LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1071.004: DNS

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.[1][2]

DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records.[3] DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices.[4] Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.

EnterpriseT1071.004Sub-techniqueObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

DNS command-and-control matters because DNS is normally required for business operations and is often allowed through network controls, which makes malicious communications easier to hide among routine traffic. The practical risk is not just “DNS tunneling”; it is whether the organization can distinguish necessary name resolution from covert command traffic across Windows, Linux, macOS, ESXi, and network-device environments.

Executive priority

Treat this as a resilience and visibility question: can the organization prove that DNS egress is governed, monitored, and investigated rather than simply allowed by default? Because ATT&CK links this technique to multiple groups, malware families, and a campaign, leaders should prioritize DNS logging, boundary filtering, and intrusion prevention as control evidence for incident response readiness, audit discussions, and network-risk reduction. The key decision is whether DNS is managed as a controlled service or as an unmanaged bypass path.

Technical view

This is an enterprise command-and-control sub-technique under Application Layer Protocol. ATT&CK notes that adversaries may embed commands and results in DNS traffic, including DNS tunneling and DNS beaconing using records such as TXT or A records. SOC and IR teams should validate whether they can analyze DNS queries, responses, record types, query frequency, destination domains, resolver paths, and traffic crossing network boundaries. There is no official MITRE detection text supplied, but the relationship to DET0400 indicates behavioral detection of DNS tunneling and application-layer abuse is relevant. Relationships to tools such as PlugX, Uroburos, Pisloader, POWERSOURCE, TEXTMATE, and Cobalt Strike support using malware and intrusion reporting as context for detection engineering, without assuming local exposure.

Likely telemetry

  • Recursive DNS resolver logs
  • Endpoint DNS query events where available
  • Network DNS packet metadata and full packet capture where retained
  • Firewall, proxy, and egress filtering logs for DNS traffic
  • Network intrusion detection or prevention alerts

Detection direction

  • Confirm whether DNS telemetry covers all listed platforms and network segments, including servers, endpoints, ESXi-adjacent infrastructure, and network devices where applicable.
  • Develop behavioral analytics for unusual DNS tunneling indicators such as high-volume or structured subdomain usage, uncommon record-type patterns, suspicious TXT/A record usage, and low-frequency beaconing that may blend with normal traffic.
  • Tune detections against known business DNS behaviors to reduce false positives from legitimate cloud, software update, security, and content-delivery services.
  • Validate that DNS requests are expected to flow through approved resolvers; direct external DNS from endpoints or servers should be investigated according to local policy.
  • Use relationship context from associated campaigns, groups, and software to enrich threat hunting, but do not treat those relationships as proof of activity in the environment.

Mitigation priorities

  • Prioritize network intrusion prevention at boundaries, consistent with M1031, using signatures or detections for known DNS tunneling and application-layer abuse where appropriate.
  • Implement network traffic filtering consistent with M1037: restrict DNS egress to approved resolvers and enforce firewall rules for ingress, egress, and lateral DNS traffic.
  • Review whether DNS is permitted before network authentication and determine whether that exposure is necessary for the business environment.
  • Centralize DNS resolution and logging so incident responders can reconstruct suspected command-and-control activity.
  • Pair filtering with monitoring; blocking alone may miss infrequent DNS beaconing or traffic designed to resemble normal DNS behavior.
Additional notes and limits

The strongest business takeaway is that DNS is a high-trust administrative protocol that can become a covert communications channel if it is not governed. The supplied relationships show broad technique relevance across multiple named groups, software families, and one campaign, but they do not establish current activity against any specific organization. Glexia would use this object to drive DNS visibility assessment, egress-control validation, SOC tuning, and IR evidence readiness.

The official ATT&CK object does not provide detection text. External references are listed, but this take uses only the supplied descriptions and relationships. Specific indicators, thresholds, vendor detections, and environment exposure require local DNS baselines, architecture review, and telemetry validation.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

DNS

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.[1][2]

DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records.[3] DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices.[4] Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1071Application Layer ProtocolThis object subtechnique of Application Layer Protocol.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0114: Chimera

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.[1][2]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0080: Cobalt Group

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.[1][2][3][4][5][6][7] Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.[8]

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G0004: Ke3chang

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.[1][2][3][4]

GroupEnterprise

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.[1][2][3][4][5]

GroupEnterprise

G1003: Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

GroupEnterprise

G0081: Tropic Trooper

Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.[1][2][3]

GroupEnterprise

G0026: APT18

APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical. [1]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

MalwareEnterprise

S0477: Goopy

Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.[1]

Windows
MalwareEnterprise

S1111: DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

Windows
MalwareEnterprise

S1020: Kevin

Kevin is a backdoor implant written in C++ that has been used by HEXANE since at least June 2020, including in operations against organizations in Tunisia.[1]

Windows
MalwareEnterprise

S0377: Ebury

Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo. Ebury is primarily installed through modifying shared libraries (`.so` files) executed by the legitimate OpenSSH program. First seen in 2009, Ebury has been used to maintain a botnet of servers, deploy additional malware, and steal cryptocurrency wallets, credentials, and credit card details.[1][2][3][4]

Linux
MalwareEnterprise

S0170: Helminth

Helminth is a backdoor that has at least two variants - one written in VBScript and PowerShell that is delivered via a macros in Excel spreadsheets, and one that is a standalone Windows executable. [1]

Windows
ToolEnterprise

S0699: Mythic

Mythic is an open source, cross-platform post-exploitation/command and control platform. Mythic is designed to "plug-n-play" with various agents and communication channels.[1][2][3] Deployed Mythic C2 servers have been observed as part of potentially malicious infrastructure.[4]

WindowsLinuxmacOS
MalwareEnterprise

S0495: RDAT

RDAT is a backdoor used by the suspected Iranian threat group OilRig. RDAT was originally identified in 2017 and targeted companies in the telecommunications sector.[1]

Windows
CampaignEnterprise

C0029: Cutting Edge

Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.[1][2][3][4][5]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.4
Created
Modified
Raw hash
1f634e3439a68ac8...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.4Current bundle1f634e3439a6…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    PAN DNS Tunneling

    Palo Alto Networks. (n.d.). What Is DNS Tunneling?. Retrieved March 15, 2020.

    Open source URL
  2. [2]
    Medium DnsTunneling

    Galobardes, R. (2018, October 30). Learn how easy is to bypass firewalls using DNS tunneling (and also how to block it). Retrieved March 15, 2020.

    Open source URL
  3. [3]
    OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government

    Kyle Wilhoit, Robert Falcone. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved July 21, 2025.

    Open source URL
  4. [4]
    DNS Beacons

    Vercara. (n.d.). Retrieved July 21, 2025.

    Open source URL
  5. [5]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  6. [6]
    Unit 42 QUADAGENT July 2018

    Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.

    Open source URL
  7. [7]
    Cybereason Oceanlotus May 2017

    Dahan, A. (2017, May 24). OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP. Retrieved November 5, 2018.

    Open source URL
  8. [8]
    Securelist Denis April 2017

    Shulmin, A., Yunakovsky, S. (2017, April 28). Use of DNS Tunneling for C&C Communications. Retrieved November 5, 2018.

    Open source URL
  9. [9]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  10. [10]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  11. [11]
    FireEye FIN7 March 2017

    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

    Open source URL
  12. [12]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  13. [13]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  14. [14]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  15. [15]
    ESET Ebury Feb 2014

    M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.

    Open source URL
  16. [16]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  17. [17]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  18. [18]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  19. [19]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  20. [20]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  21. [21]
    FireEye APT34 Webinar Dec 2017

    Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.

    Open source URL
  22. [22]
    Mandiant Cutting Edge Part 2 January 2024

    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  23. [23]
    PWC WellMess July 2020

    PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020.

    Open source URL
  24. [24]
    NCSC APT29 July 2020

    National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.

    Open source URL
  25. [25]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  26. [26]
    Palo Alto DNS Requests

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

  27. [27]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  28. [28]
    HarmonProofpoint_SystemBC_Aug2019

    Harmon, K., et al. (2019, August 1). SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits . Retrieved June 13, 2025.

    Open source URL
  29. [29]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  30. [30]
    Zscaler Lyceum DnsSystem June 2022

    Shivtarkar, N. and Kumar, A. (2022, June 9). Lyceum .NET DNS Backdoor. Retrieved June 23, 2022.

    Open source URL
  31. [31]
    cobaltstrike manual

    Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

    Open source URL
  32. [32]
    Talos Cobalt Strike September 2020

    Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.

    Open source URL
  33. [33]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  34. [34]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  35. [35]
    Palo Alto OilRig Sep 2018

    Wilhoit, K. and Falcone, R. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved February 18, 2019.

    Open source URL
  36. [36]
    Cybersecurity Advisory SVR TTP May 2021

    NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021.

    Open source URL
  37. [37]
    Bishop Fox Sliver Framework August 2019

    Kervella, R. (2019, August 4). Cross-platform General Purpose Implant Framework Written in Golang. Retrieved July 30, 2021.

    Open source URL
  38. [38]
    GitHub Sliver C2 DNS

    BishopFox. (n.d.). Sliver DNS C2 . Retrieved September 15, 2021.

    Open source URL
  39. [39]
    Cybereason Sliver Undated

    Cybereason Global SOC and Incident Response Team. (n.d.). Sliver C2 Leveraged by Many Threat Actors. Retrieved March 24, 2025.

    Open source URL
  40. [40]
    Microsoft Sliver 2022

    Microsoft Security Experts. (2022, August 24). Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks. Retrieved March 24, 2025.

    Open source URL
  41. [41]
    Objective See Green Lambert for OSX Oct 2021

    Sandvik, Runa. (2021, October 1). Made In America: Green Lambert for OS X. Retrieved March 21, 2022.

    Open source URL
  42. [42]
    Glitch-Cat Green Lambert ATTCK Oct 2021

    Sandvik, Runa. (2021, October 18). Green Lambert and ATT&CK. Retrieved November 17, 2024.

    Open source URL
  43. [43]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  44. [44]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  45. [45]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  46. [46]
    CYBERCOM Iranian Intel Cyber January 2022

    Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.

    Open source URL
  47. [47]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  48. [48]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  49. [49]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  50. [50]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  51. [51]
    Medium Anchor DNS July 2020

    Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.

    Open source URL
  52. [52]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  53. [53]
    PTSecurity Cobalt Dec 2016

    Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.

    Open source URL
  54. [54]
    Group IB Cobalt Aug 2017

    Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.

    Open source URL
  55. [55]
    Unit42 OilRig Playbook 2023

    Unit42. (2016, May 1). Evasive Serpens Unit 42 Playbook Viewer. Retrieved February 6, 2023.

    Open source URL
  56. [56]
    FireEye APT34 July 2019

    Bromiley, M., et al.. (2019, July 18). Hard Pass: Declining APT34’s Invite to Join Their Professional Network. Retrieved August 26, 2019.

    Open source URL
  57. [57]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  58. [58]
    Kaspersky ShadowPad Aug 2017

    Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.

    Open source URL
  59. [59]
    Zscaler Cobian Aug 2017

    Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

    Open source URL
  60. [60]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  61. [61]
    BitDefender Chafer May 2020

    Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020.

    Open source URL
  62. [62]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  63. [63]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  64. [64]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  65. [65]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  66. [66]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  67. [67]
    fsecure NanHaiShu July 2016

    F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018.

    Open source URL
  68. [68]
    TrendMicro Tropic Trooper May 2020

    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

    Open source URL
  69. [69]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  70. [70]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  71. [71]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  72. [72]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  73. [73]
    ClearSky Wilted Tulip July 2017

    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

  74. [74]
    CopyKittens Nov 2015

    Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.

    Open source URL
  75. [75]
    Cisco DNSMessenger March 2017

    Brumaghin, E. and Grady, C.. (2017, March 2). Covert Channels and Poor Decisions: The Tale of DNSMessenger. Retrieved March 8, 2017.

  76. [76]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  77. [77]
    Symantec Remsec IOCs

    Symantec Security Response. (2016, August 8). Backdoor.Remsec indicators of compromise. Retrieved August 17, 2016.

  78. [78]
    Kaspersky ProjectSauron Full Report

    Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Retrieved August 17, 2016.

    Open source URL
  79. [79]
    Kaspersky ProjectSauron Technical Analysis

    Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Technical Analysis. Retrieved August 17, 2016.

    Open source URL
  80. [80]
    CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025

    CrowdStrike. (2025, December 4). Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary. Retrieved April 16, 2026.

    Open source URL
  81. [81]
    CISA BRICKSTORM UNC5221 AR25-338A February 2026

    DHS/CISA. (2026, February 11). AR25-338A: BRICKSTORM Backdoor. Retrieved April 16, 2026.

    Open source URL
  82. [82]
    Picus Security BRICKSTORM UNC5221 October 2025

    Huseyin Can Yuceel. (2025, October 1). BRICKSTORM Malware: UNC5221 Targets Tech and Legal Sectors in the United States. Retrieved April 16, 2026.

    Open source URL
  83. [83]
    Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024

    Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.

    Open source URL
  84. [84]
    NVISO BRICKSTORM April 2025

    NVISO Incident Response. (2025, April 1). BRICKSTORM Backdoor Analysis: A Persistent Espionage Threat to European Industries. Retrieved April 16, 2026.

    Open source URL
  85. [85]
    Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023

    FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.

    Open source URL
  86. [86]
    DNS Beacons

    Vercara. (n.d.). Retrieved July 21, 2025.

    Open source URL
  87. [87]
    DNS Beacons

    Vercara. (n.d.). Retrieved July 21, 2025.

    Open source URL
  88. [88]
    Medium DnsTunneling

    Galobardes, R. (2018, October 30). Learn how easy is to bypass firewalls using DNS tunneling (and also how to block it). Retrieved March 15, 2020.

    Open source URL
  89. [89]
    Medium DnsTunneling

    Galobardes, R. (2018, October 30). Learn how easy is to bypass firewalls using DNS tunneling (and also how to block it). Retrieved March 15, 2020.

    Open source URL
  90. [90]
    OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government

    Kyle Wilhoit, Robert Falcone. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved July 21, 2025.

    Open source URL
  91. [91]
    OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government

    Kyle Wilhoit, Robert Falcone. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved July 21, 2025.

    Open source URL
  92. [92]
    PAN DNS Tunneling

    Palo Alto Networks. (n.d.). What Is DNS Tunneling?. Retrieved March 15, 2020.

    Open source URL
  93. [93]
    PAN DNS Tunneling

    Palo Alto Networks. (n.d.). What Is DNS Tunneling?. Retrieved March 15, 2020.

    Open source URL
  94. [94]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  95. [95]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  96. [96]
    University of Birmingham C2

    Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016.

    Open source URL
  97. [97]
    mitre-attackT1071.004
    Open source URL
  98. [98]
    mitre-attackT1071.004
    Open source URL
  99. [99]
    mitre-attackT1071.004
    Open source URL
  100. [100]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  101. [101]
    Unit 42 QUADAGENT July 2018

    Lee, B., Falcone, R. (2018, July 25). OilRig Targets Technology Service Provider and Government Agency with QUADAGENT. Retrieved August 9, 2018.

    Open source URL
  102. [102]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  103. [103]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  104. [104]
    Cybereason Oceanlotus May 2017

    Dahan, A. (2017, May 24). OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP. Retrieved November 5, 2018.

    Open source URL
  105. [105]
    Securelist Denis April 2017

    Shulmin, A., Yunakovsky, S. (2017, April 28). Use of DNS Tunneling for C&C Communications. Retrieved November 5, 2018.

    Open source URL
  106. [106]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  107. [107]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  108. [108]
    FireEye FIN7 March 2017

    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

    Open source URL
  109. [109]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  110. [110]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  111. [111]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  112. [112]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  113. [113]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  114. [114]
    ESET Ebury Feb 2014

    M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.

    Open source URL
  115. [115]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  116. [116]
    Mythc Documentation

    Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022.

    Open source URL
  117. [117]
    Unit42 RDAT July 2020

    Falcone, R. (2020, July 22). OilRig Targets Middle Eastern Telecommunications Organization and Adds Novel C2 Channel with Steganography to Its Inventory. Retrieved July 28, 2020.

    Open source URL
  118. [118]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  119. [119]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  120. [120]
    FireEye APT34 Webinar Dec 2017

    Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.

    Open source URL
  121. [121]
    Mandiant Cutting Edge Part 2 January 2024

    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  122. [122]
    NCSC APT29 July 2020

    National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.

    Open source URL
  123. [123]
    PWC WellMess July 2020

    PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020.

    Open source URL
  124. [124]
    MoustachedBouncer ESET August 2023

    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

    Open source URL
  125. [125]
    Palo Alto DNS Requests

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

  126. [126]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  127. [127]
    HarmonProofpoint_SystemBC_Aug2019

    Harmon, K., et al. (2019, August 1). SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits . Retrieved June 13, 2025.

    Open source URL
  128. [128]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  129. [129]
    Zscaler Lyceum DnsSystem June 2022

    Shivtarkar, N. and Kumar, A. (2022, June 9). Lyceum .NET DNS Backdoor. Retrieved June 23, 2022.

    Open source URL
  130. [130]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  131. [131]
    Talos Cobalt Strike September 2020

    Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.

    Open source URL
  132. [132]
    cobaltstrike manual

    Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

    Open source URL
  133. [133]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  134. [134]
    Palo Alto OilRig Sep 2018

    Wilhoit, K. and Falcone, R. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved February 18, 2019.

    Open source URL
  135. [135]
    Bishop Fox Sliver Framework August 2019

    Kervella, R. (2019, August 4). Cross-platform General Purpose Implant Framework Written in Golang. Retrieved July 30, 2021.

    Open source URL
  136. [136]
    Cybereason Sliver Undated

    Cybereason Global SOC and Incident Response Team. (n.d.). Sliver C2 Leveraged by Many Threat Actors. Retrieved March 24, 2025.

    Open source URL
  137. [137]
    Cybersecurity Advisory SVR TTP May 2021

    NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021.

    Open source URL
  138. [138]
    GitHub Sliver C2 DNS

    BishopFox. (n.d.). Sliver DNS C2 . Retrieved September 15, 2021.

    Open source URL
  139. [139]
    Microsoft Sliver 2022

    Microsoft Security Experts. (2022, August 24). Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks. Retrieved March 24, 2025.

    Open source URL
  140. [140]
    Glitch-Cat Green Lambert ATTCK Oct 2021

    Sandvik, Runa. (2021, October 18). Green Lambert and ATT&CK. Retrieved November 17, 2024.

    Open source URL
  141. [141]
    Objective See Green Lambert for OSX Oct 2021

    Sandvik, Runa. (2021, October 1). Made In America: Green Lambert for OS X. Retrieved March 21, 2022.

    Open source URL
  142. [142]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  143. [143]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  144. [144]
    CYBERCOM Iranian Intel Cyber January 2022

    Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.

    Open source URL
  145. [145]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  146. [146]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  147. [147]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  148. [148]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  149. [149]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  150. [150]
    Medium Anchor DNS July 2020

    Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.

    Open source URL
  151. [151]
    Group IB Cobalt Aug 2017

    Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.

    Open source URL
  152. [152]
    PTSecurity Cobalt Dec 2016

    Positive Technologies. (2016, December 16). Cobalt Snatch. Retrieved October 9, 2018.

    Open source URL
  153. [153]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  154. [154]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  155. [155]
    FireEye APT34 July 2019

    Bromiley, M., et al.. (2019, July 18). Hard Pass: Declining APT34’s Invite to Join Their Professional Network. Retrieved August 26, 2019.

    Open source URL
  156. [156]
    FireEye APT34 Webinar Dec 2017

    Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.

    Open source URL
  157. [157]
    FireEye APT34 Webinar Dec 2017

    Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.

    Open source URL
  158. [158]
    Unit42 OilRig Playbook 2023

    Unit42. (2016, May 1). Evasive Serpens Unit 42 Playbook Viewer. Retrieved February 6, 2023.

    Open source URL
  159. [159]
    Kaspersky ShadowPad Aug 2017

    Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.

    Open source URL
  160. [160]
    Zscaler Cobian Aug 2017

    Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

    Open source URL
  161. [161]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  162. [162]
    BitDefender Chafer May 2020

    Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020.

    Open source URL
  163. [163]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  164. [164]
    FireEye FiveHands April 2021

    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

    Open source URL
  165. [165]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  166. [166]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  167. [167]
    FireEye APT32 May 2017

    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.

    Open source URL
  168. [168]
    fsecure NanHaiShu July 2016

    F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018.

    Open source URL
  169. [169]
    TrendMicro Tropic Trooper May 2020

    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

    Open source URL
  170. [170]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  171. [171]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  172. [172]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  173. [173]
    PaloAlto DNS Requests May 2016

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved November 15, 2018.

    Open source URL
  174. [174]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  175. [175]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  176. [176]
    ClearSky Wilted Tulip July 2017

    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

  177. [177]
    CopyKittens Nov 2015

    Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.

    Open source URL
  178. [178]
    Cisco DNSMessenger March 2017

    Brumaghin, E. and Grady, C.. (2017, March 2). Covert Channels and Poor Decisions: The Tale of DNSMessenger. Retrieved March 8, 2017.

  179. [179]
    FireEye FIN7 March 2017

    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

    Open source URL
  180. [180]
    FireEye FIN7 March 2017

    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

    Open source URL
  181. [181]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  182. [182]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  183. [183]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.