LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1497.003: Time Based Checks

Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. This may include enumerating time-based properties, such as uptime or the system clock.

Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.[1]

EnterpriseT1497.003Sub-techniqueObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Time Based Checks matter because they help malware decide whether it is being watched. Instead of immediately revealing malicious behavior in a sandbox or analyst VM, a sample may inspect uptime, system time, or timer behavior and delay, change, or suppress execution if the environment looks artificial. For leaders, the business issue is not the timer check itself; it is the possibility that malware triage, detonation, and incident scoping may understate risk when evasive code refuses to run in analysis environments.

Executive priority

Prioritize this as a validation topic for malware analysis, managed detection, and incident response readiness. ATT&CK links this sub-technique to Virtualization/Sandbox Evasion and to numerous malware families and a campaign, which makes it relevant to confidence in sandbox verdicts, alert enrichment, and escalation decisions. Security leaders should ask whether SOC and IR teams treat a clean or low-activity sandbox run as provisional when timing evasion indicators are present, and whether evidence from endpoints is retained to support audit, investigation, and post-incident decisions.

Technical view

T1497.003 is a stealth/discovery sub-technique of Virtualization/Sandbox Evasion on Linux, macOS, and Windows. The official description highlights checks such as uptime, system clock, and API-style time queries including GetTickCount and GetSystemTimeAsFileTime, plus comparisons before and after sleep behavior to identify accelerated time in sandboxes. ATT&CK provides no official detection text, but relationship context includes detection strategy DET0141, Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution. SOC and detection engineering teams should validate whether detonation, EDR, and host telemetry can expose suspicious long sleeps, repeated timer loops, unusual time queries, and execution that changes after elapsed-time thresholds, while recognizing that benign software also uses timers and sleeps.

Likely telemetry

  • Endpoint process execution and parent/child process context
  • Host API or behavioral telemetry for time, uptime, sleep, and timer-loop activity where available
  • Sandbox or malware detonation traces, including elapsed runtime, sleep acceleration behavior, and observed execution path changes
  • System time, uptime, and clock-change records where collected
  • File and process activity before and after delayed execution windows

Detection direction

  • Do not rely on a single short sandbox execution result for unknown binaries when timing checks or delayed execution behavior are observed.
  • Use DET0141 relationship context as a detection-engineering starting point for sleep, timer-loop, and delayed-execution analytics, then tune against local baseline software that legitimately uses timers.
  • Correlate timing behavior with broader suspicious context, such as new or untrusted process execution, later payload activity, or network activity after a delay, rather than alerting on sleep calls alone.
  • Validate coverage across Linux, macOS, and Windows if those platforms are in scope; many related software examples in the supplied relationships are Windows-focused, but the ATT&CK technique platform field is broader.
  • Preserve sandbox traces and endpoint evidence showing both pre-delay and post-delay behavior so IR teams can distinguish non-execution from evasion.

Mitigation priorities

  • Improve malware-analysis procedures first: extend or vary detonation runtimes and document when sandbox results are inconclusive due to delayed or time-aware behavior.
  • Ensure endpoint telemetry retention can compensate for sandbox blind spots, especially process, file, timing-related behavioral traces, and post-delay network activity.
  • Use layered controls rather than a timer-specific block: prevention, EDR behavior monitoring, sandboxing, and IR playbooks should all account for virtualization and sandbox evasion.
  • Train SOC and IR analysts to escalate suspicious samples that appear inert in analysis but show timing checks, because the absence of payload behavior may be an evasion result rather than proof of harmlessness.
  • Map this behavior into compliance and assurance evidence where malware analysis, monitoring, and incident response effectiveness must be demonstrated.
Additional notes and limits

The supplied relationships show this behavior used by Operation Dream Job and multiple software entries including Crimson, TrickBot, Bisonal, Ursnif, EvilBunny, Okrum, Lokibot, Pony, GoldenSpy, FatDuke, LiteDuke, Bazar, Egregor, SUNBURST, GuLoader, Raindrop, BendyBear, AppleJeus, GoldMax, ThiefQuest, and Clop. That breadth supports treating time-based evasion as a common analysis-resilience concern, but each local detection decision still needs host and sandbox evidence.

ATT&CK provides no official detection text for this object, and the supplied fields do not include mitigations or procedure-level details for each related software item. This take should not be read as evidence of current exploitation, attribution, or guaranteed detection coverage. Local platform mix, sandbox configuration, endpoint telemetry depth, and retention determine practical visibility.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Time Based Checks

Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. This may include enumerating time-based properties, such as uptime or the system clock.

Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1497Virtualization/Sandbox EvasionThis object subtechnique of Virtualization/Sandbox Evasion.
Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0559: SUNBURST

SUNBURST is a trojanized DLL designed to fit within the SolarWinds Orion software update framework. It was used by APT29 since at least February 2020.[1][2]

Windows
MalwareEnterprise

S0574: BendyBear

BendyBear is an x64 shellcode for a stage-zero implant designed to download malware from a C2 server. First discovered in August 2020, BendyBear shares a variety of features with Waterbear, malware previously attributed to the Chinese cyber espionage group BlackTech.[1]

Windows
MalwareEnterprise

S0554: Egregor

Egregor is a Ransomware-as-a-Service (RaaS) tool that was first observed in September 2020. Researchers have noted code similarities between Egregor and Sekhmet ransomware, as well as Maze ransomware.[1][2][3]

Windows
MalwareEnterprise

S0611: Clop

Clop is a ransomware family that was first observed in February 2019 and has been used against retail, transportation and logistics, education, manufacturing, engineering, automotive, energy, financial, aerospace, telecommunications, professional and legal services, healthcare, and high tech industries. Clop is a variant of the CryptoMix ransomware.[1][2][3]

Windows
MalwareEnterprise

S0386: Ursnif

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]

Windows
ToolEnterprise

S9003: evilginx2

evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.[1][2][3]

IaaSIdentity ProviderOffice Suite
CampaignEnterprise

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.0
Created
Modified
Raw hash
16e047049887f091...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.0Current bundle16e047049887…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ISACA Malware Tricks

    Kolbitsch, C. (2017, November 1). Evasive Malware Tricks: How Malware Evades Detection by Sandboxes. Retrieved March 30, 2021.

    Open source URL
  2. [2]
    Symantec RAINDROP January 2021

    Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.

    Open source URL
  3. [3]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  4. [4]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  5. [5]
    Unit42 BendyBear Feb 2021

    Harbison, M. (2021, February 9). BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech. Retrieved February 16, 2021.

    Open source URL
  6. [6]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  7. [7]
    Unit42 Clop April 2021

    Santos, D. (2021, April 13). Threat Assessment: Clop Ransomware. Retrieved July 30, 2021.

    Open source URL
  8. [8]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  9. [9]
    TrendMicro Ursnif File Dec 2014

    Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.

    Open source URL
  10. [10]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  11. [11]
    Breakdev Evilginx 3.2 AUG 2023

    Gretzky, K. (2023, August 24). Evilginx 3.2 - Swimming With The Phishes. Retrieved January 27, 2026.

    Open source URL
  12. [12]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  13. [13]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  14. [14]
    ESET Turla Lunar toolset May 2024

    Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

    Open source URL
  15. [15]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  16. [16]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  17. [17]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  18. [18]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  19. [19]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  20. [20]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  21. [21]
    Kaspersky Tomiris Sep 2021

    Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021.

    Open source URL
  22. [22]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  23. [23]
    Talos Lokibot Jan 2021

    Muhammad, I., Unterbrink, H.. (2021, January 6). A Deep Dive into Lokibot Infection Chain. Retrieved August 31, 2021.

    Open source URL
  24. [24]
    Morphisec Snip3 May 2021

    Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.

    Open source URL
  25. [25]
    Group-IB RansomHub FEB 2025

    Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

    Open source URL
  26. [26]
    Kaspersky CactusPete Aug 2020

    Zykov, K. (2020, August 13). CactusPete APT group’s updated Bisonal backdoor. Retrieved May 5, 2021.

    Open source URL
  27. [27]
    Talos Bisonal Mar 2020

    Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.

    Open source URL
  28. [28]
    Cybereason StrifeWater Feb 2022

    Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022.

    Open source URL
  29. [29]
    Malwarebytes Pony April 2016

    hasherezade. (2016, April 11). No money, but Pony! From a mail to a trojan horse. Retrieved May 21, 2020.

    Open source URL
  30. [30]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  31. [31]
    Joe Sec Trickbot

    Joe Security. (2020, July 13). TrickBot's new API-Hammering explained. Retrieved September 30, 2021.

    Open source URL
  32. [32]
    SentinelLabs Metador Technical Appendix Sept 2022

    SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

    Open source URL
  33. [33]
    Cyberint Qakbot May 2021

    Cyberint. (2021, May 25). Qakbot Banking Trojan. Retrieved September 27, 2021.

    Open source URL
  34. [34]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  35. [35]
    Group IB GrimAgent July 2021

    Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

    Open source URL
  36. [36]
    NCC Group Team9 June 2020

    Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.

    Open source URL
  37. [37]
    Cyphort EvilBunny Dec 2014

    Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.

    Open source URL
  38. [38]
    Accenture MUDCARP March 2019

    Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.

    Open source URL
  39. [39]
    Havoc Framework Documentation

    Ungur, P. (n.d.). HAVOC. Retrieved August 4, 2025.

    Open source URL
  40. [40]
    Zscaler Havoc FEB 2023

    Shivtarkar, N. and Jain, S. (2023, February 14). Havoc Across the Cyberspace. Retrieved August 4, 2025.

    Open source URL
  41. [41]
    Trustwave GoldenSpy June 2020

    Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.

    Open source URL
  42. [42]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  43. [43]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  44. [44]
    MSTIC NOBELIUM Mar 2021

    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

    Open source URL
  45. [45]
    Medium Eli Salem GuLoader April 2021

    Salem, E. (2021, April 19). Dancing With Shellcodes: Cracking the latest version of Guloader. Retrieved July 7, 2021.

    Open source URL
  46. [46]
    HP SVCReady Jun 2022

    Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.

    Open source URL
  47. [47]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  48. [48]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  49. [49]
    trendmicro xcsset xcode project 2020

    Mac Threat Response, Mobile Research Team. (2020, August 13). The XCSSET Malware: Inserts Malicious Code Into Xcode Projects, Performs UXSS Backdoor Planting in Safari, and Leverages Two Zero-day Exploits. Retrieved October 5, 2021.

    Open source URL
  50. [50]
    wardle evilquest parti

    Patrick Wardle. (2020, June 29). OSX.EvilQuest Uncovered part i: infection, persistence, and more!. Retrieved March 18, 2021.

    Open source URL
  51. [51]
    CISA AppleJeus Feb 2021

    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

    Open source URL
  52. [52]
    ISACA Malware Tricks

    Kolbitsch, C. (2017, November 1). Evasive Malware Tricks: How Malware Evades Detection by Sandboxes. Retrieved March 30, 2021.

    Open source URL
  53. [53]
    ISACA Malware Tricks

    Kolbitsch, C. (2017, November 1). Evasive Malware Tricks: How Malware Evades Detection by Sandboxes. Retrieved March 30, 2021.

    Open source URL
  54. [54]
    mitre-attackT1497.003
    Open source URL
  55. [55]
    mitre-attackT1497.003
    Open source URL
  56. [56]
    mitre-attackT1497.003
    Open source URL
  57. [57]
    Symantec RAINDROP January 2021

    Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.

    Open source URL
  58. [58]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  59. [59]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  60. [60]
    Unit42 BendyBear Feb 2021

    Harbison, M. (2021, February 9). BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech. Retrieved February 16, 2021.

    Open source URL
  61. [61]
    JoeSecurity Egregor 2020

    Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.

    Open source URL
  62. [62]
    Unit42 Clop April 2021

    Santos, D. (2021, April 13). Threat Assessment: Clop Ransomware. Retrieved July 30, 2021.

    Open source URL
  63. [63]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  64. [64]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  65. [65]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  66. [66]
    TrendMicro Ursnif File Dec 2014

    Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.

    Open source URL
  67. [67]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  68. [68]
    Breakdev Evilginx 3.2 AUG 2023

    Gretzky, K. (2023, August 24). Evilginx 3.2 - Swimming With The Phishes. Retrieved January 27, 2026.

    Open source URL
  69. [69]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  70. [70]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  71. [71]
    ESET Turla Lunar toolset May 2024

    Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024.

    Open source URL
  72. [72]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  73. [73]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  74. [74]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  75. [75]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  76. [76]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  77. [77]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  78. [78]
    Kaspersky Tomiris Sep 2021

    Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021.

    Open source URL
  79. [79]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  80. [80]
    Talos Lokibot Jan 2021

    Muhammad, I., Unterbrink, H.. (2021, January 6). A Deep Dive into Lokibot Infection Chain. Retrieved August 31, 2021.

    Open source URL
  81. [81]
    Morphisec Snip3 May 2021

    Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.

    Open source URL
  82. [82]
    Group-IB RansomHub FEB 2025

    Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

    Open source URL
  83. [83]
    Kaspersky CactusPete Aug 2020

    Zykov, K. (2020, August 13). CactusPete APT group’s updated Bisonal backdoor. Retrieved May 5, 2021.

    Open source URL
  84. [84]
    Talos Bisonal Mar 2020

    Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.

    Open source URL
  85. [85]
    Cybereason StrifeWater Feb 2022

    Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022.

    Open source URL
  86. [86]
    Malwarebytes Pony April 2016

    hasherezade. (2016, April 11). No money, but Pony! From a mail to a trojan horse. Retrieved May 21, 2020.

    Open source URL
  87. [87]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  88. [88]
    Joe Sec Trickbot

    Joe Security. (2020, July 13). TrickBot's new API-Hammering explained. Retrieved September 30, 2021.

    Open source URL
  89. [89]
    SentinelLabs Metador Technical Appendix Sept 2022

    SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

    Open source URL
  90. [90]
    Cyberint Qakbot May 2021

    Cyberint. (2021, May 25). Qakbot Banking Trojan. Retrieved September 27, 2021.

    Open source URL
  91. [91]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  92. [92]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  93. [93]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  94. [94]
    Group IB GrimAgent July 2021

    Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

    Open source URL
  95. [95]
    NCC Group Team9 June 2020

    Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.

    Open source URL
  96. [96]
    Cyphort EvilBunny Dec 2014

    Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.

    Open source URL
  97. [97]
    Accenture MUDCARP March 2019

    Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.

    Open source URL
  98. [98]
    Havoc Framework Documentation

    Ungur, P. (n.d.). HAVOC. Retrieved August 4, 2025.

    Open source URL
  99. [99]
    Zscaler Havoc FEB 2023

    Shivtarkar, N. and Jain, S. (2023, February 14). Havoc Across the Cyberspace. Retrieved August 4, 2025.

    Open source URL
  100. [100]
    Trustwave GoldenSpy June 2020

    Trustwave SpiderLabs. (2020, June 25). The Golden Tax Department and Emergence of GoldenSpy Malware. Retrieved July 23, 2020.

    Open source URL
  101. [101]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  102. [102]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  103. [103]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  104. [104]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  105. [105]
    MSTIC NOBELIUM Mar 2021

    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

    Open source URL
  106. [106]
    Medium Eli Salem GuLoader April 2021

    Salem, E. (2021, April 19). Dancing With Shellcodes: Cracking the latest version of Guloader. Retrieved July 7, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.