LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1553.002: Code Signing

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. [1] The certificates used during an operation may be created, acquired, or stolen by the adversary. [2] [3] Unlike Invalid Code Signature, this activity will result in a valid signature.

Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform. [1][4]

Code signing certificates may be used to bypass security policies that require signed code to execute on a system.

EnterpriseT1553.002Sub-techniqueObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Code Signing matters because it attacks a basic trust decision: Windows and macOS may treat signed software as more trustworthy, but adversaries can create, acquire, or steal signing materials so malware or tools carry a valid signature. For leaders, the risk is not simply “malware is signed”; it is that signed-code controls, user prompts, allowlists, and incident triage assumptions can be weakened if the organization cannot distinguish expected signed software from suspicious signed binaries.

Executive priority

Prioritize this where signed-code execution, software trust, or third-party software updates are important to business continuity. Executives should ask whether code signing certificates and private keys are inventoried and protected, whether endpoint and SOC teams can investigate valid-but-unexpected signatures, and whether incident response plans cover certificate abuse, revocation decisions, and software trust exceptions. The relationships to multiple campaigns and groups, including supply-chain-related campaigns, show this behavior is broadly relevant, but local exposure depends on the organization’s Windows/macOS estate and signing governance.

Technical view

This is a defense-impairment sub-technique of Subvert Trust Controls for macOS and Windows. MITRE does not provide native detection text for this object, but a related detection strategy is listed: DET0230, Detect Suspicious or Malicious Code Signing Abuse. SOC and detection teams should validate whether they can inspect signed binaries beyond a simple valid/invalid result: signer identity, certificate metadata, file hash, path, first-seen time, parent process, and whether the signer is expected for that software. IR teams should treat a valid signature as one data point, not proof of legitimacy.

Likely telemetry

  • Endpoint file and process execution telemetry from Windows and macOS systems
  • Code signature status and certificate metadata, including signer, issuer, serial number, and signing timestamp where available
  • Binary hash, file path, creation/modification time, and first-seen observations
  • Software inventory or allowlist records showing expected publishers and approved signed applications
  • Code signing certificate inventory and key custody records for internally signed software

Detection direction

  • Validate detections for validly signed binaries that are unexpected for the host, user, path, publisher, or business application context.
  • Tune logic to avoid trusting signatures alone; compare signature metadata with known-good software inventory and approved certificate usage.
  • Look for newly observed signed binaries, unusual signer reuse, or signed tools appearing in suspicious execution chains.
  • Account for false positives from legitimate software updates, developer tools, and internally signed applications by maintaining certificate and publisher baselines.
  • Use the DET0230 relationship as the ATT&CK-linked detection direction, while recognizing the technique object itself provides no official detection procedure.

Mitigation priorities

  • Inventory and govern code signing certificates and signing keys, especially for internally developed software.
  • Restrict and monitor access to code signing materials; ensure custody and approval processes are auditable.
  • Define endpoint policy so signed code is not automatically trusted without publisher, path, and business-context validation.
  • Maintain approved software and publisher baselines for Windows and macOS to support SOC triage.
  • Prepare incident response procedures for suspected certificate compromise or misuse, including containment, revocation decision paths, and replacement of trusted software artifacts.
Additional notes and limits

The material decision point is whether the organization can prove that a signed binary is expected, not merely that the signature is cryptographically valid. This technique has many listed campaign and group relationships, indicating repeated relevance across different intrusion contexts, but those relationships should guide prioritization and hypothesis generation rather than be treated as evidence of current activity in any specific environment.

MITRE provides no official detection text for this technique, and the supplied data does not include specific event IDs, vendor controls, or guaranteed analytics. Coverage must be validated locally against actual Windows/macOS telemetry, certificate governance records, software inventory quality, and endpoint policy behavior.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Code Signing

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. [1] The certificates used during an operation may be created, acquired, or stolen by the adversary. [2] [3] Unlike Invalid Code Signature, this activity will result in a valid signature.

Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform. [1][4]

Code signing certificates may be used to bypass security policies that require signed code to execute on a system.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1553Subvert Trust ControlsThis object subtechnique of Subvert Trust Controls.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G1015: Scattered Spider

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. [1] [2] The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. [2] Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. [3] [4] [5] Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. [6]

GroupEnterprise

G0040: Patchwork

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.[1] [2][3][4]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0093: GALLIUM

GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers.[1] Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.[1][2][3]

GroupEnterprise

G1031: Saint Bear

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities.[1][2] Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0021: Molerats

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.[1][2][3][4]

GroupEnterprise

G0049: OilRig

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.[1][2][3][4][5][6][7]

GroupEnterprise

G1054: MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]

GroupEnterprise

G0032: Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). [1] [2] Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.[3]

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.[4][5][6]

GroupEnterprise

G1009: Moses Staff

Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly stated their motivation in attacking Israeli companies is to cause damage by leaking stolen sensitive data and encrypting the victim's networks without a ransom demand.[1]

Security researchers assess Moses Staff is politically motivated, and has targeted government, finance, travel, energy, manufacturing, and utility companies outside of Israel as well, including those in Italy, India, Germany, Chile, Turkey, the UAE, and the US.[2]

MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
MalwareEnterprise

S1240: RedLine Stealer

RedLine Stealer is an information-stealer malware variant first identified in 2020.[1][2][3] RedLine Stealer is a Malware as a Service (MaaS) and was reportedly sold as either a one-time purchase or a monthly subscription service.[1][4] Information obtained from RedLine Stealer has been known to be sold on the deep and dark web to Initial Access Brokers (IABs), who use or resell the stolen credentials for further intrusions.[5][4]

Windows
MalwareEnterprise

S1235: CorKLOG

CorKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024. CorKLOG is delivered through a RAR archive (e.g., src.rar), which contains two files: an executable (lcommute.exe) and the CorKLOG DLL (mscorsvc.dll). CorKLOG has established persistence on the system by creating services or with scheduled tasks.[1]

Windows
MalwareEnterprise

S0187: Daserf

Daserf is a backdoor that has been used to spy on and steal from Japanese, South Korean, Russian, Singaporean, and Chinese victims. Researchers have identified versions written in both Visual C and Delphi. [1] [2]

Windows
MalwareEnterprise

S1228: PUBLOAD

PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new directories to stage the malware and its components.[1] PUBLOAD malware collects details of the victim host, establishes persistence, encrypts victim details using RC4 and communicates victim details back to C2. PUBLOAD malware has previously been leveraged by China-affiliated actors identified as Mustang Panda. PUBLOAD is also known as “NoFive” and some public reporting identifies the loader component as CLAIMLOADER.[2]

Windows
MalwareEnterprise

S0170: Helminth

Helminth is a backdoor that has at least two variants - one written in VBScript and PowerShell that is delivered via a macros in Excel spreadsheets, and one that is a standalone Windows executable. [1]

Windows
MalwareEnterprise

S1070: Black Basta

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.[1][2][3][4][5][6]

WindowsESXi
MalwareEnterprise

S1016: MacMa

MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer. MacMa has been observed in the wild since November 2021.[1] MacMa shares command and control and unique libraries with MgBot and Nightdoor, indicating a relationship with the Daggerfly threat actor.[2]

macOS
MalwareEnterprise

S1183: StrelaStealer

StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024. StrelaStealer focuses on the automated identification, collection, and exfiltration of email credentials from email clients such as Outlook and Thunderbird.[1][2][3][4]

Windows
CampaignEnterprise

C0015: C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]

CampaignEnterprise

C0006: Operation Honeybee

Operation Honeybee was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. Operation Honeybee initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign "Honeybee" after the author name discovered in malicious Word documents.[1]

CampaignEnterprise

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

CampaignEnterprise

C0024: SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]

CampaignEnterprise

C0057: 3CX Supply Chain Attack

The 3CX Supply Chain Attack was the first publicly reported case of one supply chain compromise triggering another, leading to a cascading, two-stage intrusion. The initial supply chain attack began when a 3CX employee downloaded and executed a trojanized, end-of-life version of the X_Trader trading software from Trading Technologies. This provided UNC4736, a threat cluster associated with AppleJeus, access to the 3CX environment. From there UNC4736 compromised the Windows and macOS build environments used to distribute the 3CX desktop application to their customers.[1] While 3CX serves more than 600,000 customers and 12 million users, only a subset of systems were affected. Subsequent targeting focused on victims in the defense and cryptocurrency sectors, where attackers deployed secondary payloads such as Gopuram for credential theft and persistence.[2] The campaign began in late 2022 and was disrupted after security vendors publicly reported the compromise in March 2023.[3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
6467b363d56c24b5...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle6467b363d56c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Wikipedia Code Signing

    Wikipedia. (2015, November 10). Code Signing. Retrieved March 31, 2016.

    Open source URL
  2. [2]
    Securelist Digital Certificates

    Ladikov, A. (2015, January 29). Why You Shouldn’t Completely Trust Files Signed with Digital Certificates. Retrieved March 31, 2016.

    Open source URL
  3. [3]
    Symantec Digital Certificates

    Shinotsuka, H. (2013, February 22). How Attackers Steal Private Keys from Digital Certificates. Retrieved March 31, 2016.

  4. [4]
    EclecticLightChecksonEXECodeSigning

    Howard Oakley. (2020, November 16). Checks on executable code in Catalina and Big Sur: a first draft. Retrieved September 21, 2022.

    Open source URL
  5. [5]
    Talos Cobalt Strike September 2020

    Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.

    Open source URL
  6. [6]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  7. [7]
    Unit 42 BackConfig May 2020

    Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.

    Open source URL
  8. [8]
    ESET RedLine Stealer November 2024

    Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.

    Open source URL
  9. [9]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  10. [10]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  11. [11]
    CrowdStrike Scattered Spider BYOVD January 2023

    CrowdStrike. (2023, January 10). SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic in Attempt to Bypass Endpoint Security. Retrieved July 5, 2023.

    Open source URL
  12. [12]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  13. [13]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  14. [14]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  15. [15]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  16. [16]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  17. [17]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  18. [18]
    ThreatConnect Kimsuky September 2020

    ThreatConnect. (2020, September 28). Kimsuky Phishing Operations Putting In Work. Retrieved October 30, 2020.

    Open source URL
  19. [19]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  20. [20]
    ClearSky OilRig Jan 2017

    ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.

  21. [21]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  22. [22]
    SentinelOne Macma 2021

    Phil Stokes. (2021, November 15). Infect If Needed | A Deeper Dive Into Targeted Backdoor macOS.Macma. Retrieved July 26, 2024.

    Open source URL
  23. [23]
    IBM StrelaStealer 2024

    Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.

    Open source URL
  24. [24]
    Microsoft GALLIUM December 2019

    MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.

    Open source URL
  25. [25]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  26. [26]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  27. [27]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  28. [28]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  29. [29]
    FireEye Operation Molerats

    Villeneuve, N., Haq, H., Moran, N. (2013, August 23). OPERATION MOLERATS: MIDDLE EAST CYBER ATTACKS USING POISON IVY. Retrieved November 17, 2024.

    Open source URL
  30. [30]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  31. [31]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  32. [32]
    Symantec Ukraine Wipers February 2022

    Symantec Threat Hunter Team. (2022, February 24). Ukraine: Disk-wiping Attacks Precede Russian Invasion. Retrieved March 25, 2022.

    Open source URL
  33. [33]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  34. [34]
    ESET Hermetic Wiper February 2022

    ESET. (2022, February 24). HermeticWiper: New data wiping malware hits Ukraine. Retrieved March 25, 2022.

    Open source URL
  35. [35]
    Qualys Hermetic Wiper March 2022

    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

    Open source URL
  36. [36]
    ESET MirrorFace 2025

    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.

    Open source URL
  37. [37]
    ESET GreyEnergy Oct 2018

    Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.

    Open source URL
  38. [38]
    US-CERT BLINDINGCAN Aug 2020

    US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.

    Open source URL
  39. [39]
    CISA Iran Albanian Attacks September 2022

    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

    Open source URL
  40. [40]
    ASEC Troll Stealer 2024

    AhnLab ASEC. (2024, February 16). TrollAgent That Infects Systems Upon Security Program Installation Process (Kimsuky Group). Retrieved January 17, 2025.

    Open source URL
  41. [41]
    Symantec Nerex May 2012

    Ladley, F. (2012, May 15). Backdoor.Nerex. Retrieved February 23, 2018.

    Open source URL
  42. [42]
    CISA AppleJeus Feb 2021

    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

    Open source URL
  43. [43]
    McAfee Honeybee

    Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

    Open source URL
  44. [44]
    IBM ZeroCleare Wiper December 2019

    Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.

    Open source URL
  45. [45]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  46. [46]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  47. [47]
    ATT QakBot April 2021

    Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.

    Open source URL
  48. [48]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  49. [49]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  50. [50]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  51. [51]
    ESET MirrorFace DEC 2022

    Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.

    Open source URL
  52. [52]
    Lazarus APT January 2022

    Saini, A. and Hossein, J. (2022, January 27). North Korea’s Lazarus APT leverages Windows Update client, GitHub in latest campaign. Retrieved January 27, 2022.

    Open source URL
  53. [53]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  54. [54]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  55. [55]
    Checkpoint MosesStaff Nov 2021

    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

    Open source URL
  56. [56]
    Group IB Silence Aug 2019

    Group-IB. (2019, August). Silence 2.0: Going Global. Retrieved May 5, 2020.

    Open source URL
  57. [57]
    DFIR Ryuk 2 Hour Speed Run November 2020

    The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.

    Open source URL
  58. [58]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  59. [59]
    FireEye APT40 March 2019

    Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.

    Open source URL
  60. [60]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
  61. [61]
    Unit42 Clop April 2021

    Santos, D. (2021, April 13). Threat Assessment: Clop Ransomware. Retrieved July 30, 2021.

    Open source URL
  62. [62]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  63. [63]
    Mandiant 3cx UNC4736 2023

    Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodoreanu, Daniel Scott. (2023, April 20). 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible. Retrieved August 25, 2025.

    Open source URL
  64. [64]
    3cx official statement 2023

    Agathocles Prodromou. (2023, April 20). Security Update Thursday 20 April 2023 – Initial Intrusion Vector Found. Retrieved August 25, 2025.

    Open source URL
  65. [65]
    FireEye FIN7 Oct 2019

    Carr, N, et all. (2019, October 10). Mahalo FIN7: Responding to the Criminal Operators’ New Tools and Techniques. Retrieved October 11, 2019.

    Open source URL
  66. [66]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
  67. [67]
    Kaspersky Darkhotel

    Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.

    Open source URL
  68. [68]
    Securelist Darkhotel Aug 2015

    Kaspersky Lab's Global Research & Analysis Team. (2015, August 10). Darkhotel's attacks in 2015. Retrieved November 2, 2018.

    Open source URL
  69. [69]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  70. [70]
    Cybereason TA505 April 2019

    Salem, E. (2019, April 25). Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware. Retrieved May 28, 2019.

    Open source URL
  71. [71]
    Deep Instinct TA505 Apr 2019

    Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..

    Open source URL
  72. [72]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  73. [73]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  74. [74]
    Lab52 MUSTANG PANDA PUBLOAD MAY 2023

    Dex. (n.d.). New Mustang Panda’s campaing against Australia. Retrieved August 4, 2025.

    Open source URL
  75. [75]
    Palo Alto Networks, Unit 42

    Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.

    Open source URL
  76. [76]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  77. [77]
    Zscaler

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

    Open source URL
  78. [78]
    Wired Lockergoga 2019

    Greenberg, A. (2019, March 25). A Guide to LockerGoga, the Ransomware Crippling Industrial Firms. Retrieved July 17, 2019.

    Open source URL
  79. [79]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  80. [80]
    Securelist WhiteBear Aug 2017

    Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.

    Open source URL
  81. [81]
    CISA Medusa Group Medusa Ransomware March 2025

    Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  82. [82]
    Symantec Suckfly March 2016

    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

  83. [83]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  84. [84]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  85. [85]
    TrendMicro LummaStealer 2025

    Buddy Tancio, Fe Cureg, and Jovit Samaniego, Trend Micro. (2025, January 30). Lumma Stealer’s GitHub-Based Delivery Explored via Managed Detection and Response. Retrieved March 22, 2025.

    Open source URL
  86. [86]
    ESET EvasivePanda 2024

    Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.

    Open source URL
  87. [87]
    ESET Ebury Feb 2014

    M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.

    Open source URL
  88. [88]
    Secureworks GOLD KINGSWOOD September 2018

    CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.

    Open source URL
  89. [89]
    Symantec Troll Stealer 2024

    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

    Open source URL
  90. [90]
    EclecticLightChecksonEXECodeSigning

    Howard Oakley. (2020, November 16). Checks on executable code in Catalina and Big Sur: a first draft. Retrieved September 21, 2022.

    Open source URL
  91. [91]
    EclecticLightChecksonEXECodeSigning

    Howard Oakley. (2020, November 16). Checks on executable code in Catalina and Big Sur: a first draft. Retrieved September 21, 2022.

    Open source URL
  92. [92]
    Securelist Digital Certificates

    Ladikov, A. (2015, January 29). Why You Shouldn’t Completely Trust Files Signed with Digital Certificates. Retrieved March 31, 2016.

    Open source URL
  93. [93]
    Securelist Digital Certificates

    Ladikov, A. (2015, January 29). Why You Shouldn’t Completely Trust Files Signed with Digital Certificates. Retrieved March 31, 2016.

    Open source URL
  94. [94]
    Symantec Digital Certificates

    Shinotsuka, H. (2013, February 22). How Attackers Steal Private Keys from Digital Certificates. Retrieved March 31, 2016.

  95. [95]
    Symantec Digital Certificates

    Shinotsuka, H. (2013, February 22). How Attackers Steal Private Keys from Digital Certificates. Retrieved March 31, 2016.

  96. [96]
    Wikipedia Code Signing

    Wikipedia. (2015, November 10). Code Signing. Retrieved March 31, 2016.

    Open source URL
  97. [97]
    Wikipedia Code Signing

    Wikipedia. (2015, November 10). Code Signing. Retrieved March 31, 2016.

    Open source URL
  98. [98]
    mitre-attackT1553.002
    Open source URL
  99. [99]
    mitre-attackT1553.002
    Open source URL
  100. [100]
    mitre-attackT1553.002
    Open source URL
  101. [101]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  102. [102]
    Talos Cobalt Strike September 2020

    Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024.

    Open source URL
  103. [103]
    Unit 42 BackConfig May 2020

    Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.

    Open source URL
  104. [104]
    ESET RedLine Stealer November 2024

    Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.

    Open source URL
  105. [105]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  106. [106]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  107. [107]
    CrowdStrike Scattered Spider BYOVD January 2023

    CrowdStrike. (2023, January 10). SCATTERED SPIDER Exploits Windows Security Deficiencies with Bring-Your-Own-Vulnerable-Driver Tactic in Attempt to Bypass Endpoint Security. Retrieved July 5, 2023.

    Open source URL
  108. [108]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  109. [109]
    Symantec Tick Apr 2016

    DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

    Open source URL
  110. [110]
    Unit 42 BackConfig May 2020

    Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.

    Open source URL
  111. [111]
    Unit 42 BackConfig May 2020

    Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.

    Open source URL
  112. [112]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  113. [113]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  114. [114]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  115. [115]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  116. [116]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  117. [117]
    ThreatConnect Kimsuky September 2020

    ThreatConnect. (2020, September 28). Kimsuky Phishing Operations Putting In Work. Retrieved October 30, 2020.

    Open source URL
  118. [118]
    ClearSky OilRig Jan 2017

    ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.

  119. [119]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  120. [120]
    SentinelOne Macma 2021

    Phil Stokes. (2021, November 15). Infect If Needed | A Deeper Dive Into Targeted Backdoor macOS.Macma. Retrieved July 26, 2024.

    Open source URL
  121. [121]
    IBM StrelaStealer 2024

    Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.

    Open source URL
  122. [122]
    Microsoft GALLIUM December 2019

    MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.

    Open source URL
  123. [123]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  124. [124]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  125. [125]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  126. [126]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  127. [127]
    FireEye Operation Molerats

    Villeneuve, N., Haq, H., Moran, N. (2013, August 23). OPERATION MOLERATS: MIDDLE EAST CYBER ATTACKS USING POISON IVY. Retrieved November 17, 2024.

    Open source URL
  128. [128]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  129. [129]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  130. [130]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  131. [131]
    ESET Hermetic Wiper February 2022

    ESET. (2022, February 24). HermeticWiper: New data wiping malware hits Ukraine. Retrieved March 25, 2022.

    Open source URL
  132. [132]
    Qualys Hermetic Wiper March 2022

    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

    Open source URL
  133. [133]
    Symantec Ukraine Wipers February 2022

    Symantec Threat Hunter Team. (2022, February 24). Ukraine: Disk-wiping Attacks Precede Russian Invasion. Retrieved March 25, 2022.

    Open source URL
  134. [134]
    ESET MirrorFace 2025

    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.

    Open source URL
  135. [135]
    ESET GreyEnergy Oct 2018

    Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.

    Open source URL
  136. [136]
    US-CERT BLINDINGCAN Aug 2020

    US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.

    Open source URL
  137. [137]
    CISA Iran Albanian Attacks September 2022

    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

    Open source URL
  138. [138]
    ASEC Troll Stealer 2024

    AhnLab ASEC. (2024, February 16). TrollAgent That Infects Systems Upon Security Program Installation Process (Kimsuky Group). Retrieved January 17, 2025.

    Open source URL
  139. [139]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  140. [140]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  141. [141]
    Symantec Nerex May 2012

    Ladley, F. (2012, May 15). Backdoor.Nerex. Retrieved February 23, 2018.

    Open source URL
  142. [142]
    CISA AppleJeus Feb 2021

    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

    Open source URL
  143. [143]
    McAfee Honeybee

    Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

    Open source URL
  144. [144]
    IBM ZeroCleare Wiper December 2019

    Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.

    Open source URL
  145. [145]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  146. [146]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  147. [147]
    ATT QakBot April 2021

    Morrow, D. (2021, April 15). The rise of QakBot. Retrieved September 27, 2021.

    Open source URL
  148. [148]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  149. [149]
    ClearSky OilRig Jan 2017

    ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.

  150. [150]
    ClearSky OilRig Jan 2017

    ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.

  151. [151]
    ESET RTM Feb 2017

    Faou, M. and Boutin, J. (2017, February). Read The Manual: A Guide to the RTM Banking Trojan. Retrieved March 9, 2017.

    Open source URL
  152. [152]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  153. [153]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  154. [154]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  155. [155]
    ESET MirrorFace DEC 2022

    Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.

    Open source URL
  156. [156]
    Lazarus APT January 2022

    Saini, A. and Hossein, J. (2022, January 27). North Korea’s Lazarus APT leverages Windows Update client, GitHub in latest campaign. Retrieved January 27, 2022.

    Open source URL
  157. [157]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  158. [158]
    Kaspersky Turla

    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

    Open source URL
  159. [159]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  160. [160]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  161. [161]
    Checkpoint MosesStaff Nov 2021

    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

    Open source URL
  162. [162]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  163. [163]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  164. [164]
    Group IB Silence Aug 2019

    Group-IB. (2019, August). Silence 2.0: Going Global. Retrieved May 5, 2020.

    Open source URL
  165. [165]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  166. [166]
    FireEye SUNBURST Backdoor December 2020

    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.

    Open source URL
  167. [167]
    DFIR Ryuk 2 Hour Speed Run November 2020

    The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.

    Open source URL
  168. [168]
    FireEye APT40 March 2019

    Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.

    Open source URL
  169. [169]
    FireEye Periscope March 2018

    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

    Open source URL
  170. [170]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
  171. [171]
    Unit42 Clop April 2021

    Santos, D. (2021, April 13). Threat Assessment: Clop Ransomware. Retrieved July 30, 2021.

    Open source URL
  172. [172]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  173. [173]
    3cx official statement 2023

    Agathocles Prodromou. (2023, April 20). Security Update Thursday 20 April 2023 – Initial Intrusion Vector Found. Retrieved August 25, 2025.

    Open source URL
  174. [174]
    Mandiant 3cx UNC4736 2023

    Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodoreanu, Daniel Scott. (2023, April 20). 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible. Retrieved August 25, 2025.

    Open source URL
  175. [175]
    FireEye FIN7 Oct 2019

    Carr, N, et all. (2019, October 10). Mahalo FIN7: Responding to the Criminal Operators’ New Tools and Techniques. Retrieved October 11, 2019.

    Open source URL
  176. [176]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
  177. [177]
    Kaspersky Darkhotel

    Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.

    Open source URL
  178. [178]
    Securelist Darkhotel Aug 2015

    Kaspersky Lab's Global Research & Analysis Team. (2015, August 10). Darkhotel's attacks in 2015. Retrieved November 2, 2018.

    Open source URL
  179. [179]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  180. [180]
    Cybereason TA505 April 2019

    Salem, E. (2019, April 25). Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware. Retrieved May 28, 2019.

    Open source URL
  181. [181]
    Deep Instinct TA505 Apr 2019

    Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..

    Open source URL
  182. [182]
    Trend Micro TA505 June 2019

    Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

    Open source URL
  183. [183]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  184. [184]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  185. [185]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  186. [186]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  187. [187]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  188. [188]
    Lab52 MUSTANG PANDA PUBLOAD MAY 2023

    Dex. (n.d.). New Mustang Panda’s campaing against Australia. Retrieved August 4, 2025.

    Open source URL
  189. [189]
    Palo Alto Networks, Unit 42

    Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.

    Open source URL
  190. [190]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  191. [191]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  192. [192]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  193. [193]
    Zscaler

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

    Open source URL
  194. [194]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  195. [195]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  196. [196]
    Wired Lockergoga 2019

    Greenberg, A. (2019, March 25). A Guide to LockerGoga, the Ransomware Crippling Industrial Firms. Retrieved July 17, 2019.

    Open source URL
  197. [197]
    ESET Gazer Aug 2017

    ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017.

    Open source URL
  198. [198]
    Securelist WhiteBear Aug 2017

    Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.

    Open source URL
  199. [199]
    CISA Medusa Group Medusa Ransomware March 2025

    Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  200. [200]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  201. [201]
    Securelist APT10 March 2021

    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

    Open source URL
  202. [202]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  203. [203]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  204. [204]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
  205. [205]
    Security Intelligence More Eggs Aug 2019

    Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

    Open source URL
  206. [206]
    Symantec Suckfly March 2016

    DiMaggio, J. (2016, March 15). Suckfly: Revealing the secret life of your code signing certificates. Retrieved August 3, 2016.

  207. [207]
    Volexity Patchwork June 2018

    Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.

    Open source URL
  208. [208]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  209. [209]
    TrendMicro LummaStealer 2025

    Buddy Tancio, Fe Cureg, and Jovit Samaniego, Trend Micro. (2025, January 30). Lumma Stealer’s GitHub-Based Delivery Explored via Managed Detection and Response. Retrieved March 22, 2025.

    Open source URL
  210. [210]
    ESET EvasivePanda 2024

    Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.

    Open source URL
  211. [211]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  212. [212]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.