LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1547.009: Shortcut Modification

Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process.

Adversaries may abuse shortcuts in the startup folder to execute their tools and achieve persistence.[1] Although often used as payloads in an infection chain (e.g. Spearphishing Attachment), adversaries may also create a new shortcut as a means of indirection, while also abusing Masquerading to make the malicious shortcut appear as a legitimate program. Adversaries can also edit the target path or entirely replace an existing shortcut so their malware will be executed instead of the intended legitimate program.

Shortcuts can also be abused to establish persistence by implementing other methods. For example, LNK browser extensions may be modified (e.g. Browser Extensions) to persistently launch malware.

EnterpriseT1547.009Sub-techniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Shortcut Modification is a Windows persistence and privilege-escalation behavior where an adversary creates or changes shortcut/symbolic-link targets so unwanted code runs at startup, logon, or when a user launches what appears to be a normal program. For leaders, the material risk is quiet re-entry after cleanup: if startup locations and shortcut targets are not monitored and locked down, an incident can look remediated while the attacker’s code still runs on the next login.

Executive priority

Prioritize this as a Windows endpoint resilience and incident-response validation issue. Ask whether SOC and IR teams can prove they collect evidence of shortcut creation/modification in startup-related paths and can compare shortcut targets against expected business applications. Control investment should focus on least privilege, file/directory permission hardening, and execution prevention, as reflected by ATT&CK mitigations M1018, M1022, and M1038. This also supports audit evidence around endpoint hardening and account privilege management.

Technical view

ATT&CK lists this as sub-technique T1547.009 under Boot or Logon Autostart Execution for Windows, mapped to persistence and privilege escalation. Validate monitoring for shortcut files and symbolic links that are created, modified, replaced, or redirected to unexpected executables, scripts, or paths, especially where execution occurs during startup or user logon. Because MITRE provides no official detection text for this object, use the related DET0180 detection strategy as a starting point but test it against local Windows build, endpoint logging, EDR visibility, and normal software deployment behavior. Relationships to Masquerading and Spearphishing Attachment in the description mean defenders should correlate suspicious shortcut changes with deceptive file names, user-delivered files, and subsequent process execution rather than treating LNK writes as isolated events.

Likely telemetry

  • Windows file creation/modification events for shortcut files and symbolic links
  • Changes in user or system startup-related folders and shortcut target paths
  • Endpoint process execution telemetry showing programs launched at boot, logon, or via shortcut invocation
  • File metadata and path context for newly created or replaced shortcuts
  • EDR or host audit records showing the user or process responsible for shortcut modification

Detection direction

  • Inventory legitimate shortcut creation and update patterns from installers, software updates, login scripts, and user customization before alerting broadly.
  • Alert on shortcut creation or modification in startup-related locations where the target path points to unusual, user-writable, removable, or masqueraded content.
  • Correlate shortcut changes with subsequent execution at logon/startup and with suspicious parent processes or recently delivered attachments when available.
  • Review existing logic against the related DET0180 strategy, but do not assume coverage because ATT&CK supplies no official detection procedure for this technique.
  • Tune false positives from enterprise software deployment tools and sanctioned application updates while preserving visibility into target-path replacement of existing shortcuts.

Mitigation priorities

  • Apply least privilege and user account management so ordinary users and compromised accounts have fewer opportunities to modify shared or sensitive startup locations.
  • Restrict file and directory permissions on startup-related folders and other sensitive shortcut locations to limit unauthorized writes or replacement.
  • Use execution prevention controls so even if a malicious shortcut exists, unapproved payloads are less likely to run.
  • Include shortcut-target validation in endpoint hardening baselines and post-incident recovery checks.
  • Educate administrators and responders that benign-looking shortcuts can be persistence mechanisms, especially when combined with masquerading.
Additional notes and limits

The ATT&CK relationship set shows this behavior has been documented across multiple groups and malware families, including Lazarus Group, Leviathan, Gorgon Group, APT39, and several Windows malware entries. Treat that as evidence of broad technique relevance, not as attribution in any local incident. The revoked T1023 object is replaced by this sub-technique, so detection content should reference T1547.009 going forward.

The supplied ATT&CK object has no official detection text and provides only Windows as a platform. This take does not assert active exploitation, customer exposure, or guaranteed detection. Local validation is required to identify actual startup paths in use, normal shortcut modification volume, endpoint logging depth, and whether DET0180 or any internal analytic covers the required telemetry.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Shortcut Modification

Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process.

Adversaries may abuse shortcuts in the startup folder to execute their tools and achieve persistence.[1] Although often used as payloads in an infection chain (e.g. Spearphishing Attachment), adversaries may also create a new shortcut as a means of indirection, while also abusing Masquerading to make the malicious shortcut appear as a legitimate program. Adversaries can also edit the target path or entirely replace an existing shortcut so their malware will be executed instead of the intended legitimate program.

Shortcuts can also be abused to establish persistence by implementing other methods. For example, LNK browser extensions may be modified (e.g. Browser Extensions) to persistently launch malware.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1547Boot or Logon Autostart ExecutionThis object subtechnique of Boot or Logon Autostart Execution.
EnterpriseT1023Shortcut ModificationShortcut Modification revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.[1][2][3][4][5]

GroupEnterprise

G0065: Leviathan

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.[1] Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.[1][2][3][4]

GroupEnterprise

G0032: Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). [1] [2] Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.[3]

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.[4][5][6]

GroupEnterprise

G0078: Gorgon Group

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. [1]

MalwareEnterprise

S0172: Reaver

Reaver is a malware family that has been in the wild since at least late 2016. Reporting indicates victims have primarily been associated with the "Five Poisons," which are movements the Chinese government considers dangerous. The type of malware is rare due to its final payload being in the form of Control Panel items.[1]

Windows
MalwareEnterprise

S0531: Grandoreiro

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.[1][2]

Windows
MalwareEnterprise

S0170: Helminth

Helminth is a backdoor that has at least two variants - one written in VBScript and PowerShell that is delivered via a macros in Excel spreadsheets, and one that is a standalone Windows executable. [1]

Windows
MalwareEnterprise

S0089: BlackEnergy

BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3. [1]

Windows
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
d45a7a57556022fd...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundled45a7a575560…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Shortcut for Persistence

    Elastic. (n.d.). Shortcut File Written or Modified for Persistence. Retrieved June 1, 2022.

    Open source URL
  2. [2]
    Unit 42 DarkHydrus July 2018

    Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.

    Open source URL
  3. [3]
    Unit42 DarkHydrus Jan 2019

    Lee, B., Falcone, R. (2019, January 18). DarkHydrus delivers new Trojan that can use Google Drive for C2 communications. Retrieved April 17, 2019.

    Open source URL
  4. [4]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  5. [5]
    Accenture Hogfish April 2018

    Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018.

  6. [6]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  7. [7]
    Palo Alto Reaver Nov 2017

    Grunzweig, J. and Miller-Osborn, J. (2017, November 10). New Malware with Ties to SunOrcal Discovered. Retrieved November 16, 2017.

    Open source URL
  8. [8]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  9. [9]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  10. [10]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  11. [11]
    UCF STIG Symbolic Links

    UCF. (n.d.). Unauthorized accounts must not have the Create symbolic links user right.. Retrieved December 18, 2017.

    Open source URL
  12. [12]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  13. [13]
    Talos Micropsia June 2017

    Rascagneres, P., Mercer, W. (2017, June 19). Delphi Used To Score Against Palestine. Retrieved November 13, 2018.

    Open source URL
  14. [14]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  15. [15]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  16. [16]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  17. [17]
    McAfee Lazarus Resurfaces Feb 2018

    Sherstobitoff, R. (2018, February 12). Lazarus Resurfaces, Targets Global Banks and Bitcoin Users. Retrieved February 19, 2018.

    Open source URL
  18. [18]
    Palo Alto Comnie

    Grunzweig, J. (2018, January 31). Comnie Continues to Target Organizations in East Asia. Retrieved June 7, 2018.

    Open source URL
  19. [19]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  20. [20]
    Securelist WhiteBear Aug 2017

    Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.

    Open source URL
  21. [21]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  22. [22]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  23. [23]
    Cylance Cleaver

    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

    Open source URL
  24. [24]
    Cofense Astaroth Sept 2018

    Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.

    Open source URL
  25. [25]
    Cybereason Astaroth Feb 2019

    Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.

    Open source URL
  26. [26]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  27. [27]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  28. [28]
    Unit 42 SeaDuke 2015

    Grunzweig, J.. (2015, July 14). Unit 42 Technical Analysis: Seaduke. Retrieved August 3, 2016.

  29. [29]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  30. [30]
    ESET GreyEnergy Oct 2018

    Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.

    Open source URL
  31. [31]
    Talos Konni May 2017

    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

    Open source URL
  32. [32]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  33. [33]
    NCC Group Team9 June 2020

    Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.

    Open source URL
  34. [34]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  35. [35]
    Unit 42 Kazuar May 2017

    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

    Open source URL
  36. [36]
    BSidesSLC 2020 - LNK Elastic

    French, D., Filar, B.. (2020, March 21). A Chain Is No Stronger Than Its Weakest LNK. Retrieved November 30, 2020.

    Open source URL
  37. [37]
    BSidesSLC 2020 - LNK Elastic

    French, D., Filar, B.. (2020, March 21). A Chain Is No Stronger Than Its Weakest LNK. Retrieved November 30, 2020.

    Open source URL
  38. [38]
    BSidesSLC 2020 - LNK Elastic

    French, D., Filar, B.. (2020, March 21). A Chain Is No Stronger Than Its Weakest LNK. Retrieved November 30, 2020.

    Open source URL
  39. [39]
    Shortcut for Persistence

    Elastic. (n.d.). Shortcut File Written or Modified for Persistence. Retrieved June 1, 2022.

    Open source URL
  40. [40]
    Shortcut for Persistence

    Elastic. (n.d.). Shortcut File Written or Modified for Persistence. Retrieved June 1, 2022.

    Open source URL
  41. [41]
    mitre-attackT1547.009
    Open source URL
  42. [42]
    mitre-attackT1547.009
    Open source URL
  43. [43]
    mitre-attackT1547.009
    Open source URL
  44. [44]
    Unit 42 DarkHydrus July 2018

    Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.

    Open source URL
  45. [45]
    Unit42 DarkHydrus Jan 2019

    Lee, B., Falcone, R. (2019, January 18). DarkHydrus delivers new Trojan that can use Google Drive for C2 communications. Retrieved April 17, 2019.

    Open source URL
  46. [46]
    Accenture Hogfish April 2018

    Accenture Security. (2018, April 23). Hogfish Redleaves Campaign. Retrieved July 2, 2018.

  47. [47]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  48. [48]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  49. [49]
    Palo Alto Reaver Nov 2017

    Grunzweig, J. and Miller-Osborn, J. (2017, November 10). New Malware with Ties to SunOrcal Discovered. Retrieved November 16, 2017.

    Open source URL
  50. [50]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  51. [51]
    FireEye APT39 Jan 2019

    Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

    Open source URL
  52. [52]
    Palo Alto OilRig May 2016

    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

  53. [53]
    UCF STIG Symbolic Links

    UCF. (n.d.). Unauthorized accounts must not have the Create symbolic links user right.. Retrieved December 18, 2017.

    Open source URL
  54. [54]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  55. [55]
    Talos Micropsia June 2017

    Rascagneres, P., Mercer, W. (2017, June 19). Delphi Used To Score Against Palestine. Retrieved November 13, 2018.

    Open source URL
  56. [56]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  57. [57]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  58. [58]
    Baumgartner Naikon 2015

    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

    Open source URL
  59. [59]
    McAfee Lazarus Resurfaces Feb 2018

    Sherstobitoff, R. (2018, February 12). Lazarus Resurfaces, Targets Global Banks and Bitcoin Users. Retrieved February 19, 2018.

    Open source URL
  60. [60]
    Palo Alto Comnie

    Grunzweig, J. (2018, January 31). Comnie Continues to Target Organizations in East Asia. Retrieved June 7, 2018.

    Open source URL
  61. [61]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  62. [62]
    Securelist WhiteBear Aug 2017

    Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.

    Open source URL
  63. [63]
    F-Secure BlackEnergy 2014

    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

    Open source URL
  64. [64]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  65. [65]
    Cylance Cleaver

    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

    Open source URL
  66. [66]
    Cofense Astaroth Sept 2018

    Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.

    Open source URL
  67. [67]
    Cybereason Astaroth Feb 2019

    Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.

    Open source URL
  68. [68]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  69. [69]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  70. [70]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  71. [71]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  72. [72]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  73. [73]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  74. [74]
    Unit 42 SeaDuke 2015

    Grunzweig, J.. (2015, July 14). Unit 42 Technical Analysis: Seaduke. Retrieved August 3, 2016.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.