LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1110: Brute Force

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.[1] Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism.[2] Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Brute forcing credentials may take place at various points during a breach. For example, adversaries may attempt to brute force access to Valid Accounts within a victim environment leveraging knowledge gathered from other post-compromise behaviors such as OS Credential Dumping, Account Discovery, or Password Policy Discovery. Adversaries may also combine brute forcing activity with behaviors such as External Remote Services as part of Initial Access.

If an adversary guesses the correct password but fails to login to a compromised account due to location-based conditional access policies, they may change their infrastructure until they match the victim’s location and therefore bypass those policies.[3]

EnterpriseT1110TechniqueObject v2.8Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Brute Force matters because it turns weak, reused, or poorly governed credentials into a direct path to valid account access across cloud, SaaS, identity providers, endpoints, network devices, ESXi, and container environments. For leaders, this is less a “password problem” than a resilience and identity assurance problem: if authentication telemetry, lockout policies, MFA, and account lifecycle controls are inconsistent, attackers may have many places to test credentials with limited visibility.

Executive priority

Treat T1110 as a priority control-validation area for identity security, remote access exposure, cloud access, and audit readiness. The ATT&CK relationships show this behavior is broad enough to appear across espionage, financially motivated, and critical infrastructure-related reporting, including a campaign associated with disruption of Ukrainian electric power substations. Executives should ask whether high-value accounts, external services, identity providers, SaaS, IaaS, and administrative interfaces are protected by MFA, sane account use policies, strong password policies, and accountable user lifecycle management.

Technical view

SOC and IR teams should validate coverage around credential-access activity rather than relying on a single failed-login rule. ATT&CK provides no official detection text for T1110, but the related detection strategy DET0463 points to brute force authentication failures with multi-platform log correlation. Detection engineering should distinguish single-account guessing, password spraying across many accounts, credential stuffing using reused credentials, and offline password cracking after credential material such as hashes is obtained. Investigations should also consider related context from the description: OS Credential Dumping, Account Discovery, Password Policy Discovery, External Remote Services, and attempts to bypass location-based conditional access by changing infrastructure.

Likely telemetry

  • Identity provider authentication success and failure logs
  • SaaS and office suite sign-in logs
  • IaaS control plane authentication logs
  • VPN, remote access, and external service authentication logs where available
  • Windows, Linux, macOS, ESXi, network device, and container platform authentication logs

Detection direction

  • Validate correlation across platforms, not only domain controller or endpoint logs, because the listed platforms include identity providers, SaaS, IaaS, ESXi, containers, network devices, and traditional operating systems.
  • Tune for both high-volume failures against one account and low-and-slow spraying across many accounts to reduce blind spots created by account lockout avoidance.
  • Track successful login after repeated failures, unusual source changes, or conditional access denials followed by later success from a different location or infrastructure.
  • Separate likely user error from attack patterns by considering time window, account count, password reset activity, source diversity, asset criticality, and whether attempts target privileged or dormant accounts.
  • For offline cracking, look for upstream evidence such as credential material access or OS Credential Dumping rather than expecting authentication-failure telemetry to show the cracking itself.

Mitigation priorities

  • Prioritize Multi-factor Authentication for critical, privileged, remote, cloud, SaaS, and identity-provider-backed access paths.
  • Enforce Account Use Policies such as lockout, login restrictions, and inactivity controls with care to avoid avoidable business disruption from denial-of-service via lockouts.
  • Strengthen Password Policies to reduce guessability and reuse risk while validating that policies apply consistently across cloud, SaaS, endpoints, network devices, ESXi, and container-related authentication surfaces.
  • Improve User Account Management by removing stale accounts, limiting privileges, and ensuring account creation, modification, and deactivation are governed and auditable.
  • Use detection results to identify control gaps: systems with missing logs, accounts without MFA, inconsistent lockout behavior, and externally reachable services with weak authentication protections.
Additional notes and limits

The most useful Glexia assessment for T1110 is a control-and-telemetry coverage review: where can credentials be tested, what logs prove it, which accounts are protected by MFA and account policies, and where can an attacker avoid lockouts by distributing attempts. Relationship context to multiple groups and campaigns supports broad relevance, but local risk depends on exposed services, identity architecture, password practices, and logging maturity.

ATT&CK does not provide official detection guidance for this object in the supplied fields. The take is therefore based on the official description, listed platforms and tactic, the DET0463 detection-strategy relationship, mitigation relationships M1018, M1027, M1032, and M1036, and sub-technique relationships T1110.001 through T1110.004. It does not assert active exploitation, customer exposure, attribution, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Brute Force

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.[1] Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism.[2] Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Brute forcing credentials may take place at various points during a breach. For example, adversaries may attempt to brute force access to Valid Accounts within a victim environment leveraging knowledge gathered from other post-compromise behaviors such as OS Credential Dumping, Account Discovery, or Password Policy Discovery. Adversaries may also combine brute forcing activity with behaviors such as External Remote Services as part of Initial Access.

If an adversary guesses the correct password but fails to login to a compromised account due to location-based conditional access policies, they may change their infrastructure until they match the victim’s location and therefore bypass those policies.[3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

4 rows
DomainIDNameRelationship / procedure
EnterpriseT1110.004Credential StuffingSub-techniqueCredential Stuffing subtechnique of this object.
EnterpriseT1110.002Password CrackingSub-techniquePassword Cracking subtechnique of this object.
EnterpriseT1110.001Password GuessingSub-techniquePassword Guessing subtechnique of this object.
EnterpriseT1110.003Password SprayingSub-techniquePassword Spraying subtechnique of this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0117: Fox Kitten

Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.[1][2][3][4]

GroupEnterprise

G1001: HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.[1][2][3][4]

GroupEnterprise

G1003: Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

GroupEnterprise

G0010: Turla

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.[1][2][3][4][5]

GroupEnterprise

G0105: DarkVishnya

DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.[1]

GroupEnterprise

G0053: FIN5

FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian. [1] [2] [3]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0082: APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G1030: Agrius

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.[1][2] Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).[3]

GroupEnterprise

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.[1][2][3][4][5]

GroupEnterprise

G0035: Dragonfly

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.[1][2] Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.[3][4][5][6][7][8][9]

MalwareEnterprise

S0220: Chaos

Chaos is Linux malware that compromises systems by brute force attacks against SSH services. Once installed, it provides a reverse shell to its controllers, triggered by unsolicited packets. [1]

Linux
MalwareEnterprise

S0599: Kinsing

Kinsing is Golang-based malware that runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim environment. [1][2][3]

ContainersLinux
ToolEnterprise

S0378: PoshC2

PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.[1]

WindowsLinuxmacOS
MalwareEnterprise

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

Windows
MalwareEnterprise

S0583: Pysa

Pysa is a ransomware that was first used in October 2018 and has been seen to target particularly high-value finance, government and healthcare organizations.[1]

Windows
ToolEnterprise

S0488: CrackMapExec

CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.[1]

Windows
CampaignEnterprise

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.8
Created
Modified
Raw hash
7dd9d94dbd639e98...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.8Current bundle7dd9d94dbd63…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
  2. [2]
    Dragos Crashoverride 2018

    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.

    Open source URL
  3. [3]
    ReliaQuest Health Care Social Engineering Campaign 2024

    Hayden Evans. (2024, April 4). Health Care Social Engineering Campaign. Retrieved May 22, 2025.

    Open source URL
  4. [4]
    ClearSky Pay2Kitten December 2020

    ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.

    Open source URL
  5. [5]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  6. [6]
    Chaos Stolen Backdoor

    Sebastian Feldmann. (2018, February 14). Chaos: a Stolen Backdoor Rising Again. Retrieved March 5, 2018.

  7. [7]
    ClearSky Lebanese Cedar Jan 2021

    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

    Open source URL
  8. [8]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  9. [9]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  10. [10]
    Securelist DarkVishnya Dec 2018

    Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020.

    Open source URL
  11. [11]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  12. [12]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  13. [13]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  14. [14]
    Aqua Kinsing April 2020

    Singer, G. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved April 1, 2021.

    Open source URL
  15. [15]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  16. [16]
    CISA AA20-239A BeagleBoyz August 2020

    DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.

    Open source URL
  17. [17]
    FireEye APT34 Webinar Dec 2017

    Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.

    Open source URL
  18. [18]
    IBM ZeroCleare Wiper December 2019

    Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.

    Open source URL
  19. [19]
    GitHub PoshC2

    Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.

    Open source URL
  20. [20]
    Kroll Qakbot June 2020

    Sette, N. et al. (2020, June 4). Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks. Retrieved September 27, 2021.

    Open source URL
  21. [21]
    Crowdstrike Qakbot October 2020

    CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.

    Open source URL
  22. [22]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  23. [23]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  24. [24]
    Microsoft Common Conditional Access Policies

    Microsoft. (2022, December 14). Conditional Access templates. Retrieved February 21, 2023.

    Open source URL
  25. [25]
    Okta Block Anonymizing Services

    Moussa Diallo and Brett Winterford. (2024, April 26). How to Block Anonymizing Services using Okta. Retrieved May 28, 2024.

    Open source URL
  26. [26]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  27. [27]
    NIST 800-63-3

    Grassi, P., et al. (2017, December 1). SP 800-63-3, Digital Identity Guidelines. Retrieved January 16, 2019.

    Open source URL
  28. [28]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  29. [29]
    CERT-FR PYSA April 2020

    CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021.

    Open source URL
  30. [30]
    Check Point VOID MANTICORE Handala Hack March 2026

    Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.

    Open source URL
  31. [31]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  32. [32]
    CME Github September 2018

    byt3bl33d3r. (2018, September 8). SMB: Command Reference. Retrieved July 17, 2020.

    Open source URL
  33. [33]
    TrendMicro Pawn Storm 2019

    Hacquebord, F. (n.d.). Pawn Storm in 2019 A Year of Scanning and Credential Phishing on High-Profile Targets. Retrieved December 29, 2020.

    Open source URL
  34. [34]
    Microsoft Targeting Elections September 2020

    Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.

    Open source URL
  35. [35]
    Dragos Crashoverride 2018

    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.

    Open source URL
  36. [36]
    Dragos Crashoverride 2018

    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.

    Open source URL
  37. [37]
    ReliaQuest Health Care Social Engineering Campaign 2024

    Hayden Evans. (2024, April 4). Health Care Social Engineering Campaign. Retrieved May 22, 2025.

    Open source URL
  38. [38]
    ReliaQuest Health Care Social Engineering Campaign 2024

    Hayden Evans. (2024, April 4). Health Care Social Engineering Campaign. Retrieved May 22, 2025.

    Open source URL
  39. [39]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
  40. [40]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
  41. [41]
    mitre-attackT1110
    Open source URL
  42. [42]
    mitre-attackT1110
    Open source URL
  43. [43]
    mitre-attackT1110
    Open source URL
  44. [44]
    ClearSky Pay2Kitten December 2020

    ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.

    Open source URL
  45. [45]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  46. [46]
    Chaos Stolen Backdoor

    Sebastian Feldmann. (2018, February 14). Chaos: a Stolen Backdoor Rising Again. Retrieved March 5, 2018.

  47. [47]
    ClearSky Lebanese Cedar Jan 2021

    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

    Open source URL
  48. [48]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  49. [49]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  50. [50]
    Securelist DarkVishnya Dec 2018

    Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020.

    Open source URL
  51. [51]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  52. [52]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  53. [53]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  54. [54]
    Aqua Kinsing April 2020

    Singer, G. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved April 1, 2021.

    Open source URL
  55. [55]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  56. [56]
    CISA AA20-239A BeagleBoyz August 2020

    DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.

    Open source URL
  57. [57]
    FireEye APT34 Webinar Dec 2017

    Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.

    Open source URL
  58. [58]
    IBM ZeroCleare Wiper December 2019

    Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.

    Open source URL
  59. [59]
    GitHub PoshC2

    Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.

    Open source URL
  60. [60]
    Crowdstrike Qakbot October 2020

    CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.

    Open source URL
  61. [61]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  62. [62]
    Kroll Qakbot June 2020

    Sette, N. et al. (2020, June 4). Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks. Retrieved September 27, 2021.

    Open source URL
  63. [63]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  64. [64]
    Microsoft Common Conditional Access Policies

    Microsoft. (2022, December 14). Conditional Access templates. Retrieved February 21, 2023.

    Open source URL
  65. [65]
    Okta Block Anonymizing Services

    Moussa Diallo and Brett Winterford. (2024, April 26). How to Block Anonymizing Services using Okta. Retrieved May 28, 2024.

    Open source URL
  66. [66]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  67. [67]
    Dragos Crashoverride 2018

    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.

    Open source URL
  68. [68]
    Dragos Crashoverride 2018

    Joe Slowik. (2018, October 12). Anatomy of an Attack: Detecting and Defeating CRASHOVERRIDE. Retrieved December 18, 2020.

    Open source URL
  69. [69]
    NIST 800-63-3

    Grassi, P., et al. (2017, December 1). SP 800-63-3, Digital Identity Guidelines. Retrieved January 16, 2019.

    Open source URL
  70. [70]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  71. [71]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.