LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1559.001: Component Object Model

Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces.[1] Through COM, a client object can call methods of server objects, which are typically binary Dynamic Link Libraries (DLL) or executables (EXE).[2] Remote COM execution is facilitated by Remote Services such as Distributed Component Object Model (DCOM).[1]

Various COM interfaces are exposed that can be abused to invoke arbitrary execution via a variety of programming languages such as C, C++, Java, and Visual Basic.[2] Specific COM objects also exist to directly perform functions beyond code execution, such as creating a Scheduled Task/Job, fileless download/execution, and other adversary behaviors related to privilege escalation and persistence.[1][3]

EnterpriseT1559.001Sub-techniqueObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Component Object Model abuse matters because it turns normal Windows inter-process communication into a local execution path. For leaders, the risk is not that COM is inherently malicious, but that it is a built-in Windows capability used by many legitimate applications and also referenced across multiple ATT&CK group and malware relationships. That makes it a coverage-validation problem: can the organization distinguish expected COM-driven execution from suspicious use that may enable follow-on execution, persistence, privilege-related activity, or task creation?

Executive priority

Prioritize this where Windows endpoints support critical operations, privileged administration, sensitive data handling, or regulated audit evidence. Because ATT&CK lists no official detection text for this sub-technique, executives should ask whether SOC and IR teams have a documented detection strategy, whether privileged account activity involving COM-mediated execution is reviewable, and whether isolation/sandboxing controls reduce the blast radius of abused applications.

Technical view

Validate coverage for Windows execution via COM as a sub-technique of Inter-Process Communication under the Execution tactic. ATT&CK notes that COM clients can call server objects implemented as DLLs or EXEs, and that exposed COM interfaces may be abused through languages including C, C++, Java, and Visual Basic. Detection engineering should map DET0224, if available internally, to concrete Windows telemetry and test whether COM-related execution can be correlated with parent process, loaded module or launched executable, scripting context, scheduled task creation, and privileged account use. Relationship context shows this behavior is associated with multiple groups and software entries, so detections should focus on behavior rather than a single tool or actor.

Likely telemetry

  • Windows process creation and parent/child process relationships involving COM client and server execution
  • DLL/module load telemetry for COM server objects where collected
  • Executable launch telemetry for COM server objects implemented as EXEs
  • Script or language runtime telemetry where Visual Basic or other supported languages invoke COM interfaces
  • Scheduled task creation or modification events when COM interfaces are used to create tasks

Detection direction

  • Start by confirming whether DET0224 or an equivalent internal analytic exists for Component Object Model abuse; ATT&CK does not provide official detection text for this object.
  • Baseline legitimate COM-heavy applications before alerting broadly, because COM is a native Windows API used by normal software and can produce high false positives if treated as inherently suspicious.
  • Correlate COM-mediated execution with unusual parent processes, scripting activity, unexpected DLL/EXE server activation, privileged-account context, and follow-on behaviors such as scheduled task creation.
  • Use relationship-driven context for prioritization: ATT&CK links this sub-technique to multiple malware families and groups, but detections should remain behavior-based and not assume attribution.
  • Check blind spots on endpoints without process, module-load, scripting, scheduled-task, or privileged-account telemetry; lack of these sources can make COM abuse difficult to validate during incident response.

Mitigation priorities

  • Apply privileged account management first: restrict administrative permissions, enforce least privilege, and ensure privileged COM-related activity is logged and accountable.
  • Use application isolation and sandboxing where practical to contain applications that may expose or invoke COM interfaces and limit access to sensitive resources.
  • Reduce unnecessary administrative exposure on Windows systems that support critical business functions.
  • Validate that control evidence is audit-ready: privileged account policies, logging coverage, and isolation decisions should be documented for compliance and incident review.
  • Pair prevention with monitoring, because COM is a legitimate Windows mechanism and cannot generally be disabled without business impact.
Additional notes and limits

This take is based on ATT&CK T1559.001 in enterprise-attack, Windows platform, Execution tactic, the supplied description, external reference list, and relationships. The relationship set includes DET0224 as a detection strategy, M1026 Privileged Account Management, M1048 Application Isolation and Sandboxing, parent technique T1559, and multiple group/software uses. Those relationships support prioritizing behavior-based detection and privileged-use review, not making claims about current activity in any specific environment.

The official ATT&CK detection field is not provided, so telemetry and detection guidance must be validated locally against available Windows endpoint, EDR, logging, and administrative audit data. The supplied fields do not provide vendor-specific controls, exact event IDs, or a complete list of suspicious COM objects; local baselining is required.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Component Object Model

Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces.[1] Through COM, a client object can call methods of server objects, which are typically binary Dynamic Link Libraries (DLL) or executables (EXE).[2] Remote COM execution is facilitated by Remote Services such as Distributed Component Object Model (DCOM).[1]

Various COM interfaces are exposed that can be abused to invoke arbitrary execution via a variety of programming languages such as C, C++, Java, and Visual Basic.[2] Specific COM objects also exist to directly perform functions beyond code execution, such as creating a Scheduled Task/Job, fileless download/execution, and other adversary behaviors related to privilege escalation and persistence.[1][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1559Inter-Process CommunicationThis object subtechnique of Inter-Process Communication.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0069: MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).[1] Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. [2][3][4][5][6][7][8][9][10][11][12][13]

GroupEnterprise

G0047: Gamaredon Group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][5]

GroupEnterprise

G1051: Medusa Group

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” [1] [2] Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. [3] For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. [4]

MalwareEnterprise

S0266: TrickBot

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.[1][2][3][4]

Windows
MalwareEnterprise

S0260: InvisiMole

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.[1][2]

Windows
MalwareEnterprise

S0386: Ursnif

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links.[1][2] Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.[3]

Windows
MalwareEnterprise

S1160: Latrodectus

Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules. Latrodectus has most often been distributed through email campaigns, primarily by TA577 and TA578, and has infrastructure overlaps with historic IcedID operations.[1][2][3]

Windows
MalwareEnterprise

S1130: Raspberry Robin

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.[1][2][3] The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."[4] The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.[5]

Windows
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
30012659e38ceb4c...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle30012659e38c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Fireeye Hunting COM June 2019

    Hamilton, C. (2019, June 4). Hunting COM Objects. Retrieved June 10, 2019.

    Open source URL
  2. [2]
    Microsoft COM

    Microsoft. (n.d.). Component Object Model (COM). Retrieved November 22, 2017.

    Open source URL
  3. [3]
    ProjectZero File Write EoP Apr 2018

    Forshaw, J. (2018, April 18). Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevation of Privilege. Retrieved May 3, 2018.

    Open source URL
  4. [4]
    FireEye MuddyWater Mar 2018

    Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

    Open source URL
  5. [5]
    ESET Trickbot Oct 2020

    Boutin, J. (2020, October 12). ESET takes part in global operation to disrupt Trickbot. Retrieved March 15, 2021.

    Open source URL
  6. [6]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  7. [7]
    Gen Digital Kimsuky HTTPTroy October 2025

    Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.

    Open source URL
  8. [8]
    Aryaka Kimsuky July 2025

    Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026.

    Open source URL
  9. [9]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  10. [10]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  11. [11]
    Securelist MuddyWater Oct 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, October 10). MuddyWater expands operations. Retrieved November 2, 2018.

    Open source URL
  12. [12]
    ClearSky MuddyWater June 2019

    ClearSky. (2019, June). Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal. Retrieved May 14, 2020.

    Open source URL
  13. [13]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  14. [14]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  15. [15]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  16. [16]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  17. [17]
    Bitsight Latrodectus June 2024

    Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.

    Open source URL
  18. [18]
    Microsoft Process Wide Com Keys

    Microsoft. (n.d.). Setting Process-Wide Security Through the Registry. Retrieved November 21, 2017.

    Open source URL
  19. [19]
    Microsoft System Wide Com Keys

    Microsoft. (n.d.). Registry Values for System-Wide Security. Retrieved November 21, 2017.

    Open source URL
  20. [20]
    Microsoft COM ACL

    Microsoft. (n.d.). DCOM Security Enhancements in Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1. Retrieved November 22, 2017.

    Open source URL
  21. [21]
    ESET Gamaredon June 2020

    Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.

    Open source URL
  22. [22]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
  23. [23]
    Microsoft Protected View

    Microsoft. (n.d.). What is Protected View?. Retrieved November 22, 2017.

    Open source URL
  24. [24]
    Intel471 Medusa Ransomware May 2025

    Intel471. (2025, May 14). Threat hunting case study: Medusa ransomware. Retrieved October 15, 2025.

    Open source URL
  25. [25]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  26. [26]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  27. [27]
    CloudSEK_RustyWater_Jan2026

    Awasthi, P. (2026, January 8). Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant. Retrieved March 19, 2026.

    Open source URL
  28. [28]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  29. [29]
    Microsoft NICKEL December 2021

    MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.

    Open source URL
  30. [30]
    Github_SILENTTRINITY

    byt3bl33d3r. (n.d.). SILENTTRINITY. Retrieved September 12, 2024.

    Open source URL
  31. [31]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  32. [32]
    Proofpoint Bumblebee April 2022

    Merriman, K. and Trouerbach, P. (2022, April 28). This isn't Optimus Prime's Bumblebee but it's Still Transforming. Retrieved August 22, 2022.

    Open source URL
  33. [33]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  34. [34]
    ESET Gelsemium June 2021

    Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021.

    Open source URL
  35. [35]
    Enigma MMC20 COM Jan 2017

    Nelson, M. (2017, January 5). Lateral Movement using the MMC20 Application COM Object. Retrieved November 21, 2017.

    Open source URL
  36. [36]
    Enigma MMC20 COM Jan 2017

    Nelson, M. (2017, January 5). Lateral Movement using the MMC20 Application COM Object. Retrieved November 21, 2017.

    Open source URL
  37. [37]
    Enigma MMC20 COM Jan 2017

    Nelson, M. (2017, January 5). Lateral Movement using the MMC20 Application COM Object. Retrieved November 21, 2017.

    Open source URL
  38. [38]
    Enigma Outlook DCOM Lateral Movement Nov 2017

    Nelson, M. (2017, November 16). Lateral Movement using Outlook's CreateObject Method and DotNetToJScript. Retrieved November 21, 2017.

    Open source URL
  39. [39]
    Enigma Outlook DCOM Lateral Movement Nov 2017

    Nelson, M. (2017, November 16). Lateral Movement using Outlook's CreateObject Method and DotNetToJScript. Retrieved November 21, 2017.

    Open source URL
  40. [40]
    Enigma Outlook DCOM Lateral Movement Nov 2017

    Nelson, M. (2017, November 16). Lateral Movement using Outlook's CreateObject Method and DotNetToJScript. Retrieved November 21, 2017.

    Open source URL
  41. [41]
    Fireeye Hunting COM June 2019

    Hamilton, C. (2019, June 4). Hunting COM Objects. Retrieved June 10, 2019.

    Open source URL
  42. [42]
    Fireeye Hunting COM June 2019

    Hamilton, C. (2019, June 4). Hunting COM Objects. Retrieved June 10, 2019.

    Open source URL
  43. [43]
    Microsoft COM

    Microsoft. (n.d.). Component Object Model (COM). Retrieved November 22, 2017.

    Open source URL
  44. [44]
    Microsoft COM

    Microsoft. (n.d.). Component Object Model (COM). Retrieved November 22, 2017.

    Open source URL
  45. [45]
    ProjectZero File Write EoP Apr 2018

    Forshaw, J. (2018, April 18). Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevation of Privilege. Retrieved May 3, 2018.

    Open source URL
  46. [46]
    ProjectZero File Write EoP Apr 2018

    Forshaw, J. (2018, April 18). Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevation of Privilege. Retrieved May 3, 2018.

    Open source URL
  47. [47]
    mitre-attackT1559.001
    Open source URL
  48. [48]
    mitre-attackT1559.001
    Open source URL
  49. [49]
    mitre-attackT1559.001
    Open source URL
  50. [50]
    FireEye MuddyWater Mar 2018

    Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

    Open source URL
  51. [51]
    ESET Trickbot Oct 2020

    Boutin, J. (2020, October 12). ESET takes part in global operation to disrupt Trickbot. Retrieved March 15, 2021.

    Open source URL
  52. [52]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  53. [53]
    Aryaka Kimsuky July 2025

    Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026.

    Open source URL
  54. [54]
    Gen Digital Kimsuky HTTPTroy October 2025

    Alexndru-Cristian Bardas. (2025, October 30). DPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant. Retrieved April 8, 2026.

    Open source URL
  55. [55]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  56. [56]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  57. [57]
    ClearSky MuddyWater June 2019

    ClearSky. (2019, June). Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal. Retrieved May 14, 2020.

    Open source URL
  58. [58]
    DHS CISA AA22-055A MuddyWater February 2022

    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

    Open source URL
  59. [59]
    Securelist MuddyWater Oct 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, October 10). MuddyWater expands operations. Retrieved November 2, 2018.

    Open source URL
  60. [60]
    Bromium Ursnif Mar 2017

    Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

    Open source URL
  61. [61]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  62. [62]
    Bitsight Latrodectus June 2024

    Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.

    Open source URL
  63. [63]
    Elastic Latrodectus May 2024

    Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.

    Open source URL
  64. [64]
    Microsoft COM ACL

    Microsoft. (n.d.). DCOM Security Enhancements in Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1. Retrieved November 22, 2017.

    Open source URL
  65. [65]
    Microsoft Process Wide Com Keys

    Microsoft. (n.d.). Setting Process-Wide Security Through the Registry. Retrieved November 21, 2017.

    Open source URL
  66. [66]
    Microsoft System Wide Com Keys

    Microsoft. (n.d.). Registry Values for System-Wide Security. Retrieved November 21, 2017.

    Open source URL
  67. [67]
    ESET Gamaredon June 2020

    Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.

    Open source URL
  68. [68]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
  69. [69]
    Microsoft Protected View

    Microsoft. (n.d.). What is Protected View?. Retrieved November 22, 2017.

    Open source URL
  70. [70]
    Intel471 Medusa Ransomware May 2025

    Intel471. (2025, May 14). Threat hunting case study: Medusa ransomware. Retrieved October 15, 2025.

    Open source URL
  71. [71]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  72. [72]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  73. [73]
    CloudSEK_RustyWater_Jan2026

    Awasthi, P. (2026, January 8). Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant. Retrieved March 19, 2026.

    Open source URL
  74. [74]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  75. [75]
    Microsoft NICKEL December 2021

    MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.

    Open source URL
  76. [76]
    Github_SILENTTRINITY

    byt3bl33d3r. (n.d.). SILENTTRINITY. Retrieved September 12, 2024.

    Open source URL
  77. [77]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.