LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1219.002: Remote Desktop Software

An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as `VNC`, `Team Viewer`, `AnyDesk`, `ScreenConnect`, `LogMein`, `AmmyyAdmin`, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.[1][2][3] Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.[4][5]

EnterpriseT1219.002Sub-techniqueObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Remote Desktop Software is risky because adversaries can turn the same approved support tools used by IT into an interactive command-and-control channel. Since tools such as VNC, TeamViewer, AnyDesk, ScreenConnect, LogMeIn, AmmyyAdmin, RMM products, and remote-access features in products like Chrome Remote Desktop may be legitimate, the business issue is governance and visibility: know which tools are authorized, where they are allowed, and whether SOC teams can distinguish help-desk activity from adversary control.

Executive priority

Treat this as a resilience and auditability issue, not only a malware issue. Leaders should ask whether remote support software is inventoried, approved by policy, restricted by network controls, and logged well enough to support incident response and compliance evidence. The ATT&CK relationships connect this behavior to multiple campaigns, groups, and ransomware-related software, so prioritizing controls around remote desktop/RMM use can reduce ambiguity during high-pressure incidents and help prevent unauthorized interactive access from becoming operational disruption.

Technical view

For Windows, macOS, and Linux, validate coverage around legitimate remote desktop and RMM execution, installation, beaconing, and remote session activity. ATT&CK provides no official detection text for this sub-technique, but the related detection strategy DET0259 indicates a focus on Remote Desktop Software Execution and Beaconing Detection. SOC teams should baseline approved support tools, monitor for unapproved binaries or unexpected remote-access features, and correlate endpoint execution with egress network activity and help-desk change records. Because this is command-and-control using legitimate software, detections should emphasize context, authorization, asset role, user role, and timing rather than tool name alone.

Likely telemetry

  • Endpoint process execution and command-line metadata for remote desktop, desktop support, and RMM tools on Windows, macOS, and Linux
  • Software inventory and installation records showing approved and unapproved remote access applications or features
  • Network egress telemetry from firewalls, proxies, DNS, and endpoint network sensors for remote access service connections or recurring beaconing
  • Application control allow/block events and policy exceptions for support tools
  • Service, startup, persistence, or configuration-change records associated with remote support software

Detection direction

  • Build and maintain an allowlist of approved remote desktop/RMM tools, expected users, expected assets, and expected network destinations; alert on deviations rather than on tool presence alone.
  • Tune detections for execution plus network beaconing, especially when a remote support tool appears on a system class or user population that does not normally require it.
  • Correlate sessions with business context such as help-desk tickets, maintenance windows, and known administrator activity to reduce false positives from legitimate support operations.
  • Look for blind spots where browser-based or embedded remote-access features, such as Chrome Remote Desktop-style functionality, may not appear in standard software inventory.
  • Validate that telemetry exists across Linux, macOS, and Windows; coverage limited to Windows endpoints will miss supported platforms for this ATT&CK object.

Mitigation priorities

  • First, define an approved remote access standard: which tools are permitted, who may use them, on which systems, and under what change-control or support process.
  • Use M1042-aligned reduction: remove or disable unnecessary remote desktop, support, RMM, or remote-access features that are not required for business operations.
  • Use M1038-aligned execution prevention: restrict unauthorized remote access software through application control or equivalent execution controls.
  • Use M1037-aligned network filtering: limit ingress, egress, and lateral traffic for remote access tools to authorized services, destinations, and administrative paths.
  • Review exceptions regularly so emergency support access does not become a permanent unmanaged command-and-control path.
Additional notes and limits

This take is based on ATT&CK T1219.002 Remote Desktop Software, its command-and-control tactic, Windows/macOS/Linux platforms, official description, external references, and supplied relationships. The object is a sub-technique of T1219 Remote Access Tools. Relationship context shows mitigation links to Filter Network Traffic, Execution Prevention, and Disable or Remove Feature or Program, and a detection strategy relationship to Remote Desktop Software Execution and Beaconing Detection.

ATT&CK provides no official detection text for this object, so detection guidance must be validated against local tooling, approved support workflows, and available logs. The supplied relationships show that campaigns, groups, and software have used this behavior, but they do not prove current activity or exposure in any specific environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Remote Desktop Software

An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as `VNC`, `Team Viewer`, `AnyDesk`, `ScreenConnect`, `LogMein`, `AmmyyAdmin`, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.[1][2][3] Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.[4][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1219Remote Access ToolsThis object subtechnique of Remote Access Tools.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G1053: Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.[1][2][3][4]

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

GroupEnterprise

G0129: Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. [1][2][3][4][5][6][7][8][9][10][11][12][13]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0076: Thrip

Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well as "living off the land" techniques. [1]

GroupEnterprise

G0048: RTM

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM). [1]

GroupEnterprise

G1055: VOID MANTICORE

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).[1] Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.[1][2] VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.[1][3] VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.[4]

GroupEnterprise

G1015: Scattered Spider

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. [1] [2] The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. [2] Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. [3] [4] [5] Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. [6]

GroupEnterprise

G0069: MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).[1] Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. [2][3][4][5][6][7][8][9][10][11][12][13]

MalwareEnterprise

S1242: Qilin

Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.[1][2][3][4][5]

ESXiWindowsLinux
CampaignEnterprise

C0018: C0018

C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing AvosLocker.[1][2]

CampaignEnterprise

C0027: C0027

C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through December of 2022. During C0027 Scattered Spider used various forms of social engineering, performed SIM swapping, and attempted to leverage access from victim environments to mobile carrier networks.[1]

CampaignEnterprise

C0015: C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
a127242fcd6e3647...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlea127242fcd6e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Symantec Living off the Land

    Wueest, C., Anand, H. (2017, July). Living off the land and fileless attack techniques. Retrieved April 10, 2018.

    Open source URL
  2. [2]
    CrowdStrike 2015 Global Threat Report

    CrowdStrike Intelligence. (2016). 2015 Global Threat Report. Retrieved April 11, 2018.

    Open source URL
  3. [3]
    CrySyS Blog TeamSpy

    CrySyS Lab. (2013, March 20). TeamSpy – Obshie manevri. Ispolzovat’ tolko s razreshenija S-a. Retrieved April 11, 2018.

    Open source URL
  4. [4]
    Google Chrome Remote Desktop

    Google. (n.d.). Retrieved March 14, 2024.

    Open source URL
  5. [5]
    Chrome Remote Desktop

    Huntress. (n.d.). Retrieved March 14, 2024.

    Open source URL
  6. [6]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  7. [7]
    Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024

    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.

    Open source URL
  8. [8]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  9. [9]
    SecurityScorecard Contagious Interview October 2024

    Ryan Sherstobitoff. (2024, October 29). Inside a North Korean Phishing Operation Targeting DevOps Employees. Retrieved October 20, 2025.

    Open source URL
  10. [10]
    PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.

    Open source URL
  11. [11]
    PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024

    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.

    Open source URL
  12. [12]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  13. [13]
    Microsoft Storm-1811 2024

    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

    Open source URL
  14. [14]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  15. [15]
    Secureworks BRONZE PRESIDENT December 2019

    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

    Open source URL
  16. [16]
    Cisco Talos Avos Jun 2022

    Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023.

    Open source URL
  17. [17]
    Costa AvosLocker May 2022

    Costa, F. (2022, May 1). RaaS AvosLocker Incident Response Analysis. Retrieved January 11, 2023.

    Open source URL
  18. [18]
    Securelist Kimsuky Sept 2013

    Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.

    Open source URL
  19. [19]
    Crowdstrike GTR2020 Mar 2020

    Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.

    Open source URL
  20. [20]
    Symantec Thrip June 2018

    Security Response Attack Investigation Team. (2018, June 19). Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies. Retrieved July 10, 2018.

    Open source URL
  21. [21]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  22. [22]
    Check Point VOID MANTICORE Handala Hack March 2026

    Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.

    Open source URL
  23. [23]
    CISA Scattered Spider Advisory November 2023

    CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.

    Open source URL
  24. [24]
    Trellix Scattered Spider MO August 2023

    Trellix et. al.. (2023, August 17). Scattered Spider: The Modus Operandi. Retrieved March 18, 2024.

    Open source URL
  25. [25]
    Mandiant UNC3944 May 2025

    Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.

    Open source URL
  26. [26]
    CrowdStrike Scattered Spider JUL 2025

    Counter Adversary Operations. (2025, July 2). CrowdStrike Services Observes SCATTERED SPIDER Escalate Attacks Across Industries. Retrieved October 13, 2025.

    Open source URL
  27. [27]
    Check Point Scattered Spider JUL 2025

    Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.

    Open source URL
  28. [28]
    Crowdstrike TELCO BPO Campaign December 2022

    Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.

    Open source URL
  29. [29]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  30. [30]
    Trend Micro Muddy Water March 2021

    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

    Open source URL
  31. [31]
    Anomali Static Kitten February 2021

    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

    Open source URL
  32. [32]
    Proofpoint TA450 Phishing March 2024

    Miller, J. et al. (2024, March 21). Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign. Retrieved March 27, 2024.

    Open source URL
  33. [33]
    group-ib_muddywater_infra

    Rostovcev, N. (2023, April 18). SimpleHarm: Tracking MuddyWater’s infrastructure. Retrieved July 11, 2024.

    Open source URL
  34. [34]
    FalconFeeds_Iran_Mar2026

    FalconFeeds.io. (2026, March 5). The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict. Retrieved March 9, 2026.

    Open source URL
  35. [35]
    NaumaanProofpoint_GlobalClickFix_April2025

    Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.

    Open source URL
  36. [36]
    FalconFeeds_MuddyWaterPSRust_Mar2026

    FalconFeeds.io. (2026, March 6). MuddyWater in the Iran–Israel Cyber War: From PowerShell Scripts to Rust Implants. Retrieved March 12, 2026.

    Open source URL
  37. [37]
    Trend Micro Agenda Ransomware OCT 2025

    Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

    Open source URL
  38. [38]
    Chrome Remote Desktop

    Huntress. (n.d.). Retrieved March 14, 2024.

    Open source URL
  39. [39]
    Chrome Remote Desktop

    Huntress. (n.d.). Retrieved March 14, 2024.

    Open source URL
  40. [40]
    CrowdStrike 2015 Global Threat Report

    CrowdStrike Intelligence. (2016). 2015 Global Threat Report. Retrieved April 11, 2018.

    Open source URL
  41. [41]
    CrowdStrike 2015 Global Threat Report

    CrowdStrike Intelligence. (2016). 2015 Global Threat Report. Retrieved April 11, 2018.

    Open source URL
  42. [42]
    CrySyS Blog TeamSpy

    CrySyS Lab. (2013, March 20). TeamSpy – Obshie manevri. Ispolzovat’ tolko s razreshenija S-a. Retrieved April 11, 2018.

    Open source URL
  43. [43]
    CrySyS Blog TeamSpy

    CrySyS Lab. (2013, March 20). TeamSpy – Obshie manevri. Ispolzovat’ tolko s razreshenija S-a. Retrieved April 11, 2018.

    Open source URL
  44. [44]
    Google Chrome Remote Desktop

    Google. (n.d.). Retrieved March 14, 2024.

    Open source URL
  45. [45]
    Google Chrome Remote Desktop

    Google. (n.d.). Retrieved March 14, 2024.

    Open source URL
  46. [46]
    Symantec Living off the Land

    Wueest, C., Anand, H. (2017, July). Living off the land and fileless attack techniques. Retrieved April 10, 2018.

    Open source URL
  47. [47]
    Symantec Living off the Land

    Wueest, C., Anand, H. (2017, July). Living off the land and fileless attack techniques. Retrieved April 10, 2018.

    Open source URL
  48. [48]
    mitre-attackT1219.002
    Open source URL
  49. [49]
    mitre-attackT1219.002
    Open source URL
  50. [50]
    mitre-attackT1219.002
    Open source URL
  51. [51]
    Microsoft Storm-501 Sabbath Ransomware Embargo September 2024

    Microsoft Threat Intelligence. (2024, September 26). Storm-0501: Ransomware attacks expanding to hybrid cloud environments. Retrieved October 19, 2025.

    Open source URL
  52. [52]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  53. [53]
    Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024

    eSentire Threat Response Unit (TRU). (2024, November 14). Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2. Retrieved October 17, 2025.

    Open source URL
  54. [54]
    PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023

    Unit 42. (2023, November 21). Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors. Retrieved October 17, 2025.

    Open source URL
  55. [55]
    PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024

    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.

    Open source URL
  56. [56]
    SecurityScorecard Contagious Interview October 2024

    Ryan Sherstobitoff. (2024, October 29). Inside a North Korean Phishing Operation Targeting DevOps Employees. Retrieved October 20, 2025.

    Open source URL
  57. [57]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  58. [58]
    Microsoft Storm-1811 2024

    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

    Open source URL
  59. [59]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  60. [60]
    Secureworks BRONZE PRESIDENT December 2019

    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

    Open source URL
  61. [61]
    Cisco Talos Avos Jun 2022

    Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023.

    Open source URL
  62. [62]
    Costa AvosLocker May 2022

    Costa, F. (2022, May 1). RaaS AvosLocker Incident Response Analysis. Retrieved January 11, 2023.

    Open source URL
  63. [63]
    Crowdstrike GTR2020 Mar 2020

    Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.

    Open source URL
  64. [64]
    Securelist Kimsuky Sept 2013

    Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.

    Open source URL
  65. [65]
    Symantec Thrip June 2018

    Security Response Attack Investigation Team. (2018, June 19). Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies. Retrieved July 10, 2018.

    Open source URL
  66. [66]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  67. [67]
    Check Point VOID MANTICORE Handala Hack March 2026

    Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.

    Open source URL
  68. [68]
    CISA Scattered Spider Advisory November 2023

    CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.

    Open source URL
  69. [69]
    Check Point Scattered Spider JUL 2025

    Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.

    Open source URL
  70. [70]
    CrowdStrike Scattered Spider JUL 2025

    Counter Adversary Operations. (2025, July 2). CrowdStrike Services Observes SCATTERED SPIDER Escalate Attacks Across Industries. Retrieved October 13, 2025.

    Open source URL
  71. [71]
    Mandiant UNC3944 May 2025

    Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.

    Open source URL
  72. [72]
    Trellix Scattered Spider MO August 2023

    Trellix et. al.. (2023, August 17). Scattered Spider: The Modus Operandi. Retrieved March 18, 2024.

    Open source URL
  73. [73]
    Crowdstrike TELCO BPO Campaign December 2022

    Parisi, T. (2022, December 2). Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Retrieved June 30, 2023.

    Open source URL
  74. [74]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  75. [75]
    Anomali Static Kitten February 2021

    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.

    Open source URL
  76. [76]
    FalconFeeds_Iran_Mar2026

    FalconFeeds.io. (2026, March 5). The Digital Redoubt: Iran’s National Information Network and the Asymmetry of Modern Cyber Conflict. Retrieved March 9, 2026.

    Open source URL
  77. [77]
    FalconFeeds_MuddyWaterPSRust_Mar2026

    FalconFeeds.io. (2026, March 6). MuddyWater in the Iran–Israel Cyber War: From PowerShell Scripts to Rust Implants. Retrieved March 12, 2026.

    Open source URL
  78. [78]
    NaumaanProofpoint_GlobalClickFix_April2025

    Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.

    Open source URL
  79. [79]
    Proofpoint TA450 Phishing March 2024

    Miller, J. et al. (2024, March 21). Security Brief: TA450 Uses Embedded Links in PDF Attachments in Latest Campaign. Retrieved March 27, 2024.

    Open source URL
  80. [80]
    Trend Micro Muddy Water March 2021

    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

    Open source URL
  81. [81]
    group-ib_muddywater_infra

    Rostovcev, N. (2023, April 18). SimpleHarm: Tracking MuddyWater’s infrastructure. Retrieved July 11, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.