LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1036.004: Masquerade Task or Service

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.[1][2] Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.

Tasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.[3][4]

EnterpriseT1036.004Sub-techniqueObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Masquerade Task or Service matters because scheduled tasks, systemd units, and Windows services often look routine and trusted. If an attacker gives a malicious task or service a name or description similar to legitimate administration or operating system components, it can stay hidden during normal operations and complicate incident response. The business issue is not just malware naming; it is whether teams can quickly tell which persistence or execution mechanisms are authorized across Windows, Linux, and macOS systems.

Executive priority

Prioritize this as a control-validation and evidence problem for endpoint resilience and incident readiness. Leaders should ask whether the organization has an authoritative inventory of approved tasks and services, whether changes to those objects are logged and reviewed, and whether SOC teams can distinguish expected administrative activity from lookalike names. The relationship context shows this behavior appears across multiple ATT&CK campaigns and groups, including financially motivated, espionage, supply-chain, and critical-infrastructure-related reporting, so coverage should not be limited to one threat profile.

Technical view

For SOC, detection engineering, and IR teams, validate visibility into task and service names, display names, descriptions, configuration paths, creators, execution commands, and parent processes across Windows Task Scheduler, Windows services, systemd service units, and comparable macOS service/task mechanisms where applicable. Because ATT&CK provides no official detection text for this object, use the related detection strategy DET0117 as a starting point: focus on suspicious naming and execution patterns, especially names that are identical or deceptively similar to legitimate tasks/services but have unusual paths, commands, descriptions, accounts, timestamps, or hosts.

Likely telemetry

  • Windows scheduled task creation, modification, deletion, and execution records
  • Windows service creation and configuration-change events, including service name and display name
  • Linux systemd unit files, service configuration, enable/start events, and related process execution
  • macOS task/service or launch-related configuration and execution evidence where collected
  • Endpoint process creation telemetry showing task or service parent-child execution chains

Detection direction

  • Build or validate baselines of approved task and service names, descriptions, paths, accounts, and expected hosts; alert on close lookalikes or newly introduced objects outside change windows.
  • Correlate suspicious names with execution context: command path, signer or file provenance where available, parent process, service account, creation time, and whether the object appears on an unusual subset of systems.
  • Tune carefully for legitimate IT administration, software deployment, and OS updates, which commonly create or rename tasks and services.
  • Review DET0117, Detection of Masqueraded Tasks or Services with Suspicious Naming and Execution, as the relationship-supported detection strategy, but confirm it is implemented against local telemetry sources.
  • Hunt for objects whose names or descriptions appear benign while other fields point to unusual binaries, scripts, locations, or execution behavior.

Mitigation priorities

  • Maintain an approved inventory of scheduled tasks, services, and systemd units for high-value systems first, then expand coverage across Windows, Linux, and macOS fleets.
  • Restrict who can create or modify tasks and services, and ensure those administrative actions are logged and reviewable.
  • Use configuration/change management to reconcile task and service changes against authorized maintenance activity.
  • During incident response, include task and service name, description, path, and execution review in persistence and stealth triage.
  • Treat this as a detection-quality control: prevention alone may not identify deceptive naming if the underlying task or service mechanism is legitimate.
Additional notes and limits

This is a sub-technique of Masquerading (T1036) focused specifically on task and service naming or descriptive fields. The supplied relationship context includes many groups and campaigns that have used the technique, but those relationships should be used for prioritization and threat-model breadth rather than as proof of current exposure. The most useful local validation is whether defenders can compare task/service identity fields against execution behavior and approved configuration baselines.

MITRE did not provide official detection guidance for this object in the supplied fields. Platform scope is limited to Linux, macOS, and Windows as supplied. Specific event IDs, vendor detections, prevention guarantees, and active exploitation claims are not included because they are not present in the provided ATT&CK fields or relationships.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Masquerade Task or Service

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.[1][2] Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.

Tasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.[3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1036MasqueradingThis object subtechnique of Masquerading.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0143: Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G1016: FIN13

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.[1][2]

GroupEnterprise

G0099: APT-C-36

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G1035: Winter Vivern

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.[1][2][3][4][5]

GroupEnterprise

G0102: Wizard Spider

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]

GroupEnterprise

G1002: BITTER

BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.[1][2]

GroupEnterprise

G0037: FIN6

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.[1][2]

GroupEnterprise

G0019: Naikon

Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).[1] Active since at least 2010, Naikon has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).[1][2]

While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.[3]

MalwareEnterprise

S1064: SVCReady

SVCReady is a loader that has been used since at least April 2022 in malicious spam campaigns. Security researchers have noted overlaps between TA551 activity and SVCReady distribution, including similarities in file names, lure images, and identical grammatical errors.[1]

Windows
MalwareEnterprise

S0438: Attor

Attor is a Windows-based espionage platform that has been seen in use since 2013. Attor has a loadable plugin architecture to customize functionality for specific targets.[1]

Windows
MalwareEnterprise

S0449: Maze

Maze ransomware, previously known as "ChaCha", was discovered in May 2019. In addition to encrypting files on victim machines for impact, Maze operators conduct information stealing campaigns prior to encryption and post the information online to extort affected companies.[1][2][3]

Windows
MalwareEnterprise

S0495: RDAT

RDAT is a backdoor used by the suspected Iranian threat group OilRig. RDAT was originally identified in 2017 and targeted companies in the telecommunications sector.[1]

Windows
MalwareEnterprise

S1042: SUGARDUMP

SUGARDUMP is a proprietary browser credential harvesting tool that was used by UNC3890 during the C0010 campaign. The first known SUGARDUMP version was used since at least early 2021, a second SMTP C2 version was used from late 2021-early 2022, and a third HTTP C2 variant was used since at least April 2022.[1]

Windows
MalwareEnterprise

S0688: Meteor

Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. Meteor is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.[1]

Windows
MalwareEnterprise

S0169: RawPOS

RawPOS is a point-of-sale (POS) malware family that searches for cardholder data on victims. It has been in use since at least 2008. [1] [2] [3] FireEye divides RawPOS into three components: FIENDCRY, DUEBREW, and DRIFTWOOD. [4] [5]

Windows
CampaignEnterprise

C0017: C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]

CampaignEnterprise

C0035: KV Botnet Activity

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.[1] This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.[2]

CampaignEnterprise

C0001: Frankenstein

Frankenstein was described by security researchers as a highly-targeted campaign conducted by moderately sophisticated and highly resourceful threat actors in early 2019. The unidentified actors primarily relied on open source tools, including Empire. The campaign name refers to the actors' ability to piece together several unrelated open-source tool components.[1]

CampaignEnterprise

C0024: SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
5cd08925d5076ab1...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle5cd08925d507…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    TechNet Schtasks

    Microsoft. (n.d.). Schtasks. Retrieved April 28, 2016.

    Open source URL
  2. [2]
    Systemd Service Units

    Freedesktop.org. (n.d.). systemd.service — Service unit configuration. Retrieved March 16, 2020.

    Open source URL
  3. [3]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  4. [4]
    Fysbis Dr Web Analysis

    Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.

    Open source URL
  5. [5]
    Checkpoint MosesStaff Nov 2021

    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

    Open source URL
  6. [6]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  7. [7]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  8. [8]
    HP SVCReady Jun 2022

    Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.

    Open source URL
  9. [9]
    Mandiant-Sandworm-Ukraine-2022

    Ken Proska, John Wolfram, Jared Wilson, Dan Black, Keith Lunden, Daniel Kapellmann Zafra, Nathan Brubaker, Tyler Mclellan, Chris Sistrunk. (2023, November 9). Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology. Retrieved March 28, 2024.

    Open source URL
  10. [10]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  11. [11]
    ESET Attor Oct 2019

    Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

    Open source URL
  12. [12]
    Sophos Maze VM September 2020

    Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.

    Open source URL
  13. [13]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  14. [14]
    CISA AA20-301A Kimsuky

    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

    Open source URL
  15. [15]
    Securonix Kimsuky February 2025

    Den Iuzvyk, Tim Peck. (2025, February 13). Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks. Retrieved August 19, 2025.

    Open source URL
  16. [16]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  17. [17]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  18. [18]
    ClearSky MuddyWater Nov 2018

    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

    Open source URL
  19. [19]
    Check Point Meteor Aug 2021

    Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.

    Open source URL
  20. [20]
    Kroll RawPOS Jan 2017

    Nesbit, B. and Ackerman, D. (2017, January). Malware Analysis Report - RawPOS Malware: Deconstructing an Intruder’s Toolkit. Retrieved October 4, 2017.

    Open source URL
  21. [21]
    TrendMicro RawPOS April 2015

    TrendLabs Security Intelligence Blog. (2015, April). RawPOS Technical Brief. Retrieved October 4, 2017.

  22. [22]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  23. [23]
    Morphisec FIN7 June 2017

    Gorelik, M.. (2017, June 9). FIN7 Takes Another Bite at the Restaurant Industry. Retrieved July 13, 2017.

  24. [24]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  25. [25]
    McAfee Shamoon December 2018

    Mundo, A., Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 14). Shamoon Returns to Wipe Systems in Middle East, Europe . Retrieved May 29, 2020.

    Open source URL
  26. [26]
    Cisco Talos Bitter Bangladesh May 2022

    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

    Open source URL
  27. [27]
    Cisco Talos Qilin Ransomware OCT 2025

    Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

    Open source URL
  28. [28]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  29. [29]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  30. [30]
    Unit 42 PingPull Jun 2022

    Unit 42. (2022, June 13). GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool. Retrieved August 7, 2022.

    Open source URL
  31. [31]
    Talos Promethium June 2020

    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

    Open source URL
  32. [32]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
  33. [33]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  34. [34]
    Malwarebytes Konni Aug 2021

    Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.

    Open source URL
  35. [35]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  36. [36]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  37. [37]
    QiAnXin APT-C-36 Feb2019

    QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

    Open source URL
  38. [38]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  39. [39]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  40. [40]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  41. [41]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  42. [42]
    Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023

    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.

    Open source URL
  43. [43]
    FOX-IT May 2016 Mofang

    Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

    Open source URL
  44. [44]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  45. [45]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  46. [46]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  47. [47]
    SentinelOne WinterVivern 2023

    Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.

    Open source URL
  48. [48]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  49. [49]
    Unit 42 Hildegard Malware

    Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.

    Open source URL
  50. [50]
    CrowdStrike Grim Spider May 2019

    John, E. and Carvey, H. (2019, May 30). Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER. Retrieved May 12, 2020.

    Open source URL
  51. [51]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  52. [52]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  53. [53]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  54. [54]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  55. [55]
    Microsoft Win Defender Truvasys Sep 2017

    Microsoft. (2017, September 15). Backdoor:Win32/Truvasys.A!dha. Retrieved November 30, 2017.

    Open source URL
  56. [56]
    Unit42 Redaman January 2019

    Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.

    Open source URL
  57. [57]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  58. [58]
    Unit 42 IronNetInjector February 2021

    Reichel, D. (2021, February 19). IronNetInjector: Turla’s New Malware Loading Tool. Retrieved February 24, 2021.

    Open source URL
  59. [59]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  60. [60]
    Lumen KVBotnet 2023

    Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

    Open source URL
  61. [61]
    Symantec Backdoor.Nidiran

    Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.

    Open source URL
  62. [62]
    Microsoft SAM

    Microsoft. (2006, October 30). How to use the SysKey utility to secure the Windows Security Accounts Manager database. Retrieved August 3, 2016.

    Open source URL
  63. [63]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  64. [64]
    ESET Crutch December 2020

    Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020.

    Open source URL
  65. [65]
    Binary Defense Emotes Wi-Fi Spreader

    Binary Defense. (n.d.). Emotet Evolves With new Wi-Fi Spreader. Retrieved September 8, 2023.

    Open source URL
  66. [66]
    Unit42 OceanLotus 2017

    Erye Hernandez and Danny Tsechansky. (2017, June 22). The New and Improved macOS Backdoor from OceanLotus. Retrieved September 8, 2023.

    Open source URL
  67. [67]
    CISA AA20-259A Iran-Based Actor September 2020

    CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020.

    Open source URL
  68. [68]
    ASERT InnaputRAT April 2018

    ASERT Team. (2018, April 04). Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files. Retrieved July 9, 2018.

    Open source URL
  69. [69]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  70. [70]
    Mandiant Fortinet Zero Day

    Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.

    Open source URL
  71. [71]
    Symantec Orangeworm April 2018

    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

    Open source URL
  72. [72]
    Google Cloud Threat Intelligence ESXi VIBs 2022

    Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.

    Open source URL
  73. [73]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  74. [74]
    Symantec Catchamas April 2018

    Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.

    Open source URL
  75. [75]
    Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023

    Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.

    Open source URL
  76. [76]
    Talos Frankenstein June 2019

    Adamitis, D. et al. (2019, June 4). It's alive: Threat actors cobble together open-source pieces into monstrous Frankenstein campaign. Retrieved May 11, 2020.

    Open source URL
  77. [77]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  78. [78]
    Objective See Green Lambert for OSX Oct 2021

    Sandvik, Runa. (2021, October 1). Made In America: Green Lambert for OS X. Retrieved March 21, 2022.

    Open source URL
  79. [79]
    Glitch-Cat Green Lambert ATTCK Oct 2021

    Sandvik, Runa. (2021, October 18). Green Lambert and ATT&CK. Retrieved November 17, 2024.

    Open source URL
  80. [80]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  81. [81]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  82. [82]
    ESET Telebots Dec 2016

    Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.

    Open source URL
  83. [83]
    Volexity SolarWinds

    Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.

    Open source URL
  84. [84]
    ESET TeleBots Oct 2018

    Cherepanov, A., Lipovsky, R. (2018, October 11). New TeleBots backdoor: First evidence linking Industroyer to NotPetya. Retrieved November 27, 2018.

    Open source URL
  85. [85]
    Fysbis Dr Web Analysis

    Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.

    Open source URL
  86. [86]
    Fysbis Dr Web Analysis

    Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.

    Open source URL
  87. [87]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  88. [88]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  89. [89]
    Systemd Service Units

    Freedesktop.org. (n.d.). systemd.service — Service unit configuration. Retrieved March 16, 2020.

    Open source URL
  90. [90]
    Systemd Service Units

    Freedesktop.org. (n.d.). systemd.service — Service unit configuration. Retrieved March 16, 2020.

    Open source URL
  91. [91]
    TechNet Schtasks

    Microsoft. (n.d.). Schtasks. Retrieved April 28, 2016.

    Open source URL
  92. [92]
    TechNet Schtasks

    Microsoft. (n.d.). Schtasks. Retrieved April 28, 2016.

    Open source URL
  93. [93]
    mitre-attackT1036.004
    Open source URL
  94. [94]
    mitre-attackT1036.004
    Open source URL
  95. [95]
    mitre-attackT1036.004
    Open source URL
  96. [96]
    Checkpoint MosesStaff Nov 2021

    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

    Open source URL
  97. [97]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  98. [98]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  99. [99]
    HP SVCReady Jun 2022

    Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.

    Open source URL
  100. [100]
    Mandiant-Sandworm-Ukraine-2022

    Ken Proska, John Wolfram, Jared Wilson, Dan Black, Keith Lunden, Daniel Kapellmann Zafra, Nathan Brubaker, Tyler Mclellan, Chris Sistrunk. (2023, November 9). Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology. Retrieved March 28, 2024.

    Open source URL
  101. [101]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  102. [102]
    ESET Attor Oct 2019

    Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

    Open source URL
  103. [103]
    Sophos Maze VM September 2020

    Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.

    Open source URL
  104. [104]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  105. [105]
    CISA AA20-301A Kimsuky

    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

    Open source URL
  106. [106]
    Securonix Kimsuky February 2025

    Den Iuzvyk, Tim Peck. (2025, February 13). Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks. Retrieved August 19, 2025.

    Open source URL
  107. [107]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  108. [108]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  109. [109]
    ClearSky MuddyWater Nov 2018

    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

    Open source URL
  110. [110]
    Fysbis Dr Web Analysis

    Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.

    Open source URL
  111. [111]
    Fysbis Dr Web Analysis

    Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.

    Open source URL
  112. [112]
    Check Point Meteor Aug 2021

    Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.

    Open source URL
  113. [113]
    Kroll RawPOS Jan 2017

    Nesbit, B. and Ackerman, D. (2017, January). Malware Analysis Report - RawPOS Malware: Deconstructing an Intruder’s Toolkit. Retrieved October 4, 2017.

    Open source URL
  114. [114]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  115. [115]
    TrendMicro RawPOS April 2015

    TrendLabs Security Intelligence Blog. (2015, April). RawPOS Technical Brief. Retrieved October 4, 2017.

  116. [116]
    Morphisec FIN7 June 2017

    Gorelik, M.. (2017, June 9). FIN7 Takes Another Bite at the Restaurant Industry. Retrieved July 13, 2017.

  117. [117]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  118. [118]
    McAfee Shamoon December 2018

    Mundo, A., Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 14). Shamoon Returns to Wipe Systems in Middle East, Europe . Retrieved May 29, 2020.

    Open source URL
  119. [119]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  120. [120]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  121. [121]
    Cisco Talos Bitter Bangladesh May 2022

    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

    Open source URL
  122. [122]
    Cisco Talos Qilin Ransomware OCT 2025

    Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

    Open source URL
  123. [123]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  124. [124]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  125. [125]
    Unit 42 PingPull Jun 2022

    Unit 42. (2022, June 13). GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool. Retrieved August 7, 2022.

    Open source URL
  126. [126]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
  127. [127]
    Talos Promethium June 2020

    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

    Open source URL
  128. [128]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  129. [129]
    Malwarebytes Konni Aug 2021

    Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.

    Open source URL
  130. [130]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  131. [131]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  132. [132]
    QiAnXin APT-C-36 Feb2019

    QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

    Open source URL
  133. [133]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  134. [134]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  135. [135]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  136. [136]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  137. [137]
    Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023

    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.

    Open source URL
  138. [138]
    FOX-IT May 2016 Mofang

    Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

    Open source URL
  139. [139]
    Intrinsec Egregor Nov 2020

    Bichet, J. (2020, November 12). Egregor – Prolock: Fraternal Twins ?. Retrieved January 6, 2021.

    Open source URL
  140. [140]
    ESET Machete July 2019

    ESET. (2019, July). MACHETE JUST GOT SHARPER Venezuelan government institutions under attack. Retrieved September 13, 2019.

    Open source URL
  141. [141]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  142. [142]
    SentinelOne WinterVivern 2023

    Tom Hegel. (2023, March 16). Winter Vivern | Uncovering a Wave of Global Espionage. Retrieved July 29, 2024.

    Open source URL
  143. [143]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  144. [144]
    Unit 42 Hildegard Malware

    Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.

    Open source URL
  145. [145]
    CrowdStrike Grim Spider May 2019

    John, E. and Carvey, H. (2019, May 30). Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER. Retrieved May 12, 2020.

    Open source URL
  146. [146]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  147. [147]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  148. [148]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  149. [149]
    Cisco Talos Bitter Bangladesh May 2022

    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

    Open source URL
  150. [150]
    Cisco Talos Bitter Bangladesh May 2022

    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

    Open source URL
  151. [151]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  152. [152]
    Microsoft Win Defender Truvasys Sep 2017

    Microsoft. (2017, September 15). Backdoor:Win32/Truvasys.A!dha. Retrieved November 30, 2017.

    Open source URL
  153. [153]
    Unit42 Redaman January 2019

    Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.

    Open source URL
  154. [154]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  155. [155]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  156. [156]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  157. [157]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  158. [158]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  159. [159]
    Unit 42 IronNetInjector February 2021

    Reichel, D. (2021, February 19). IronNetInjector: Turla’s New Malware Loading Tool. Retrieved February 24, 2021.

    Open source URL
  160. [160]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  161. [161]
    Lumen KVBotnet 2023

    Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

    Open source URL
  162. [162]
    Microsoft SAM

    Microsoft. (2006, October 30). How to use the SysKey utility to secure the Windows Security Accounts Manager database. Retrieved August 3, 2016.

    Open source URL
  163. [163]
    Symantec Backdoor.Nidiran

    Sponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.

    Open source URL
  164. [164]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  165. [165]
    ESET Crutch December 2020

    Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020.

    Open source URL
  166. [166]
    Binary Defense Emotes Wi-Fi Spreader

    Binary Defense. (n.d.). Emotet Evolves With new Wi-Fi Spreader. Retrieved September 8, 2023.

    Open source URL
  167. [167]
    Unit42 OceanLotus 2017

    Erye Hernandez and Danny Tsechansky. (2017, June 22). The New and Improved macOS Backdoor from OceanLotus. Retrieved September 8, 2023.

    Open source URL
  168. [168]
    CISA AA20-259A Iran-Based Actor September 2020

    CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020.

    Open source URL
  169. [169]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
  170. [170]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
  171. [171]
    Talos Promethium June 2020

    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

    Open source URL
  172. [172]
    Talos Promethium June 2020

    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

    Open source URL
  173. [173]
    ASERT InnaputRAT April 2018

    ASERT Team. (2018, April 04). Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files. Retrieved July 9, 2018.

    Open source URL
  174. [174]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  175. [175]
    Mandiant Fortinet Zero Day

    Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.

    Open source URL
  176. [176]
    Symantec Orangeworm April 2018

    Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

    Open source URL
  177. [177]
    Google Cloud Threat Intelligence ESXi VIBs 2022

    Alexander Marvi, Jeremy Koppen, Tufail Ahmed, and Jonathan Lepore. (2022, September 29). Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors. Retrieved March 26, 2025.

    Open source URL
  178. [178]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  179. [179]
    Symantec Catchamas April 2018

    Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.

    Open source URL
  180. [180]
    Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023

    Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.

    Open source URL
  181. [181]
    Talos Frankenstein June 2019

    Adamitis, D. et al. (2019, June 4). It's alive: Threat actors cobble together open-source pieces into monstrous Frankenstein campaign. Retrieved May 11, 2020.

    Open source URL
  182. [182]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  183. [183]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  184. [184]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  185. [185]
    Glitch-Cat Green Lambert ATTCK Oct 2021

    Sandvik, Runa. (2021, October 18). Green Lambert and ATT&CK. Retrieved November 17, 2024.

    Open source URL
  186. [186]
    Objective See Green Lambert for OSX Oct 2021

    Sandvik, Runa. (2021, October 1). Made In America: Green Lambert for OS X. Retrieved March 21, 2022.

    Open source URL
  187. [187]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  188. [188]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  189. [189]
    ESET Telebots Dec 2016

    Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.

    Open source URL
  190. [190]
    Volexity SolarWinds

    Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.

    Open source URL
  191. [191]
    ESET TeleBots Oct 2018

    Cherepanov, A., Lipovsky, R. (2018, October 11). New TeleBots backdoor: First evidence linking Industroyer to NotPetya. Retrieved November 27, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.