LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1547.001: Registry Run Keys / Startup Folder

MITRE ATT&CK T1547.001: Registry Run Keys / Startup Folder Technique details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseT1547.001Sub-techniqueObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Registry Run Keys and Startup Folder persistence matters because it lets code come back automatically when a Windows user logs in or the system boots. For leaders, this is a resilience and incident-response issue: a host that appears cleaned can re-execute unwanted tooling if these autostart locations are not reviewed. Because execution occurs in the user’s context, identity privilege, endpoint hygiene, and Windows configuration monitoring all affect business risk.

Executive priority

Prioritize this technique for Windows endpoint and server environments where persistence after reboot would materially slow containment or recovery. Ask whether SOC and IR teams can prove they monitor common and less-obvious autostart locations, including HKCU/HKLM Run and RunOnce keys, Startup folders, policy-based Explorer Run keys, RunServices keys, RunOnceEx, Shell Folder redirection keys, and BootExecute. The ATT&CK relationships show this behavior is used across many named groups and campaigns, so coverage should be treated as baseline defensive evidence rather than a niche detection.

Technical view

Validate Windows persistence coverage across the persistence and privilege-escalation tactics. Detection should not stop at default Run and RunOnce keys; the supplied ATT&CK description also calls out Wow6432Node-related registry views, RunOnceEx dependency loading, per-user and all-users Startup folders, Shell/User Shell Folder keys that define startup locations, RunServices/RunServicesOnce, policy Explorer Run keys, the Windows NT CurrentVersion Windows load value, and Session Manager BootExecute. IR triage should compare the referenced executable or DLL, the writing account, the modified registry path or folder, and subsequent execution at boot or logon. Relationship context to DET0365 indicates there is a specific ATT&CK detection strategy for this behavior, but the object itself provides no official detection text.

Likely telemetry

  • Windows registry value creation, modification, and deletion events for Run, RunOnce, RunOnceEx, RunServices, policy Explorer Run, Shell Folder, User Shell Folder, Windows load, and BootExecute locations.
  • File creation, modification, and shortcut placement in per-user and all-users Startup folders.
  • Process creation telemetry showing programs launched during user logon or system boot, including parent/child process context.
  • Command-line or script activity that writes registry values or places files in Startup folders.
  • User logon events and account context to determine whether persistence runs under a standard user, administrator, or system-wide path.

Detection direction

  • Baseline legitimate autostart entries, then alert on new, rare, unsigned, user-writable, temporary-directory, or suspiciously named values and files.
  • Cover both HKCU and HKLM paths; HKCU persistence may be missed if monitoring focuses only on machine-wide locations.
  • Include 32-bit and 64-bit registry views where relevant, as ATT&CK notes run keys may exist under multiple hives and references Wow6432Node behavior.
  • Do not rely only on common Run/RunOnce locations; tune for RunOnceEx dependencies, policy Explorer Run keys, Startup folder redirection, RunServices, and BootExecute changes.
  • Correlate registry or Startup folder changes with the first execution after reboot or user logon to reduce false positives from legitimate software installers and administrative tooling.

Mitigation priorities

  • Establish an approved baseline for Windows autostart locations and review deviations during endpoint hardening and incident response.
  • Limit unnecessary administrative rights and write access to system-wide startup locations and HKLM autostart keys.
  • Apply change control and monitoring to startup policy keys and boot/logon autostart configuration.
  • During containment, remove or disable malicious entries and the referenced files together; deleting only the payload or only the registry value may leave recovery gaps.
  • Include these locations in forensic collection, gold-image validation, and compliance evidence for endpoint configuration monitoring.
Additional notes and limits

This is a high-value Windows persistence validation item because it is simple, durable across reboots, and represented in relationships to numerous ATT&CK groups and campaigns including Operation Sharpshooter, Operation Dream Job, APT28, APT29, Lazarus Group, Dragonfly, FIN6, FIN7, and others. Those mappings support defensive prioritization, not assumptions about current activity in any specific environment.

The supplied ATT&CK object has no official detection text and no explicit mitigation records. Recommendations here are derived from the official description, platforms, tactics, external references, and relationships. Local endpoint logging, retention, baselines, and administrative practices determine whether the behavior is actually visible or actionable.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Registry Run Keys / Startup Folder

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1060Registry Run Keys / Startup FolderRegistry Run Keys / Startup Folder revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0073: APT19

APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. [1] Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same. [2] [3] [4]

GroupEnterprise

G0067: APT37

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.[1][2][3]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

GroupEnterprise

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.[1][2][3][4][5]

GroupEnterprise

G1018: TA2541

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.[1][2]

GroupEnterprise

G0048: RTM

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM). [1]

GroupEnterprise

G0059: Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.[1][2][3][4][5]

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

GroupEnterprise

G0100: Inception

Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.[1][2][3]

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

GroupEnterprise

G0139: TeamTNT

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.[1][2][3][4][5][6][7][8][9]

GroupEnterprise

G0065: Leviathan

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.[1] Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.[1][2][3][4]

GroupEnterprise

G0019: Naikon

Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).[1] Active since at least 2010, Naikon has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).[1][2]

While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.[3]

MalwareEnterprise

S0124: Pisloader

Pisloader is a malware family that is notable due to its use of DNS as a C2 protocol as well as its use of anti-analysis tactics. It has been used by APT18 and is similar to another malware family, HTTPBrowser, that has been used by the group. [1]

Windows
MalwareEnterprise

S0198: NETWIRE

NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.[1][2][3]

WindowsLinuxmacOS
MalwareEnterprise

S0386: Ursnif

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]

Windows
MalwareEnterprise

S0028: SHIPSHAPE

SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps. [1]

MalwareEnterprise

S0090: Rover

Rover is malware suspected of being used for espionage purposes. It was used in 2015 in a targeted email sent to an Indian Ambassador to Afghanistan. [1]

Windows
MalwareEnterprise

S0182: FinFisher

FinFisher is a government-grade commercial surveillance spyware reportedly sold exclusively to government agencies for use in targeted and lawful criminal investigations. It is heavily obfuscated and uses multiple anti-analysis techniques. It has other variants including Wingbird. [1] [2] [3] [4] [5]

WindowsAndroid
CampaignEnterprise

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
9e6052412362607d...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.1Current bundle9e6052412362…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft Run Key

    Microsoft. (n.d.). Run and RunOnce Registry Keys. Retrieved September 12, 2024.

    Open source URL
  2. [2]
    Microsoft Wow6432Node 2018

    Microsoft. (2018, May 31). 32-bit and 64-bit Application Data in the Registry. Retrieved August 3, 2020.

    Open source URL
  3. [3]
    Malwarebytes Wow6432Node 2016

    Arntz, P. (2016, March 30). Hiding in Plain Sight. Retrieved August 3, 2020.

    Open source URL
  4. [4]
    Oddvar Moe RunOnceEx Mar 2018

    Moe, O. (2018, March 21). Persistence using RunOnceEx - Hidden from Autoruns.exe. Retrieved June 29, 2018.

    Open source URL
  5. [5]
    Emissary Trojan Feb 2016

    Falcone, R. and Miller-Osborn, J. (2016, February 3). Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?. Retrieved February 15, 2016.

  6. [6]
    Palo Alto DNS Requests

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

  7. [7]
    Cyphort EvilBunny Dec 2014

    Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.

    Open source URL
  8. [8]
    Unit 42 C0d0so0 Jan 2016

    Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.

    Open source URL
  9. [9]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  10. [10]
    Talos Group123

    Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.

    Open source URL
  11. [11]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  12. [12]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  13. [13]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  14. [14]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  15. [15]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  16. [16]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  17. [17]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  18. [18]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  19. [19]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  20. [20]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  21. [21]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  22. [22]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  23. [23]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  24. [24]
    Unit 42 Magic Hound Feb 2017

    Lee, B. and Falcone, R. (2017, February 15). Magic Hound Campaign Attacks Saudi Targets. Retrieved December 27, 2017.

    Open source URL
  25. [25]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  26. [26]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  27. [27]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  28. [28]
    Fortinet Agent Tesla April 2018

    Zhang, X. (2018, April 05). Analysis of New Agent Tesla Spyware Variant. Retrieved November 5, 2018.

    Open source URL
  29. [29]
    SentinelLabs Agent Tesla Aug 2020

    Walter, J. (2020, August 10). Agent Tesla | Old RAT Uses New Tricks to Stay on Top. Retrieved December 11, 2020.

    Open source URL
  30. [30]
    MalwareBytes SideCopy Dec 2021

    Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

    Open source URL
  31. [31]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  32. [32]
    Palo Alto Rover

    Ray, V., Hayashi, K. (2016, February 29). New Malware ‘Rover’ Targets Indian Ambassador to Afghanistan. Retrieved February 29, 2016.

  33. [33]
    FinFisher Citation

    FinFisher. (n.d.). Retrieved September 12, 2024.

    Open source URL
  34. [34]
    Microsoft FinFisher March 2018

    Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018.

    Open source URL
  35. [35]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  36. [36]
    Sophos Maze VM September 2020

    Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.

    Open source URL
  37. [37]
    Unit 42 Nokki Oct 2018

    Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.

    Open source URL
  38. [38]
    Unit 42 BadPatch Oct 2017

    Bar, T., Conant, S. (2017, October 20). BadPatch. Retrieved November 13, 2018.

    Open source URL
  39. [39]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  40. [40]
    FBI Lockbit 2.0 FEB 2022

    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

    Open source URL
  41. [41]
    McAfee Lazarus Jul 2020

    Cashman, M. (2020, July 29). Operation North Star Campaign. Retrieved December 20, 2021.

    Open source URL
  42. [42]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
  43. [43]
    ATT TeamTNT Chimaera September 2020

    AT&T Alien Labs. (2021, September 8). TeamTNT with new campaign aka Chimaera. Retrieved September 22, 2021.

    Open source URL
  44. [44]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  45. [45]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  46. [46]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  47. [47]
    Prevailion EvilNum May 2020

    Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.

    Open source URL
  48. [48]
    Carbon Black JCry May 2019

    Lee, S.. (2019, May 14). JCry Ransomware. Retrieved June 18, 2019.

    Open source URL
  49. [49]
    Zscaler Cobian Aug 2017

    Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

    Open source URL
  50. [50]
    Symantec Darkmoon Aug 2005

    Hayashi, K. (2005, August 18). Backdoor.Darkmoon. Retrieved February 23, 2018.

    Open source URL
  51. [51]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  52. [52]
    Unit 42 Lucifer June 2020

    Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.

    Open source URL
  53. [53]
    Group IB GrimAgent July 2021

    Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

    Open source URL
  54. [54]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  55. [55]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  56. [56]
    Kaspersky ThreatNeedle Feb 2021

    Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021.

    Open source URL
  57. [57]
    Group-IB RansomHub FEB 2025

    Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

    Open source URL
  58. [58]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  59. [59]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  60. [60]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  61. [61]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  62. [62]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  63. [63]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  64. [64]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  65. [65]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  66. [66]
    Trend Micro Qakbot May 2020

    Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.

    Open source URL
  67. [67]
    Crowdstrike Qakbot October 2020

    CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.

    Open source URL
  68. [68]
    Trend Micro Qakbot December 2020

    Trend Micro. (2020, December 17). QAKBOT: A decade-old malware still with new tricks. Retrieved November 17, 2024.

    Open source URL
  69. [69]
    Group IB Ransomware September 2020

    Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.

    Open source URL
  70. [70]
    Group IB Silence Sept 2018

    Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.

    Open source URL
  71. [71]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  72. [72]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  73. [73]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  74. [74]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  75. [75]
    Securelist WhiteBear Aug 2017

    Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.

    Open source URL
  76. [76]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  77. [77]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  78. [78]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  79. [79]
    Symantec Emotet Jul 2018

    Symantec. (2018, July 18). The Evolution of Emotet: From Banking Trojan to Threat Distributor. Retrieved March 25, 2019.

    Open source URL
  80. [80]
    US-CERT Emotet Jul 2018

    US-CERT. (2018, July 20). Alert (TA18-201A) Emotet Malware. Retrieved March 25, 2019.

    Open source URL
  81. [81]
    Picus Emotet Dec 2018

    Özarslan, S. (2018, December 21). The Christmas Card you never wanted - A new wave of Emotet is back to wreak havoc. Retrieved March 25, 2019.

    Open source URL
  82. [82]
    F-Secure CozyDuke

    F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.

    Open source URL
  83. [83]
    Unit42 Xbash Sept 2018

    Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.

    Open source URL
  84. [84]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  85. [85]
    Mandiant No Easy Breach

    Dunwoody, M. and Carr, N.. (2016, September 27). No Easy Breach DerbyCon 2016. Retrieved September 12, 2024.

    Open source URL
  86. [86]
    IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025

    Golo Muhr, Joshua Chung. (2025, June 23). Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor. Retrieved August 4, 2025.

    Open source URL
  87. [87]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  88. [88]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  89. [89]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  90. [90]
    Talent-Jump Clambling February 2020

    Chen, T. and Chen, Z. (2020, February 17). CLAMBLING - A New Backdoor Base On Dropbox. Retrieved November 12, 2021.

    Open source URL
  91. [91]
    Dell Sakula

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, July 30). Sakula Malware Family. Retrieved January 26, 2016.

  92. [92]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  93. [93]
    Palo Alto Reaver Nov 2017

    Grunzweig, J. and Miller-Osborn, J. (2017, November 10). New Malware with Ties to SunOrcal Discovered. Retrieved November 16, 2017.

    Open source URL
  94. [94]
    GitHub QuasarRAT

    MaxXor. (n.d.). QuasarRAT. Retrieved July 10, 2018.

    Open source URL
  95. [95]
    CISA AR18-352A Quasar RAT December 2018

    CISA. (2018, December 18). Analysis Report (AR18-352A) Quasar Open-Source Remote Administration Tool. Retrieved August 1, 2022.

    Open source URL
  96. [96]
    ESET LoJax Sept 2018

    ESET. (2018, September). LOJAX First UEFI rootkit found in the wild, courtesy of the Sednit group. Retrieved July 2, 2019.

    Open source URL
  97. [97]
    Cymmetria Patchwork

    Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.

    Open source URL
  98. [98]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  99. [99]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  100. [100]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  101. [101]
    Mandiant UNC3313 Feb 2022

    Tomcik, R. et al. (2022, February 24). Left On Read: Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity. Retrieved August 18, 2022.

    Open source URL
  102. [102]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  103. [103]
    Palo Alto Gamaredon Feb 2017

    Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.

    Open source URL
  104. [104]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  105. [105]
    ClearSky Wilted Tulip July 2017

    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

  106. [106]
    CopyKittens Nov 2015

    Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.

    Open source URL
  107. [107]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  108. [108]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  109. [109]
    Talos Konni May 2017

    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

    Open source URL
  110. [110]
    Symantec Vasport May 2012

    Zhou, R. (2012, May 15). Backdoor.Vasport. Retrieved February 22, 2018.

    Open source URL
  111. [111]
    Talos Oblique RAT March 2021

    Malhotra, A. (2021, March 2). ObliqueRAT returns with new campaign using hijacked websites. Retrieved September 2, 2021.

    Open source URL
  112. [112]
    Malwarebytes Wow6432Node 2016

    Arntz, P. (2016, March 30). Hiding in Plain Sight. Retrieved August 3, 2020.

    Open source URL
  113. [113]
    Malwarebytes Wow6432Node 2016

    Arntz, P. (2016, March 30). Hiding in Plain Sight. Retrieved August 3, 2020.

    Open source URL
  114. [114]
    Microsoft Run Key

    Microsoft. (n.d.). Run and RunOnce Registry Keys. Retrieved September 12, 2024.

    Open source URL
  115. [115]
    Microsoft Run Key

    Microsoft. (n.d.). Run and RunOnce Registry Keys. Retrieved September 12, 2024.

    Open source URL
  116. [116]
    Microsoft Wow6432Node 2018

    Microsoft. (2018, May 31). 32-bit and 64-bit Application Data in the Registry. Retrieved August 3, 2020.

    Open source URL
  117. [117]
    Microsoft Wow6432Node 2018

    Microsoft. (2018, May 31). 32-bit and 64-bit Application Data in the Registry. Retrieved August 3, 2020.

    Open source URL
  118. [118]
    Oddvar Moe RunOnceEx Mar 2018

    Moe, O. (2018, March 21). Persistence using RunOnceEx - Hidden from Autoruns.exe. Retrieved June 29, 2018.

    Open source URL
  119. [119]
    Oddvar Moe RunOnceEx Mar 2018

    Moe, O. (2018, March 21). Persistence using RunOnceEx - Hidden from Autoruns.exe. Retrieved June 29, 2018.

    Open source URL
  120. [120]
    TechNet Autoruns

    Russinovich, M. (2016, January 4). Autoruns for Windows v13.51. Retrieved June 6, 2016.

    Open source URL
  121. [121]
    TechNet Autoruns

    Russinovich, M. (2016, January 4). Autoruns for Windows v13.51. Retrieved June 6, 2016.

    Open source URL
  122. [122]
    TechNet Autoruns

    Russinovich, M. (2016, January 4). Autoruns for Windows v13.51. Retrieved June 6, 2016.

    Open source URL
  123. [123]
    mitre-attackT1547.001
    Open source URL
  124. [124]
    mitre-attackT1547.001
    Open source URL
  125. [125]
    mitre-attackT1547.001
    Open source URL
  126. [126]
    Emissary Trojan Feb 2016

    Falcone, R. and Miller-Osborn, J. (2016, February 3). Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?. Retrieved February 15, 2016.

  127. [127]
    Palo Alto DNS Requests

    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

  128. [128]
    Cyphort EvilBunny Dec 2014

    Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.

    Open source URL
  129. [129]
    Unit 42 C0d0so0 Jan 2016

    Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.

    Open source URL
  130. [130]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  131. [131]
    Talos Group123

    Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.

    Open source URL
  132. [132]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  133. [133]
    McAfee Netwire Mar 2015

    McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

    Open source URL
  134. [134]
    Proofpoint NETWIRE December 2020

    Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

    Open source URL
  135. [135]
    Red Canary NETWIRE January 2020

    Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

    Open source URL
  136. [136]
    Unit 42 NETWIRE April 2020

    Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

    Open source URL
  137. [137]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  138. [138]
    TrendMicro BKDR_URSNIF.SM

    Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

    Open source URL
  139. [139]
    TrendMicro PE_URSNIF.A2

    Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

    Open source URL
  140. [140]
    Gigamon Berserk Bear October 2021

    Slowik, J. (2021, October). THE BAFFLING BERSERK BEAR: A DECADE’S ACTIVITY TARGETING CRITICAL INFRASTRUCTURE. Retrieved December 6, 2021.

    Open source URL
  141. [141]
    Symantec Dragonfly

    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

    Open source URL
  142. [142]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  143. [143]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  144. [144]
    Group IB RTM August 2019

    Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.

    Open source URL
  145. [145]
    DFIR Phosphorus November 2021

    DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.

    Open source URL
  146. [146]
    Microsoft Iranian Threat Actor Trends November 2021

    MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.

    Open source URL
  147. [147]
    Unit 42 Magic Hound Feb 2017

    Lee, B. and Falcone, R. (2017, February 15). Magic Hound Campaign Attacks Saudi Targets. Retrieved December 27, 2017.

    Open source URL
  148. [148]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  149. [149]
    Fortinet Agent Tesla April 2018

    Zhang, X. (2018, April 05). Analysis of New Agent Tesla Spyware Variant. Retrieved November 5, 2018.

    Open source URL
  150. [150]
    SentinelLabs Agent Tesla Aug 2020

    Walter, J. (2020, August 10). Agent Tesla | Old RAT Uses New Tricks to Stay on Top. Retrieved December 11, 2020.

    Open source URL
  151. [151]
    MalwareBytes SideCopy Dec 2021

    Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

    Open source URL
  152. [152]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  153. [153]
    Palo Alto Rover

    Ray, V., Hayashi, K. (2016, February 29). New Malware ‘Rover’ Targets Indian Ambassador to Afghanistan. Retrieved February 29, 2016.

  154. [154]
    FinFisher Citation

    FinFisher. (n.d.). Retrieved September 12, 2024.

    Open source URL
  155. [155]
    Microsoft FinFisher March 2018

    Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018.

    Open source URL
  156. [156]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  157. [157]
    Sophos Maze VM September 2020

    Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.

    Open source URL
  158. [158]
    Unit 42 Nokki Oct 2018

    Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.

    Open source URL
  159. [159]
    Unit 42 BadPatch Oct 2017

    Bar, T., Conant, S. (2017, October 20). BadPatch. Retrieved November 13, 2018.

    Open source URL
  160. [160]
    Kaspersky Cloud Atlas December 2014

    GReAT. (2014, December 10). Cloud Atlas: RedOctober APT is back in style. Retrieved May 8, 2020.

    Open source URL
  161. [161]
    FBI Lockbit 2.0 FEB 2022

    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

    Open source URL
  162. [162]
    McAfee Lazarus Jul 2020

    Cashman, M. (2020, July 29). Operation North Star Campaign. Retrieved December 20, 2021.

    Open source URL
  163. [163]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
  164. [164]
    ATT TeamTNT Chimaera September 2020

    AT&T Alien Labs. (2021, September 8). TeamTNT with new campaign aka Chimaera. Retrieved September 22, 2021.

    Open source URL
  165. [165]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  166. [166]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  167. [167]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  168. [168]
    Prevailion EvilNum May 2020

    Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.

    Open source URL
  169. [169]
    Carbon Black JCry May 2019

    Lee, S.. (2019, May 14). JCry Ransomware. Retrieved June 18, 2019.

    Open source URL
  170. [170]
    Zscaler Cobian Aug 2017

    Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

    Open source URL
  171. [171]
    Symantec Darkmoon Aug 2005

    Hayashi, K. (2005, August 18). Backdoor.Darkmoon. Retrieved February 23, 2018.

    Open source URL
  172. [172]
    Prevx Carberp March 2011

    Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

    Open source URL
  173. [173]
    Unit 42 Lucifer June 2020

    Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.

    Open source URL
  174. [174]
    Group IB GrimAgent July 2021

    Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

    Open source URL
  175. [175]
    ThreatStream Evasion Analysis

    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

    Open source URL
  176. [176]
    ZScaler Hacking Team

    Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.

  177. [177]
    Kaspersky ThreatNeedle Feb 2021

    Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021.

    Open source URL
  178. [178]
    Group-IB RansomHub FEB 2025

    Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.

    Open source URL
  179. [179]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  180. [180]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  181. [181]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  182. [182]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  183. [183]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  184. [184]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  185. [185]
    Bitdefender Naikon April 2021

    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

    Open source URL
  186. [186]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  187. [187]
    Crowdstrike Qakbot October 2020

    CS. (2020, October 7). Duck Hunting with Falcon Complete: A Fowl Banking Trojan Evolves, Part 2. Retrieved September 27, 2021.

    Open source URL
  188. [188]
    Group IB Ransomware September 2020

    Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.

    Open source URL
  189. [189]
    Trend Micro Qakbot December 2020

    Trend Micro. (2020, December 17). QAKBOT: A decade-old malware still with new tricks. Retrieved November 17, 2024.

    Open source URL
  190. [190]
    Trend Micro Qakbot May 2020

    Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.

    Open source URL
  191. [191]
    Group IB Silence Sept 2018

    Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.

    Open source URL
  192. [192]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  193. [193]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  194. [194]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  195. [195]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  196. [196]
    Securelist WhiteBear Aug 2017

    Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.

    Open source URL
  197. [197]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  198. [198]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  199. [199]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  200. [200]
    Picus Emotet Dec 2018

    Özarslan, S. (2018, December 21). The Christmas Card you never wanted - A new wave of Emotet is back to wreak havoc. Retrieved March 25, 2019.

    Open source URL
  201. [201]
    Symantec Emotet Jul 2018

    Symantec. (2018, July 18). The Evolution of Emotet: From Banking Trojan to Threat Distributor. Retrieved March 25, 2019.

    Open source URL
  202. [202]
    US-CERT Emotet Jul 2018

    US-CERT. (2018, July 20). Alert (TA18-201A) Emotet Malware. Retrieved March 25, 2019.

    Open source URL
  203. [203]
    F-Secure CozyDuke

    F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.

    Open source URL
  204. [204]
    Unit42 Xbash Sept 2018

    Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.

    Open source URL
  205. [205]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  206. [206]
    Mandiant No Easy Breach

    Dunwoody, M. and Carr, N.. (2016, September 27). No Easy Breach DerbyCon 2016. Retrieved September 12, 2024.

    Open source URL
  207. [207]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  208. [208]
    IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025

    Golo Muhr, Joshua Chung. (2025, June 23). Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor. Retrieved August 4, 2025.

    Open source URL
  209. [209]
    Cybereason Molerats Dec 2020

    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

    Open source URL
  210. [210]
    Talent-Jump Clambling February 2020

    Chen, T. and Chen, Z. (2020, February 17). CLAMBLING - A New Backdoor Base On Dropbox. Retrieved November 12, 2021.

    Open source URL
  211. [211]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  212. [212]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  213. [213]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  214. [214]
    Dell Sakula

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, July 30). Sakula Malware Family. Retrieved January 26, 2016.

  215. [215]
    Zscaler APT31 Covid-19 October 2020

    Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.

    Open source URL
  216. [216]
    Palo Alto Reaver Nov 2017

    Grunzweig, J. and Miller-Osborn, J. (2017, November 10). New Malware with Ties to SunOrcal Discovered. Retrieved November 16, 2017.

    Open source URL
  217. [217]
    CISA AR18-352A Quasar RAT December 2018

    CISA. (2018, December 18). Analysis Report (AR18-352A) Quasar Open-Source Remote Administration Tool. Retrieved August 1, 2022.

    Open source URL
  218. [218]
    GitHub QuasarRAT

    MaxXor. (n.d.). QuasarRAT. Retrieved July 10, 2018.

    Open source URL
  219. [219]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  220. [220]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  221. [221]
    ESET LoJax Sept 2018

    ESET. (2018, September). LOJAX First UEFI rootkit found in the wild, courtesy of the Sednit group. Retrieved July 2, 2019.

    Open source URL
  222. [222]
    Cymmetria Patchwork

    Cymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.

    Open source URL
  223. [223]
    TrendMicro Patchwork Dec 2017

    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

    Open source URL
  224. [224]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  225. [225]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  226. [226]
    Mandiant UNC3313 Feb 2022

    Tomcik, R. et al. (2022, February 24). Left On Read: Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity. Retrieved August 18, 2022.

    Open source URL
  227. [227]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  228. [228]
    Palo Alto Gamaredon Feb 2017

    Kasza, A. and Reichel, D. (2017, February 27). The Gamaredon Group Toolset Evolution. Retrieved March 1, 2017.

    Open source URL
  229. [229]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  230. [230]
    ClearSky Wilted Tulip July 2017

    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.

  231. [231]
    CopyKittens Nov 2015

    Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.

    Open source URL
  232. [232]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  233. [233]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  234. [234]
    Talos Konni May 2017

    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

    Open source URL
  235. [235]
    Symantec Vasport May 2012

    Zhou, R. (2012, May 15). Backdoor.Vasport. Retrieved February 22, 2018.

    Open source URL
  236. [236]
    Talos Oblique RAT March 2021

    Malhotra, A. (2021, March 2). ObliqueRAT returns with new campaign using hijacked websites. Retrieved September 2, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.