LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1569.002: Service Execution

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services.[1] The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net.

PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API.[2] Tools such as PsExec and sc.exe can accept remote servers as arguments and may be used to conduct remote execution.

Adversaries may leverage these mechanisms to execute malicious content. This can be done by either executing a new or modified service. This technique is the execution used in conjunction with Windows Service during service persistence or privilege escalation.

EnterpriseT1569.002Sub-techniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Service Execution matters because Windows services are a normal administrative mechanism that can also run attacker-controlled commands locally or remotely. For leaders, the risk is not just malware execution; it is whether privileged Windows administration paths are governed, logged, and reviewable when an incident responder needs to determine how code ran on a server or workstation.

Executive priority

Prioritize this as a Windows execution-risk and privileged-administration control question. Executives should ask whether service creation, modification, and remote service use are monitored across critical Windows assets, whether privileged accounts are limited and accountable, and whether audit evidence can show who changed or started services during an incident. The ATT&CK relationships to multiple groups and campaigns make this a useful validation scenario for managed detection, incident response readiness, and control assurance, without implying current exposure in any specific environment.

Technical view

This sub-technique covers abuse of the Windows Service Control Manager, including use through GUI tools, sc.exe, Net, PsExec, and service control APIs, to execute commands or payloads by creating or modifying services. SOC and IR teams should validate coverage for service lifecycle activity on Windows endpoints and servers, especially where remote servers are used as arguments or temporary services are created. MITRE does not provide official detection text for this object, but the related DET0421 detection strategy indicates detection engineering should be centered on system services service execution behavior. Correlate service events with process execution, privileged logon context, remote administration paths, and file changes to service binaries or directories.

Likely telemetry

  • Windows service creation, modification, start, stop, and deletion events
  • Process execution telemetry for services.exe, sc.exe, Net, PsExec-related activity, and child processes launched by services
  • Endpoint detection telemetry covering service control API behavior and suspicious service-launched payloads
  • Windows authentication and privileged account usage logs, especially for remote administration
  • File system telemetry for writes or permission changes involving service binaries, service directories, and temporary payload locations

Detection direction

  • Establish baselines for legitimate service administration so alerts can focus on unusual service names, paths, accounts, hosts, timing, or remote sources.
  • Tune for new or modified services that execute from unexpected directories, use unusual command lines, or are created shortly before execution and removed afterward.
  • Correlate service execution with privileged account activity; service abuse often depends on administrative rights, so identity context is essential for triage.
  • Review coverage gaps on servers where Windows event logging or endpoint telemetry is incomplete, because service execution may otherwise look like normal operating system activity.
  • Account for false positives from software deployment, endpoint management, backup, monitoring, and administrator troubleshooting tools that legitimately create or modify services.

Mitigation priorities

  • Apply privileged account management first: restrict who can create, modify, or remotely control Windows services and ensure privileged use is logged and accountable.
  • Restrict file and directory permissions for service binaries and sensitive paths so unauthorized users or processes cannot replace or plant executable content.
  • Use endpoint behavior-prevention controls to block or challenge suspicious service creation, service-launched payloads, or abnormal service control behavior where appropriate.
  • Harden administrative workflows by separating routine administration from broad domain-level privileges and reviewing remote service management access on critical assets.
  • Validate mitigations through controlled defensive testing that confirms unauthorized service changes are blocked or generate actionable alerts.
Additional notes and limits

The supplied ATT&CK object is Windows-only and scoped to execution via the Service Control Manager. It explicitly connects to Windows Service persistence or privilege escalation behavior, but this take stays focused on the execution sub-technique. Relationships show use by several campaigns and groups and mitigations M1022, M1026, and M1040; those relationships support prioritizing control validation but do not prove activity in any given environment.

MITRE provides no official detection text for this object in the supplied fields, so detection guidance is derived from the technique description, the related DET0421 detection strategy, and mitigation relationships. Local service baselines, endpoint logging depth, privileged access design, and administrative tooling determine what is detectable and what is normal.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Service Execution

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services.[1] The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net.

PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API.[2] Tools such as PsExec and sc.exe can accept remote servers as arguments and may be used to conduct remote execution.

Adversaries may leverage these mechanisms to execute malicious content. This can be done by either executing a new or modified service. This technique is the execution used in conjunction with Windows Service during service persistence or privilege escalation.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1569System ServicesThis object subtechnique of System Services.
EnterpriseT1035Service ExecutionService Execution revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0114: Chimera

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.[1][2]

GroupEnterprise

G0087: APT39

APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.[1][2][3][4][5]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G1047: Velvet Ant

Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.[1][2]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0091: Silence

Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.[1][2]

GroupEnterprise

G0004: Ke3chang

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.[1][2][3][4]

GroupEnterprise

G1051: Medusa Group

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” [1] [2] Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. [3] For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. [4]

GroupEnterprise

G0108: Blue Mockingbird

Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.[1]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

GroupEnterprise

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

ToolEnterprise

S0192: Pupy

Pupy is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool. [1] It is written in Python and can be generated as a payload in several different ways (Windows exe, Python file, PowerShell oneliner/file, Linux elf, APK, Rubber Ducky, etc.). [1] Pupy is publicly available on GitHub. [1]

LinuxWindowsmacOS
MalwareEnterprise

S1111: DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
MalwareEnterprise

S0260: InvisiMole

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.[1][2]

Windows
ToolEnterprise

S1063: Brute Ratel C4

Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.[1][2][3][4][5]

Windows
MalwareEnterprise

S0368: NotPetya

NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While NotPetya appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, NotPetya may be more appropriately thought of as a form of wiper malware. NotPetya contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.[1][2][3][4]

Windows
CampaignEnterprise

C0014: Operation Wocao

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.[1]

Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.[1]

CampaignEnterprise

C0061: Operation Digital Eye

Operation Digital Eye was conducted in June and July of 2024 by suspected People's Republic of China (PRC)-nexus threat actors targeting business-to-business IT service providers in Southern Europe. Operation Digital Eye activity included the use of Visual Studio Code tunnels for command and control (C2) and custom lateral movement capabilities. Overlaps in tooling between Digital Eye and previous China-nexus campaigns, Operation Soft Cell and Operation Tainted Love, indicate the potential use of shared vendors or digital quartermasters.[1]

CampaignEnterprise

C0006: Operation Honeybee

Operation Honeybee was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. Operation Honeybee initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign "Honeybee" after the author name discovered in malicious Word documents.[1]

CampaignEnterprise

C0058: SharePoint ToolShell Exploitation

The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.[1][2][3][4][5]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
de06f9a6209044ec...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundlede06f9a62090…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Microsoft Service Control Manager

    Microsoft. (2018, May 31). Service Control Manager. Retrieved March 28, 2020.

    Open source URL
  2. [2]
    Russinovich Sysinternals

    Russinovich, M. (2014, May 2). Windows Sysinternals PsExec v2.11. Retrieved May 13, 2015.

    Open source URL
  3. [3]
    GitHub Pupy

    Nicolas Verdier. (n.d.). Retrieved January 29, 2018.

    Open source URL
  4. [4]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  5. [5]
    cobaltstrike manual

    Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

    Open source URL
  6. [6]
    Cobalt Strike TTPs Dec 2017

    Cobalt Strike. (2017, December 8). Tactics, Techniques, and Procedures. Retrieved November 17, 2024.

    Open source URL
  7. [7]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  8. [8]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  9. [9]
    Symantec Hydraq Persistence Jan 2010

    Fitzgerald, P. (2010, January 26). How Trojan.Hydraq Stays On Your Computer. Retrieved February 22, 2018.

    Open source URL
  10. [10]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  11. [11]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  12. [12]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  13. [13]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  14. [14]
    Symantec Buckeye

    Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.

    Open source URL
  15. [15]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  16. [16]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  17. [17]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  18. [18]
    BitDefender Chafer May 2020

    Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020.

    Open source URL
  19. [19]
    Symantec Chafer February 2018

    Symantec. (2018, February 28). Chafer: Latest Attacks Reveal Heightened Ambitions. Retrieved May 22, 2020.

    Open source URL
  20. [20]
    GitHub PoshC2

    Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.

    Open source URL
  21. [21]
    SentinelLabs Metador Technical Appendix Sept 2022

    SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

    Open source URL
  22. [22]
    Joint Cybersecurity Advisory LockBit JUN 2023

    CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.

    Open source URL
  23. [23]
    xCmd

    Rayaprolu, A.. (2011, April 12). xCmd an Alternative to PsExec. Retrieved August 10, 2016.

    Open source URL
  24. [24]
    win10_asr

    Microsoft. (2021, July 2). Use attack surface reduction rules to prevent malware infection. Retrieved June 24, 2021.

    Open source URL
  25. [25]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  26. [26]
    Secpod Winexe June 2017

    Prakash, T. (2017, June 21). Run commands on Windows system remotely using Winexe. Retrieved September 12, 2024.

    Open source URL
  27. [27]
    Palo Alto Networks BBSRAT

    Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

  28. [28]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  29. [29]
    McAfee GhostSecret

    Sherstobitoff, R., Malhotra, A. (2018, April 24). Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide. Retrieved May 16, 2018.

    Open source URL
  30. [30]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  31. [31]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  32. [32]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  33. [33]
    Gh0stRAT ATT March 2019

    Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.

    Open source URL
  34. [34]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  35. [35]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  36. [36]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  37. [37]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  38. [38]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  39. [39]
    McAfee Shamoon December19 2018

    Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 19). Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems. Retrieved May 29, 2020.

    Open source URL
  40. [40]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  41. [41]
    sentinelone operationDigitalEye Dec 2024

    Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.

    Open source URL
  42. [42]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  43. [43]
    FireEye APT41 March 2020

    Glyer, C, et al. (2020, March). This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved April 28, 2020.

    Open source URL
  44. [44]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  45. [45]
    SecureList Silence Nov 2017

    GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.

    Open source URL
  46. [46]
    Group IB Silence Sept 2018

    Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.

    Open source URL
  47. [47]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  48. [48]
    Palo Alto Unit 42 Medusa Group Medusa Ransomware January 2024

    Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.

    Open source URL
  49. [49]
    CISA Medusa Group Medusa Ransomware March 2025

    Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  50. [50]
    Broadcom Medusa Ransomware Medusa Group March 2025

    Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.

    Open source URL
  51. [51]
    RedCanary Mockingbird May 2020

    Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

    Open source URL
  52. [52]
    US-CERT HOPLIGHT Apr 2019

    US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019.

    Open source URL
  53. [53]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  54. [54]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  55. [55]
    Microsoft SIR Vol 21

    Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.

  56. [56]
    Microsoft Wingbird Nov 2017

    Microsoft. (2017, November 9). Backdoor:Win32/Wingbird.A!dha. Retrieved November 27, 2017.

    Open source URL
  57. [57]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  58. [58]
    Cylance Cleaver

    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

    Open source URL
  59. [59]
    ESET LoudMiner June 2019

    Malik, M. (2019, June 20). LoudMiner: Cross-platform mining in cracked VST software. Retrieved May 18, 2020.

    Open source URL
  60. [60]
    CERT-FR PYSA April 2020

    CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021.

    Open source URL
  61. [61]
    McAfee Honeybee

    Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

    Open source URL
  62. [62]
    Novetta Winnti April 2015

    Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.

    Open source URL
  63. [63]
    ESET OceanLotus Mar 2019

    Dumont, R. (2019, March 20). Fake or Fake: Keeping up with OceanLotus decoys. Retrieved April 1, 2019.

    Open source URL
  64. [64]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  65. [65]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  66. [66]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  67. [67]
    Github Koadic

    Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.

    Open source URL
  68. [68]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  69. [69]
    ESET Attor Oct 2019

    Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

    Open source URL
  70. [70]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  71. [71]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  72. [72]
    NCC Group WastedLocker June 2020

    Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021.

    Open source URL
  73. [73]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  74. [74]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  75. [75]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  76. [76]
    SentinelOne Hermetic Wiper February 2022

    Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022.

    Open source URL
  77. [77]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  78. [78]
    Qualys Hermetic Wiper March 2022

    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

    Open source URL
  79. [79]
    Sophos Netwalker May 2020

    Szappanos, G., Brandt, A.. (2020, May 27). Netwalker ransomware tools give insight into threat actor. Retrieved May 27, 2020.

    Open source URL
  80. [80]
    ESET Embargo Ransomware October 2024

    Jan Holman, Tomas Zvara. (2024, October 23). Embargo ransomware: Rock’n’Rust. Retrieved October 19, 2025.

    Open source URL
  81. [81]
    Talos Promethium June 2020

    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

    Open source URL
  82. [82]
    Bitdefender StrongPity June 2020

    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

    Open source URL
  83. [83]
    Talos ZxShell Oct 2014

    Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019.

    Open source URL
  84. [84]
    CISA AA20-239A BeagleBoyz August 2020

    DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.

    Open source URL
  85. [85]
    DFIR Ryuk's Return October 2020

    The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

    Open source URL
  86. [86]
    DFIR Ryuk in 5 Hours October 2020

    The DFIR Report. (2020, October 18). Ryuk in 5 Hours. Retrieved October 19, 2020.

    Open source URL
  87. [87]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  88. [88]
    Cyberreason Anchor December 2019

    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.

    Open source URL
  89. [89]
    Medium Anchor DNS July 2020

    Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.

    Open source URL
  90. [90]
    Microsoft Service Control Manager

    Microsoft. (2018, May 31). Service Control Manager. Retrieved March 28, 2020.

    Open source URL
  91. [91]
    Microsoft Service Control Manager

    Microsoft. (2018, May 31). Service Control Manager. Retrieved March 28, 2020.

    Open source URL
  92. [92]
    Russinovich Sysinternals

    Russinovich, M. (2014, May 2). Windows Sysinternals PsExec v2.11. Retrieved May 13, 2015.

    Open source URL
  93. [93]
    Russinovich Sysinternals

    Russinovich, M. (2014, May 2). Windows Sysinternals PsExec v2.11. Retrieved May 13, 2015.

    Open source URL
  94. [94]
    mitre-attackT1569.002
    Open source URL
  95. [95]
    mitre-attackT1569.002
    Open source URL
  96. [96]
    mitre-attackT1569.002
    Open source URL
  97. [97]
    GitHub Pupy

    Nicolas Verdier. (n.d.). Retrieved January 29, 2018.

    Open source URL
  98. [98]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  99. [99]
    Cobalt Strike Manual 4.3 November 2020

    Strategic Cyber LLC. (2020, November 5). Cobalt Strike: Advanced Threat Tactics for Penetration Testers. Retrieved April 13, 2021.

    Open source URL
  100. [100]
    Cobalt Strike TTPs Dec 2017

    Cobalt Strike. (2017, December 8). Tactics, Techniques, and Procedures. Retrieved November 17, 2024.

    Open source URL
  101. [101]
    cobaltstrike manual

    Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

    Open source URL
  102. [102]
    ESET InvisiMole June 2020

    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

    Open source URL
  103. [103]
    Symantec Hydraq Persistence Jan 2010

    Fitzgerald, P. (2010, January 26). How Trojan.Hydraq Stays On Your Computer. Retrieved February 22, 2018.

    Open source URL
  104. [104]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  105. [105]
    Talos Nyetya June 2017

    Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

    Open source URL
  106. [106]
    US-CERT NotPetya 2017

    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

    Open source URL
  107. [107]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  108. [108]
    Symantec Buckeye

    Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.

    Open source URL
  109. [109]
    ESET Hermetic Wizard March 2022

    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

    Open source URL
  110. [110]
    Talos TinyTurla September 2021

    Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021.

    Open source URL
  111. [111]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  112. [112]
    BitDefender Chafer May 2020

    Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020.

    Open source URL
  113. [113]
    Symantec Chafer February 2018

    Symantec. (2018, February 28). Chafer: Latest Attacks Reveal Heightened Ambitions. Retrieved May 22, 2020.

    Open source URL
  114. [114]
    GitHub PoshC2

    Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.

    Open source URL
  115. [115]
    SentinelLabs Metador Technical Appendix Sept 2022

    SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

    Open source URL
  116. [116]
    Joint Cybersecurity Advisory LockBit JUN 2023

    CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.

    Open source URL
  117. [117]
    xCmd

    Rayaprolu, A.. (2011, April 12). xCmd an Alternative to PsExec. Retrieved August 10, 2016.

    Open source URL
  118. [118]
    win10_asr

    Microsoft. (2021, July 2). Use attack surface reduction rules to prevent malware infection. Retrieved June 24, 2021.

    Open source URL
  119. [119]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  120. [120]
    Secpod Winexe June 2017

    Prakash, T. (2017, June 21). Run commands on Windows system remotely using Winexe. Retrieved September 12, 2024.

    Open source URL
  121. [121]
    Palo Alto Networks BBSRAT

    Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

  122. [122]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  123. [123]
    McAfee GhostSecret

    Sherstobitoff, R., Malhotra, A. (2018, April 24). Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide. Retrieved May 16, 2018.

    Open source URL
  124. [124]
    Savill 1999

    Savill, J. (1999, March 4). Net.exe reference. Retrieved September 22, 2015.

    Open source URL
  125. [125]
    CISA MAR SLOTHFULMEDIA October 2020

    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.

    Open source URL
  126. [126]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  127. [127]
    Gh0stRAT ATT March 2019

    Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.

    Open source URL
  128. [128]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  129. [129]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  130. [130]
    Impacket Tools

    SecureAuth. (n.d.). Retrieved January 15, 2019.

    Open source URL
  131. [131]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  132. [132]
    McAfee Shamoon December19 2018

    Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 19). Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems. Retrieved May 29, 2020.

    Open source URL
  133. [133]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  134. [134]
    Github PowerShell Empire

    Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016.

    Open source URL
  135. [135]
    sentinelone operationDigitalEye Dec 2024

    Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.

    Open source URL
  136. [136]
    ESET Okrum July 2019

    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

    Open source URL
  137. [137]
    FireEye APT41 March 2020

    Glyer, C, et al. (2020, March). This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved April 28, 2020.

    Open source URL
  138. [138]
    Group IB APT 41 June 2021

    Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.

    Open source URL
  139. [139]
    Group IB Silence Sept 2018

    Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.

    Open source URL
  140. [140]
    SecureList Silence Nov 2017

    GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019.

    Open source URL
  141. [141]
    NCC Group APT15 Alive and Strong

    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

    Open source URL
  142. [142]
    Broadcom Medusa Ransomware Medusa Group March 2025

    Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.

    Open source URL
  143. [143]
    CISA Medusa Group Medusa Ransomware March 2025

    Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025.

    Open source URL
  144. [144]
    Palo Alto Unit 42 Medusa Group Medusa Ransomware January 2024

    Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.

    Open source URL
  145. [145]
    RedCanary Mockingbird May 2020

    Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

    Open source URL
  146. [146]
    US-CERT HOPLIGHT Apr 2019

    US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019.

    Open source URL
  147. [147]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  148. [148]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  149. [149]
    Microsoft SIR Vol 21

    Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.

  150. [150]
    Microsoft Wingbird Nov 2017

    Microsoft. (2017, November 9). Backdoor:Win32/Wingbird.A!dha. Retrieved November 27, 2017.

    Open source URL
  151. [151]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  152. [152]
    Cylance Cleaver

    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

    Open source URL
  153. [153]
    ESET LoudMiner June 2019

    Malik, M. (2019, June 20). LoudMiner: Cross-platform mining in cracked VST software. Retrieved May 18, 2020.

    Open source URL
  154. [154]
    CERT-FR PYSA April 2020

    CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021.

    Open source URL
  155. [155]
    McAfee Honeybee

    Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

    Open source URL
  156. [156]
    Novetta Winnti April 2015

    Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.

    Open source URL
  157. [157]
    ESET OceanLotus Mar 2019

    Dumont, R. (2019, March 20). Fake or Fake: Keeping up with OceanLotus decoys. Retrieved April 1, 2019.

    Open source URL
  158. [158]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  159. [159]
    Russinovich Sysinternals

    Russinovich, M. (2014, May 2). Windows Sysinternals PsExec v2.11. Retrieved May 13, 2015.

    Open source URL
  160. [160]
    Russinovich Sysinternals

    Russinovich, M. (2014, May 2). Windows Sysinternals PsExec v2.11. Retrieved May 13, 2015.

    Open source URL
  161. [161]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  162. [162]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  163. [163]
    Github Koadic

    Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.

    Open source URL
  164. [164]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  165. [165]
    ESET Attor Oct 2019

    Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

    Open source URL
  166. [166]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  167. [167]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  168. [168]
    Google Cloud APT41 2024

    Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024.

    Open source URL
  169. [169]
    Talos Olympic Destroyer 2018

    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

    Open source URL
  170. [170]
    NCC Group WastedLocker June 2020

    Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021.

    Open source URL
  171. [171]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  172. [172]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  173. [173]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.