LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1059.007: JavaScript

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.[1]

JScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the Component Object Model and Internet Explorer HTML Application (HTA) pages.[2][3][4]

JavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple’s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple’s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple’s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and AppleScript. Scripts can be executed via the command line utility osascript, they can be compiled into applications or script files via osacompile, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework.[5][6][7][8][9]

Adversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a Drive-by Compromise or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of Obfuscated Files or Information.

EnterpriseT1059.007Sub-techniqueObject v2.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

JavaScript execution abuse matters because it turns a common business technology into an execution path across Windows, macOS, and Linux. The risk is not only browser script activity: ATT&CK notes JScript through Windows Script components, JavaScript for Automation through macOS OSA tooling, and runtime environments such as Node.js. For leaders, the practical question is whether the organization can distinguish legitimate scripting and web use from script-based payload execution, downloads, obfuscation, and follow-on activity.

Executive priority

Prioritize this as an execution-control and visibility issue. JavaScript is widely present and often business-necessary, so blanket removal may be unrealistic; instead, leadership should ask where JavaScript execution is allowed, which users and systems need it, whether web filtering and script controls are enforced, and whether SOC/IR teams can prove coverage across Windows, macOS, and Linux. The many ATT&CK relationships to campaigns and groups make this a material behavior to include in detection validation, incident playbooks, and compliance evidence around endpoint control and web-content restriction.

Technical view

This is ATT&CK T1059.007, a sub-technique of Command and Scripting Interpreter under the execution tactic. Validate visibility for JavaScript/JScript/JXA execution paths rather than only browser events. On Windows, focus on Windows Script engine/JScript, HTA-related execution, and COM-adjacent abuse where observable. On macOS, validate command-line and compiled-script activity involving osascript, osacompile, and OSA/JXA usage. On Linux and cross-platform systems, account for JavaScript runtimes such as Node.js. Because official ATT&CK detection text is not provided, use the related detection strategy DET0264 as a prompt for cross-platform detection engineering, then test locally against approved administrative, developer, and automation workflows.

Likely telemetry

  • Endpoint process creation, parent-child process relationships, command lines, and script interpreter execution events
  • macOS telemetry for osascript, osacompile, OSA/JXA activity, and application/script execution context
  • Windows telemetry associated with Windows Script engine/JScript, HTA pages, and related script-hosted execution
  • File creation and download events for JavaScript or script-like payloads, including text-based and obfuscated content
  • Web proxy, browser, DNS, and download-control logs for suspicious hosted scripts, unsafe downloads, and drive-by style delivery paths

Detection direction

  • Baseline legitimate JavaScript runtime, JScript, and JXA usage by role, system type, and platform before treating all script execution as suspicious.
  • Correlate script execution with source context: browser download, email/link-driven archive, web proxy event, unusual parent process, new file creation, or secondary payload behavior.
  • Tune for obfuscation indicators and unusual text-based script payloads, while recognizing that developer, automation, and administrative workflows can produce benign JavaScript execution.
  • Validate cross-platform coverage; macOS JXA and Linux/Node.js activity are common blind spots when detection content is Windows-centric.
  • Use ATT&CK relationship context to prioritize emulation and detection tests, but do not assume local exposure to any listed campaign or group without environment evidence.

Mitigation priorities

  • Start with M1021 Restrict Web-Based Content: enforce web filtering, unsafe download restrictions, script blocking where appropriate, and browser/extension controls for web-delivered scripts.
  • Apply M1038 Execution Prevention to limit unauthorized script and code execution using application control and script-control policy appropriate to each platform.
  • Use M1042 Disable or Remove Feature or Program to remove or disable unnecessary script runtimes, legacy components, or automation features where there is no business need.
  • Use M1040 Behavior Prevention on Endpoint to block suspicious script-driven behaviors based on process, file, API, and endpoint activity rather than signatures alone.
  • Sequence controls by business role: developer and automation systems may need exceptions, while standard user endpoints should have tighter execution and download restrictions.
Additional notes and limits

ATT&CK maps this behavior to multiple campaigns and threat groups, including financially motivated, espionage, and ransomware-related contexts, but those relationships should be used for prioritization and detection design rather than as evidence of current activity in any environment. The most important local validation question is whether defenders can see JavaScript execution outside normal browser rendering and can connect it to delivery, download, obfuscation, and follow-on execution context.

The supplied ATT&CK object does not include official detection text, detection analytics, data sources, or procedure-level examples in the prompt. This take is therefore based on the official description, listed platforms and tactic, external references, and supplied relationships only. Local asset inventory, approved scripting use, endpoint logging configuration, and web-control architecture are required to determine actual risk and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

JavaScript

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.[1]

JScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the Component Object Model and Internet Explorer HTML Application (HTA) pages.[2][3][4]

JavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple’s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple’s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple’s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and AppleScript. Scripts can be executed via the command line utility osascript, they can be compiled into applications or script files via osacompile, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework.[5][6][7][8][9]

Adversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a Drive-by Compromise or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of Obfuscated Files or Information.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1059Command and Scripting InterpreterThis object subtechnique of Command and Scripting Interpreter.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0010: Turla

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G1031: Saint Bear

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities.[1][2] Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

GroupEnterprise

G0037: FIN6

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.[1][2]

GroupEnterprise

G0121: Sidewinder

Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.[1][2][3]

GroupEnterprise

G0099: APT-C-36

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]

GroupEnterprise

G0069: MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).[1] Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. [2][3][4][5][6][7][8][9][10][11][12][13]

GroupEnterprise

G1006: Earth Lusca

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.[1]

Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.[1]

GroupEnterprise

G1035: Winter Vivern

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.[1][2][3][4][5]

GroupEnterprise

G0091: Silence

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.[1][2]

MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
MalwareEnterprise

S0455: Metamorfo

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.[1][2]

Windows
MalwareEnterprise

S1246: BeaverTail

BeaverTail is a malware that has both a JavaScript and C++ variant. Active since 2022, BeaverTail is capable of stealing logins from browsers and serves as a downloader for second stage payloads. BeaverTail has previously been leveraged by North Korea-affiliated actors identified as DeceptiveDevelopment or Contagious Interview. BeaverTail has been delivered to victims through code repository sites and has been embedded within malicious attachments.[1][2][3][4]

LinuxmacOSWindows
ToolEnterprise

S1144: FRP

FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or Network Address Translation (NAT) to the Internet. FRP can support multiple protocols including TCP, UDP, and HTTP(S) and has been abused by threat actors to proxy command and control communications.[1][2][3][4]

LinuxmacOSWindows
ToolEnterprise

S9003: evilginx2

evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.[1][2][3]

IaaSIdentity ProviderOffice Suite
MalwareEnterprise

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

Windows
MalwareEnterprise

S0640: Avaddon

Avaddon is ransomware written in C++ that has been offered as Ransomware-as-a-Service (RaaS) since at least June 2020.[1][2]

Windows
MalwareEnterprise

S1183: StrelaStealer

StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024. StrelaStealer focuses on the automated identification, collection, and exfiltration of email credentials from email clients such as Outlook and Thunderbird.[1][2][3][4]

Windows
CampaignEnterprise

C0017: C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]

CampaignEnterprise

C0037: Water Curupira Pikabot Distribution

Pikabot was distributed in Water Curupira Pikabot Distribution throughout 2023 by an entity linked to BlackBasta ransomware deployment via email attachments. This activity followed the take-down of QakBot, with several technical overlaps and similarities with QakBot, indicating a possible connection. The identified activity led to the deployment of tools such as Cobalt Strike, while coinciding with campaigns delivering DarkGate and IcedID en route to ransomware deployment.[1]

CampaignEnterprise

C0016: Operation Dust Storm

Operation Dust Storm was a long-standing persistent cyber espionage campaign that targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast Asian countries. By 2015, the Operation Dust Storm threat actors shifted from government and defense-related intelligence targets to Japanese companies or Japanese subdivisions of larger foreign organizations supporting Japan's critical infrastructure, including electricity generation, oil and natural gas, finance, transportation, and construction.[1]

Operation Dust Storm threat actors also began to use Android backdoors in their operations by 2015, with all identified victims at the time residing in Japan or South Korea.[1]

CampaignEnterprise

C0015: C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.2
Created
Modified
Raw hash
776e93f15d7ed567...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.2Current bundle776e93f15d7e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    NodeJS

    OpenJS Foundation. (n.d.). Node.js. Retrieved June 23, 2020.

    Open source URL
  2. [2]
    JScrip May 2018

    Microsoft. (2018, May 31). Translating to JScript. Retrieved June 23, 2020.

    Open source URL
  3. [3]
    Microsoft JScript 2007

    Microsoft. (2007, August 15). The World of JScript, JavaScript, ECMAScript …. Retrieved June 23, 2020.

    Open source URL
  4. [4]
    Microsoft Windows Scripts

    Microsoft. (2017, January 18). Windows Script Interfaces. Retrieved June 23, 2020.

    Open source URL
  5. [5]
    Apple About Mac Scripting 2016

    Apple. (2016, June 13). About Mac Scripting. Retrieved April 14, 2021.

    Open source URL
  6. [6]
    SpecterOps JXA 2020

    Pitt, L. (2020, August 6). Persistent JXA. Retrieved April 14, 2021.

    Open source URL
  7. [7]
    SentinelOne macOS Red Team

    Phil Stokes. (2019, December 5). macOS Red Team: Calling Apple APIs Without Building Binaries. Retrieved July 17, 2020.

    Open source URL
  8. [8]
    Red Canary Silver Sparrow Feb2021

    Tony Lambert. (2021, February 18). Clipping Silver Sparrow’s wings: Outing macOS malware before it takes flight. Retrieved April 20, 2021.

    Open source URL
  9. [9]
    MDSec macOS JXA and VSCode

    Dominic Chell. (2021, January 1). macOS Post-Exploitation Shenanigans with VSCode Extensions. Retrieved April 20, 2021.

    Open source URL
  10. [10]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  11. [11]
    Talos Cobalt Strike September 2020

    Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.

    Open source URL
  12. [12]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  13. [13]
    Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024

    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.

    Open source URL
  14. [14]
    Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.

    Open source URL
  15. [15]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  16. [16]
    Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024

    Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.

    Open source URL
  17. [17]
    PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.

    Open source URL
  18. [18]
    PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024

    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.

    Open source URL
  19. [19]
    ESET Turla Mosquito Jan 2018

    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

    Open source URL
  20. [20]
    FRP GitHub

    fatedier. (n.d.). What is frp?. Retrieved July 10, 2024.

    Open source URL
  21. [21]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  22. [22]
    Volexity Ocean Lotus November 2020

    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

    Open source URL
  23. [23]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  24. [24]
    Breakdev Evilginx 2.3 JAN 2019

    Gretzky, K. (2019, January 18). Evilginx 2.3 - Phisherman's Dream. Retrieved January 27, 2026.

    Open source URL
  25. [25]
    fsecure NanHaiShu July 2016

    F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018.

    Open source URL
  26. [26]
    win10_asr

    Microsoft. (2021, July 2). Use attack surface reduction rules to prevent malware infection. Retrieved June 24, 2021.

    Open source URL
  27. [27]
    Trend Micro FIN6 October 2019

    Chen, J. (2019, October 10). Magecart Card Skimmers Injected Into Online Shops. Retrieved September 9, 2020.

    Open source URL
  28. [28]
    ATT Sidewinder January 2021

    Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.

    Open source URL
  29. [29]
    Rewterz Sidewinder COVID-19 June 2020

    Rewterz. (2020, June 22). Analysis on Sidewinder APT Group – COVID-19. Retrieved January 29, 2021.

    Open source URL
  30. [30]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  31. [31]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  32. [32]
    Trustwave BlackByte 2021

    Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.

    Open source URL
  33. [33]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  34. [34]
    Zscaler BlindEagle DEC 2025

    Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

    Open source URL
  35. [35]
    Hornet Security Avaddon June 2020

    Security Lab. (2020, June 5). Avaddon: From seeking affiliates to in-the-wild in 2 days. Retrieved August 19, 2021.

    Open source URL
  36. [36]
    Awake Security Avaddon

    Gahlot, A. (n.d.). Threat Hunting for Avaddon Ransomware. Retrieved August 19, 2021.

    Open source URL
  37. [37]
    ClearSky MuddyWater Nov 2018

    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

    Open source URL
  38. [38]
    FireEye MuddyWater Mar 2018

    Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

    Open source URL
  39. [39]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  40. [40]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  41. [41]
    PaloAlto StrelaStealer 2024

    Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya & Vishwa Thothathri, Palo Alto Networks. (2024, March 22). Large-Scale StrelaStealer Campaign in Early 2024. Retrieved December 31, 2024.

    Open source URL
  42. [42]
    Fortgale StrelaStealer 2023

    Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.

    Open source URL
  43. [43]
    IBM StrelaStealer 2024

    Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.

    Open source URL
  44. [44]
    SecureList Griffon May 2019

    Namestnikov, Y. and Aime, F. (2019, May 8). FIN7.5: the infamous cybercrime rig “FIN7” continues its activities. Retrieved October 11, 2019.

    Open source URL
  45. [45]
    Latrodectus APR 2024

    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

    Open source URL
  46. [46]
    ESET WinterVivern 2023

    Matthieu Faou. (2023, October 25). Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers. Retrieved July 29, 2024.

    Open source URL
  47. [47]
    Cyber Forensicator Silence Jan 2019

    Skulkin, O.. (2019, January 20). Silence: Dissecting Malicious CHM Files and Performing Forensic Analysis. Retrieved November 17, 2024.

    Open source URL
  48. [48]
    Sekoia ClickFake 2025

    Amaury G., Coline Chavane, Felix Aimé and Sekoia TDR. (2025, March 31). From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic. Retrieved April 1, 2025.

    Open source URL
  49. [49]
    Socket Contagious Interview NPM April 2025

    Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.

    Open source URL
  50. [50]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  51. [51]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  52. [52]
    SocGholish-update

    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

    Open source URL
  53. [53]
    SentinelOne SocGholish Infrastructure November 2022

    Milenkoski, A. (2022, November 7). SocGholish Diversifies and Expands Its Malware Staging Infrastructure to Counter Defenders. Retrieved March 22, 2024.

    Open source URL
  54. [54]
    Red Canary SocGholish March 2024

    Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.

    Open source URL
  55. [55]
    Secureworks Gold Prelude Profile

    Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.

    Open source URL
  56. [56]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  57. [57]
    Cybereason Valak May 2020

    Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.

    Open source URL
  58. [58]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  59. [59]
    Bitsight Latrodectus June 2024

    Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.

    Open source URL
  60. [60]
    Palo Alto Latrodectus Activity June 2024

    Unit 42. (2024, June 25). 2024-06-25-IOCs-from-Latrodectus-activity. Retrieved September 13, 2024.

    Open source URL
  61. [61]
    Proofpoint TA505 Sep 2017

    Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019.

    Open source URL
  62. [62]
    Proofpoint TA505 June 2018

    Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019.

    Open source URL
  63. [63]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  64. [64]
    Cofense Astaroth Sept 2018

    Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.

    Open source URL
  65. [65]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  66. [66]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  67. [67]
    Flashpoint FIN 7 March 2019

    Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.

    Open source URL
  68. [68]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  69. [69]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  70. [70]
    Mandiant Cutting Edge January 2024

    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  71. [71]
    SecureListUbiedo_Tsundere_Nov2025

    Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

    Open source URL
  72. [72]
    Donut Github

    TheWover. (2019, May 9). donut. Retrieved March 25, 2022.

    Open source URL
  73. [73]
    Unit42 Xbash Sept 2018

    Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.

    Open source URL
  74. [74]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  75. [75]
    PTSecurity Cobalt Group Aug 2017

    Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.

    Open source URL
  76. [76]
    Group IB Cobalt Aug 2017

    Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.

    Open source URL
  77. [77]
    Morphisec Cobalt Gang Oct 2018

    Gorelik, M. (2018, October 08). Cobalt Group 2.0. Retrieved November 5, 2018.

    Open source URL
  78. [78]
    Unit 42 Cobalt Gang Oct 2018

    Unit 42. (2018, October 25). New Techniques to Uncover and Attribute Financial actors Commodity Builders and Infrastructure Revealed. Retrieved December 11, 2018.

    Open source URL
  79. [79]
    TrendMicro Cobalt Group Nov 2017

    Giagone, R., Bermejo, L., and Yarochkin, F. (2017, November 20). Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks. Retrieved March 7, 2019.

    Open source URL
  80. [80]
    Malwarebytes Higaisa 2020

    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

    Open source URL
  81. [81]
    Zscaler Higaisa 2020

    Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021.

    Open source URL
  82. [82]
    PTSecurity Higaisa 2020

    PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.

    Open source URL
  83. [83]
    VirusBulletin Kimsuky October 2019

    Kim, J. et al. (2019, October). KIMSUKY GROUP: TRACKING THE KING OF THE SPEAR PHISHING. Retrieved November 2, 2020.

    Open source URL
  84. [84]
    CISA AA20-301A Kimsuky

    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

    Open source URL
  85. [85]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  86. [86]
    Kaspersky Adwind Feb 2016

    Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.

    Open source URL
  87. [87]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  88. [88]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  89. [89]
    Palo Alto Ashen Lepus DEC 2025

    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

    Open source URL
  90. [90]
    Koi Glassworm Extensions November 2025

    Idan Dardikman, Yuval Ronen, Lotan Sery. (2025, November 6). GlassWorm Returns: New Wave Strikes as We Expose Attacker Infrastructure. Retrieved April 10, 2026.

    Open source URL
  91. [91]
    Koi Glassworm InvisibleCode October 2025

    Idan Dardikman. (2025, October 18). GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace. Retrieved April 10, 2026.

    Open source URL
  92. [92]
    Aikido GlassWorm October 2025

    Ilyas Makari. (2025, October 31). The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties. Retrieved April 10, 2026.

    Open source URL
  93. [93]
    Socket GlassWorm January 2026

    Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

    Open source URL
  94. [94]
    Koi Glassworm New Tricks December 2025

    Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.

    Open source URL
  95. [95]
    Secureworks GOLD KINGSWOOD September 2018

    CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.

    Open source URL
  96. [96]
    TrendMicro Pikabot 2024

    Shinji Robert Arasawa, Joshua Aquino, Charles Steven Derion, Juhn Emmanuel Atanque, Francisrey Joshua Castillo, John Carlo Marquez, Henry Salcedo, John Rainier Navato, Arianne Dela Cruz, Raymart Yambot & Ian Kenefick. (2024, January 9). Black Basta-Affiliated Water Curupira’s Pikabot Spam Campaign. Retrieved July 17, 2024.

    Open source URL
  97. [97]
    Symantec WastedLocker June 2020

    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

    Open source URL
  98. [98]
    Elastic Pikabot 2024

    Daniel Stepanic & Salim Bitam. (2024, February 23). PIKABOT, I choose you!. Retrieved July 12, 2024.

    Open source URL
  99. [99]
    Kaspersky MoleRATs April 2019

    GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.

    Open source URL
  100. [100]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  101. [101]
    Symantec Leafminer July 2018

    Symantec Security Response. (2018, July 25). Leafminer: New Espionage Campaigns Targeting Middle Eastern Regions. Retrieved August 28, 2018.

    Open source URL
  102. [102]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  103. [103]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  104. [104]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  105. [105]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  106. [106]
    Malwarebytes Konni Aug 2021

    Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.

    Open source URL
  107. [107]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  108. [108]
    Socket BeaverTail XORIndex HexEval Contagious Interview July 2025

    Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.

    Open source URL
  109. [109]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  110. [110]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  111. [111]
    Aikido Shai-Hulud September 2025

    Charlie Eriksen. (2025, September 16). S1ngularity/nx attackers strike again. Retrieved April 9, 2026.

    Open source URL
  112. [112]
    Netskope Shai-Hulud November 2025

    Gianpietro Cutolo. (2025, November 26). Shai-Hulud 2.0: Aggressive, Automated, and Fast Spreading. Retrieved April 9, 2026.

    Open source URL
  113. [113]
    Palo Alto Unit 42 Shai-Hulud November 2025

    Justin Moore. (2025, November 25). "Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26). Retrieved April 9, 2026.

    Open source URL
  114. [114]
    Wiz Shai-Hulud September 2025

    Merav Bar, Rami McCarthy, Barak Sharoni. (2025, September 16). Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware. Retrieved April 9, 2026.

    Open source URL
  115. [115]
    Microsoft Shai-Hulud December 2025

    Microsoft Defender Security Team. (n.d.). Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack. Retrieved April 9, 2026.

    Open source URL
  116. [116]
    Socket Shai-Hulud November 2025

    Socket Research Team. (2025, November 24). Shai Hulud Strikes Again (v2). Retrieved April 9, 2026.

    Open source URL
  117. [117]
    Socket Shai-Hulud Trufflehog September 2025

    Socket Research Team. (2025, September 15). Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages. Retrieved April 9, 2026.

    Open source URL
  118. [118]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  119. [119]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  120. [120]
    Apple About Mac Scripting 2016

    Apple. (2016, June 13). About Mac Scripting. Retrieved April 14, 2021.

    Open source URL
  121. [121]
    Apple About Mac Scripting 2016

    Apple. (2016, June 13). About Mac Scripting. Retrieved April 14, 2021.

    Open source URL
  122. [122]
    JScrip May 2018

    Microsoft. (2018, May 31). Translating to JScript. Retrieved June 23, 2020.

    Open source URL
  123. [123]
    JScrip May 2018

    Microsoft. (2018, May 31). Translating to JScript. Retrieved June 23, 2020.

    Open source URL
  124. [124]
    MDSec macOS JXA and VSCode

    Dominic Chell. (2021, January 1). macOS Post-Exploitation Shenanigans with VSCode Extensions. Retrieved April 20, 2021.

    Open source URL
  125. [125]
    MDSec macOS JXA and VSCode

    Dominic Chell. (2021, January 1). macOS Post-Exploitation Shenanigans with VSCode Extensions. Retrieved April 20, 2021.

    Open source URL
  126. [126]
    Microsoft JScript 2007

    Microsoft. (2007, August 15). The World of JScript, JavaScript, ECMAScript …. Retrieved June 23, 2020.

    Open source URL
  127. [127]
    Microsoft JScript 2007

    Microsoft. (2007, August 15). The World of JScript, JavaScript, ECMAScript …. Retrieved June 23, 2020.

    Open source URL
  128. [128]
    Microsoft Windows Scripts

    Microsoft. (2017, January 18). Windows Script Interfaces. Retrieved June 23, 2020.

    Open source URL
  129. [129]
    Microsoft Windows Scripts

    Microsoft. (2017, January 18). Windows Script Interfaces. Retrieved June 23, 2020.

    Open source URL
  130. [130]
    NodeJS

    OpenJS Foundation. (n.d.). Node.js. Retrieved June 23, 2020.

    Open source URL
  131. [131]
    NodeJS

    OpenJS Foundation. (n.d.). Node.js. Retrieved June 23, 2020.

    Open source URL
  132. [132]
    Red Canary Silver Sparrow Feb2021

    Tony Lambert. (2021, February 18). Clipping Silver Sparrow’s wings: Outing macOS malware before it takes flight. Retrieved April 20, 2021.

    Open source URL
  133. [133]
    Red Canary Silver Sparrow Feb2021

    Tony Lambert. (2021, February 18). Clipping Silver Sparrow’s wings: Outing macOS malware before it takes flight. Retrieved April 20, 2021.

    Open source URL
  134. [134]
    SentinelOne macOS Red Team

    Phil Stokes. (2019, December 5). macOS Red Team: Calling Apple APIs Without Building Binaries. Retrieved July 17, 2020.

    Open source URL
  135. [135]
    SentinelOne macOS Red Team

    Phil Stokes. (2019, December 5). macOS Red Team: Calling Apple APIs Without Building Binaries. Retrieved July 17, 2020.

    Open source URL
  136. [136]
    SpecterOps JXA 2020

    Pitt, L. (2020, August 6). Persistent JXA. Retrieved April 14, 2021.

    Open source URL
  137. [137]
    SpecterOps JXA 2020

    Pitt, L. (2020, August 6). Persistent JXA. Retrieved April 14, 2021.

    Open source URL
  138. [138]
    mitre-attackT1059.007
    Open source URL
  139. [139]
    mitre-attackT1059.007
    Open source URL
  140. [140]
    mitre-attackT1059.007
    Open source URL
  141. [141]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  142. [142]
    Talos Cobalt Strike September 2020

    Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.

    Open source URL
  143. [143]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  144. [144]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  145. [145]
    Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024

    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.

    Open source URL
  146. [146]
    PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.

    Open source URL
  147. [147]
    PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024

    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.

    Open source URL
  148. [148]
    Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.

    Open source URL
  149. [149]
    Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024

    Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.

    Open source URL
  150. [150]
    ESET Turla Mosquito Jan 2018

    ESET, et al. (2018, January). Diplomats in Eastern Europe bitten by a Turla mosquito. Retrieved July 3, 2018.

    Open source URL
  151. [151]
    FRP GitHub

    fatedier. (n.d.). What is frp?. Retrieved July 10, 2024.

    Open source URL
  152. [152]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  153. [153]
    Volexity Ocean Lotus November 2020

    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

    Open source URL
  154. [154]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  155. [155]
    Breakdev Evilginx 2.3 JAN 2019

    Gretzky, K. (2019, January 18). Evilginx 2.3 - Phisherman's Dream. Retrieved January 27, 2026.

    Open source URL
  156. [156]
    fsecure NanHaiShu July 2016

    F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018.

    Open source URL
  157. [157]
    win10_asr

    Microsoft. (2021, July 2). Use attack surface reduction rules to prevent malware infection. Retrieved June 24, 2021.

    Open source URL
  158. [158]
    Trend Micro FIN6 October 2019

    Chen, J. (2019, October 10). Magecart Card Skimmers Injected Into Online Shops. Retrieved September 9, 2020.

    Open source URL
  159. [159]
    ATT Sidewinder January 2021

    Hegel, T. (2021, January 13). A Global Perspective of the SideWinder APT. Retrieved January 27, 2021.

    Open source URL
  160. [160]
    Rewterz Sidewinder COVID-19 June 2020

    Rewterz. (2020, June 22). Analysis on Sidewinder APT Group – COVID-19. Retrieved January 29, 2021.

    Open source URL
  161. [161]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  162. [162]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  163. [163]
    Trustwave BlackByte 2021

    Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.

    Open source URL
  164. [164]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  165. [165]
    Zscaler BlindEagle DEC 2025

    Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

    Open source URL
  166. [166]
    Awake Security Avaddon

    Gahlot, A. (n.d.). Threat Hunting for Avaddon Ransomware. Retrieved August 19, 2021.

    Open source URL
  167. [167]
    Hornet Security Avaddon June 2020

    Security Lab. (2020, June 5). Avaddon: From seeking affiliates to in-the-wild in 2 days. Retrieved August 19, 2021.

    Open source URL
  168. [168]
    ClearSky MuddyWater Nov 2018

    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

    Open source URL
  169. [169]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  170. [170]
    FireEye MuddyWater Mar 2018

    Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

    Open source URL
  171. [171]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  172. [172]
    Fortgale StrelaStealer 2023

    Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.

    Open source URL
  173. [173]
    IBM StrelaStealer 2024

    Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.

    Open source URL
  174. [174]
    PaloAlto StrelaStealer 2024

    Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya & Vishwa Thothathri, Palo Alto Networks. (2024, March 22). Large-Scale StrelaStealer Campaign in Early 2024. Retrieved December 31, 2024.

    Open source URL
  175. [175]
    SecureList Griffon May 2019

    Namestnikov, Y. and Aime, F. (2019, May 8). FIN7.5: the infamous cybercrime rig “FIN7” continues its activities. Retrieved October 11, 2019.

    Open source URL
  176. [176]
    Latrodectus APR 2024

    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

    Open source URL
  177. [177]
    ESET WinterVivern 2023

    Matthieu Faou. (2023, October 25). Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers. Retrieved July 29, 2024.

    Open source URL
  178. [178]
    Cyber Forensicator Silence Jan 2019

    Skulkin, O.. (2019, January 20). Silence: Dissecting Malicious CHM Files and Performing Forensic Analysis. Retrieved November 17, 2024.

    Open source URL
  179. [179]
    Sekoia ClickFake 2025

    Amaury G., Coline Chavane, Felix Aimé and Sekoia TDR. (2025, March 31). From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic. Retrieved April 1, 2025.

    Open source URL
  180. [180]
    Socket Contagious Interview NPM April 2025

    Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.

    Open source URL
  181. [181]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  182. [182]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  183. [183]
    Red Canary SocGholish March 2024

    Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.

    Open source URL
  184. [184]
    Secureworks Gold Prelude Profile

    Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.

    Open source URL
  185. [185]
    SentinelOne SocGholish Infrastructure November 2022

    Milenkoski, A. (2022, November 7). SocGholish Diversifies and Expands Its Malware Staging Infrastructure to Counter Defenders. Retrieved March 22, 2024.

    Open source URL
  186. [186]
    SocGholish-update

    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

    Open source URL
  187. [187]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  188. [188]
    Cybereason Valak May 2020

    Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.

    Open source URL
  189. [189]
    Bitsight Latrodectus June 2024

    Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.

    Open source URL
  190. [190]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  191. [191]
    Palo Alto Latrodectus Activity June 2024

    Unit 42. (2024, June 25). 2024-06-25-IOCs-from-Latrodectus-activity. Retrieved September 13, 2024.

    Open source URL
  192. [192]
    Proofpoint TA505 June 2018

    Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019.

    Open source URL
  193. [193]
    Proofpoint TA505 Sep 2017

    Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019.

    Open source URL
  194. [194]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  195. [195]
    Cofense Astaroth Sept 2018

    Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.

    Open source URL
  196. [196]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  197. [197]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  198. [198]
    Flashpoint FIN 7 March 2019

    Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.

    Open source URL
  199. [199]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  200. [200]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  201. [201]
    Mandiant Cutting Edge January 2024

    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  202. [202]
    SecureListUbiedo_Tsundere_Nov2025

    Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

    Open source URL
  203. [203]
    Donut Github

    TheWover. (2019, May 9). donut. Retrieved March 25, 2022.

    Open source URL
  204. [204]
    Unit42 Xbash Sept 2018

    Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.

    Open source URL
  205. [205]
    Group IB Cobalt Aug 2017

    Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.

    Open source URL
  206. [206]
    Morphisec Cobalt Gang Oct 2018

    Gorelik, M. (2018, October 08). Cobalt Group 2.0. Retrieved November 5, 2018.

    Open source URL
  207. [207]
    PTSecurity Cobalt Group Aug 2017

    Positive Technologies. (2017, August 16). Cobalt Strikes Back: An Evolving Multinational Threat to Finance. Retrieved September 5, 2018.

    Open source URL
  208. [208]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  209. [209]
    TrendMicro Cobalt Group Nov 2017

    Giagone, R., Bermejo, L., and Yarochkin, F. (2017, November 20). Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks. Retrieved March 7, 2019.

    Open source URL
  210. [210]
    Unit 42 Cobalt Gang Oct 2018

    Unit 42. (2018, October 25). New Techniques to Uncover and Attribute Financial actors Commodity Builders and Infrastructure Revealed. Retrieved December 11, 2018.

    Open source URL
  211. [211]
    Malwarebytes Higaisa 2020

    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

    Open source URL
  212. [212]
    PTSecurity Higaisa 2020

    PT ESC Threat Intelligence. (2020, June 4). COVID-19 and New Year greetings: an investigation into the tools and methods used by the Higaisa group. Retrieved March 2, 2021.

    Open source URL
  213. [213]
    Zscaler Higaisa 2020

    Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021.

    Open source URL
  214. [214]
    CISA AA20-301A Kimsuky

    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

    Open source URL
  215. [215]
    VirusBulletin Kimsuky October 2019

    Kim, J. et al. (2019, October). KIMSUKY GROUP: TRACKING THE KING OF THE SPEAR PHISHING. Retrieved November 2, 2020.

    Open source URL
  216. [216]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  217. [217]
    Kaspersky Adwind Feb 2016

    Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.

    Open source URL
  218. [218]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  219. [219]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  220. [220]
    Palo Alto Ashen Lepus DEC 2025

    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

    Open source URL
  221. [221]
    Aikido GlassWorm October 2025

    Ilyas Makari. (2025, October 31). The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties. Retrieved April 10, 2026.

    Open source URL
  222. [222]
    Koi Glassworm Extensions November 2025

    Idan Dardikman, Yuval Ronen, Lotan Sery. (2025, November 6). GlassWorm Returns: New Wave Strikes as We Expose Attacker Infrastructure. Retrieved April 10, 2026.

    Open source URL
  223. [223]
    Koi Glassworm InvisibleCode October 2025

    Idan Dardikman. (2025, October 18). GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace. Retrieved April 10, 2026.

    Open source URL
  224. [224]
    Koi Glassworm New Tricks December 2025

    Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.

    Open source URL
  225. [225]
    Socket GlassWorm January 2026

    Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

    Open source URL
  226. [226]
    Secureworks GOLD KINGSWOOD September 2018

    CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.

    Open source URL
  227. [227]
    TrendMicro Pikabot 2024

    Shinji Robert Arasawa, Joshua Aquino, Charles Steven Derion, Juhn Emmanuel Atanque, Francisrey Joshua Castillo, John Carlo Marquez, Henry Salcedo, John Rainier Navato, Arianne Dela Cruz, Raymart Yambot & Ian Kenefick. (2024, January 9). Black Basta-Affiliated Water Curupira’s Pikabot Spam Campaign. Retrieved July 17, 2024.

    Open source URL
  228. [228]
    Symantec WastedLocker June 2020

    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

    Open source URL
  229. [229]
    Elastic Pikabot 2024

    Daniel Stepanic & Salim Bitam. (2024, February 23). PIKABOT, I choose you!. Retrieved July 12, 2024.

    Open source URL
  230. [230]
    ClearSky MuddyWater Nov 2018

    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

    Open source URL
  231. [231]
    ClearSky MuddyWater Nov 2018

    ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

    Open source URL
  232. [232]
    Kaspersky MoleRATs April 2019

    GReAT. (2019, April 10). Gaza Cybergang Group1, operation SneakyPastes. Retrieved May 13, 2020.

    Open source URL
  233. [233]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  234. [234]
    Symantec Leafminer July 2018

    Symantec Security Response. (2018, July 25). Leafminer: New Espionage Campaigns Targeting Middle Eastern Regions. Retrieved August 28, 2018.

    Open source URL
  235. [235]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  236. [236]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  237. [237]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  238. [238]
    Latrodectus APR 2024

    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.