LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1218.007: Msiexec

Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi).[1] The Msiexec.exe binary may also be digitally signed by Microsoft.

Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs.[2][3] Since it may be signed and native on Windows systems, msiexec.exe can be used to bypass application control solutions that do not account for its potential abuse. Msiexec.exe execution may also be elevated to SYSTEM privileges if the AlwaysInstallElevated policy is enabled.[4]

EnterpriseT1218.007Sub-techniqueObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Msiexec matters because it is a normal, Microsoft-signed Windows installer utility that can also be used to run malicious MSI packages or DLLs from local or network locations. For leaders, the risk is not that msiexec exists, but that trusted system tooling can make malicious execution look like routine software installation, especially where application control or installer policy is weak.

Executive priority

Prioritize this as a Windows control-validation issue: can the organization distinguish approved software installation from suspicious msiexec-driven execution? The ATT&CK relationships show use across multiple campaigns, groups, and malware families, so this is relevant to SOC readiness, incident triage, privileged access governance, and audit evidence around application control and least privilege. A key executive question is whether policies such as AlwaysInstallElevated are known, governed, and monitored because MITRE notes they may allow msiexec execution to be elevated to SYSTEM privileges.

Technical view

Validate visibility and controls around msiexec.exe process execution on Windows. Focus on command-line arguments, parent/child process context, local versus network-accessible MSI paths, DLL execution patterns, and privilege context. Because the official detection field is not provided, use the related detection strategy DET0158 as direction to validate local, network, and DLL execution abuse rather than assuming existing coverage. Treat msiexec as a signed living-off-the-land binary under System Binary Proxy Execution, where allowlisting based only on publisher or file signature may be insufficient.

Likely telemetry

  • Windows process creation events for msiexec.exe, including full command line
  • Parent and child process relationships involving msiexec.exe
  • File path evidence for MSI packages or DLLs executed by msiexec.exe
  • Network path or remote share indicators referenced by msiexec.exe command lines
  • Privilege and user context for msiexec.exe execution, including elevated or SYSTEM context

Detection direction

  • Baseline normal enterprise software deployment behavior so alerts do not overwhelm teams during legitimate installation activity.
  • Alert or hunt for msiexec.exe launching content from unusual local paths, user-writable locations, or network-accessible locations when that context is available.
  • Review msiexec.exe command lines for DLL execution and other nonstandard installer usage referenced by ATT&CK and LOLBAS context.
  • Correlate msiexec execution with parent processes that are unusual for software deployment, while accounting for legitimate management tools.
  • Validate whether signed-binary or publisher-based application control rules permit msiexec abuse without inspecting arguments or allowed installation sources.

Mitigation priorities

  • Apply privileged account management principles: restrict administrative installation rights, enforce least privilege, and monitor privileged installer activity.
  • Review and govern installer-related policies, especially AlwaysInstallElevated, and disable risky configurations where not required.
  • Use application control with rules that account for msiexec abuse patterns, not only Microsoft signature trust.
  • Reduce attack surface by disabling or removing unnecessary features, programs, or installer capabilities where operationally feasible.
  • Maintain audit evidence showing who can install software, from where packages may be run, and how exceptions are approved.
Additional notes and limits

This object is a Windows sub-technique of System Binary Proxy Execution under the stealth tactic. MITRE provides no official detection text for this technique, but the supplied relationship identifies DET0158, Detection of Msiexec Abuse for Local, Network, and DLL Execution. The relationship set includes multiple campaigns, groups, and software entries using this technique; that supports defensive prioritization but should not be read as evidence of current activity in any specific environment.

This take is limited to the supplied ATT&CK STIX fields, references, and relationships. Local risk depends on Windows estate size, installer workflows, application control design, logging coverage, privileged access model, and policy state. No claim is made that a specific organization is exposed or that any detection is guaranteed.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Msiexec

Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi).[1] The Msiexec.exe binary may also be digitally signed by Microsoft.

Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs.[2][3] Since it may be signed and native on Windows systems, msiexec.exe can be used to bypass application control solutions that do not account for its potential abuse. Msiexec.exe execution may also be elevated to SYSTEM privileges if the AlwaysInstallElevated policy is enabled.[4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1218System Binary Proxy ExecutionThis object subtechnique of System Binary Proxy Execution.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0021: Molerats

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.[1][2][3][4]

GroupEnterprise

G0092: TA505

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.[1][2][3][4][5]

GroupEnterprise

G0075: Rancor

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. [1]

GroupEnterprise

G0128: ZIRCONIUM

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.[1][2]

GroupEnterprise

G0095: Machete

Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.[1][2][3][4]

GroupEnterprise

G0082: APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

MalwareEnterprise

S0631: Chaes

Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers, and other financial information. Chaes was first observed in 2020, and appears to primarily target victims in Brazil as well as other e-commerce customers in Latin America.[1]

Windows
MalwareEnterprise

S0038: Duqu

Duqu is a malware platform that uses a modular approach to extend functionality after deployment within a target network. [1]

Windows
MalwareEnterprise

S0455: Metamorfo

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.[1][2]

Windows
MalwareEnterprise

S1160: Latrodectus

Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules. Latrodectus has most often been distributed through email campaigns, primarily by TA577 and TA578, and has infrastructure overlaps with historic IcedID operations.[1][2][3]

Windows
MalwareEnterprise

S1052: DEADEYE

DEADEYE is a malware launcher that has been used by APT41 since at least May 2021. DEADEYE has variants that can either embed a payload inside a compiled binary (DEADEYE.EMBED) or append it to the end of a file (DEADEYE.APPEND).[1]

Windows
MalwareEnterprise

S0483: IcedID

IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.[1][2]

Windows
MalwareEnterprise

S1122: Mispadu

Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model.[1][2] This malware is operated, managed, and sold by the Malteiro cybercriminal group.[2] Mispadu has mainly been used to target victims in Brazil and Mexico, and has also had confirmed operations throughout Latin America and Europe.[2][3][4]

Windows
MalwareEnterprise

S0530: Melcoz

Melcoz is a banking trojan family built from the open source tool Remote Access PC. Melcoz was first observed in attacks in Brazil and since 2018 has spread to Chile, Mexico, Spain, and Portugal.[1]

Windows
MalwareEnterprise

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

Windows
MalwareEnterprise

S0531: Grandoreiro

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.[1][2]

Windows
CampaignEnterprise

C0057: 3CX Supply Chain Attack

The 3CX Supply Chain Attack was the first publicly reported case of one supply chain compromise triggering another, leading to a cascading, two-stage intrusion. The initial supply chain attack began when a 3CX employee downloaded and executed a trojanized, end-of-life version of the X_Trader trading software from Trading Technologies. This provided UNC4736, a threat cluster associated with AppleJeus, access to the 3CX environment. From there UNC4736 compromised the Windows and macOS build environments used to distribute the 3CX desktop application to their customers.[1] While 3CX serves more than 600,000 customers and 12 million users, only a subset of systems were affected. Subsequent targeting focused on victims in the defense and cryptocurrency sectors, where attackers deployed secondary payloads such as Gopuram for credential theft and persistence.[2] The campaign began in late 2022 and was disrupted after security vendors publicly reported the compromise in March 2023.[3][4]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
138182c13491d4c2...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.0Current bundle138182c13491…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft msiexec

    Microsoft. (2017, October 15). msiexec. Retrieved January 24, 2020.

    Open source URL
  2. [2]
    LOLBAS Msiexec

    LOLBAS. (n.d.). Msiexec.exe. Retrieved April 18, 2019.

    Open source URL
  3. [3]
    TrendMicro Msiexec Feb 2018

    Co, M. and Sison, G. (2018, February 8). Attack Using Windows Installer msiexec.exe leads to LokiBot. Retrieved April 18, 2019.

    Open source URL
  4. [4]
    Microsoft AlwaysInstallElevated 2018

    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.

    Open source URL
  5. [5]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  6. [6]
    Unit42 Molerat Mar 2020

    Falcone, R., et al. (2020, March 3). Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations. Retrieved December 14, 2020.

    Open source URL
  7. [7]
    Kaspersky Duqu 2.0

    Kaspersky Lab. (2015, June 11). The Duqu 2.0. Retrieved April 21, 2017.

    Open source URL
  8. [8]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  9. [9]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  10. [10]
    Latrodectus APR 2024

    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

    Open source URL
  11. [11]
    Bleeping Computer Latrodectus April 2024

    Abrams, L. (2024, April 30). New Latrodectus malware attacks use Microsoft, Cloudflare themes. Retrieved September 13, 2024.

    Open source URL
  12. [12]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  13. [13]
    Juniper IcedID June 2020

    Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.

    Open source URL
  14. [14]
    Trendmicro_IcedID

    Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.

    Open source URL
  15. [15]
    SCILabs Malteiro 2021

    SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.

    Open source URL
  16. [16]
    ESET Security Mispadu Facebook Ads 2019

    ESET Security. (2019, November 19). Mispadu: Advertisement for a discounted Unhappy Meal. Retrieved March 13, 2024.

    Open source URL
  17. [17]
    Profero APT27 December 2020

    Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.

    Open source URL
  18. [18]
    Cybereason TA505 April 2019

    Salem, E. (2019, April 25). Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware. Retrieved May 28, 2019.

    Open source URL
  19. [19]
    Deep Instinct TA505 Apr 2019

    Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..

    Open source URL
  20. [20]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  21. [21]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  22. [22]
    Crowdstrike Qakbot October 2020

    CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.

    Open source URL
  23. [23]
    Unit42 3cx supply chain 2023

    Robert Falcone, Josh Grunzweig. (2023, March 30). Threat Brief: 3CXDesktopApp Supply Chain Attack. Retrieved September 15, 2025.

    Open source URL
  24. [24]
    Kaspersky LODEINFO OCT 2022

    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.

    Open source URL
  25. [25]
    CISA AppleJeus Feb 2021

    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

    Open source URL
  26. [26]
    McAfee RedLine Stealer April 2024

    Mohansundaram M, Neil Tyagi. (2024, April 17). Redline Stealer: A Novel Approach. Retrieved September 17, 2025.

    Open source URL
  27. [27]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  28. [28]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  29. [29]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  30. [30]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  31. [31]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  32. [32]
    SecureListUbiedo_Tsundere_Nov2025

    Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

    Open source URL
  33. [33]
    RedCanary RaspberryRobin 2022

    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

    Open source URL
  34. [34]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  35. [35]
    1 - appv

    SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.

    Open source URL
  36. [36]
    ESET LoudMiner June 2019

    Malik, M. (2019, June 20). LoudMiner: Cross-platform mining in cracked VST software. Retrieved May 18, 2020.

    Open source URL
  37. [37]
    Sophos Maze VM September 2020

    Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.

    Open source URL
  38. [38]
    Trend Micro Muddy Water March 2021

    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

    Open source URL
  39. [39]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  40. [40]
    Cybereason Clop Dec 2020

    Cybereason Nocturnus. (2020, December 23). Cybereason vs. Clop Ransomware. Retrieved May 11, 2021.

    Open source URL
  41. [41]
    LOLBAS Msiexec

    LOLBAS. (n.d.). Msiexec.exe. Retrieved April 18, 2019.

    Open source URL
  42. [42]
    LOLBAS Msiexec

    LOLBAS. (n.d.). Msiexec.exe. Retrieved April 18, 2019.

    Open source URL
  43. [43]
    Microsoft AlwaysInstallElevated 2018

    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.

    Open source URL
  44. [44]
    Microsoft AlwaysInstallElevated 2018

    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.

    Open source URL
  45. [45]
    Microsoft msiexec

    Microsoft. (2017, October 15). msiexec. Retrieved January 24, 2020.

    Open source URL
  46. [46]
    Microsoft msiexec

    Microsoft. (2017, October 15). msiexec. Retrieved January 24, 2020.

    Open source URL
  47. [47]
    TrendMicro Msiexec Feb 2018

    Co, M. and Sison, G. (2018, February 8). Attack Using Windows Installer msiexec.exe leads to LokiBot. Retrieved April 18, 2019.

    Open source URL
  48. [48]
    TrendMicro Msiexec Feb 2018

    Co, M. and Sison, G. (2018, February 8). Attack Using Windows Installer msiexec.exe leads to LokiBot. Retrieved April 18, 2019.

    Open source URL
  49. [49]
    mitre-attackT1218.007
    Open source URL
  50. [50]
    mitre-attackT1218.007
    Open source URL
  51. [51]
    mitre-attackT1218.007
    Open source URL
  52. [52]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  53. [53]
    Unit42 Molerat Mar 2020

    Falcone, R., et al. (2020, March 3). Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations. Retrieved December 14, 2020.

    Open source URL
  54. [54]
    Kaspersky Duqu 2.0

    Kaspersky Lab. (2015, June 11). The Duqu 2.0. Retrieved April 21, 2017.

    Open source URL
  55. [55]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  56. [56]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  57. [57]
    Bleeping Computer Latrodectus April 2024

    Abrams, L. (2024, April 30). New Latrodectus malware attacks use Microsoft, Cloudflare themes. Retrieved September 13, 2024.

    Open source URL
  58. [58]
    Latrodectus APR 2024

    Proofpoint Threat Research and Team Cymru S2 Threat Research. (2024, April 4). Latrodectus: This Spider Bytes Like Ice . Retrieved May 31, 2024.

    Open source URL
  59. [59]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  60. [60]
    Juniper IcedID June 2020

    Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.

    Open source URL
  61. [61]
    Trendmicro_IcedID

    Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.

    Open source URL
  62. [62]
    ESET Security Mispadu Facebook Ads 2019

    ESET Security. (2019, November 19). Mispadu: Advertisement for a discounted Unhappy Meal. Retrieved March 13, 2024.

    Open source URL
  63. [63]
    SCILabs Malteiro 2021

    SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.

    Open source URL
  64. [64]
    Profero APT27 December 2020

    Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.

    Open source URL
  65. [65]
    Cybereason TA505 April 2019

    Salem, E. (2019, April 25). Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware. Retrieved May 28, 2019.

    Open source URL
  66. [66]
    Deep Instinct TA505 Apr 2019

    Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..

    Open source URL
  67. [67]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  68. [68]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  69. [69]
    Crowdstrike Qakbot October 2020

    CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.

    Open source URL
  70. [70]
    Unit42 3cx supply chain 2023

    Robert Falcone, Josh Grunzweig. (2023, March 30). Threat Brief: 3CXDesktopApp Supply Chain Attack. Retrieved September 15, 2025.

    Open source URL
  71. [71]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  72. [72]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  73. [73]
    Kaspersky LODEINFO OCT 2022

    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.

    Open source URL
  74. [74]
    CISA AppleJeus Feb 2021

    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

    Open source URL
  75. [75]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  76. [76]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  77. [77]
    Microsoft AlwaysInstallElevated 2018

    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.

    Open source URL
  78. [78]
    Microsoft AlwaysInstallElevated 2018

    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.

    Open source URL
  79. [79]
    McAfee RedLine Stealer April 2024

    Mohansundaram M, Neil Tyagi. (2024, April 17). Redline Stealer: A Novel Approach. Retrieved September 17, 2025.

    Open source URL
  80. [80]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  81. [81]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  82. [82]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  83. [83]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  84. [84]
    360 Machete Sep 2020

    kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.

    Open source URL
  85. [85]
    SecureListUbiedo_Tsundere_Nov2025

    Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.