LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1568.002: Domain Generation Algorithms

Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions.[1][2][3]

DGAs can take the form of apparently random or “gibberish” strings (ex: istgmxdejdnxuyla.ru) when they construct domain names by generating each letter. Alternatively, some DGAs employ whole words as the unit by concatenating words together instead of letters (ex: cityjulydish.net). Many DGAs are time-based, generating a different domain for each time period (hourly, daily, monthly, etc). Others incorporate a seed value as well to make predicting future domains more difficult for defenders.[1][2][4][5]

Adversaries may use DGAs for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ a DGA as a means to reestablishing command and control.[4][6][7]

EnterpriseT1568.002Sub-techniqueObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Domain Generation Algorithms matter because they make command-and-control harder to disrupt with simple blocklists. Instead of calling one known bad domain, malware can calculate many possible domains over time and try whichever one the adversary has registered. For leaders, the practical issue is resilience: if DNS, proxy, and network monitoring are weak or fragmented, an infected Windows, Linux, macOS, or ESXi system may regain contact even after obvious infrastructure is blocked.

Executive priority

Treat DGA coverage as a test of whether security operations can see and contain adaptive command-and-control, not just known indicators. Ask whether DNS and web egress controls are centrally logged, whether unmanaged servers and virtualization platforms are included, and whether incident response playbooks account for fallback channels. This technique is relevant to budget and audit discussions because prevention depends on web restriction and network prevention controls, while response depends on evidence that can show which hosts resolved or attempted unusual generated domains.

Technical view

This is an enterprise command-and-control sub-technique of Dynamic Resolution affecting ESXi, Linux, macOS, and Windows. MITRE does not provide a detection paragraph for this object, but the relationship to DET0419 indicates a detection strategy exists for Dynamic Resolution using DGAs. SOC and detection teams should validate DNS and proxy analytics for high-volume failed lookups, algorithmically generated or gibberish-looking domains, time-correlated domain churn, and word-concatenation patterns, while recognizing that seed-based and time-based DGAs can reduce predictability. IR teams should preserve DNS resolver, endpoint, proxy, and network boundary evidence before blocking domains, because DGA activity can indicate fallback command-and-control rather than the only C2 channel.

Likely telemetry

  • Recursive DNS query and response logs, including NXDOMAIN and low-reputation or newly observed domains
  • Endpoint network connection telemetry from Windows, Linux, macOS, and ESXi where available
  • Web proxy and URL filtering logs for outbound domain access attempts
  • Network intrusion detection/prevention alerts at egress boundaries
  • Firewall or secure web gateway egress records tying domains to internal hosts

Detection direction

  • Validate DET0419-aligned analytics for DGA-style dynamic resolution rather than relying only on static domain or IP blocklists.
  • Tune for both random-looking domains and word-based concatenation patterns; not all DGAs look like obvious gibberish.
  • Correlate suspicious DNS activity with endpoint process and network telemetry to reduce false positives from legitimate software updaters, telemetry services, and content delivery behavior.
  • Pay attention to bursts of failed domain lookups and changing domains over hourly, daily, or monthly windows, consistent with time-based generation described by MITRE.
  • Check blind spots around servers, Linux systems, ESXi management networks, and resolver paths that bypass central logging.

Mitigation priorities

  • Prioritize Restrict Web-Based Content controls such as URL filtering, download restrictions, script blocking, and extension control where applicable to reduce access to unsafe destinations.
  • Use Network Intrusion Prevention at network boundaries to block known malicious traffic patterns and enforce egress policy.
  • Centralize DNS resolution and logging so hosts cannot quietly bypass monitored resolvers.
  • Use containment playbooks that block confirmed malicious domains while also hunting for related generated-domain attempts and fallback command-and-control behavior.
  • Review egress policy for non-browser workloads and infrastructure platforms, including Linux and ESXi, because DGA-based C2 is not limited to user workstations.
Additional notes and limits

MITRE links this technique to many groups and software families, including APT41, TA551, CHOPSTICK, MiniDuke, POSHSPY, CCBkdr, BONDUPDATER, Astaroth, Ebury, Ursnif, Aria-body, ngrok, Grandoreiro, Bazar, ShadowPad, Doki, Conficker, SombRAT, and QakBot. Use those relationships for threat-informed prioritization, not as proof of local exposure or current activity. The revoked T1483 object is represented by this sub-technique, so older reporting may use the prior identifier.

The official ATT&CK object provides no native detection text, so detection guidance here is derived from the official description, the DET0419 relationship, listed mitigations, platforms, and external-reference context. Local validation is required to confirm whether DNS, proxy, endpoint, and network telemetry are collected consistently enough to detect this behavior.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Domain Generation Algorithms

Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions.[1][2][3]

DGAs can take the form of apparently random or “gibberish” strings (ex: istgmxdejdnxuyla.ru) when they construct domain names by generating each letter. Alternatively, some DGAs employ whole words as the unit by concatenating words together instead of letters (ex: cityjulydish.net). Many DGAs are time-based, generating a different domain for each time period (hourly, daily, monthly, etc). Others incorporate a seed value as well to make predicting future domains more difficult for defenders.[1][2][4][5]

Adversaries may use DGAs for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ a DGA as a means to reestablishing command and control.[4][6][7]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1568Dynamic ResolutionThis object subtechnique of Dynamic Resolution.
EnterpriseT1483Domain Generation AlgorithmsDomain Generation Algorithms revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0127: TA551

TA551 is a financially-motivated threat group that has been active since at least 2018. [1] The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns. [2]

ToolEnterprise

S1087: AsyncRAT

AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns.[1][2][3]

Windows
MalwareEnterprise

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

Windows
MalwareEnterprise

S0600: Doki

Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020. Doki was used in conjunction with the ngrok Mining Botnet in a campaign that targeted Docker servers in cloud platforms. [1]

LinuxContainers
MalwareEnterprise

S0150: POSHSPY

POSHSPY is a backdoor that has been used by APT29 since at least 2015. It appears to be used as a secondary backdoor used if the actors lost access to their primary backdoors. [1]

Windows
MalwareEnterprise

S0360: BONDUPDATER

BONDUPDATER is a PowerShell backdoor used by OilRig. It was first observed in November 2017 during targeting of a Middle Eastern government organization, and an updated version was observed in August 2018 being used to target a government organization with spearphishing emails.[1][2]

Windows
MalwareEnterprise

S0608: Conficker

Conficker is a computer worm first detected in October 2008 that targeted Microsoft Windows using the MS08-067 Windows vulnerability to spread.[1] In 2016, a variant of Conficker made its way on computers and removable disk drives belonging to a nuclear power plant.[2]

Windows
MalwareEnterprise

S0023: CHOPSTICK

CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants. [1] [2] [3] [4] It is tracked separately from the X-Agent for Android.

WindowsLinux
ToolEnterprise

S0508: ngrok

ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.[1][2][3][4]

Windows
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
81f0f5b4f38ab4e6...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle81f0f5b4f38a…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Cybereason Dissecting DGAs

    Sternfeld, U. (2016). Dissecting Domain Generation Algorithms: Eight Real World DGA Variants. Retrieved February 18, 2019.

  2. [2]
    Cisco Umbrella DGA

    Scarfo, A. (2016, October 10). Domain Generation Algorithms – Why so effective?. Retrieved February 18, 2019.

    Open source URL
  3. [3]
    Unit 42 DGA Feb 2019

    Unit 42. (2019, February 7). Threat Brief: Understanding Domain Generation Algorithms (DGA). Retrieved February 19, 2019.

    Open source URL
  4. [4]
    Talos CCleanup 2017

    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

  5. [5]
    Akamai DGA Mitigation

    Liu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019.

    Open source URL
  6. [6]
    FireEye POSHSPY April 2017

    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.

    Open source URL
  7. [7]
    ESET Sednit 2017 Activity

    ESET. (2017, December 21). Sednit update: How Fancy Bear Spent the Year. Retrieved February 18, 2019.

    Open source URL
  8. [8]
    CheckPoint Naikon May 2020

    CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.

    Open source URL
  9. [9]
    Cisco Umbrella DGA Brute Force

    Kasza, A. (2015, February 18). Using Algorithms to Brute Force Algorithms. Retrieved February 18, 2019.

    Open source URL
  10. [10]
    ESET MirrorFace 2025

    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.

    Open source URL
  11. [11]
    Trend Micro Qakbot May 2020

    Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.

    Open source URL
  12. [12]
    Intezer Doki July 20

    Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021.

    Open source URL
  13. [13]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  14. [14]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  15. [15]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  16. [16]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  17. [17]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  18. [18]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  19. [19]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  20. [20]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  21. [21]
    Unit 42 TA551 Jan 2021

    Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.

    Open source URL
  22. [22]
    Secureworks GOLD CABIN

    Secureworks. (n.d.). GOLD CABIN Threat Profile. Retrieved March 17, 2021.

    Open source URL
  23. [23]
    SANS Conficker

    Burton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.

    Open source URL
  24. [24]
    Trend Micro Conficker

    Trend Micro. (2014, March 18). Conficker. Retrieved February 18, 2021.

    Open source URL
  25. [25]
    Zdnet Ngrok September 2018

    Cimpanu, C. (2018, September 13). Sly malware author hides cryptomining botnet behind ever-shifting proxy service. Retrieved September 15, 2020.

    Open source URL
  26. [26]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  27. [27]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  28. [28]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  29. [29]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  30. [30]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  31. [31]
    Securelist ShadowPad Aug 2017

    GReAT. (2017, August 15). ShadowPad in corporate networks. Retrieved March 22, 2021.

    Open source URL
  32. [32]
    Kaspersky ShadowPad Aug 2017

    Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.

    Open source URL
  33. [33]
    Cybereason Astaroth Feb 2019

    Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.

    Open source URL
  34. [34]
    Cybereason Bazar July 2020

    Cybereason Nocturnus. (2020, July 16). A BAZAR OF TRICKS: FOLLOWING TEAM9’S DEVELOPMENT CYCLES. Retrieved November 18, 2020.

    Open source URL
  35. [35]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  36. [36]
    ESET Ebury Feb 2014

    M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.

    Open source URL
  37. [37]
    ESET Ebury Oct 2017

    Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021.

    Open source URL
  38. [38]
    Akamai DGA Mitigation

    Liu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019.

    Open source URL
  39. [39]
    Akamai DGA Mitigation

    Liu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019.

    Open source URL
  40. [40]
    Cisco Umbrella DGA

    Scarfo, A. (2016, October 10). Domain Generation Algorithms – Why so effective?. Retrieved February 18, 2019.

    Open source URL
  41. [41]
    Cisco Umbrella DGA

    Scarfo, A. (2016, October 10). Domain Generation Algorithms – Why so effective?. Retrieved February 18, 2019.

    Open source URL
  42. [42]
    Cybereason Dissecting DGAs

    Sternfeld, U. (2016). Dissecting Domain Generation Algorithms: Eight Real World DGA Variants. Retrieved February 18, 2019.

  43. [43]
    Cybereason Dissecting DGAs

    Sternfeld, U. (2016). Dissecting Domain Generation Algorithms: Eight Real World DGA Variants. Retrieved February 18, 2019.

  44. [44]
    Data Driven Security DGA

    Jacobs, J. (2014, October 2). Building a DGA Classifier: Part 2, Feature Engineering. Retrieved February 18, 2019.

    Open source URL
  45. [45]
    Data Driven Security DGA

    Jacobs, J. (2014, October 2). Building a DGA Classifier: Part 2, Feature Engineering. Retrieved February 18, 2019.

    Open source URL
  46. [46]
    Data Driven Security DGA

    Jacobs, J. (2014, October 2). Building a DGA Classifier: Part 2, Feature Engineering. Retrieved February 18, 2019.

    Open source URL
  47. [47]
    ESET Sednit 2017 Activity

    ESET. (2017, December 21). Sednit update: How Fancy Bear Spent the Year. Retrieved February 18, 2019.

    Open source URL
  48. [48]
    ESET Sednit 2017 Activity

    ESET. (2017, December 21). Sednit update: How Fancy Bear Spent the Year. Retrieved February 18, 2019.

    Open source URL
  49. [49]
    Elastic Predicting DGA

    Ahuja, A., Anderson, H., Grant, D., Woodbridge, J.. (2016, November 2). Predicting Domain Generation Algorithms with Long Short-Term Memory Networks. Retrieved April 26, 2019.

    Open source URL
  50. [50]
    Elastic Predicting DGA

    Ahuja, A., Anderson, H., Grant, D., Woodbridge, J.. (2016, November 2). Predicting Domain Generation Algorithms with Long Short-Term Memory Networks. Retrieved April 26, 2019.

    Open source URL
  51. [51]
    Elastic Predicting DGA

    Ahuja, A., Anderson, H., Grant, D., Woodbridge, J.. (2016, November 2). Predicting Domain Generation Algorithms with Long Short-Term Memory Networks. Retrieved April 26, 2019.

    Open source URL
  52. [52]
    FireEye POSHSPY April 2017

    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.

    Open source URL
  53. [53]
    FireEye POSHSPY April 2017

    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.

    Open source URL
  54. [54]
    Pace University Detecting DGA May 2017

    Chen, L., Wang, T.. (2017, May 5). Detecting Algorithmically Generated Domains Using Data Visualization and N-Grams Methods . Retrieved April 26, 2019.

  55. [55]
    Pace University Detecting DGA May 2017

    Chen, L., Wang, T.. (2017, May 5). Detecting Algorithmically Generated Domains Using Data Visualization and N-Grams Methods . Retrieved April 26, 2019.

  56. [56]
    Pace University Detecting DGA May 2017

    Chen, L., Wang, T.. (2017, May 5). Detecting Algorithmically Generated Domains Using Data Visualization and N-Grams Methods . Retrieved April 26, 2019.

  57. [57]
    Talos CCleanup 2017

    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

  58. [58]
    Talos CCleanup 2017

    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

  59. [59]
    Unit 42 DGA Feb 2019

    Unit 42. (2019, February 7). Threat Brief: Understanding Domain Generation Algorithms (DGA). Retrieved February 19, 2019.

    Open source URL
  60. [60]
    Unit 42 DGA Feb 2019

    Unit 42. (2019, February 7). Threat Brief: Understanding Domain Generation Algorithms (DGA). Retrieved February 19, 2019.

    Open source URL
  61. [61]
    mitre-attackT1568.002
    Open source URL
  62. [62]
    mitre-attackT1568.002
    Open source URL
  63. [63]
    mitre-attackT1568.002
    Open source URL
  64. [64]
    CheckPoint Naikon May 2020

    CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.

    Open source URL
  65. [65]
    Akamai DGA Mitigation

    Liu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019.

    Open source URL
  66. [66]
    Akamai DGA Mitigation

    Liu, H. and Yuzifovich, Y. (2018, January 9). A Death Match of Domain Generation Algorithms. Retrieved February 18, 2019.

    Open source URL
  67. [67]
    Cisco Umbrella DGA Brute Force

    Kasza, A. (2015, February 18). Using Algorithms to Brute Force Algorithms. Retrieved February 18, 2019.

    Open source URL
  68. [68]
    Cybereason Dissecting DGAs

    Sternfeld, U. (2016). Dissecting Domain Generation Algorithms: Eight Real World DGA Variants. Retrieved February 18, 2019.

  69. [69]
    Cybereason Dissecting DGAs

    Sternfeld, U. (2016). Dissecting Domain Generation Algorithms: Eight Real World DGA Variants. Retrieved February 18, 2019.

  70. [70]
    ESET MirrorFace 2025

    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.

    Open source URL
  71. [71]
    Trend Micro Qakbot May 2020

    Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.

    Open source URL
  72. [72]
    Intezer Doki July 20

    Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021.

    Open source URL
  73. [73]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  74. [74]
    FireEye POSHSPY April 2017

    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.

    Open source URL
  75. [75]
    FireEye POSHSPY April 2017

    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.

    Open source URL
  76. [76]
    Prevailion DarkWatchman 2021

    Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022.

    Open source URL
  77. [77]
    FireEye APT34 Dec 2017

    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

    Open source URL
  78. [78]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  79. [79]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  80. [80]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  81. [81]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  82. [82]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  83. [83]
    Secureworks GOLD CABIN

    Secureworks. (n.d.). GOLD CABIN Threat Profile. Retrieved March 17, 2021.

    Open source URL
  84. [84]
    Unit 42 TA551 Jan 2021

    Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.

    Open source URL
  85. [85]
    SANS Conficker

    Burton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.

    Open source URL
  86. [86]
    Trend Micro Conficker

    Trend Micro. (2014, March 18). Conficker. Retrieved February 18, 2021.

    Open source URL
  87. [87]
    ESET Sednit 2017 Activity

    ESET. (2017, December 21). Sednit update: How Fancy Bear Spent the Year. Retrieved February 18, 2019.

    Open source URL
  88. [88]
    ESET Sednit 2017 Activity

    ESET. (2017, December 21). Sednit update: How Fancy Bear Spent the Year. Retrieved February 18, 2019.

    Open source URL
  89. [89]
    Zdnet Ngrok September 2018

    Cimpanu, C. (2018, September 13). Sly malware author hides cryptomining botnet behind ever-shifting proxy service. Retrieved September 15, 2020.

    Open source URL
  90. [90]
    ProofPoint Ursnif Aug 2016

    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

    Open source URL
  91. [91]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
  92. [92]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  93. [93]
    Talos CCleanup 2017

    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

  94. [94]
    Talos CCleanup 2017

    Brumaghin, E. et al. (2017, September 18). CCleanup: A Vast Number of Machines at Risk. Retrieved March 9, 2018.

  95. [95]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  96. [96]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  97. [97]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  98. [98]
    Accenture Lyceum Targets November 2021

    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.