LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1036.005: Match Legitimate Resource Name or Location

MITRE ATT&CK T1036.005: Match Legitimate Resource Name or Location Technique details for Containers, ESXi, Linux, with detection guidance, relationships and mapped…

EnterpriseT1036.005Sub-techniqueObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

This technique matters because attackers can hide in plain sight by giving malicious or unauthorized resources names or locations that look normal, such as trusted directories, familiar process names, near-match Registry keys, or container resources in trusted namespaces. The business issue is not just malware naming; it is whether teams can distinguish approved operational assets from lookalikes before an intrusion becomes harder to investigate or contain.

Executive priority

Prioritize this as a control-validation and audit-evidence issue for endpoint, server, virtualization, and container environments. Leaders should ask whether critical systems have enforceable baselines for trusted paths, signed code, approved deployment locations, and who can write into them. ATT&CK relationships show this behavior appears across many campaigns and groups, including espionage, ransomware/disruptive, supply-chain, and cyber-physical/energy-related contexts, so it is material to incident response readiness and operational resilience even when it is only a stealth technique.

Technical view

T1036.005 is a Masquerading sub-technique under the stealth tactic for Containers, ESXi, Linux, macOS, and Windows. SOC and IR teams should validate their ability to identify resources whose name or location approximates legitimate files, Registry keys, trusted directories, or container naming conventions. Because ATT&CK provides no official detection text, use the related DET0347 detection strategy as the mapped detection reference and test local telemetry against known-good baselines rather than relying only on string matches such as svchost.exe or System32-like locations.

Likely telemetry

  • File creation, rename, modification, and execution events, especially in trusted or commonly abused directories
  • Process execution metadata including image path, command line, parent process, signer, hash, and user context
  • Windows Registry key creation and modification events where applicable
  • Code-signing and executable trust metadata for binaries, scripts, and other code artifacts
  • Container control-plane or orchestration logs showing resource creation, namespace placement, pod or cluster naming, and actor identity

Detection direction

  • Validate DET0347-style coverage against both name-based and location-based masquerading; detection should compare names, paths, signers, hashes, ownership, and expected deployment source.
  • Tune for near-matches and trusted-location abuse, not just exact malicious filenames; attackers may approximate legitimate names or place artifacts where analysts expect trusted resources.
  • For Windows, include Registry lookalike keys and trusted-directory execution in hunting logic where telemetry exists.
  • For container environments, compare namespace, pod, cluster, and resource naming against approved deployment patterns and authorized actors.
  • Reduce false positives by maintaining baselines for legitimate administrative tools, software updates, build artifacts, and platform-managed resources.

Mitigation priorities

  • First establish baselines for legitimate resource names, trusted locations, ownership, and deployment sources across endpoint, server, ESXi, and container estates.
  • Apply M1022 Restrict File and Directory Permissions so only authorized users, groups, and processes can write to sensitive or trusted locations.
  • Use M1038 Execution Prevention to limit execution of unauthorized code, especially from locations where adversaries may try to blend in.
  • Use M1045 Code Signing controls to verify authenticity and integrity of executables, scripts, and other code artifacts before execution where supported.
  • Periodically review permissions and control exceptions; excessive write access to trusted paths undermines both prevention and detection.
Additional notes and limits

The ATT&CK object has broad platform coverage and many relationships to campaigns and groups, which supports treating the behavior as widely relevant. The most useful defensive decision is whether the organization can prove what is expected in trusted names and locations, then detect deviations with enough context to avoid high-volume false positives.

MITRE provides no official detection text for this object, and the supplied relationship descriptions are partial. This take does not assert active exploitation, customer exposure, or guaranteed detection. Local asset baselines, logging configuration, and control enforcement determine whether this behavior can be reliably found or prevented.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Match Legitimate Resource Name or Location

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0139: TeamTNT

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.[1][2][3][4][5][6][7][8][9]

GroupEnterprise

G0047: Gamaredon Group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][5]

GroupEnterprise

G1017: Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]

GroupEnterprise

G0060: BRONZE BUTLER

BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.[1][2][3]

GroupEnterprise

G1018: TA2541

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.[1][2]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G1044: APT42

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.[1] The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.[1] APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices.[1] Finally, APT42 exfiltrates data using native features and open-source tools.[2]

APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G0069: MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).[1] Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. [2][3][4][5][6][7][8][9][10][11][12][13]

MalwareEnterprise

S0459: MechaFlounder

MechaFlounder is a python-based remote access tool (RAT) that has been used by APT39. The payload uses a combination of actor developed code and code snippets freely available online in development communities.[1]

Windows
ToolEnterprise

S1050: PcShare

PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream campaign since late 2018.[1][2]

Windows
MalwareEnterprise

S0533: SLOTHFULMEDIA

SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017.[1][2] It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.[3][4]

In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing".[4] ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".[5]

Windows
MalwareEnterprise

S0081: Elise

Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.[1][2]

Windows
MalwareEnterprise

S0482: Bundlore

Bundlore is adware written for macOS that has been in use since at least 2015. Though categorized as adware, Bundlore has many features associated with more traditional backdoors.[1]

macOS
CampaignEnterprise

C0030: Triton Safety Instrumented System Attack

Triton Safety Instrumented System Attack was a campaign employed by TEMP.Veles which leveraged the Triton malware framework against a petrochemical organization.[1] The malware and techniques used within this campaign targeted specific Triconex Safety Controllers within the environment.[2] The incident was eventually discovered due to a safety trip that occurred as a result of an issue in the malware.[3]

CampaignEnterprise

C0018: C0018

C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing AvosLocker.[1][2]

CampaignEnterprise

C0024: SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
976f44e8063c2aa9...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.0Current bundle976f44e8063c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Aquasec Kubernetes Backdoor 2023

    Michael Katchinskiy and Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved March 24, 2025.

    Open source URL
  2. [2]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  3. [3]
    Microsoft DTC

    Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016.

    Open source URL
  4. [4]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  5. [5]
    Cisco Talos Intelligence Group

    Darin Smith. (2022, April 21). TeamTNT targeting AWS, Alibaba. Retrieved August 4, 2022.

    Open source URL
  6. [6]
    Unit 42 MechaFlounder March 2019

    Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020.

    Open source URL
  7. [7]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  8. [8]
    2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

    Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.

    Open source URL
  9. [9]
    Zscaler

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

    Open source URL
  10. [10]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  11. [11]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  12. [12]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  13. [13]
    Dragos Crashoverride 2017

    Dragos Inc.. (2017, June 13). CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations. Retrieved December 18, 2020.

    Open source URL
  14. [14]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  15. [15]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  16. [16]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  17. [17]
    Unit 42 Gamaredon February 2022

    Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

    Open source URL
  18. [18]
    VenereCiscoTalos_Gamaredon_Mar2025

    Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.

    Open source URL
  19. [19]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  20. [20]
    Lumen J-Magic JAN 2025

    Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.

    Open source URL
  21. [21]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  22. [22]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  23. [23]
    Joint Cybersecurity Advisory Volt Typhoon June 2023

    NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.

    Open source URL
  24. [24]
    Secureworks BRONZE SILHOUETTE May 2023

    Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.

    Open source URL
  25. [25]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  26. [26]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  27. [27]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  28. [28]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  29. [29]
    CrowdStrike IceApple May 2022

    CrowdStrike. (2022, May). ICEAPPLE: A NOVEL INTERNET INFORMATION SERVICES (IIS) POST-EXPLOITATION FRAMEWORK. Retrieved June 27, 2022.

    Open source URL
  30. [30]
    CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025

    CrowdStrike. (2025, December 4). Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary. Retrieved April 16, 2026.

    Open source URL
  31. [31]
    Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024

    Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.

    Open source URL
  32. [32]
    Google BRICKSTORM September 2025

    Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen. (2025, September 24). Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors. Retrieved April 16, 2026.

    Open source URL
  33. [33]
    CISA BRICKSTORM UNC5221 AR25-338A February 2026

    DHS/CISA. (2026, February 11). AR25-338A: BRICKSTORM Backdoor. Retrieved April 16, 2026.

    Open source URL
  34. [34]
    ATT Felismus

    Julia Kisielius. (2017, April 25). The Felismus RAT: Powerful Threat, Mysterious Purpose. Retrieved November 17, 2024.

    Open source URL
  35. [35]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  36. [36]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  37. [37]
    Mandiant APT42-charms

    Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.

    Open source URL
  38. [38]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  39. [39]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  40. [40]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  41. [41]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  42. [42]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  43. [43]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  44. [44]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  45. [45]
    Trend Micro Skidmap

    Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020.

    Open source URL
  46. [46]
    Kaspersky ToddyCat Check Logs October 2023

    Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

    Open source URL
  47. [47]
    Cisco Talos Avos Jun 2022

    Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023.

    Open source URL
  48. [48]
    Volexity SolarWinds

    Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.

    Open source URL
  49. [49]
    Microsoft Analyzing Solorigate Dec 2020

    MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.

    Open source URL
  50. [50]
    Red Canary SocGholish March 2024

    Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.

    Open source URL
  51. [51]
    SocGholish-update

    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

    Open source URL
  52. [52]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  53. [53]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  54. [54]
    Cisco MagicRAT 2022

    Asheer Malhotra, Vitor Ventura & Jungsoo An, Cisco Talos. (2022, September 7). MagicRAT: Lazarus’ latest gateway into victim networks. Retrieved December 30, 2024.

    Open source URL
  55. [55]
    MSTIC NOBELIUM Mar 2021

    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

    Open source URL
  56. [56]
    FireEye MuddyWater Mar 2018

    Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

    Open source URL
  57. [57]
    Talos MuddyWater May 2019

    Adamitis, D. et al. (2019, May 20). Recent MuddyWater-associated BlackWater campaign shows signs of new anti-detection techniques. Retrieved June 5, 2019.

    Open source URL
  58. [58]
    Anomali Static Kitten February 2021

    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

    Open source URL
  59. [59]
    Checkpoint MosesStaff Nov 2021

    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

    Open source URL
  60. [60]
    Kaspersky WIRTE November 2021

    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

    Open source URL
  61. [61]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  62. [62]
    Cymmetria Patchwork

    Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.

    Open source URL
  63. [63]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  64. [64]
    US-CERT BLINDINGCAN Aug 2020

    US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.

    Open source URL
  65. [65]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  66. [66]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  67. [67]
    ComputerWeekly Strider

    Warwick Ashford. (2016, August 8). Strider cyber attack group deploying malware for espionage. Retrieved January 10, 2024.

    Open source URL
  68. [68]
    Kaspersky ProjectSauron Full Report

    Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Retrieved August 17, 2016.

    Open source URL
  69. [69]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  70. [70]
    Symantec RAINDROP January 2021

    Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.

    Open source URL
  71. [71]
    Microsoft Deep Dive Solorigate January 2021

    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.

    Open source URL
  72. [72]
    DOJ FBI Handala Hack March 2026

    DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.

    Open source URL
  73. [73]
    FBI IC3 Flash VOID MANTICORE Handala Hack March 2026

    FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. Retrieved April 20, 2026.

    Open source URL
  74. [74]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  75. [75]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  76. [76]
    Splunk LAMEHUG SEP 2025

    Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

    Open source URL
  77. [77]
    Nov AI Threat Tracker

    Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.

    Open source URL
  78. [78]
    FireEye TRITON 2019

    Miller, S, et al. (2019, April 10). TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping. Retrieved April 16, 2019.

    Open source URL
  79. [79]
    Trendmicro_IcedID

    Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.

    Open source URL
  80. [80]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  81. [81]
    ESET BackdoorDiplomacy Jun 2021

    Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021

    Open source URL
  82. [82]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  83. [83]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  84. [84]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  85. [85]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  86. [86]
    CyberBit Dtrack

    Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021.

    Open source URL
  87. [87]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  88. [88]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  89. [89]
    Symantec Troll Stealer 2024

    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

    Open source URL
  90. [90]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  91. [91]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  92. [92]
    FireEye Know Your Enemy FIN8 Aug 2016

    Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.

    Open source URL
  93. [93]
    Morphisec ShellTea June 2019

    Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019.

  94. [94]
    Securelist Octopus Oct 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.

    Open source URL
  95. [95]
    ESET Nomadic Octopus 2018

    Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.

    Open source URL
  96. [96]
    CrowdStrike Ryuk January 2019

    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.

    Open source URL
  97. [97]
    group-ib_redcurl1

    Group-IB. (2020, August). RedCurl: The Pentest You Didn’t Know About. Retrieved August 9, 2024.

    Open source URL
  98. [98]
    group-ib_redcurl2

    Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024.

    Open source URL
  99. [99]
    Cisco Talos Qilin Ransomware OCT 2025

    Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

    Open source URL
  100. [100]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  101. [101]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  102. [102]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  103. [103]
    Aquasec Kubernetes Backdoor 2023

    Michael Katchinskiy and Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved March 24, 2025.

    Open source URL
  104. [104]
    Aquasec Kubernetes Backdoor 2023

    Michael Katchinskiy and Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved March 24, 2025.

    Open source URL
  105. [105]
    mitre-attackT1036.005
    Open source URL
  106. [106]
    mitre-attackT1036.005
    Open source URL
  107. [107]
    mitre-attackT1036.005
    Open source URL
  108. [108]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  109. [109]
    Microsoft DTC

    Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016.

    Open source URL
  110. [110]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  111. [111]
    Cisco Talos Intelligence Group

    Darin Smith. (2022, April 21). TeamTNT targeting AWS, Alibaba. Retrieved August 4, 2022.

    Open source URL
  112. [112]
    Unit 42 MechaFlounder March 2019

    Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020.

    Open source URL
  113. [113]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  114. [114]
    2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

    Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.

    Open source URL
  115. [115]
    Zscaler

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

    Open source URL
  116. [116]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  117. [117]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  118. [118]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  119. [119]
    Dragos Crashoverride 2017

    Dragos Inc.. (2017, June 13). CRASHOVERRIDE Analysis of the Threat to Electric Grid Operations. Retrieved December 18, 2020.

    Open source URL
  120. [120]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  121. [121]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  122. [122]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  123. [123]
    Microsoft DTC

    Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016.

    Open source URL
  124. [124]
    Microsoft DTC

    Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016.

    Open source URL
  125. [125]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  126. [126]
    NCSC Cyclops Blink February 2022

    NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

    Open source URL
  127. [127]
    Unit 42 Gamaredon February 2022

    Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

    Open source URL
  128. [128]
    VenereCiscoTalos_Gamaredon_Mar2025

    Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.

    Open source URL
  129. [129]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  130. [130]
    Lumen J-Magic JAN 2025

    Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.

    Open source URL
  131. [131]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  132. [132]
    Trusteer Carberp October 2010

    Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

    Open source URL
  133. [133]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  134. [134]
    Joint Cybersecurity Advisory Volt Typhoon June 2023

    NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.

    Open source URL
  135. [135]
    Secureworks BRONZE SILHOUETTE May 2023

    Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.

    Open source URL
  136. [136]
    Secureworks BRONZE BUTLER Oct 2017

    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.

    Open source URL
  137. [137]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  138. [138]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  139. [139]
    CrowdStrike IceApple May 2022

    CrowdStrike. (2022, May). ICEAPPLE: A NOVEL INTERNET INFORMATION SERVICES (IIS) POST-EXPLOITATION FRAMEWORK. Retrieved June 27, 2022.

    Open source URL
  140. [140]
    CISA BRICKSTORM UNC5221 AR25-338A February 2026

    DHS/CISA. (2026, February 11). AR25-338A: BRICKSTORM Backdoor. Retrieved April 16, 2026.

    Open source URL
  141. [141]
    CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025

    CrowdStrike. (2025, December 4). Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary. Retrieved April 16, 2026.

    Open source URL
  142. [142]
    Google BRICKSTORM September 2025

    Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen. (2025, September 24). Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors. Retrieved April 16, 2026.

    Open source URL
  143. [143]
    Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024

    Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.

    Open source URL
  144. [144]
    ATT Felismus

    Julia Kisielius. (2017, April 25). The Felismus RAT: Powerful Threat, Mysterious Purpose. Retrieved November 17, 2024.

    Open source URL
  145. [145]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  146. [146]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  147. [147]
    Mandiant APT42-charms

    Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.

    Open source URL
  148. [148]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  149. [149]
    Picus Sodinokibi January 2020

    Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

    Open source URL
  150. [150]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  151. [151]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  152. [152]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  153. [153]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  154. [154]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  155. [155]
    Trend Micro Skidmap

    Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020.

    Open source URL
  156. [156]
    Kaspersky ToddyCat Check Logs October 2023

    Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

    Open source URL
  157. [157]
    Cisco Talos Avos Jun 2022

    Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023.

    Open source URL
  158. [158]
    Microsoft Analyzing Solorigate Dec 2020

    MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.

    Open source URL
  159. [159]
    Volexity SolarWinds

    Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.

    Open source URL
  160. [160]
    Red Canary SocGholish March 2024

    Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.

    Open source URL
  161. [161]
    SocGholish-update

    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

    Open source URL
  162. [162]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  163. [163]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  164. [164]
    Cisco MagicRAT 2022

    Asheer Malhotra, Vitor Ventura & Jungsoo An, Cisco Talos. (2022, September 7). MagicRAT: Lazarus’ latest gateway into victim networks. Retrieved December 30, 2024.

    Open source URL
  165. [165]
    MSTIC NOBELIUM Mar 2021

    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

    Open source URL
  166. [166]
    Anomali Static Kitten February 2021

    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

    Open source URL
  167. [167]
    FireEye MuddyWater Mar 2018

    Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

    Open source URL
  168. [168]
    Talos MuddyWater May 2019

    Adamitis, D. et al. (2019, May 20). Recent MuddyWater-associated BlackWater campaign shows signs of new anti-detection techniques. Retrieved June 5, 2019.

    Open source URL
  169. [169]
    Checkpoint MosesStaff Nov 2021

    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

    Open source URL
  170. [170]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  171. [171]
    Kaspersky WIRTE November 2021

    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

    Open source URL
  172. [172]
    Cymmetria Patchwork

    Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.

    Open source URL
  173. [173]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  174. [174]
    US-CERT BLINDINGCAN Aug 2020

    US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.

    Open source URL
  175. [175]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  176. [176]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  177. [177]
    ComputerWeekly Strider

    Warwick Ashford. (2016, August 8). Strider cyber attack group deploying malware for espionage. Retrieved January 10, 2024.

    Open source URL
  178. [178]
    Kaspersky ProjectSauron Full Report

    Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Retrieved August 17, 2016.

    Open source URL
  179. [179]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  180. [180]
    Microsoft Deep Dive Solorigate January 2021

    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.

    Open source URL
  181. [181]
    Symantec RAINDROP January 2021

    Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.

    Open source URL
  182. [182]
    DOJ FBI Handala Hack March 2026

    DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.

    Open source URL
  183. [183]
    FBI IC3 Flash VOID MANTICORE Handala Hack March 2026

    FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. Retrieved April 20, 2026.

    Open source URL
  184. [184]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  185. [185]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  186. [186]
    Nov AI Threat Tracker

    Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.

    Open source URL
  187. [187]
    Splunk LAMEHUG SEP 2025

    Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

    Open source URL
  188. [188]
    FireEye TRITON 2019

    Miller, S, et al. (2019, April 10). TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping. Retrieved April 16, 2019.

    Open source URL
  189. [189]
    Trendmicro_IcedID

    Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.

    Open source URL
  190. [190]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  191. [191]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  192. [192]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  193. [193]
    Microsoft DTC

    Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016.

    Open source URL
  194. [194]
    Microsoft DTC

    Microsoft. (2011, January 12). Distributed Transaction Coordinator. Retrieved February 25, 2016.

    Open source URL
  195. [195]
    ESET BackdoorDiplomacy Jun 2021

    Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021

    Open source URL
  196. [196]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  197. [197]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  198. [198]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  199. [199]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  200. [200]
    CyberBit Dtrack

    Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021.

    Open source URL
  201. [201]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  202. [202]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  203. [203]
    Symantec Troll Stealer 2024

    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

    Open source URL
  204. [204]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  205. [205]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  206. [206]
    FireEye Know Your Enemy FIN8 Aug 2016

    Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.

    Open source URL
  207. [207]
    Morphisec ShellTea June 2019

    Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019.

  208. [208]
    ESET Nomadic Octopus 2018

    Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.

    Open source URL
  209. [209]
    Securelist Octopus Oct 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.

    Open source URL
  210. [210]
    CrowdStrike Ryuk January 2019

    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.

    Open source URL
  211. [211]
    group-ib_redcurl1

    Group-IB. (2020, August). RedCurl: The Pentest You Didn’t Know About. Retrieved August 9, 2024.

    Open source URL
  212. [212]
    group-ib_redcurl2

    Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024.

    Open source URL
  213. [213]
    Cisco Talos Qilin Ransomware OCT 2025

    Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

    Open source URL
  214. [214]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  215. [215]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  216. [216]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.