LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1082: System Information Discovery

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version).[1] On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.[2][3]

Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.[4][5][6]

System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.[7][8]

EnterpriseT1082TechniqueObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

System Information Discovery is the attacker behavior of checking what kind of machine, network device, hypervisor, or cloud instance they have reached before deciding what to do next. For leaders, this matters because it is often an early decision point in an intrusion: the information collected can influence payload choice, concealment, lateral movement planning, or whether the actor continues at all.

Executive priority

Treat this as a coverage-validation technique rather than a standalone high-severity event. It appears across many ATT&CK relationships and applies to Windows, Linux, macOS, ESXi, network devices, and IaaS environments, so the business question is whether SOC, cloud, endpoint, and network-device logging can show who queried system details, from where, and in what session context. It is especially relevant to resilience planning for cloud workloads, virtualization platforms, managed network infrastructure, and regulated environments where audit evidence depends on proving visibility into discovery activity.

Technical view

ATT&CK provides no official detection text for T1082, but it does identify a related detection strategy: DET0525, System Discovery via Native and Remote Utilities. Detection engineering should validate visibility into native system-information utilities, privileged macOS configuration queries, network device CLI activity such as version discovery, ESXi management utility usage, and authenticated IaaS API calls that return instance or VM metadata. Because legitimate administrators and management tools also perform these actions, detections should emphasize unusual user, host, privilege, timing, remote access path, sequence with other discovery activity, or execution from unexpected processes rather than command or API use alone.

Likely telemetry

  • Endpoint process creation and command-line logging for native system information utilities
  • macOS audit or endpoint telemetry for privileged configuration queries
  • Linux and Windows host logs showing process execution and user context
  • ESXi management and shell/CLI logs for system and version queries
  • Network device command accounting, administrative session logs, and configuration/CLI audit trails

Detection direction

  • Validate whether DET0525-style coverage exists across endpoints, cloud control planes, ESXi, and network devices rather than only traditional workstations and servers.
  • Tune detections around context: newly observed accounts, non-administrative users, unusual source systems, scripted or remote execution, abnormal time windows, or discovery clustered with other reconnaissance behavior.
  • Account for high false-positive potential from inventory agents, vulnerability scanners, configuration management, help desk activity, and cloud automation.
  • Confirm cloud detections distinguish routine inventory collection from unusual API use by unexpected identities, regions, workloads, or service accounts.
  • For network devices and ESXi, verify that administrative command logging is actually retained and forwarded; these platforms are common blind spots compared with endpoint telemetry.

Mitigation priorities

  • Prioritize least-privilege access for administrative interfaces, cloud APIs, ESXi management, and network device CLIs so routine users and workloads cannot broadly enumerate system details.
  • Ensure logging is enabled and centrally retained for endpoint process activity, cloud API calls, ESXi administration, and network device command sessions.
  • Baseline approved inventory, asset management, vulnerability management, and configuration management activity to reduce false positives and expose abnormal discovery.
  • Harden and monitor remote administration paths because this technique often becomes meaningful when paired with authenticated access or privileged sessions.
  • Use asset inventory and patch/status management defensively: if adversaries can query versions and patch levels, defenders should be able to prove the same data is complete and current.
Additional notes and limits

The object is an enterprise ATT&CK technique in the Discovery tactic with broad platform coverage: ESXi, IaaS, Linux, macOS, network devices, and Windows. MITRE’s description emphasizes operating system, hardware, version, patch, hotfix, service pack, architecture, ESXi, network device CLI, and cloud instance/VM information. Relationship data shows this behavior is used by multiple campaigns and groups and is detected by DET0525, but the supplied object does not provide a detailed official detection analytic.

Official detection guidance is not provided for this ATT&CK object, so detection recommendations are derived from the official description, platforms, external references, and the DET0525 relationship. This take does not assert active exploitation, current targeting, or guaranteed detection coverage. Local baselines, logging configuration, identity model, and administrative tooling are required to determine severity and alert logic.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

System Information Discovery

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version).[1] On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`.[2][3]

Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine.[4][5][6]

System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.[7][8]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0124: Windigo

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.[1][2]

GroupEnterprise

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G0128: ZIRCONIUM

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.[1][2]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0108: Blue Mockingbird

Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.[1]

GroupEnterprise

G1001: HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.[1][2][3][4]

MalwareEnterprise

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

Windows
MalwareEnterprise

S1111: DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

Windows
MalwareEnterprise

S1242: Qilin

Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.[1][2][3][4][5]

ESXiWindowsLinux
MalwareEnterprise

S1249: HexEval Loader

HexEval Loader is a hex-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail malware. HexEval Loader was first reported in April 2025. HexEval Loader has previously been leveraged by North Korea-affiliated threat actors identified as Contagious Interview. HexEval Loader has been delivered to victims through code repository sites utilizing typosquatting naming conventions of various npm packages.[1][2][3]

LinuxmacOSWindows
MalwareEnterprise

S1245: InvisibleFerret

InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities.[1][2][3] InvisibleFerret consists of four modules: main, payload, browser, and AnyDesk.[1] InvisibleFerret malware has been leveraged by North Korea-affiliated threat actors identified as DeceptiveDevelopment or Contagious Interview since 2023.[4][2][3][5] InvisibleFerret has historically been introduced to the victim environment through the use of the BeaverTail malware.[6][1][2][3][5]

LinuxmacOSWindows
MalwareEnterprise

S0266: TrickBot

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.[1][2][3][4]

Windows
MalwareEnterprise

S0553: MoleNet

MoleNet is a downloader tool with backdoor capabilities that has been observed in use since at least 2019.[1]

Windows
MalwareEnterprise

S1039: Bumblebee

Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. Bumblebee has been linked to ransomware operations including Conti, Quantum, and Mountlocker and derived its name from the appearance of "bumblebee" in the user-agent.[1][2][3]

Windows
CampaignEnterprise

C0001: Frankenstein

Frankenstein was described by security researchers as a highly-targeted campaign conducted by moderately sophisticated and highly resourceful threat actors in early 2019. The unidentified actors primarily relied on open source tools, including Empire. The campaign name refers to the actors' ability to piece together several unrelated open-source tool components.[1]

CampaignEnterprise

C0012: Operation CuckooBees

Operation CuckooBees was a cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019. Security researchers noted the goal of Operation CuckooBees, which was still ongoing as of May 2022, was likely the theft of proprietary information, research and development documents, source code, and blueprints for various technologies. Researchers assessed Operation CuckooBees was conducted by actors affiliated with Winnti Group, APT41, and BARIUM.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
5f2d907bcc26259f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.0Current bundle5f2d907bcc26…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    US-CERT-TA18-106A

    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

    Open source URL
  2. [2]
    Crowdstrike Hypervisor Jackpotting Pt 2 2021

    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.

    Open source URL
  3. [3]
    Varonis

    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

    Open source URL
  4. [4]
    Amazon Describe Instance

    Amazon. (n.d.). describe-instance-information. Retrieved March 3, 2020.

    Open source URL
  5. [5]
    Google Instances Resource

    Google. (n.d.). Rest Resource: instance. Retrieved March 3, 2020.

    Open source URL
  6. [6]
    Microsoft Virutal Machine API

    Microsoft. (2019, March 1). Virtual Machines - Get. Retrieved October 8, 2019.

    Open source URL
  7. [7]
    OSX.FairyTale

    Phile Stokes. (2018, September 20). On the Trail of OSX.FairyTale | Adware Playing at Malware. Retrieved August 24, 2021.

    Open source URL
  8. [8]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  9. [9]
    Talos Micropsia June 2017

    Rascagneres, P., Mercer, W. (2017, June 19). Delphi Used To Score Against Palestine. Retrieved November 13, 2018.

    Open source URL
  10. [10]
    Radware Micropsia July 2018

    Tsarfaty, Y. (2018, July 25). Micropsia Malware. Retrieved November 13, 2018.

    Open source URL
  11. [11]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  12. [12]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  13. [13]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  14. [14]
    Trend Micro Agenda Ransomware OCT 2025

    Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

    Open source URL
  15. [15]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  16. [16]
    Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024

    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.

    Open source URL
  17. [17]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  18. [18]
    Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.

    Open source URL
  19. [19]
    PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.

    Open source URL
  20. [20]
    S2 Grupo TrickBot June 2017

    Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.

    Open source URL
  21. [21]
    Fidelis TrickBot Oct 2016

    Reaves, J. (2016, October 15). TrickBot: We Missed you, Dyre. Retrieved August 2, 2018.

    Open source URL
  22. [22]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  23. [23]
    Eclypsium Trickboot December 2020

    Eclypsium, Advanced Intelligence. (2020, December 1). TRICKBOT NOW OFFERS ‘TRICKBOOT’: PERSIST, BRICK, PROFIT. Retrieved March 15, 2021.

    Open source URL
  24. [24]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  25. [25]
    TrendMicro TropicTrooper 2015

    Alintanahin, K. (2015). Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers. Retrieved June 14, 2019.

    Open source URL
  26. [26]
    Unit 42 CARROTBAT January 2020

    McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.

    Open source URL
  27. [27]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  28. [28]
    Google EXOTIC LILY March 2022

    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

    Open source URL
  29. [29]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  30. [30]
    Symantec Bumblebee June 2022

    Kamble, V. (2022, June 28). Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem. Retrieved August 24, 2022.

    Open source URL
  31. [31]
    Talos GravityRAT

    Mercer, W., Rascagneres, P. (2018, April 26). GravityRAT - The Two-Year Evolution Of An APT Targeting India. Retrieved May 16, 2018.

    Open source URL
  32. [32]
    Symantec Linfo May 2012

    Zhou, R. (2012, May 15). Backdoor.Linfo. Retrieved February 23, 2018.

    Open source URL
  33. [33]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  34. [34]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  35. [35]
    Check Point APT35 CharmPower January 2022

    Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.

    Open source URL
  36. [36]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  37. [37]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  38. [38]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  39. [39]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  40. [40]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  41. [41]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  42. [42]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  43. [43]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  44. [44]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  45. [45]
    CheckPoint SpeakUp Feb 2019

    Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.

    Open source URL
  46. [46]
    Unit 42 CARROTBAT November 2018

    Grunzweig, J. and Wilhoit, K. (2018, November 29). The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia. Retrieved June 2, 2020.

    Open source URL
  47. [47]
    PWC KeyBoys Feb 2017

    Parys, B. (2017, February 11). The KeyBoys are back in town. Retrieved June 13, 2019.

    Open source URL
  48. [48]
    Rapid7 KeyBoy Jun 2013

    Guarnieri, C., Schloesser M. (2013, June 7). KeyBoy, Targeted Attacks against Vietnam and India. Retrieved June 14, 2019.

    Open source URL
  49. [49]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  50. [50]
    Palo Alto OilRig Oct 2016

    Grunzweig, J. and Falcone, R.. (2016, October 4). OilRig Malware Campaign Updates Toolset and Expands Targets. Retrieved May 3, 2017.

  51. [51]
    FireEye APT34 July 2019

    Bromiley, M., et al.. (2019, July 18). Hard Pass: Declining APT34’s Invite to Join Their Professional Network. Retrieved August 26, 2019.

    Open source URL
  52. [52]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  53. [53]
    Symantec Crambus OCT 2023

    Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

    Open source URL
  54. [54]
    McAfee Maze March 2020

    Mundo, A. (2020, March 26). Ransomware Maze. Retrieved May 18, 2020.

    Open source URL
  55. [55]
    Carbon Black HotCroissant April 2020

    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

    Open source URL
  56. [56]
    Kersten Akira 2023

    Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.

    Open source URL
  57. [57]
    Proofpoint TA505 Mar 2018

    Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019.

    Open source URL
  58. [58]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  59. [59]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  60. [60]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  61. [61]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  62. [62]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  63. [63]
    ESET Turla Lunar toolset May 2024

    Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

    Open source URL
  64. [64]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  65. [65]
    ZScaler Squirrelwaffle Sep 2021

    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

    Open source URL
  66. [66]
    Rostovcev APT41 2021

    Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.

    Open source URL
  67. [67]
    Talos Manjusaka 2022

    Asheer Malhotra & Vitor Ventura. (2022, August 2). Manjusaka: A Chinese sibling of Sliver and Cobalt Strike. Retrieved September 4, 2024.

    Open source URL
  68. [68]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  69. [69]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
  70. [70]
    Trend Micro Earth Kasha Anel NOV 2024

    Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

    Open source URL
  71. [71]
    HP RaspberryRobin 2024

    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.

    Open source URL
  72. [72]
    US-CERT BLINDINGCAN Aug 2020

    US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.

    Open source URL
  73. [73]
    Mandiant UNC3313 Feb 2022

    Tomcik, R. et al. (2022, February 24). Left On Read: Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity. Retrieved August 18, 2022.

    Open source URL
  74. [74]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  75. [75]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  76. [76]
    Bitdefender Sardonic Aug 2021

    Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.

    Open source URL
  77. [77]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  78. [78]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  79. [79]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  80. [80]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  81. [81]
    Microsoft Analyzing Solorigate Dec 2020

    MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.

    Open source URL
  82. [82]
    Trustwave GoldenSpy June 2020

    Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.

    Open source URL
  83. [83]
    ESET DazzleSpy Jan 2022

    M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.

    Open source URL
  84. [84]
    F-Secure CozyDuke

    F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.

    Open source URL
  85. [85]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  86. [86]
    Cisco Talos Bitter Bangladesh May 2022

    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

    Open source URL
  87. [87]
    Splunk LAMEHUG SEP 2025

    Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

    Open source URL
  88. [88]
    Nov AI Threat Tracker

    Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.

    Open source URL
  89. [89]
    Talos Konni May 2017

    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

    Open source URL
  90. [90]
    Medium KONNI Jan 2020

    Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020.

    Open source URL
  91. [91]
    Malwarebytes Konni Aug 2021

    Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.

    Open source URL
  92. [92]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  93. [93]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  94. [94]
    Talos Frankenstein June 2019

    Adamitis, D. et al. (2019, June 4). It's alive: Threat actors cobble together open-source pieces into monstrous Frankenstein campaign. Retrieved May 11, 2020.

    Open source URL
  95. [95]
    Socket BeaverTail XORIndex HexEval Contagious Interview July 2025

    Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.

    Open source URL
  96. [96]
    SocGholish-update

    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

    Open source URL
  97. [97]
    Red Canary SocGholish March 2024

    Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.

    Open source URL
  98. [98]
    Secureworks Gold Prelude Profile

    Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.

    Open source URL
  99. [99]
    Kaspersky ShrinkLocker 2024

    Cristian Souza, Eduardo Ovalle, Ashley Muñoz, & Christopher Zachor. (2024, May 23). ShrinkLocker: Turning BitLocker into ransomware. Retrieved December 7, 2024.

    Open source URL
  100. [100]
    Splunk ShrinkLocker 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

    Open source URL
  101. [101]
    Securelist Dtrack

    Konstantin Zykov. (2019, September 23). Hello! My name is Dtrack. Retrieved January 20, 2021.

    Open source URL
  102. [102]
    CyberBit Dtrack

    Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021.

    Open source URL
  103. [103]
    RedCanary Mockingbird May 2020

    Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

    Open source URL
  104. [104]
    TrendMicro Netwalker May 2020

    Victor, K.. (2020, May 18). Netwalker Fileless Ransomware Injected via Reflective Loading . Retrieved May 26, 2020.

    Open source URL
  105. [105]
    Volexity InkySquid BLUELIGHT August 2021

    Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.

    Open source URL
  106. [106]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  107. [107]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  108. [108]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  109. [109]
    Volexity PowerDuke November 2016

    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

    Open source URL
  110. [110]
    Cybereason OperationCuckooBees May 2022

    Cybereason Nocturnus. (2022, May 4). Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques. Retrieved September 22, 2022.

    Open source URL
  111. [111]
    Talos ZxShell Oct 2014

    Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019.

    Open source URL
  112. [112]
    Cybereason Royal December 2022

    Cybereason Global SOC and Cybereason Security Research Teams. (2022, December 14). Royal Rumble: Analysis of Royal Ransomware. Retrieved March 30, 2023.

    Open source URL
  113. [113]
    Trend Micro Royal Linux ESXi February 2023

    Morales, N. et al. (2023, February 20). Royal Ransomware Expands Attacks by Targeting Linux ESXi Servers. Retrieved March 30, 2023.

    Open source URL
  114. [114]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  115. [115]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  116. [116]
    Medium Anchor DNS July 2020

    Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.

    Open source URL
  117. [117]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  118. [118]
    Palo Alto Ashen Lepus DEC 2025

    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

    Open source URL
  119. [119]
    ESET PipeMon May 2020

    Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020.

    Open source URL
  120. [120]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  121. [121]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  122. [122]
    Amazon Describe Instance

    Amazon. (n.d.). describe-instance-information. Retrieved March 3, 2020.

    Open source URL
  123. [123]
    Amazon Describe Instance

    Amazon. (n.d.). describe-instance-information. Retrieved March 3, 2020.

    Open source URL
  124. [124]
    Crowdstrike Hypervisor Jackpotting Pt 2 2021

    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.

    Open source URL
  125. [125]
    Crowdstrike Hypervisor Jackpotting Pt 2 2021

    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.

    Open source URL
  126. [126]
    Google Instances Resource

    Google. (n.d.). Rest Resource: instance. Retrieved March 3, 2020.

    Open source URL
  127. [127]
    Google Instances Resource

    Google. (n.d.). Rest Resource: instance. Retrieved March 3, 2020.

    Open source URL
  128. [128]
    Microsoft Virutal Machine API

    Microsoft. (2019, March 1). Virtual Machines - Get. Retrieved October 8, 2019.

    Open source URL
  129. [129]
    Microsoft Virutal Machine API

    Microsoft. (2019, March 1). Virtual Machines - Get. Retrieved October 8, 2019.

    Open source URL
  130. [130]
    OSX.FairyTale

    Phile Stokes. (2018, September 20). On the Trail of OSX.FairyTale | Adware Playing at Malware. Retrieved August 24, 2021.

    Open source URL
  131. [131]
    OSX.FairyTale

    Phile Stokes. (2018, September 20). On the Trail of OSX.FairyTale | Adware Playing at Malware. Retrieved August 24, 2021.

    Open source URL
  132. [132]
    US-CERT-TA18-106A

    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

    Open source URL
  133. [133]
    US-CERT-TA18-106A

    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

    Open source URL
  134. [134]
    Varonis

    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

    Open source URL
  135. [135]
    Varonis

    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

    Open source URL
  136. [136]
    mitre-attackT1082
    Open source URL
  137. [137]
    mitre-attackT1082
    Open source URL
  138. [138]
    mitre-attackT1082
    Open source URL
  139. [139]
    Radware Micropsia July 2018

    Tsarfaty, Y. (2018, July 25). Micropsia Malware. Retrieved November 13, 2018.

    Open source URL
  140. [140]
    Talos Micropsia June 2017

    Rascagneres, P., Mercer, W. (2017, June 19). Delphi Used To Score Against Palestine. Retrieved November 13, 2018.

    Open source URL
  141. [141]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  142. [142]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  143. [143]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  144. [144]
    Trend Micro Agenda Ransomware OCT 2025

    Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

    Open source URL
  145. [145]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  146. [146]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  147. [147]
    Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024

    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.

    Open source URL
  148. [148]
    PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.

    Open source URL
  149. [149]
    Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.

    Open source URL
  150. [150]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  151. [151]
    Eclypsium Trickboot December 2020

    Eclypsium, Advanced Intelligence. (2020, December 1). TRICKBOT NOW OFFERS ‘TRICKBOOT’: PERSIST, BRICK, PROFIT. Retrieved March 15, 2021.

    Open source URL
  152. [152]
    Fidelis TrickBot Oct 2016

    Reaves, J. (2016, October 15). TrickBot: We Missed you, Dyre. Retrieved August 2, 2018.

    Open source URL
  153. [153]
    S2 Grupo TrickBot June 2017

    Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.

    Open source URL
  154. [154]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  155. [155]
    TrendMicro TropicTrooper 2015

    Alintanahin, K. (2015). Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers. Retrieved June 14, 2019.

    Open source URL
  156. [156]
    Unit 42 CARROTBAT January 2020

    McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.

    Open source URL
  157. [157]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  158. [158]
    Google EXOTIC LILY March 2022

    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

    Open source URL
  159. [159]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  160. [160]
    Symantec Bumblebee June 2022

    Kamble, V. (2022, June 28). Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem. Retrieved August 24, 2022.

    Open source URL
  161. [161]
    Talos GravityRAT

    Mercer, W., Rascagneres, P. (2018, April 26). GravityRAT - The Two-Year Evolution Of An APT Targeting India. Retrieved May 16, 2018.

    Open source URL
  162. [162]
    Symantec Linfo May 2012

    Zhou, R. (2012, May 15). Backdoor.Linfo. Retrieved February 23, 2018.

    Open source URL
  163. [163]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  164. [164]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  165. [165]
    Check Point APT35 CharmPower January 2022

    Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.

    Open source URL
  166. [166]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  167. [167]
    ESET ForSSHe December 2018

    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

    Open source URL
  168. [168]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  169. [169]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  170. [170]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  171. [171]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  172. [172]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  173. [173]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  174. [174]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  175. [175]
    CheckPoint SpeakUp Feb 2019

    Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.

    Open source URL
  176. [176]
    Unit 42 CARROTBAT January 2020

    McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.

    Open source URL
  177. [177]
    Unit 42 CARROTBAT January 2020

    McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.

    Open source URL
  178. [178]
    Unit 42 CARROTBAT November 2018

    Grunzweig, J. and Wilhoit, K. (2018, November 29). The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia. Retrieved June 2, 2020.

    Open source URL
  179. [179]
    PWC KeyBoys Feb 2017

    Parys, B. (2017, February 11). The KeyBoys are back in town. Retrieved June 13, 2019.

    Open source URL
  180. [180]
    Rapid7 KeyBoy Jun 2013

    Guarnieri, C., Schloesser M. (2013, June 7). KeyBoy, Targeted Attacks against Vietnam and India. Retrieved June 14, 2019.

    Open source URL
  181. [181]
    Check Point APT34 April 2021

    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

    Open source URL
  182. [182]
    FireEye APT34 July 2019

    Bromiley, M., et al.. (2019, July 18). Hard Pass: Declining APT34’s Invite to Join Their Professional Network. Retrieved August 26, 2019.

    Open source URL
  183. [183]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  184. [184]
    Palo Alto OilRig Oct 2016

    Grunzweig, J. and Falcone, R.. (2016, October 4). OilRig Malware Campaign Updates Toolset and Expands Targets. Retrieved May 3, 2017.

  185. [185]
    Symantec Crambus OCT 2023

    Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

    Open source URL
  186. [186]
    McAfee Maze March 2020

    Mundo, A. (2020, March 26). Ransomware Maze. Retrieved May 18, 2020.

    Open source URL
  187. [187]
    Carbon Black HotCroissant April 2020

    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

    Open source URL
  188. [188]
    Kersten Akira 2023

    Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.

    Open source URL
  189. [189]
    Proofpoint TA505 Mar 2018

    Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019.

    Open source URL
  190. [190]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  191. [191]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  192. [192]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  193. [193]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  194. [194]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  195. [195]
    ESET Turla Lunar toolset May 2024

    Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

    Open source URL
  196. [196]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  197. [197]
    ZScaler Squirrelwaffle Sep 2021

    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

    Open source URL
  198. [198]
    Rostovcev APT41 2021

    Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.

    Open source URL
  199. [199]
    Talos Manjusaka 2022

    Asheer Malhotra & Vitor Ventura. (2022, August 2). Manjusaka: A Chinese sibling of Sliver and Cobalt Strike. Retrieved September 4, 2024.

    Open source URL
  200. [200]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
  201. [201]
    Talos Cobalt Group July 2018

    Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.

    Open source URL
  202. [202]
    Trend Micro Earth Kasha Anel NOV 2024

    Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

    Open source URL
  203. [203]
    HP RaspberryRobin 2024

    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.

    Open source URL
  204. [204]
    US-CERT BLINDINGCAN Aug 2020

    US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.

    Open source URL
  205. [205]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  206. [206]
    Mandiant UNC3313 Feb 2022

    Tomcik, R. et al. (2022, February 24). Left On Read: Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity. Retrieved August 18, 2022.

    Open source URL
  207. [207]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  208. [208]
    Bitdefender Sardonic Aug 2021

    Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.

    Open source URL
  209. [209]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  210. [210]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  211. [211]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  212. [212]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  213. [213]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  214. [214]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  215. [215]
    Microsoft Analyzing Solorigate Dec 2020

    MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.

    Open source URL
  216. [216]
    Trustwave GoldenSpy June 2020

    Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.

    Open source URL
  217. [217]
    ESET DazzleSpy Jan 2022

    M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022.

    Open source URL
  218. [218]
    F-Secure CozyDuke

    F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.

    Open source URL
  219. [219]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  220. [220]
    Cisco Talos Bitter Bangladesh May 2022

    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

    Open source URL
  221. [221]
    Nov AI Threat Tracker

    Google Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.

    Open source URL
  222. [222]
    Splunk LAMEHUG SEP 2025

    Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.

    Open source URL
  223. [223]
    Malwarebytes Konni Aug 2021

    Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.

    Open source URL
  224. [224]
    Medium KONNI Jan 2020

    Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020.

    Open source URL
  225. [225]
    Talos Konni May 2017

    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

    Open source URL
  226. [226]
    Unit 42 Inception November 2018

    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

    Open source URL
  227. [227]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  228. [228]
    Talos Frankenstein June 2019

    Adamitis, D. et al. (2019, June 4). It's alive: Threat actors cobble together open-source pieces into monstrous Frankenstein campaign. Retrieved May 11, 2020.

    Open source URL
  229. [229]
    Socket BeaverTail XORIndex HexEval Contagious Interview July 2025

    Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.

    Open source URL
  230. [230]
    Red Canary SocGholish March 2024

    Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.

    Open source URL
  231. [231]
    Secureworks Gold Prelude Profile

    Secureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.

    Open source URL
  232. [232]
    SocGholish-update

    Andrew Northern. (2022, November 22). SocGholish, a very real threat from a very fake update. Retrieved February 13, 2024.

    Open source URL
  233. [233]
    Kaspersky ShrinkLocker 2024

    Cristian Souza, Eduardo Ovalle, Ashley Muñoz, & Christopher Zachor. (2024, May 23). ShrinkLocker: Turning BitLocker into ransomware. Retrieved December 7, 2024.

    Open source URL
  234. [234]
    Splunk ShrinkLocker 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

    Open source URL
  235. [235]
    CyberBit Dtrack

    Hod Gavriel. (2019, November 21). Dtrack: In-depth analysis of APT on a nuclear power plant. Retrieved January 20, 2021.

    Open source URL
  236. [236]
    Securelist Dtrack

    Konstantin Zykov. (2019, September 23). Hello! My name is Dtrack. Retrieved January 20, 2021.

    Open source URL
  237. [237]
    RedCanary Mockingbird May 2020

    Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

    Open source URL
  238. [238]
    TrendMicro Netwalker May 2020

    Victor, K.. (2020, May 18). Netwalker Fileless Ransomware Injected via Reflective Loading . Retrieved May 26, 2020.

    Open source URL
  239. [239]
    Volexity InkySquid BLUELIGHT August 2021

    Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.

    Open source URL
  240. [240]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  241. [241]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  242. [242]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  243. [243]
    Volexity PowerDuke November 2016

    Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.

    Open source URL
  244. [244]
    Cybereason OperationCuckooBees May 2022

    Cybereason Nocturnus. (2022, May 4). Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques. Retrieved September 22, 2022.

    Open source URL
  245. [245]
    Talos ZxShell Oct 2014

    Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019.

    Open source URL
  246. [246]
    Cybereason Royal December 2022

    Cybereason Global SOC and Cybereason Security Research Teams. (2022, December 14). Royal Rumble: Analysis of Royal Ransomware. Retrieved March 30, 2023.

    Open source URL
  247. [247]
    Trend Micro Royal Linux ESXi February 2023

    Morales, N. et al. (2023, February 20). Royal Ransomware Expands Attacks by Targeting Linux ESXi Servers. Retrieved March 30, 2023.

    Open source URL
  248. [248]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  249. [249]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  250. [250]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  251. [251]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  252. [252]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  253. [253]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  254. [254]
    Medium Anchor DNS July 2020

    Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.

    Open source URL
  255. [255]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  256. [256]
    Palo Alto Ashen Lepus DEC 2025

    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

    Open source URL
  257. [257]
    ESET PipeMon May 2020

    Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.