LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1195.002: Compromise Software Supply Chain

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.[1][2]

EnterpriseT1195.002Sub-techniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Compromise Software Supply Chain is an initial-access technique where adversaries alter software before the customer receives it, such as source code, update mechanisms, distribution channels, or compiled releases. Its business significance is that trusted software can become the entry point, so normal purchasing, patching, and deployment processes may also become intrusion paths.

Executive priority

Treat this as a resilience and third-party risk issue, not only a malware issue. Leaders should ask whether the organization can identify widely deployed software, verify update integrity, prioritize vulnerable or unsupported applications, and produce audit evidence for software governance. Because ATT&CK links this behavior to major campaigns and multiple groups, the priority is to reduce blind trust in vendor-delivered code and improve incident decision-making when a trusted application behaves unexpectedly.

Technical view

For Linux, Windows, and macOS environments, SOC and IR teams should validate visibility around software installation, update execution, first-run behavior, child processes, network egress, and signature or integrity anomalies. ATT&CK provides no official detection text for this object, but the related detection strategy DET0309 points to correlating installer or update writes with first-run or child-process activity and abnormal egress or signing anomalies. Detection engineering should focus on trusted software paths that create unusual execution chains or communications after install/update events.

Likely telemetry

  • Software inventory and version data across Linux, Windows, and macOS
  • Installer, package manager, and software update logs
  • Endpoint process creation and child-process telemetry
  • File creation, modification, and integrity metadata for application directories and update locations
  • Code signing, certificate, package signature, or hash validation results where available

Detection direction

  • Validate whether telemetry can connect a software update or installer event to subsequent first-run execution, child processes, and outbound network activity.
  • Tune for high-value or broadly deployed software where a trusted update channel would create large blast radius.
  • Review anomalies in signed software, replaced binaries, unexpected compiled releases, or update mechanisms, while accounting for legitimate vendor update behavior.
  • Use relationship context from campaigns such as SolarWinds Compromise and 3CX Supply Chain Attack as scenario inputs for tabletop exercises and detection validation, not as proof of current exposure.
  • Because MITRE does not provide official detection guidance for this technique, prioritize environment-specific baselining and incident response playbooks for trusted software behaving outside expected patterns.

Mitigation priorities

  • Maintain accurate software inventory so responders can quickly determine where affected products or versions are installed.
  • Use vulnerability scanning and assessment processes, aligned with M1016, to identify misconfigurations, unpatched software, and risky application exposure for remediation prioritization.
  • Keep software updated through governed patching processes, aligned with M1051, while also validating the integrity and expected behavior of updates.
  • Strengthen software acquisition and update governance: approved sources, change control, integrity checks, and vendor risk review where applicable.
  • Prepare IR procedures for suspected trusted-software compromise, including scoping installed versions, isolating affected systems, reviewing egress, and preserving installer/update artifacts.
Additional notes and limits

This object is a sub-technique of Supply Chain Compromise and applies to initial access on Linux, Windows, and macOS. ATT&CK relationships link it to campaigns, groups, and malware examples including SolarWinds Compromise, 3CX Supply Chain Attack, CCBkdr, GoldenSpy, and SUNSPOT; these relationships support the materiality of the behavior but should not be interpreted as current activity against any specific organization.

The official ATT&CK object does not include detection guidance, and some related descriptions are truncated in the supplied data. Practical coverage depends on local software inventory quality, endpoint telemetry, update logging, code-signing visibility, network monitoring, and third-party software governance evidence.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Compromise Software Supply Chain

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1195Supply Chain CompromiseThis object subtechnique of Supply Chain Compromise.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0080: Cobalt Group

Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims.[1][2][3][4][5][6][7] Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.[8]

GroupEnterprise

G0115: GOLD SOUTHFIELD

GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.[1][2][3][4]

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

GroupEnterprise

G0035: Dragonfly

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.[1][2] Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.[3][4][5][6][7][8][9]

GroupEnterprise

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

GroupEnterprise

G1034: Daggerfly

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.[1][2][3][4]

GroupEnterprise

G1036: Moonstone Sleet

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.[1]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

MalwareEnterprise

S0493: GoldenSpy

GoldenSpy is a backdoor malware which has been packaged with legitimate tax preparation software. GoldenSpy was discovered targeting organizations in China, being delivered with the "Intelligent Tax" software suite which is produced by the Golden Tax Department of Aisino Credit Information Co. and required to pay local taxes.[1]

Windows
MalwareEnterprise

S0222: CCBkdr

CCBkdr is malware that was injected into a signed version of CCleaner and distributed from CCleaner's distribution website. [1] [2]

Windows
CampaignEnterprise

C0057: 3CX Supply Chain Attack

The 3CX Supply Chain Attack was the first publicly reported case of one supply chain compromise triggering another, leading to a cascading, two-stage intrusion. The initial supply chain attack began when a 3CX employee downloaded and executed a trojanized, end-of-life version of the X_Trader trading software from Trading Technologies. This provided UNC4736, a threat cluster associated with AppleJeus, access to the 3CX environment. From there UNC4736 compromised the Windows and macOS build environments used to distribute the 3CX desktop application to their customers.[1] While 3CX serves more than 600,000 customers and 12 million users, only a subset of systems were affected. Subsequent targeting focused on victims in the defense and cryptocurrency sectors, where attackers deployed secondary payloads such as Gopuram for credential theft and persistence.[2] The campaign began in late 2022 and was disrupted after security vendors publicly reported the compromise in March 2023.[3][4]

CampaignEnterprise

C0024: SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
b92e0716c1cd1316...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundleb92e0716c1cd…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Avast CCleaner3 2018

    Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.

    Open source URL
  2. [2]
    Command Five SK 2011

    Command Five Pty Ltd. (2011, September). SK Hack by an Advanced Persistent Threat. Retrieved November 17, 2024.

    Open source URL
  3. [3]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  4. [4]
    Crowdstrike GTR2020 Mar 2020

    Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.

    Open source URL
  5. [5]
    Mandiant 3cx UNC4736 2023

    Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodoreanu, Daniel Scott. (2023, April 20). 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible. Retrieved August 25, 2025.

    Open source URL
  6. [6]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  7. [7]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  8. [8]
    Secureworks GOLD SOUTHFIELD

    Secureworks. (n.d.). GOLD SOUTHFIELD. Retrieved October 6, 2020.

    Open source URL
  9. [9]
    Trustwave GoldenSpy June 2020

    Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.

    Open source URL
  10. [10]
    CrowdStrike SUNSPOT Implant January 2021

    CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021.

    Open source URL
  11. [11]
    Secureworks NotPetya June 2017

    Counter Threat Research Team. (2017, June 28). NotPetya Campaign: What We Know About the Latest Global Ransomware Attack. Retrieved June 11, 2020.

    Open source URL
  12. [12]
    ESET Telebots June 2017

    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

    Open source URL
  13. [13]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  14. [14]
    Talos CCleanup 2017

    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

  15. [15]
    Intezer Aurora Sept 2017

    Rosenberg, J. (2017, September 20). Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner. Retrieved February 13, 2018.

  16. [16]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  17. [17]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  18. [18]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  19. [19]
    ESET EvasivePanda 2023

    Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.

    Open source URL
  20. [20]
    ESET EvasivePanda 2024

    Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.

    Open source URL
  21. [21]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  22. [22]
    SolarWinds Sunburst Sunspot Update January 2021

    Sudhakar Ramakrishna . (2021, January 11). New Findings From Our Investigation of SUNBURST. Retrieved January 13, 2021.

    Open source URL
  23. [23]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  24. [24]
    Cybersecurity Advisory SVR TTP May 2021

    NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021.

    Open source URL
  25. [25]
    Microsoft Deep Dive Solorigate January 2021

    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.

    Open source URL
  26. [26]
    Mandiant FIN7 Apr 2022

    Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

    Open source URL
  27. [27]
    OWASP Top 10

    OWASP. (2018, February 23). OWASP Top Ten Project. Retrieved April 3, 2018.

    Open source URL
  28. [28]
    Avast CCleaner3 2018

    Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.

    Open source URL
  29. [29]
    Avast CCleaner3 2018

    Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.

    Open source URL
  30. [30]
    Command Five SK 2011

    Command Five Pty Ltd. (2011, September). SK Hack by an Advanced Persistent Threat. Retrieved November 17, 2024.

    Open source URL
  31. [31]
    Command Five SK 2011

    Command Five Pty Ltd. (2011, September). SK Hack by an Advanced Persistent Threat. Retrieved November 17, 2024.

    Open source URL
  32. [32]
    mitre-attackT1195.002
    Open source URL
  33. [33]
    mitre-attackT1195.002
    Open source URL
  34. [34]
    mitre-attackT1195.002
    Open source URL
  35. [35]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  36. [36]
    Crowdstrike GTR2020 Mar 2020

    Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.

    Open source URL
  37. [37]
    Mandiant 3cx UNC4736 2023

    Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodoreanu, Daniel Scott. (2023, April 20). 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible. Retrieved August 25, 2025.

    Open source URL
  38. [38]
    Secureworks GOLD SOUTHFIELD

    Secureworks. (n.d.). GOLD SOUTHFIELD. Retrieved October 6, 2020.

    Open source URL
  39. [39]
    Secureworks GandCrab and REvil September 2019

    Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

    Open source URL
  40. [40]
    Secureworks REvil September 2019

    Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  41. [41]
    Trustwave GoldenSpy June 2020

    Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.

    Open source URL
  42. [42]
    CrowdStrike SUNSPOT Implant January 2021

    CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021.

    Open source URL
  43. [43]
    ESET Telebots June 2017

    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

    Open source URL
  44. [44]
    Secureworks NotPetya June 2017

    Counter Threat Research Team. (2017, June 28). NotPetya Campaign: What We Know About the Latest Global Ransomware Attack. Retrieved June 11, 2020.

    Open source URL
  45. [45]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  46. [46]
    Avast CCleaner3 2018

    Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.

    Open source URL
  47. [47]
    Avast CCleaner3 2018

    Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.

    Open source URL
  48. [48]
    Intezer Aurora Sept 2017

    Rosenberg, J. (2017, September 20). Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner. Retrieved February 13, 2018.

  49. [49]
    Talos CCleanup 2017

    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

  50. [50]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  51. [51]
    Secureworks IRON LIBERTY July 2019

    Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.

    Open source URL
  52. [52]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  53. [53]
    ESET EvasivePanda 2023

    Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.

    Open source URL
  54. [54]
    ESET EvasivePanda 2024

    Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.

    Open source URL
  55. [55]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.