2018

    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

    Open source URL
  108. [108]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  109. [109]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  110. [110]
    Kaspersky ShadowPad Aug 2017

    Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.

    Open source URL
  111. [111]
    ZScaler Squirrelwaffle Sep 2021

    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

    Open source URL
  112. [112]
    CISA AA20-239A BeagleBoyz August 2020

    DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.

    Open source URL
  113. [113]
    Debian nbtscan Nov 2019

    Bezroutchko, A. (2019, November 19). NBTscan man page. Retrieved March 17, 2021.

    Open source URL
  114. [114]
    SecTools nbtscan June 2003

    SecTools. (2003, June 11). NBTscan. Retrieved March 17, 2021.

    Open source URL
  115. [115]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  116. [116]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  117. [117]
    Unit42 BabyShark Feb 2019

    Unit 42. (2019, February 22). New BabyShark Malware Targets U.S. National Security Think Tanks. Retrieved October 7, 2019.

    Open source URL
  118. [118]
    CISA WellMess July 2020

    CISA. (2020, July 16). MAR-10296782-2.v1 – WELLMESS. Retrieved September 24, 2020.

    Open source URL
  119. [119]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  120. [120]
    ESET DazzleSpy Jan 2022

    M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.

    Open source URL
  121. [121]
    CloudSEK_RustyWater_Jan2026

    Awasthi, P. (2026, January 8). Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant. Retrieved March 19, 2026.

    Open source URL
  122. [122]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  123. [123]
    Volexity InkySquid BLUELIGHT August 2021

    Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.

    Open source URL
  124. [124]
    Symantec Daggerfly 2023

    Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.

    Open source URL
  125. [125]
    Cybereason StrifeWater Feb 2022

    Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022.

    Open source URL
  126. [126]
    Google EXOTIC LILY March 2022

    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

    Open source URL
  127. [127]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  128. [128]
    SentinelOne ToolShell JUL 2025

    Kenin, S. et al. (2025, July 21). SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers. Retrieved October 15, 2025.

    Open source URL
  129. [129]
    Kandji Cuckoo April 2024

    Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024.

    Open source URL
  130. [130]
    Malwarebytes Dyreza November 2015

    hasherezade. (2015, November 4). A Technical Look At Dyreza. Retrieved June 15, 2020.

    Open source URL
  131. [131]
    MalwareBytes WoodyRAT Aug 2022

    MalwareBytes Threat Intelligence Team. (2022, August 3). Woody RAT: A new feature-rich malware spotted in the wild. Retrieved December 6, 2022.

    Open source URL
  132. [132]
    Fortinet Diavol July 2021

    Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.

    Open source URL
  133. [133]
    Kaspersky Turla Aug 2014

    Kaspersky Lab's Global Research & Analysis Team. (2014, August 06). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroboros. Retrieved November 7, 2018.

    Open source URL
  134. [134]
    TrendMicro POWERSTATS V3 June 2019

    Lunghi, D. and Horejsi, J.. (2019, June 10). MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools. Retrieved May 14, 2020.

    Open source URL
  135. [135]
    Symantec FIN8 Jul 2023

    Symantec Threat Hunter Team. (2023, July 18). FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware. Retrieved August 9, 2023.

    Open source URL
  136. [136]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  137. [137]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  138. [138]
    Microsoft NICKEL December 2021

    MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.

    Open source URL
  139. [139]
    Fortinet Havoc MAR 2025

    Wan, Y. (2025, March 3). Havoc: SharePoint with Microsoft Graph API turns into FUD C2. Retrieved August 4, 2025.

    Open source URL
  140. [140]
    Zscaler Havoc FEB 2023

    Shivtarkar, N. and Jain, S. (2023, February 14). Havoc Across the Cyberspace. Retrieved August 4, 2025.

    Open source URL
  141. [141]
    ESET Turla Mosquito Jan 2018

    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

    Open source URL
  142. [142]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  143. [143]
    Unit42 Azorult Nov 2018

    Yan, T., et al. (2018, November 21). New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit. Retrieved November 29, 2018.

    Open source URL
  144. [144]
    S2W Racoon 2022

    S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.

    Open source URL
  145. [145]
    Sekoia Raccoon1 2022

    Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.

    Open source URL
  146. [146]
    Sekoia Raccoon2 2022

    Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.

    Open source URL
  147. [147]
    SentinelLabs Metador Technical Appendix Sept 2022

    SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

    Open source URL
  148. [148]
    Mandiant FIN7 Apr 2022

    Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

    Open source URL
  149. [149]
    MalwareBytes SideCopy Dec 2021

    Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

    Open source URL
  150. [150]
    Rapid7 HAFNIUM Mar 2021

    Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.

    Open source URL
  151. [151]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  152. [152]
    2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

    Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.

    Open source URL
  153. [153]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  154. [154]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  155. [155]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  156. [156]
    ANSSI Sandworm January 2021

    ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.

    Open source URL
  157. [157]
    Proofpoint RedLine Stealer March 2020

    Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.

    Open source URL
  158. [158]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  159. [159]
    Veriti RedLine Stealer MAAS April 2023

    Yair Herling. (2023, April 4). From ChatGPT to RedLine Stealer: The Dark Side of OpenAI and Google Bard. Retrieved September 17, 2025.

    Open source URL
  160. [160]
    Splunk LAMEHUG SEP 2025

    Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

    Open source URL
  161. [161]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  162. [162]
    SentinelOne WinterVivern 2023

    Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.

    Open source URL
  163. [163]
    RATANKBA

    Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.

    Open source URL
  164. [164]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  165. [165]
    Proofpoint TA505 Mar 2018

    Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019.

    Open source URL
  166. [166]
    McAfee Sharpshooter December 2018

    Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020.

    Open source URL
  167. [167]
    FireEye APT10 Sept 2018

    Matsuda, A., Muhammad I. (2018, September 13). APT10 Targeting Japanese Corporations Using Updated TTPs. Retrieved September 17, 2018.

    Open source URL
  168. [168]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  169. [169]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  170. [170]
    SecureList SynAck Doppelgänging May 2018

    Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.

    Open source URL
  171. [171]
    XAgentOSX 2017

    Robert Falcone. (2017, February 14). XAgentOSX: Sofacy's Xagent macOS Tool. Retrieved July 12, 2017.

    Open source URL
  172. [172]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  173. [173]
    Github Koadic

    Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.

    Open source URL
  174. [174]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  175. [175]
    Kaspersky WIRTE November 2021

    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

    Open source URL
  176. [176]
    Unit 42 C0d0so0 Jan 2016

    Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.

    Open source URL
  177. [177]
    Securelist Octopus Oct 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.

    Open source URL
  178. [178]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  179. [179]
    CheckPoint SpeakUp Feb 2019

    Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.

    Open source URL
  180. [180]
    Group IB GrimAgent July 2021

    Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

    Open source URL
  181. [181]
    PaloAlto CardinalRat Apr 2017

    Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018.

    Open source URL
  182. [182]
    GitHub Pupy

    Nicolas Verdier. (n.d.). Retrieved January 29, 2018.

    Open source URL
  183. [183]
    FSecure Lokibot November 2019

    Kazem, M. (2019, November 25). Trojan:W32/Lokibot. Retrieved May 15, 2020.

    Open source URL
  184. [184]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  185. [185]
    FireEye FIN10 June 2017

    FireEye iSIGHT Intelligence. (2017, June 16). FIN10: Anatomy of a Cyber Extortion Operation. Retrieved November 17, 2024.

    Open source URL
  186. [186]
    DigiTrust Agent Tesla Jan 2017

    The DigiTrust Group. (2017, January 12). The Rise of Agent Tesla. Retrieved November 5, 2018.

    Open source URL
  187. [187]
    Fortinet Agent Tesla April 2018

    Zhang, X. (2018, April 05). Analysis of New Agent Tesla Spyware Variant. Retrieved November 5, 2018.

    Open source URL
  188. [188]
    Malwarebytes Agent Tesla April 2020

    Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020.

    Open source URL
  189. [189]
    Unit 42 MechaFlounder March 2019

    Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020.

    Open source URL
  190. [190]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  191. [191]
    ESET OceanLotus

    Foltýn, T. (2018, March 13). OceanLotus ships new backdoor using old tricks. Retrieved May 22, 2018.

    Open source URL
  192. [192]
    FireEye APT32 April 2020

    Henderson, S., et al. (2020, April 22). Vietnamese Threat Actors APT32 Targeting Wuhan Government and Chinese Ministry of Emergency Management in Latest Example of COVID-19 Related Espionage. Retrieved April 28, 2020.

    Open source URL
  193. [193]
    Talos Konni May 2017

    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

    Open source URL
  194. [194]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  195. [195]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  196. [196]
    Unit 42 Lucifer June 2020

    Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.

    Open source URL
  197. [197]
    Forcepoint Felismus Mar 2017

    Somerville, L. and Toro, A. (2017, March 30). Playing Cat & Mouse: Introducing the Felismus Malware. Retrieved November 16, 2017.

    Open source URL
  198. [198]
    Symantec Chafer Dec 2015

    Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

    Open source URL
  199. [199]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.