LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1125: Video Capture

An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.

Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture video or images. Video or image files may be written to disk and exfiltrated later. This technique differs from Screen Capture due to use of specific devices or applications for video recording rather than capturing the victim's screen.

In macOS, there are a few different malware samples that record the user's webcam such as FruitFly and Proton. [1]

EnterpriseT1125TechniqueObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Video Capture matters because it turns an endpoint peripheral or video application into an intelligence collection source. For leaders, the issue is not only malware recording a webcam; it is whether the organization can prove that camera-capable endpoints, conference-room systems, and user devices have enforceable access controls, usable telemetry, and an incident response path when unauthorized recording is suspected.

Executive priority

Prioritize this technique where sensitive discussions, regulated data, executive activity, operational facilities, or financial workflows occur near camera-enabled systems. The ATT&CK relationships show use by multiple groups and many remote access or spyware tools, so coverage should be treated as a privacy, insider-risk, espionage, and incident-readiness control question rather than a narrow malware signature problem.

Technical view

T1125 is a collection technique on Linux, macOS, and Windows. ATT&CK does not provide official detection text, but a related detection strategy, DET0197, is mapped to this technique. SOC and detection teams should validate whether they can observe unexpected processes interacting with camera devices or video-call applications, creation of image/video files by unusual processes, and subsequent staging or exfiltration context. Relationship context is important: many mapped software families are RATs, spyware, or post-exploitation frameworks, so detection should correlate video capture behavior with remote access, persistence, command-and-control, and file collection activity rather than relying on a single event.

Likely telemetry

  • Endpoint process telemetry for processes accessing camera devices or video-capture APIs
  • Operating system or application permission events for camera access where available
  • File creation telemetry for image or video artifacts written by unusual processes
  • Application logs from video call or camera-capable applications where available
  • EDR alerts or behavioral events associated with RAT/spyware activity

Detection direction

  • Validate DET0197-style behavior-chain coverage in the local environment; ATT&CK does not include native detection guidance for this technique.
  • Tune for unusual parent/child process relationships and non-business processes accessing camera devices or producing media files.
  • Baseline approved video applications to reduce false positives from normal conferencing, recording, accessibility, or support tools.
  • Correlate video capture indicators with mapped software context such as RATs, spyware, and post-exploitation frameworks rather than treating camera access alone as conclusive malicious activity.
  • Check blind spots on endpoints without camera permission logging, unmanaged peripherals, conference-room systems, and systems where EDR visibility is limited.

Mitigation priorities

  • Inventory camera-enabled endpoints and systems in sensitive business areas.
  • Restrict camera access to approved applications and users where platform controls allow it.
  • Apply least-privilege and application-control principles to reduce unauthorized RAT, spyware, or post-exploitation tool execution.
  • Review endpoint hardening and privacy settings across Linux, macOS, and Windows rather than assuming a single platform policy covers all cases.
  • Ensure incident response procedures include privacy, legal, communications, and evidence-handling steps for suspected unauthorized recording.
Additional notes and limits

The object is a collection technique, not an exploit or vulnerability. Its importance comes from the sensitivity of what may be observed and from its repeated mapping to groups and software in ATT&CK, including FIN7, Silence, Ember Bear, VOID MANTICORE, and multiple RAT/spyware families. Local risk depends heavily on where cameras exist, what users do near them, and whether endpoint telemetry records camera access or media creation.

Official ATT&CK detection guidance is not provided for T1125, and the relationship to DET0197 does not include detection details in the supplied fields. This take does not assert current activity, customer exposure, or guaranteed detection. Control and telemetry recommendations must be validated against the organization’s actual platforms, applications, privacy settings, and logging capabilities.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Video Capture

An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.

Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture video or images. Video or image files may be written to disk and exfiltrated later. This technique differs from Screen Capture due to use of specific devices or applications for video recording rather than capturing the victim's screen.

In macOS, there are a few different malware samples that record the user's webcam such as FruitFly and Proton. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1003: Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

GroupEnterprise

G0091: Silence

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.[1][2]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G1055: VOID MANTICORE

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).[1] Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.[1][2] VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.[1][3] VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.[4]

ToolEnterprise

S0363: Empire

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]

LinuxmacOSWindows
MalwareEnterprise

S0467: TajMahal

TajMahal is a multifunctional spying framework that has been in use since at least 2014. TajMahal is comprised of two separate packages, named Tokyo and Yokohama, and can deploy up to 80 plugins.[1]

Windows
MalwareEnterprise

S0336: NanoCore

NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013.[1][2][3][4]

Windows
MalwareEnterprise

S0283: jRAT

jRAT is a cross-platform, Java-based backdoor originally available for purchase in 2012. Variants of jRAT have been distributed via a software-as-a-service platform, similar to an online subscription model.[1] [2]

LinuxWindowsmacOS
MalwareEnterprise

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
5fbfdc7d2557c6fc...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle5fbfdc7d2557…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    objective-see 2017 review

    Patrick Wardle. (n.d.). Retrieved March 20, 2018.

    Open source URL
  2. [2]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  3. [3]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  4. [4]
    Talent-Jump Clambling February 2020

    Chen, T. and Chen, Z. (2020, February 17). CLAMBLING - A New Backdoor Base On Dropbox. Retrieved November 12, 2021.

    Open source URL
  5. [5]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  6. [6]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  7. [7]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  8. [8]
    Zscaler Cobian Aug 2017

    Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

    Open source URL
  9. [9]
    DigiTrust NanoCore Jan 2017

    The DigiTrust Group. (2017, January 01). NanoCore Is Not Your Average RAT. Retrieved November 9, 2018.

    Open source URL
  10. [10]
    PaloAlto NanoCore Feb 2016

    Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.

    Open source URL
  11. [11]
    jRAT Symantec Aug 2018

    Sharma, R. (2018, August 15). Revamped jRAT Uses New Anti-Parsing Techniques. Retrieved September 21, 2018.

    Open source URL
  12. [12]
    Kaspersky Adwind Feb 2016

    Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.

    Open source URL
  13. [13]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  14. [14]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  15. [15]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  16. [16]
    Cylance Shaheen Nov 2018

    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

    Open source URL
  17. [17]
    Cofense RevengeRAT Feb 2019

    Gannon, M. (2019, February 11). With Upgrades in Delivery and Support Infrastructure, Revenge RAT Malware is a Bigger Threat. Retrieved November 17, 2024.

    Open source URL
  18. [18]
    TrendMicro DarkComet Sept 2014

    TrendMicro. (2014, September 03). DARKCOMET. Retrieved November 6, 2018.

    Open source URL
  19. [19]
    Malwarebytes DarkComet March 2018

    Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.

    Open source URL
  20. [20]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  21. [21]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  22. [22]
    DigiTrust Agent Tesla Jan 2017

    The DigiTrust Group. (2017, January 12). The Rise of Agent Tesla. Retrieved November 5, 2018.

    Open source URL
  23. [23]
    Talos Agent Tesla Oct 2018

    Brumaghin, E., et al. (2018, October 15). Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox. Retrieved November 5, 2018.

    Open source URL
  24. [24]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  25. [25]
    Talos PoetRAT April 2020

    Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.

    Open source URL
  26. [26]
    SecureList Silence Nov 2017

    GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.

    Open source URL
  27. [27]
    Group IB Silence Sept 2018

    Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.

    Open source URL
  28. [28]
    Imminent Unit42 Dec2019

    Unit 42. (2019, December 2). Imminent Monitor – a RAT Down Under. Retrieved May 5, 2020.

    Open source URL
  29. [29]
    QiAnXin APT-C-36 Feb2019

    QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

    Open source URL
  30. [30]
    Anomali Static Kitten February 2021

    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

    Open source URL
  31. [31]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  32. [32]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  33. [33]
    AsyncRAT GitHub

    Nyan-x-Cat. (n.d.). NYAN-x-CAT / AsyncRAT-C-Sharp. Retrieved October 3, 2023.

    Open source URL
  34. [34]
    Proofpoint TA505 October 2019

    Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.

    Open source URL
  35. [35]
    IBM TA505 April 2020

    Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.

    Open source URL
  36. [36]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  37. [37]
    DOJ FIN7 Aug 2018

    Department of Justice. (2018, August 01). HOW FIN7 ATTACKED AND STOLE DATA. Retrieved August 24, 2018.

    Open source URL
  38. [38]
    Microsoft Quick Assist 2024

    Microsoft. (2024, September 4). Use Quick Assist to help users. Retrieved March 14, 2025.

    Open source URL
  39. [39]
    Microsoft Storm-1811 2024

    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

    Open source URL
  40. [40]
    Talos ZxShell Oct 2014

    Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019.

    Open source URL
  41. [41]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  42. [42]
    Uptycs Warzone UAC Bypass November 2020

    Mohanta, A. (2020, November 25). Warzone RAT comes with UAC bypass technique. Retrieved April 7, 2022.

    Open source URL
  43. [43]
    GitHub Pupy

    Nicolas Verdier. (n.d.). Retrieved January 29, 2018.

    Open source URL
  44. [44]
    EFF Manul Aug 2016

    Galperin, E., Et al.. (2016, August). I Got a Letter From the Government the Other Day.... Retrieved April 25, 2018.

    Open source URL
  45. [45]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  46. [46]
    FBI IC3 Flash VOID MANTICORE Handala Hack March 2026

    FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. Retrieved April 20, 2026.

    Open source URL
  47. [47]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  48. [48]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  49. [49]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  50. [50]
    Talos Oblique RAT March 2021

    Malhotra, A. (2021, March 2). ObliqueRAT returns with new campaign using hijacked websites. Retrieved September 2, 2021.

    Open source URL
  51. [51]
    Palo Alto T9000 Feb 2016

    Grunzweig, J. and Miller-Osborn, J.. (2016, February 4). T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques. Retrieved April 15, 2016.

  52. [52]
    GitHub QuasarRAT

    MaxXor. (n.d.). QuasarRAT. Retrieved July 10, 2018.

    Open source URL
  53. [53]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  54. [54]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  55. [55]
    mitre-attackT1125
    Open source URL
  56. [56]
    mitre-attackT1125
    Open source URL
  57. [57]
    mitre-attackT1125
    Open source URL
  58. [58]
    objective-see 2017 review

    Patrick Wardle. (n.d.). Retrieved March 20, 2018.

    Open source URL
  59. [59]
    objective-see 2017 review

    Patrick Wardle. (n.d.). Retrieved March 20, 2018.

    Open source URL
  60. [60]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  61. [61]
    Talent-Jump Clambling February 2020

    Chen, T. and Chen, Z. (2020, February 17). CLAMBLING - A New Backdoor Base On Dropbox. Retrieved November 12, 2021.

    Open source URL
  62. [62]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  63. [63]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  64. [64]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  65. [65]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  66. [66]
    Zscaler Cobian Aug 2017

    Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

    Open source URL
  67. [67]
    DigiTrust NanoCore Jan 2017

    The DigiTrust Group. (2017, January 01). NanoCore Is Not Your Average RAT. Retrieved November 9, 2018.

    Open source URL
  68. [68]
    PaloAlto NanoCore Feb 2016

    Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.

    Open source URL
  69. [69]
    Kaspersky Adwind Feb 2016

    Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.

    Open source URL
  70. [70]
    jRAT Symantec Aug 2018

    Sharma, R. (2018, August 15). Revamped jRAT Uses New Anti-Parsing Techniques. Retrieved September 21, 2018.

    Open source URL
  71. [71]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  72. [72]
    Cylance Machete Mar 2017

    The Cylance Threat Research Team. (2017, March 22). El Machete's Malware Attacks Cut Through LATAM. Retrieved September 13, 2019.

    Open source URL
  73. [73]
    Securelist Machete Aug 2014

    Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019.

    Open source URL
  74. [74]
    Cofense RevengeRAT Feb 2019

    Gannon, M. (2019, February 11). With Upgrades in Delivery and Support Infrastructure, Revenge RAT Malware is a Bigger Threat. Retrieved November 17, 2024.

    Open source URL
  75. [75]
    Cylance Shaheen Nov 2018

    Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

    Open source URL
  76. [76]
    Malwarebytes DarkComet March 2018

    Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.

    Open source URL
  77. [77]
    TrendMicro DarkComet Sept 2014

    TrendMicro. (2014, September 03). DARKCOMET. Retrieved November 6, 2018.

    Open source URL
  78. [78]
    Citizen Lab Group5

    Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

    Open source URL
  79. [79]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  80. [80]
    DigiTrust Agent Tesla Jan 2017

    The DigiTrust Group. (2017, January 12). The Rise of Agent Tesla. Retrieved November 5, 2018.

    Open source URL
  81. [81]
    Talos Agent Tesla Oct 2018

    Brumaghin, E., et al. (2018, October 15). Old dog, new tricks - Analysing new RTF-based campaign distributing Agent Tesla, Loki with PyREbox. Retrieved November 5, 2018.

    Open source URL
  82. [82]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  83. [83]
    Talos PoetRAT April 2020

    Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.

    Open source URL
  84. [84]
    Group IB Silence Sept 2018

    Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.

    Open source URL
  85. [85]
    SecureList Silence Nov 2017

    GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.

    Open source URL
  86. [86]
    Imminent Unit42 Dec2019

    Unit 42. (2019, December 2). Imminent Monitor – a RAT Down Under. Retrieved May 5, 2020.

    Open source URL
  87. [87]
    QiAnXin APT-C-36 Feb2019

    QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.

    Open source URL
  88. [88]
    Anomali Static Kitten February 2021

    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

    Open source URL
  89. [89]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  90. [90]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  91. [91]
    AsyncRAT GitHub

    Nyan-x-Cat. (n.d.). NYAN-x-CAT / AsyncRAT-C-Sharp. Retrieved October 3, 2023.

    Open source URL
  92. [92]
    IBM TA505 April 2020

    Frydrych, M. (2020, April 14). TA505 Continues to Infect Networks With SDBbot RAT. Retrieved May 29, 2020.

    Open source URL
  93. [93]
    Proofpoint TA505 October 2019

    Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.

    Open source URL
  94. [94]
    DOJ FIN7 Aug 2018

    Department of Justice. (2018, August 01). HOW FIN7 ATTACKED AND STOLE DATA. Retrieved August 24, 2018.

    Open source URL
  95. [95]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  96. [96]
    Microsoft Quick Assist 2024

    Microsoft. (2024, September 4). Use Quick Assist to help users. Retrieved March 14, 2025.

    Open source URL
  97. [97]
    Microsoft Storm-1811 2024

    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

    Open source URL
  98. [98]
    Talos ZxShell Oct 2014

    Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019.

    Open source URL
  99. [99]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  100. [100]
    Uptycs Warzone UAC Bypass November 2020

    Mohanta, A. (2020, November 25). Warzone RAT comes with UAC bypass technique. Retrieved April 7, 2022.

    Open source URL
  101. [101]
    GitHub Pupy

    Nicolas Verdier. (n.d.). Retrieved January 29, 2018.

    Open source URL
  102. [102]
    EFF Manul Aug 2016

    Galperin, E., Et al.. (2016, August). I Got a Letter From the Government the Other Day.... Retrieved April 25, 2018.

    Open source URL
  103. [103]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  104. [104]
    FBI IC3 Flash VOID MANTICORE Handala Hack March 2026

    FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. Retrieved April 20, 2026.

    Open source URL
  105. [105]
    ESET InvisiMole June 2018

    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

    Open source URL
  106. [106]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  107. [107]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.