LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1497: Virtualization/Sandbox Evasion

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.[1]

Adversaries may use several methods to accomplish Virtualization/Sandbox Evasion such as checking for security monitoring tools (e.g., Sysinternals, Wireshark, etc.) or other system artifacts associated with analysis or virtualization. Adversaries may also check for legitimate user activity to help determine if it is in an analysis environment. Additional methods include use of sleep timers or loops within malware code to avoid operating within a temporary sandbox.[2]

EnterpriseT1497TechniqueObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Virtualization/Sandbox Evasion matters because it can cause malware to behave differently when it thinks it is being analyzed. For leaders, the practical risk is that automated detonation, malware triage, and some managed detection workflows may understate what a payload can do if the sample detects a virtual machine, sandbox, monitoring tool, short runtime window, or lack of normal user activity.

Executive priority

Treat this as an assurance and readiness issue, not only a malware feature. Ask whether security teams can validate suspicious files and implants across Linux, macOS, and Windows without relying on a single sandbox result. This technique is relevant to incident decision-making because a “no behavior observed” sandbox verdict may be inconclusive. It also supports audit and resilience discussions around whether detection engineering, incident response, and threat intelligence processes account for evasive malware behavior.

Technical view

ATT&CK places T1497 under stealth and discovery for Linux, macOS, and Windows. The supplied relationships show sub-techniques for System Checks and Time Based Checks, so defenders should validate both environment-artifact discovery and delayed or timing-aware execution. SOC and IR teams should correlate sandbox findings with endpoint telemetry from real or representative hosts, especially when samples inspect monitoring tools, virtualization artifacts, uptime, clocks, sleep timers, or signs of real user activity. The related DET0046 detection strategy indicates there is ATT&CK detection-strategy context for this object, but the official technique field supplied here does not include specific detection text.

Likely telemetry

  • Endpoint process creation and command-line activity on Linux, macOS, and Windows
  • API or system-call level evidence related to system, clock, uptime, and environment queries where available
  • File, registry, device, driver, service, or system artifact access that may indicate checks for virtualization or analysis environments
  • Security tool or monitoring tool enumeration activity, including references to tools such as Sysinternals or Wireshark when visible
  • Sandbox detonation logs, including execution duration, sleep behavior, dropped payload timing, and differences across analysis profiles

Detection direction

  • Do not treat a clean or low-activity sandbox run as decisive when the sample shows long sleeps, environment checks, or analysis-tool awareness.
  • Compare behavior across sandbox, VM, and representative endpoint environments to identify payloads that disengage or withhold secondary stages.
  • Tune analytics around discovery of virtualization artifacts, security tools, uptime, system time, and clock manipulation indicators, while accounting for legitimate admin, QA, research, and IT troubleshooting activity.
  • Use relationship context from T1497.001 System Checks and T1497.003 Time Based Checks to split detection validation into environment-inspection behavior and delayed/timing behavior.
  • Review DET0046 as the ATT&CK-linked detection strategy for this technique, but confirm local telemetry and rule logic before claiming coverage.

Mitigation priorities

  • Prioritize resilient analysis workflows: combine sandboxing with endpoint telemetry, manual IR review, and repeat detonation under varied runtime and environment conditions.
  • Harden SOC procedures so evasive or inconclusive malware analysis results trigger escalation criteria rather than closure.
  • Ensure EDR, logging, and malware-analysis tooling retain enough process, file, system query, and timing evidence to reconstruct evasion behavior.
  • Maintain representative analysis environments where practical, while recognizing that adversaries may still detect artifacts or lack of normal user activity.
  • Use findings from evasive samples to improve detection engineering and incident response playbooks across supported platforms rather than relying on one control layer.
Additional notes and limits

The object is broadly applicable across Linux, macOS, and Windows and has many relationships to campaigns, groups, and malware/software, including loaders, backdoors, banking malware, spyware, ransomware, and wipers. That breadth makes the technique useful for defensive coverage planning, but the relationships should not be read as current activity or exposure without local intelligence.

The supplied ATT&CK object does not provide official detection guidance, and relationship descriptions are partial. This take is limited to the official fields, external references, and listed relationships. Local telemetry, tooling, sandbox configuration, and incident context are required to determine actual coverage or risk.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Virtualization/Sandbox Evasion

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.[1]

Adversaries may use several methods to accomplish Virtualization/Sandbox Evasion such as checking for security monitoring tools (e.g., Sysinternals, Wireshark, etc.) or other system artifacts associated with analysis or virtualization. Adversaries may also check for legitimate user activity to help determine if it is in an analysis environment. Additional methods include use of sleep timers or loops within malware code to avoid operating within a temporary sandbox.[2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

3 rows
DomainIDNameRelationship / procedure
EnterpriseT1497.002User Activity Based ChecksSub-techniqueUser Activity Based Checks subtechnique of this object.
EnterpriseT1497.001System ChecksSub-techniqueSystem Checks subtechnique of this object.
EnterpriseT1497.003Time Based ChecksSub-techniqueTime Based Checks subtechnique of this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G1031: Saint Bear

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities.[1][2] Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

GroupEnterprise

G0012: Darkhotel

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.[1][2][3]

MalwareEnterprise

S0483: IcedID

IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.[1][2]

Windows
MalwareEnterprise

S0268: Bisonal

Bisonal is a remote access tool (RAT) that has been used by Tonto Team against public and private sector organizations in Russia, South Korea, and Japan since at least December 2010.[1][2]

Windows
MalwareEnterprise

S0484: Carberp

Carberp is a credential and information stealing malware that has been active since at least 2009. Carberp's source code was leaked online in 2013, and subsequently used as the foundation for the Carbanak backdoor.[1][2][3]

Windows
MalwareEnterprise

S1070: Black Basta

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.[1][2][3][4][5][6]

WindowsESXi
MalwareEnterprise

S1130: Raspberry Robin

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.[1][2][3] The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."[4] The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.[5]

Windows
MalwareEnterprise

S0534: Bazar

Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.[1]

Windows
MalwareEnterprise

S0666: Gelsemium

Gelsemium is a modular malware comprised of a dropper (Gelsemine), a loader (Gelsenicine), and main (Gelsevirine) plug-ins written using the Microsoft Foundation Class (MFC) framework. Gelsemium has been used by the Gelsemium group since at least 2014.[1]

Windows
MalwareEnterprise

S0023: CHOPSTICK

CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants. [1] [2] [3] [4] It is tracked separately from the X-Agent for Android.

WindowsLinux
MalwareEnterprise

S0455: Metamorfo

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.[1][2]

Windows
MalwareEnterprise

S1039: Bumblebee

Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since at least March 2022. Bumblebee has been linked to ransomware operations including Conti, Quantum, and Mountlocker and derived its name from the appearance of "bumblebee" in the user-agent.[1][2][3]

Windows
CampaignEnterprise

C0005: Operation Spalax

Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical industries. The Operation Spalax threat actors distributed commodity malware and tools using generic phishing topics related to COVID-19, banking, and law enforcement action. Security researchers noted indicators of compromise and some infrastructure overlaps with other campaigns dating back to April 2018, including at least one separately attributed to APT-C-36, however identified enough differences to report this as separate, unattributed activity.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
eac26eb9c8d28d7a...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundleeac26eb9c8d2…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Deloitte Environment Awareness

    Torello, A. & Guibernau, F. (n.d.). Environment Awareness. Retrieved September 13, 2024.

    Open source URL
  2. [2]
    Unit 42 Pirpi July 2015

    Falcone, R., Wartell, R.. (2015, July 27). UPS: Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload. Retrieved April 23, 2019.

    Open source URL
  3. [3]
    Kaspersky StoneDrill 2017

    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.

    Open source URL
  4. [4]
    Trendmicro_IcedID

    Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.

    Open source URL
  5. [5]
    Malwarebytes Agent Tesla April 2020

    Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020.

    Open source URL
  6. [6]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  7. [7]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  8. [8]
    Talos Bisonal Mar 2020

    Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.

    Open source URL
  9. [9]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  10. [10]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  11. [11]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  12. [12]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  13. [13]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  14. [14]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  15. [15]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  16. [16]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  17. [17]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  18. [18]
    ANY.RUN XLoader 2023

    ANY.RUN. (2023, February 28). XLoader/FormBook: Encryption Analysis and Malware Decryption . Retrieved March 11, 2025.

    Open source URL
  19. [19]
    CheckPoint XLoader 2022

    Alexey Bukhteyev & Raman Ladutska, Check Point Research. (2022, May 31). XLoader Botnet: Find Me If You Can. Retrieved March 11, 2025.

    Open source URL
  20. [20]
    PaloAlto StrelaStealer 2024

    Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya & Vishwa Thothathri, Palo Alto Networks. (2024, March 22). Large-Scale StrelaStealer Campaign in Early 2024. Retrieved December 31, 2024.

    Open source URL
  21. [21]
    Fortgale StrelaStealer 2023

    Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.

    Open source URL
  22. [22]
    Unit42 Redaman January 2019

    Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.

    Open source URL
  23. [23]
    Lastline DarkHotel Just In Time Decryption Nov 2015

    Arunpreet Singh, Clemens Kolbitsch. (2015, November 5). Defeating Darkhotel Just-In-Time Decryption. Retrieved April 15, 2021.

    Open source URL
  24. [24]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  25. [25]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  26. [26]
    F-Secure CozyDuke

    F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.

    Open source URL
  27. [27]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  28. [28]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  29. [29]
    Unit 42 Gamaredon February 2022

    Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

    Open source URL
  30. [30]
    ZScaler Squirrelwaffle Sep 2021

    Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022.

    Open source URL
  31. [31]
    Netskope Squirrelwaffle Oct 2021

    Palazolo, G. (2021, October 7). SquirrelWaffle: New Malware Loader Delivering Cobalt Strike and QakBot. Retrieved August 9, 2022.

    Open source URL
  32. [32]
    FireEye Hancitor

    Anubhav, A., Jallepalli, D. (2016, September 23). Hancitor (AKA Chanitor) observed using multiple attack approaches. Retrieved August 13, 2020.

    Open source URL
  33. [33]
    Deloitte Environment Awareness

    Torello, A. & Guibernau, F. (n.d.). Environment Awareness. Retrieved September 13, 2024.

    Open source URL
  34. [34]
    Deloitte Environment Awareness

    Torello, A. & Guibernau, F. (n.d.). Environment Awareness. Retrieved September 13, 2024.

    Open source URL
  35. [35]
    Unit 42 Pirpi July 2015

    Falcone, R., Wartell, R.. (2015, July 27). UPS: Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload. Retrieved April 23, 2019.

    Open source URL
  36. [36]
    Unit 42 Pirpi July 2015

    Falcone, R., Wartell, R.. (2015, July 27). UPS: Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload. Retrieved April 23, 2019.

    Open source URL
  37. [37]
    mitre-attackT1497
    Open source URL
  38. [38]
    mitre-attackT1497
    Open source URL
  39. [39]
    mitre-attackT1497
    Open source URL
  40. [40]
    Kaspersky StoneDrill 2017

    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.

    Open source URL
  41. [41]
    Trendmicro_IcedID

    Kenefick , I. (2022, December 23). IcedID Botnet Distributors Abuse Google PPC to Distribute Malware. Retrieved July 24, 2024.

    Open source URL
  42. [42]
    Malwarebytes Agent Tesla April 2020

    Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020.

    Open source URL
  43. [43]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  44. [44]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  45. [45]
    Talos Bisonal Mar 2020

    Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.

    Open source URL
  46. [46]
    ESET Carberp March 2012

    Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020.

    Open source URL
  47. [47]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  48. [48]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  49. [49]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  50. [50]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  51. [51]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  52. [52]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  53. [53]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  54. [54]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  55. [55]
    ANY.RUN XLoader 2023

    ANY.RUN. (2023, February 28). XLoader/FormBook: Encryption Analysis and Malware Decryption . Retrieved March 11, 2025.

    Open source URL
  56. [56]
    CheckPoint XLoader 2022

    Alexey Bukhteyev & Raman Ladutska, Check Point Research. (2022, May 31). XLoader Botnet: Find Me If You Can. Retrieved March 11, 2025.

    Open source URL
  57. [57]
    Fortgale StrelaStealer 2023

    Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.

    Open source URL
  58. [58]
    PaloAlto StrelaStealer 2024

    Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya & Vishwa Thothathri, Palo Alto Networks. (2024, March 22). Large-Scale StrelaStealer Campaign in Early 2024. Retrieved December 31, 2024.

    Open source URL
  59. [59]
    Unit42 Redaman January 2019

    Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.

    Open source URL
  60. [60]
    Lastline DarkHotel Just In Time Decryption Nov 2015

    Arunpreet Singh, Clemens Kolbitsch. (2015, November 5). Defeating Darkhotel Just-In-Time Decryption. Retrieved April 15, 2021.

    Open source URL
  61. [61]
    Cyble Egregor Oct 2020

    Cybleinc. (2020, October 31). Egregor Ransomware – A Deep Dive Into Its Activities and Techniques. Retrieved December 29, 2020.

    Open source URL
  62. [62]
    NHS Digital Egregor Nov 2020

    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.

    Open source URL
  63. [63]
    F-Secure CozyDuke

    F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.

    Open source URL
  64. [64]
    Kaspersky Lyceum October 2021

    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

    Open source URL
  65. [65]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  66. [66]
    Unit 42 Gamaredon February 2022

    Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.