LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1480: Execution Guardrails

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign.[1] Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.[2]

Guardrails can be used to prevent exposure of capabilities in environments that are not intended to be compromised or operated within. This use of guardrails is distinct from typical Virtualization/Sandbox Evasion. While use of Virtualization/Sandbox Evasion may involve checking for known sandbox values and continuing with execution only if there is no match, the use of guardrails will involve checking for an expected target-specific value and only continuing with execution if there is such a match.

Adversaries may identify and block certain user-agents to evade defenses and narrow the scope of their attack to victims and platforms on which it will be most effective. A user-agent self-identifies data such as a user's software application, operating system, vendor, and version. Adversaries may check user-agents for operating system identification and then only serve malware for the exploitable software while ignoring all other operating systems.[3]

EnterpriseT1480TechniqueObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Execution Guardrails are checks that make malicious code run only when target-specific conditions are present, such as a particular AD domain, file, network share, IP address, physical device, mutex, or user-agent. For leaders, the practical issue is that the same payload may look harmless in a sandbox or test environment but execute in production, which can create false confidence in malware analysis, email detonation, and incident triage.

Executive priority

Prioritize this as a detection and response-readiness problem rather than a simple prevention item. MITRE maps the mitigation to M1055 Do Not Mitigate, meaning direct mitigation may not be practical or may create instability; coverage depends on whether the organization can observe environment checks, suspicious conditional execution, and follow-on behavior across Windows, Linux, macOS, and ESXi. Executives should ask whether SOC and IR teams can prove what telemetry is collected from production-like environments, not only from sandboxes.

Technical view

T1480 sits under stealth and applies to ESXi, Linux, macOS, and Windows. SOC and IR teams should validate detection logic against programs or scripts that query target-specific values before continuing execution, including AD domain membership, local or external IPs, network share names, files, attached devices, user-agent or OS values, and mutex-related behavior reflected by sub-technique T1480.002. The related DET0562 detection strategy indicates ATT&CK has a detection strategy for multi-platform environmental validation, but the core technique object itself provides no official detection text, so local analytics must be derived and tested against available telemetry.

Likely telemetry

  • Process creation and command-line or script execution showing environment discovery before payload execution
  • File, path, and network share access events used as target-specific checks
  • Identity and directory context such as joined AD domain or host/domain attributes
  • Network connection metadata, local and external IP context, and HTTP user-agent strings
  • Host inventory or device attachment evidence where physical device checks are relevant

Detection direction

  • Validate that sandbox and detonation environments contain enough realistic enterprise context to expose guardrail-gated behavior; otherwise treat a non-executing sample as inconclusive.
  • Look for tight sequences of environment validation followed by execution, download, or payload activation, rather than single checks in isolation.
  • Tune carefully because many legitimate installers, enterprise agents, and management scripts check OS, domain, files, shares, devices, or user-agent values before running.
  • Use relationship context to enrich hunting: ATT&CK links this behavior to multiple software entries and groups/campaigns, but those relationships should guide prioritization, not be treated as proof of local activity.
  • Include Linux, macOS, Windows, and ESXi visibility gaps in coverage reviews; guardrails are not limited to one endpoint platform.

Mitigation priorities

  • Do not rely on direct blocking of environment checks as the primary control, consistent with MITRE’s M1055 Do Not Mitigate relationship.
  • Improve detection, monitoring, and response workflows for suspicious conditional execution and follow-on actions.
  • Harden malware analysis processes by comparing sandbox results with production-like telemetry and by documenting when a sample may be guardrail-gated.
  • Maintain complete host, identity, network, and web telemetry needed to reconstruct what condition was checked and what executed afterward.
  • Use incident response playbooks that account for payloads that may not execute outside the intended target environment.
Additional notes and limits

Execution Guardrails matter because they can reduce adversary exposure and collateral execution while frustrating defensive analysis. Sub-techniques supplied for this object include Environmental Keying and Mutual Exclusion, and relationships show use by several ATT&CK groups, campaigns, and software families. Those relationships support threat-informed prioritization but do not establish activity in any specific environment.

The official ATT&CK detection field for T1480 is not provided. The object describes behavior and examples of guardrail values, but it does not provide vendor-specific controls, guaranteed detections, or local prevalence. Effective assessment requires local telemetry review and testing in production-like analysis conditions.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Execution Guardrails

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign.[1] Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses.[2]

Guardrails can be used to prevent exposure of capabilities in environments that are not intended to be compromised or operated within. This use of guardrails is distinct from typical Virtualization/Sandbox Evasion. While use of Virtualization/Sandbox Evasion may involve checking for known sandbox values and continuing with execution only if there is no match, the use of guardrails will involve checking for an expected target-specific value and only continuing with execution if there is such a match.

Adversaries may identify and block certain user-agents to evade defenses and narrow the scope of their attack to victims and platforms on which it will be most effective. A user-agent self-identifies data such as a user's software application, operating system, vendor, and version. Adversaries may check user-agents for operating system identification and then only serve malware for the exploitable software while ignoring all other operating systems.[3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1480.001Environmental KeyingSub-techniqueEnvironmental Keying subtechnique of this object.
EnterpriseT1480.002Mutual ExclusionSub-techniqueMutual Exclusion subtechnique of this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0099: APT-C-36

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]

GroupEnterprise

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

GroupEnterprise

G0047: Gamaredon Group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][5]

MalwareEnterprise

S1052: DEADEYE

DEADEYE is a malware launcher that has been used by APT41 since at least May 2021. DEADEYE has variants that can either embed a payload inside a compiled binary (DEADEYE.EMBED) or append it to the end of a file (DEADEYE.APPEND).[1]

Windows
MalwareEnterprise

S1179: Exbyte

Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.[1]

Windows
MalwareEnterprise

S9034: Tsundere Botnet

Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script. It leverages Node.js and JavaScript for payload delivery and execution, and uses smart contracts on the blockchain to host command and control (C2) addresses. Tsundere Botnet is attributed to a likely Russian-speaking threat actor.

A variant named DinDoor has been linked to MuddyWater operations and uses the Deno runtime for execution rather than Node.js.[1][2][3][4]

LinuxmacOSWindows
MalwareEnterprise

S1212: RansomHub

RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least 2024 to target organizations in multiple sectors globally. RansomHub operators may have purchased and rebranded resources from Knight (formerly Cyclops) Ransomware which shares infrastructure, feature, and code overlaps with RansomHub.[1][2]

LinuxWindows
MalwareEnterprise

S9010: GlassWorm

GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems.[1][2][3] GlassWorm has numerous variants, including Rust binaries, encrypted JavaScript and a variant leveraging invisible Unicode characters that made reverse engineering difficult.[4][1][5] GlassWorm has employed a unique command and control (C2) methodology using Solana blockchain.[6][1] GlassWorm was first reported in October 2025.[6][1][3]

macOSWindows
MalwareEnterprise

S0504: Anchor

Anchor is one of a family of backdoor malware that has been used in conjunction with TrickBot on selected high profile targets since at least 2018.[1][2]

LinuxWindows
MalwareEnterprise

S0570: BitPaymer

BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.[1]

Windows
MalwareEnterprise

S1161: BPFDoor

BPFDoor is a Linux based passive long-term backdoor used by China-based threat actors. First seen in 2021, BPFDoor is named after its usage of Berkley Packet Filter (BPF) to execute single task instructions. BPFDoor supports multiple protocols for communicating with a C2 including TCP, UDP, and ICMP and can start local or reverse shells that bypass firewalls using iptables.[1][2]

Linux
MalwareEnterprise

S1111: DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

Windows
MalwareEnterprise

S1130: Raspberry Robin

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.[1][2][3] The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."[4] The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.[5]

Windows
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
37a24e0d2574b067...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle37a24e0d2574…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    FireEye Kevin Mandia Guardrails

    Shoorbajee, Z. (2018, June 1). Playing nice? FireEye CEO says U.S. malware is more restrained than adversaries'. Retrieved January 17, 2019.

    Open source URL
  2. [2]
    FireEye Outlook Dec 2019

    McWhirt, M., Carr, N., Bienstock, D. (2019, December 4). Breaking the Rules: A Tough Outlook for Home Page Attacks (CVE-2017-11774). Retrieved June 23, 2020.

    Open source URL
  3. [3]
    Trellix-Qakbot

    Pham Duy Phuc, John Fokker J.E., Alejandro Houspanossian and Mathanraj Thangaraju. (2023, March 7). Qakbot Evolves to OneNote Malware Distribution. Retrieved June 7, 2024.

    Open source URL
  4. [4]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  5. [5]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  6. [6]
    Mandiant ROADSWEEP August 2022

    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

    Open source URL
  7. [7]
    Trend Micro Mustang Panda Earth Preta Toneshell February 2025

    Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.

    Open source URL
  8. [8]
    SecureListUbiedo_Tsundere_Nov2025

    Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

    Open source URL
  9. [9]
    Group-IB RansomHub FEB 2025

    Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

    Open source URL
  10. [10]
    Socket GlassWorm January 2026

    Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

    Open source URL
  11. [11]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  12. [12]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  13. [13]
    Sandfly BPFDoor 2022

    The Sandfly Security Team. (2022, May 11). BPFDoor - An Evasive Linux Backdoor Technical Analysis. Retrieved September 29, 2023.

    Open source URL
  14. [14]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  15. [15]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  16. [16]
    HP RaspberryRobin 2024

    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.

    Open source URL
  17. [17]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  18. [18]
    Huntress LightSpy macOS 2024

    Stuart Ashenbrenner, Alden Schmidt. (2024, April 25). LightSpy Malware Variant Targeting macOS. Retrieved January 3, 2025.

    Open source URL
  19. [19]
    McAfee Lazarus Nov 2020

    Beek, C. (2020, November 5). Operation North Star: Behind The Scenes. Retrieved December 20, 2021.

    Open source URL
  20. [20]
    NCSC GCHQ Small Sieve Jan 2022

    NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022.

    Open source URL
  21. [21]
    Fortgale StrelaStealer 2023

    Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.

    Open source URL
  22. [22]
    IBM StrelaStealer 2024

    Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.

    Open source URL
  23. [23]
    Breakdev Evilginx 2.4 SEP 2020

    Gretzky, K. (2020, September 14). Evilginx 2.4 - Gone Phishing. Retrieved January 27, 2026.

    Open source URL
  24. [24]
    Kaspersky LODEINFO Part II OCT 2022

    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.

    Open source URL
  25. [25]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  26. [26]
    CERT Polska

    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

    Open source URL
  27. [27]
    Joint Cybersecurity Advisory LockBit JUN 2023

    CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.

    Open source URL
  28. [28]
    Sentinel Labs LockBit 3.0 JUL 2022

    Walter, J. (2022, July 21). LockBit 3.0 Update | Unpicking the Ransomware’s Latest Anti-Analysis and Evasion Techniques. Retrieved February 5, 2025.

    Open source URL
  29. [29]
    Joint Cybersecurity Advisory LockBit 3.0 MAR 2023

    FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.

    Open source URL
  30. [30]
    Picus Qilin MAR 2025

    Hacioglu, S. (2025, March 10). Qilin Ransomware: Exposing the TTPs Behind One of the Most Active Ransomware Campaigns of 2024. Retrieved September 26, 2025.

    Open source URL
  31. [31]
    Trend Micro Agenda Ransomware OCT 2025

    Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

    Open source URL
  32. [32]
    HarmonProofpoint_SystemBC_Aug2019

    Harmon, K., et al. (2019, August 1). SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits . Retrieved June 13, 2025.

    Open source URL
  33. [33]
    SophosGnGal_SystemBC_Dec2020

    Gallagher, S., Gn, S. (2020, December 16). Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor. Retrieved May 16, 2025.

    Open source URL
  34. [34]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  35. [35]
    CrowdStrike SUNSPOT Implant January 2021

    CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021.

    Open source URL
  36. [36]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  37. [37]
    ESET Turla Lunar toolset May 2024

    Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

    Open source URL
  38. [38]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  39. [39]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  40. [40]
    Cybereason StealBit Exfiltration Tool

    Cybereason Global SOC Team. (n.d.). THREAT ANALYSIS REPORT: Inside the LockBit Arsenal - The StealBit Exfiltration Tool. Retrieved January 29, 2025.

    Open source URL
  41. [41]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  42. [42]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  43. [43]
    FBI Lockbit 2.0 FEB 2022

    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

    Open source URL
  44. [44]
    Palo Alto Lockbit 2.0 JUN 2022

    Elsad, A. et al. (2022, June 9). LockBit 2.0: How This RaaS Operates and How to Protect Against It. Retrieved January 24, 2025.

    Open source URL
  45. [45]
    ESET RedLine Stealer November 2024

    Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.

    Open source URL
  46. [46]
    Proofpoint RedLine Stealer March 2020

    Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.

    Open source URL
  47. [47]
    SentinelOne NobleBaron June 2021

    Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021.

    Open source URL
  48. [48]
    CISA Iran Albanian Attacks September 2022

    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

    Open source URL
  49. [49]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  50. [50]
    Trustwave BlackByte 2021

    Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.

    Open source URL
  51. [51]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  52. [52]
    Splunk ShrinkLocker 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

    Open source URL
  53. [53]
    Cisco LotusBlossom 2025

    Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.

    Open source URL
  54. [54]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  55. [55]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  56. [56]
    Google Cloud BOLDMOVE 2023

    Scott Henderson, Cristiana Kittner, Sarah Hawley & Mark Lechtik, Google Cloud. (2023, January 19). Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475). Retrieved December 31, 2024.

    Open source URL
  57. [57]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  58. [58]
    unit42_gamaredon_dec2022

    Unit 42. (2022, December 20). Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine. Retrieved September 12, 2024.

    Open source URL
  59. [59]
    VenereCiscoTalos_Gamaredon_Mar2025

    Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.

    Open source URL
  60. [60]
    Cisco Akira Ransomware OCT 2024

    Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024.

    Open source URL
  61. [61]
    FireEye Kevin Mandia Guardrails

    Shoorbajee, Z. (2018, June 1). Playing nice? FireEye CEO says U.S. malware is more restrained than adversaries'. Retrieved January 17, 2019.

    Open source URL
  62. [62]
    FireEye Kevin Mandia Guardrails

    Shoorbajee, Z. (2018, June 1). Playing nice? FireEye CEO says U.S. malware is more restrained than adversaries'. Retrieved January 17, 2019.

    Open source URL
  63. [63]
    FireEye Outlook Dec 2019

    McWhirt, M., Carr, N., Bienstock, D. (2019, December 4). Breaking the Rules: A Tough Outlook for Home Page Attacks (CVE-2017-11774). Retrieved June 23, 2020.

    Open source URL
  64. [64]
    FireEye Outlook Dec 2019

    McWhirt, M., Carr, N., Bienstock, D. (2019, December 4). Breaking the Rules: A Tough Outlook for Home Page Attacks (CVE-2017-11774). Retrieved June 23, 2020.

    Open source URL
  65. [65]
    Trellix-Qakbot

    Pham Duy Phuc, John Fokker J.E., Alejandro Houspanossian and Mathanraj Thangaraju. (2023, March 7). Qakbot Evolves to OneNote Malware Distribution. Retrieved June 7, 2024.

    Open source URL
  66. [66]
    Trellix-Qakbot

    Pham Duy Phuc, John Fokker J.E., Alejandro Houspanossian and Mathanraj Thangaraju. (2023, March 7). Qakbot Evolves to OneNote Malware Distribution. Retrieved June 7, 2024.

    Open source URL
  67. [67]
    mitre-attackT1480
    Open source URL
  68. [68]
    mitre-attackT1480
    Open source URL
  69. [69]
    mitre-attackT1480
    Open source URL
  70. [70]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  71. [71]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  72. [72]
    Mandiant ROADSWEEP August 2022

    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

    Open source URL
  73. [73]
    Trend Micro Mustang Panda Earth Preta Toneshell February 2025

    Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.

    Open source URL
  74. [74]
    SecureListUbiedo_Tsundere_Nov2025

    Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

    Open source URL
  75. [75]
    Group-IB RansomHub FEB 2025

    Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

    Open source URL
  76. [76]
    Socket GlassWorm January 2026

    Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

    Open source URL
  77. [77]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  78. [78]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  79. [79]
    Sandfly BPFDoor 2022

    The Sandfly Security Team. (2022, May 11). BPFDoor - An Evasive Linux Backdoor Technical Analysis. Retrieved September 29, 2023.

    Open source URL
  80. [80]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  81. [81]
    HP RaspberryRobin 2024

    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.

    Open source URL
  82. [82]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  83. [83]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  84. [84]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  85. [85]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  86. [86]
    Huntress LightSpy macOS 2024

    Stuart Ashenbrenner, Alden Schmidt. (2024, April 25). LightSpy Malware Variant Targeting macOS. Retrieved January 3, 2025.

    Open source URL
  87. [87]
    McAfee Lazarus Nov 2020

    Beek, C. (2020, November 5). Operation North Star: Behind The Scenes. Retrieved December 20, 2021.

    Open source URL
  88. [88]
    NCSC GCHQ Small Sieve Jan 2022

    NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022.

    Open source URL
  89. [89]
    Fortgale StrelaStealer 2023

    Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.

    Open source URL
  90. [90]
    IBM StrelaStealer 2024

    Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.

    Open source URL
  91. [91]
    Breakdev Evilginx 2.4 SEP 2020

    Gretzky, K. (2020, September 14). Evilginx 2.4 - Gone Phishing. Retrieved January 27, 2026.

    Open source URL
  92. [92]
    Kaspersky LODEINFO Part II OCT 2022

    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.

    Open source URL
  93. [93]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  94. [94]
    CERT Polska

    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

    Open source URL
  95. [95]
    Joint Cybersecurity Advisory LockBit 3.0 MAR 2023

    FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.

    Open source URL
  96. [96]
    Joint Cybersecurity Advisory LockBit JUN 2023

    CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.

    Open source URL
  97. [97]
    Sentinel Labs LockBit 3.0 JUL 2022

    Walter, J. (2022, July 21). LockBit 3.0 Update | Unpicking the Ransomware’s Latest Anti-Analysis and Evasion Techniques. Retrieved February 5, 2025.

    Open source URL
  98. [98]
    Picus Qilin MAR 2025

    Hacioglu, S. (2025, March 10). Qilin Ransomware: Exposing the TTPs Behind One of the Most Active Ransomware Campaigns of 2024. Retrieved September 26, 2025.

    Open source URL
  99. [99]
    Trend Micro Agenda Ransomware OCT 2025

    Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

    Open source URL
  100. [100]
    HarmonProofpoint_SystemBC_Aug2019

    Harmon, K., et al. (2019, August 1). SystemBC is like Christmas in July for SOCKS5 Malware and Exploit Kits . Retrieved June 13, 2025.

    Open source URL
  101. [101]
    SophosGnGal_SystemBC_Dec2020

    Gallagher, S., Gn, S. (2020, December 16). Ransomware operators use SystemBC RAT as off-the-shelf Tor backdoor. Retrieved May 16, 2025.

    Open source URL
  102. [102]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  103. [103]
    CrowdStrike SUNSPOT Implant January 2021

    CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021.

    Open source URL
  104. [104]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  105. [105]
    ESET Turla Lunar toolset May 2024

    Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

    Open source URL
  106. [106]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  107. [107]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  108. [108]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  109. [109]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  110. [110]
    Cybereason StealBit Exfiltration Tool

    Cybereason Global SOC Team. (n.d.). THREAT ANALYSIS REPORT: Inside the LockBit Arsenal - The StealBit Exfiltration Tool. Retrieved January 29, 2025.

    Open source URL
  111. [111]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  112. [112]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  113. [113]
    FBI Lockbit 2.0 FEB 2022

    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

    Open source URL
  114. [114]
    Palo Alto Lockbit 2.0 JUN 2022

    Elsad, A. et al. (2022, June 9). LockBit 2.0: How This RaaS Operates and How to Protect Against It. Retrieved January 24, 2025.

    Open source URL
  115. [115]
    ESET RedLine Stealer November 2024

    Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.

    Open source URL
  116. [116]
    Proofpoint RedLine Stealer March 2020

    Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.

    Open source URL
  117. [117]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  118. [118]
    MSTIC Nobelium Toolset May 2021

    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

    Open source URL
  119. [119]
    SentinelOne NobleBaron June 2021

    Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021.

    Open source URL
  120. [120]
    CISA Iran Albanian Attacks September 2022

    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

    Open source URL
  121. [121]
    Mandiant ROADSWEEP August 2022

    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

    Open source URL
  122. [122]
    Mandiant ROADSWEEP August 2022

    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

    Open source URL
  123. [123]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  124. [124]
    Trustwave BlackByte 2021

    Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.

    Open source URL
  125. [125]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.