LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1583.001: Domains

Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.

Adversaries may use acquired domains for a variety of purposes, including for Phishing, Drive-by Compromise, and Command and Control.[1] Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD).[2][3] Typosquatting may be used to aid in delivery of payloads via Drive-by Compromise. Adversaries may also use internationalized domain names (IDNs) and different character sets (e.g. Cyrillic, Greek, etc.) to execute "IDN homograph attacks," creating visually similar lookalike domains used to deliver malware to victim machines.[4][5][6][7][8]

Different URIs/URLs may also be dynamically generated to uniquely serve malicious content to victims (including one-time, single use domain names).[9][10][11][12]

Adversaries may also acquire and repurpose expired domains, which may be potentially already allowlisted/trusted by defenders based on an existing reputation/history.[13][14][15][16]

Domain registrars each maintain a publicly viewable database that displays contact information for every registered domain. Private WHOIS services display alternative information, such as their own company data, rather than the owner of the domain. Adversaries may use such private WHOIS services to obscure information about who owns a purchased domain. Adversaries may further interrupt efforts to track their infrastructure by using varied registration information and purchasing domains with different domain registrars.[17]

In addition to legitimately purchasing a domain, an adversary may register a new domain in a compromised environment. For example, in AWS environments, adversaries may leverage the Route53 domain service to register a domain and create hosted zones pointing to resources of the threat actor’s choosing.[18]

EnterpriseT1583.001Sub-techniqueObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Domain acquisition matters because it happens before the obvious intrusion. Adversaries can buy, obtain, or re-register domains to make phishing, drive-by compromise, and command-and-control infrastructure look believable or trusted. The business issue is not just “bad domains”; it is whether the organization can spot lookalike brands, expired trusted domains, suspicious new infrastructure, and unauthorized domain activity in cloud environments before users, partners, or controls trust them.

Executive priority

Treat this as a pre-compromise visibility and governance problem. Leaders should ask who owns domain risk across brand protection, DNS operations, cloud security, email/web filtering, and incident response. Priority should go to evidence that the organization monitors lookalike and expired domains, controls domain registration capability in cloud services such as AWS Route53, and can explain how domain intelligence influences phishing, web, and C2 investigations.

Technical view

ATT&CK places T1583.001 under Resource Development on the PRE platform, as a sub-technique of Acquire Infrastructure. MITRE provides no official detection text, but the related DET0892 detection strategy indicates domain-focused detection is relevant. SOC and detection teams should validate coverage for newly registered, re-registered, homoglyph/IDN, alternate-TLD, and dynamically generated URI/domain patterns, especially where they intersect with phishing, drive-by compromise, or command-and-control investigations. IR teams should also check cloud audit evidence for domain registration or hosted-zone creation in compromised environments, specifically the Route53 scenario described by MITRE.

Likely telemetry

  • Domain registrar and WHOIS registration records, including private WHOIS indicators where available
  • DNS resolution and passive DNS history for suspicious, re-registered, or lookalike domains
  • Email security telemetry containing URLs and domains used in phishing delivery
  • Web proxy or secure web gateway logs for user visits to suspicious domains and unique URLs
  • Cloud control-plane audit logs for AWS Route53 domain registration and hosted-zone creation

Detection direction

  • Validate DET0892-aligned domain detection against lookalike domains, homoglyphs, internationalized domain names, alternate TLDs, and typosquatting patterns.
  • Tune detections to account for legitimate brand, marketing, and third-party domain registrations to reduce false positives.
  • Review whether web and email controls over-trust domains based only on historical reputation, since MITRE notes expired or re-purposed domains may retain trusted status.
  • Correlate suspicious domain observations with phishing, drive-by compromise, and command-and-control cases rather than treating domain registration as a standalone signal.
  • In AWS environments, alert on unusual Route53 domain registration or hosted-zone activity, especially from identities or accounts that do not normally manage DNS.

Mitigation priorities

  • Implement pre-compromise controls consistent with M1056: reduce exposed and abusable domain-related attack surface and identify adversary preparation activity early.
  • Maintain governance over owned, expired, and business-critical domains so abandoned domains do not become trusted attacker infrastructure.
  • Restrict and monitor who can register domains or create hosted zones in cloud environments such as AWS Route53.
  • Use domain intelligence to inform email, web, and incident response workflows, with special attention to lookalike, IDN, homoglyph, and re-registered domains.
  • Periodically test whether allowlists and reputation-based controls can be bypassed by trusted-looking or previously reputable domains.
Additional notes and limits

This technique is widely connected in ATT&CK relationships to campaigns and groups, including CostaRicto, Operation Spalax, Operation Honeybee, FunnyDream, Operation Dream Job, Operation Ghost, SolarWinds Compromise, APT1, APT28, Lazarus Group, Sandworm Team, Dragonfly, and others. That relationship context supports the importance of domain acquisition as a common preparatory behavior, but it should not be read as evidence that any specific organization is currently targeted.

MITRE provides no official detection procedure for this object, and the related DET0892 strategy details were not supplied. Local conclusions require environment-specific evidence: registrar data access, DNS visibility, email/web logging, cloud audit coverage, allowlist practices, and knowledge of legitimate domain registration workflows.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Domains

Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.

Adversaries may use acquired domains for a variety of purposes, including for Phishing, Drive-by Compromise, and Command and Control.[1] Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD).[2][3] Typosquatting may be used to aid in delivery of payloads via Drive-by Compromise. Adversaries may also use internationalized domain names (IDNs) and different character sets (e.g. Cyrillic, Greek, etc.) to execute "IDN homograph attacks," creating visually similar lookalike domains used to deliver malware to victim machines.[4][5][6][7][8]

Different URIs/URLs may also be dynamically generated to uniquely serve malicious content to victims (including one-time, single use domain names).[9][10][11][12]

Adversaries may also acquire and repurpose expired domains, which may be potentially already allowlisted/trusted by defenders based on an existing reputation/history.[13][14][15][16]

Domain registrars each maintain a publicly viewable database that displays contact information for every registered domain. Private WHOIS services display alternative information, such as their own company data, rather than the owner of the domain. Adversaries may use such private WHOIS services to obscure information about who owns a purchased domain. Adversaries may further interrupt efforts to track their infrastructure by using varied registration information and purchasing domains with different domain registrars.[17]

In addition to legitimately purchasing a domain, an adversary may register a new domain in a compromised environment. For example, in AWS environments, adversaries may leverage the Route53 domain service to register a domain and create hosted zones pointing to resources of the threat actor’s choosing.[18]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1583Acquire InfrastructureThis object subtechnique of Acquire Infrastructure.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

GroupEnterprise

G0092: TA505

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.[1][2][3][4][5]

GroupEnterprise

G0099: APT-C-36

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

GroupEnterprise

G0069: MuddyWater

MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).[1] Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication. [2][3][4][5][6][7][8][9][10][11][12][13]

GroupEnterprise

G1001: HEXANE

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.[1][2][3][4]

GroupEnterprise

G1055: VOID MANTICORE

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).[1] Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.[1][2] VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.[1][3] VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.[4]

GroupEnterprise

G1033: Star Blizzard

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.[1][2][3][4]

GroupEnterprise

G1044: APT42

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.[1] The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.[1] APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices.[1] Finally, APT42 exfiltrates data using native features and open-source tools.[2]

APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.

GroupEnterprise

G0006: APT1

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. [1]

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

MalwareEnterprise

S1130: Raspberry Robin

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.[1][2][3] The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."[4] The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.[5]

Windows
MalwareEnterprise

S1111: DarkGate

DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named "DarkGate" by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions.[1] DarkGate use increased significantly starting in 2022 and is under active development by its author, who provides it as a Malware-as-a-Service offering.[2]

Windows
MalwareEnterprise

S1207: XLoader

XLoader is an infostealer malware in use since at least 2016. Previously known and sometimes still referred to as Formbook, XLoader is a Malware as a Service (MaaS) known for stealing data from web browsers, email clients and File Transfer Protocol (FTP) applications.[1][2][3][4][5]

Windows
CampaignEnterprise

C0021: C0021

C0021 was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private-sector corporations in the oil and gas, chemical, and hospitality industries. The majority of targets were located in the US, particularly in and around Washington D.C., with other targets located in Europe, Hong Kong, India, and Canada. C0021's technical artifacts, tactics, techniques, and procedures (TTPs), and targeting overlap with previous suspected APT29 activity.[1][2]

CampaignEnterprise

C0005: Operation Spalax

Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical industries. The Operation Spalax threat actors distributed commodity malware and tools using generic phishing topics related to COVID-19, banking, and law enforcement action. Security researchers noted indicators of compromise and some infrastructure overlaps with other campaigns dating back to April 2018, including at least one separately attributed to APT-C-36, however identified enough differences to report this as separate, unattributed activity.[1]

CampaignEnterprise

C0043: Indian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions is a sequence of intrusions from 2021 through early 2022 linked to People’s Republic of China (PRC) threat actors, particularly RedEcho and Threat Activity Group 38 (TAG38). The intrusions appear focused on IT system breach in Indian electric utility entities and logistics firms, as well as potentially managed service providers operating within India. Although focused on OT-operating entities, there is no evidence this campaign was able to progress beyond IT breach and information gathering to OT environment access.[1][2]

CampaignEnterprise

C0058: SharePoint ToolShell Exploitation

The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and remote code execution (CVE-2025-49704) vulnerabilities affecting on-premises Microsoft SharePoint servers. Later patched and updated as CVE-2025-53770 and CVE-2025-53771, the ToolShell vulnerabilities were widely exploited including by China-based ransomware actor Storm-2603 and espionage actors Threat Group-3390 and ZIRCONIUM. SharePoint ToolShell Exploitation targeted multiple regions and industries including finance, education, energy, and healthcare across Asia, Europe, and the United States.[1][2][3][4][5]

CampaignEnterprise

C0006: Operation Honeybee

Operation Honeybee was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. Operation Honeybee initially targeted South Korea, but expanded to include Vietnam, Singapore, Japan, Indonesia, Argentina, and Canada. Security researchers assessed the threat actors were likely Korean speakers based on metadata used in both lure documents and executables, and named the campaign "Honeybee" after the author name discovered in malicious Word documents.[1]

CampaignEnterprise

C0016: Operation Dust Storm

Operation Dust Storm was a long-standing persistent cyber espionage campaign that targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast Asian countries. By 2015, the Operation Dust Storm threat actors shifted from government and defense-related intelligence targets to Japanese companies or Japanese subdivisions of larger foreign organizations supporting Japan's critical infrastructure, including electricity generation, oil and natural gas, finance, transportation, and construction.[1]

Operation Dust Storm threat actors also began to use Android backdoors in their operations by 2015, with all identified victims at the time residing in Japan or South Korea.[1]

CampaignEnterprise

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

CampaignEnterprise

C0023: Operation Ghost

Operation Ghost was an APT29 campaign starting in 2013 that included operations against ministries of foreign affairs in Europe and the Washington, D.C. embassy of a European Union country. During Operation Ghost, APT29 used new families of malware and leveraged web services, steganography, and unique C2 infrastructure for each victim.[1]

CampaignEnterprise

C0004: CostaRicto

CostaRicto was a suspected hacker-for-hire cyber espionage campaign that targeted multiple industries worldwide, with a large number being financial institutions. CostaRicto actors targeted organizations in Europe, the Americas, Asia, Australia, and Africa, with a large concentration in South Asia (especially India, Bangladesh, and Singapore), using custom malware, open source tools, and a complex network of proxies and SSH tunnels.[1]

CampaignEnterprise

C0010: C0010

C0010 was a cyber espionage campaign conducted by UNC3890 that targeted Israeli shipping, government, aviation, energy, and healthcare organizations. Security researcher assess UNC3890 conducts operations in support of Iranian interests, and noted several limited technical connections to Iran, including PDB strings and Farsi language artifacts. C0010 began by at least late 2020, and was still ongoing as of mid-2022.[1]

CampaignEnterprise

C0011: C0011

C0011 was a suspected cyber espionage campaign conducted by Transparent Tribe that targeted students at universities and colleges in India. Security researchers noted this campaign against students was a significant shift from Transparent Tribe's historic targeting Indian government, military, and think tank personnel, and assessed it was still ongoing as of July 2022.[1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.4
Created
Modified
Raw hash
08147cd7643aa24f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.4Current bundle08147cd7643a…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CISA MSS Sep 2020

    CISA. (2020, September 14). Alert (AA20-258A): Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity. Retrieved October 1, 2020.

    Open source URL
  2. [2]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  3. [3]
    PaypalScam

    Bob Sullivan. (2000, July 24). PayPal alert! Beware the 'PaypaI' scam. Retrieved March 2, 2017.

    Open source URL
  4. [4]
    CISA IDN ST05-016

    CISA. (2019, September 27). Security Tip (ST05-016): Understanding Internationalized Domain Names. Retrieved October 20, 2020.

    Open source URL
  5. [5]
    tt_httrack_fake_domains

    Malhotra, A., Thattil, J. et al. (2022, March 29). Transparent Tribe campaign uses new bespoke malware to target Indian government officials . Retrieved September 6, 2022.

    Open source URL
  6. [6]
    tt_obliqueRAT

    Malhotra, A., McKay, K. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal . Retrieved July 29, 2022.

    Open source URL
  7. [7]
    httrack_unhcr

    RISKIQ. (2022, March 15). RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure. Retrieved July 29, 2022.

    Open source URL
  8. [8]
    lazgroup_idn_phishing

    RISKIQ. (2017, December 20). Mining Insights: Infrastructure Analysis of Lazarus Group Cyber Attacks on the Cryptocurrency Industry. Retrieved July 29, 2022.

    Open source URL
  9. [9]
    iOS URL Scheme

    Ostorlab. (n.d.). iOS URL Scheme Hijacking. Retrieved February 9, 2024.

    Open source URL
  10. [10]
    URI

    Michael Cobb. (2007, October 11). Preparing for uniform resource identifier (URI) exploits. Retrieved February 9, 2024.

    Open source URL
  11. [11]
    URI Use

    Nathan McFeters. Billy Kim Rios. Rob Carter.. (2008). URI Use and Abuse. Retrieved February 9, 2024.

    Open source URL
  12. [12]
    URI Unique

    Australian Cyber Security Centre. National Security Agency. (2020, April 21). Detect and Prevent Web Shell Malware. Retrieved February 9, 2024.

    Open source URL
  13. [13]
    Categorisation_not_boundary

    MDSec Research. (2017, July). Categorisation is not a Security Boundary. Retrieved September 20, 2019.

    Open source URL
  14. [14]
    Domain_Steal_CC

    Krebs, B. (2018, November 13). That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards. Retrieved September 20, 2019.

    Open source URL
  15. [15]
    Redirectors_Domain_Fronting

    Mudge, R. (2017, February 6). High-reputation Redirectors and Domain Fronting. Retrieved July 11, 2022.

    Open source URL
  16. [16]
    bypass_webproxy_filtering

    Fehrman, B. (2017, April 13). How to Bypass Web-Proxy Filtering. Retrieved September 20, 2019.

    Open source URL
  17. [17]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  18. [18]
    Invictus IR DangerDev 2024

    Invictus Incident Response. (2024, January 31). The curious case of DangerDev@protonmail.me. Retrieved March 19, 2024.

    Open source URL
  19. [19]
    FireEye APT29 Nov 2018

    Dunwoody, M., et al. (2018, November 19). Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign. Retrieved November 27, 2018.

    Open source URL
  20. [20]
    US District Court Indictment GRU Oct 2018

    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

    Open source URL
  21. [21]
    Google TAG Ukraine Threat Landscape March 2022

    Huntley, S. (2022, March 7). An update on the threat landscape. Retrieved March 16, 2022.

    Open source URL
  22. [22]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  23. [23]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  24. [24]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  25. [25]
    LevelBlue Blind Eagle Proton66 JUN 2025

    Melnyk, S. (2025, June 27). Tracing Blind Eagle to Proton66. Retrieved April 16, 2026.

    Open source URL
  26. [26]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  27. [27]
    Zscaler BlindEagle DEC 2025

    Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

    Open source URL
  28. [28]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  29. [29]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  30. [30]
    NaumaanProofpoint_GlobalClickFix_April2025

    Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.

    Open source URL
  31. [31]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  32. [32]
    Dragos Hexane

    Dragos. (n.d.). Hexane. Retrieved October 27, 2019.

    Open source URL
  33. [33]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  34. [34]
    SPECOPS Outpost24 Handala Hack Stryker March 2026

    David Ketler. (2026, March 30). Stryker Cyber-Attack: What we Know so Far About the Remote Wipe Attack. Retrieved April 20, 2026.

    Open source URL
  35. [35]
    DOJ FBI Handala Hack March 2026

    DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.

    Open source URL
  36. [36]
    FBI IC3 Flash VOID MANTICORE Handala Hack March 2026

    FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. Retrieved April 20, 2026.

    Open source URL
  37. [37]
    Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026

    DomainTools Investigations. (2026, April 6). Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment. Retrieved April 20, 2026.

    Open source URL
  38. [38]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  39. [39]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  40. [40]
    RecordedFuture RedEcho 2021

    Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.

    Open source URL
  41. [41]
    Mandiant APT42-charms

    Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.

    Open source URL
  42. [42]
    TAG APT42

    Google Threat Analysis Group. (2024, August 14). Iranian backed group steps up phishing campaigns against Israel, U.S.. Retrieved October 9, 2024.

    Open source URL
  43. [43]
    Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.

    Open source URL
  44. [44]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  45. [45]
    PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024

    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.

    Open source URL
  46. [46]
    Sentinel One Contagious Interview ClickFix September 2025

    Aleksandar Milenkoski, Sreekar Madabushi, Kenneth Kinion. (2025, September 4). Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms. Retrieved October 20, 2025.

    Open source URL
  47. [47]
    Sekoia ClickFake 2025

    Amaury G., Coline Chavane, Felix Aimé and Sekoia TDR. (2025, March 31). From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic. Retrieved April 1, 2025.

    Open source URL
  48. [48]
    Validin Contagious Interview North Korea ClickFix January 2025

    Efstratios Lontzetidis. (2025, January 16). Lazarus APT: Techniques for Hunting Contagious Interview. Retrieved October 20, 2025.

    Open source URL
  49. [49]
    Socket Contagious Interview NPM April 2025

    Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.

    Open source URL
  50. [50]
    Socket BeaverTail XORIndex HexEval Contagious Interview July 2025

    Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.

    Open source URL
  51. [51]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  52. [52]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  53. [53]
    Palo Alto SharePoint Vulnerabilities JUL 2025

    Unit 42. (2025, July 31). Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated). Retrieved October 15, 2025.

    Open source URL
  54. [54]
    McAfee Honeybee

    Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

    Open source URL
  55. [55]
    Volexity Ocean Lotus November 2020

    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

    Open source URL
  56. [56]
    Checkpoint IndigoZebra July 2021

    CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.

    Open source URL
  57. [57]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  58. [58]
    CISA AA21-200A APT40 July 2021

    CISA. (2021, July 19). (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department. Retrieved August 12, 2021.

    Open source URL
  59. [59]
    Accenture MUDCARP March 2019

    Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.

    Open source URL
  60. [60]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  61. [61]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  62. [62]
    ThreatConnect Kimsuky September 2020

    ThreatConnect. (2020, September 28). Kimsuky Phishing Operations Putting In Work. Retrieved October 30, 2020.

    Open source URL
  63. [63]
    Zdnet Kimsuky Group September 2020

    Cimpanu, C. (2020, September 30). North Korea has tried to hack 11 officials of the UN Security Council. Retrieved November 4, 2020.

    Open source URL
  64. [64]
    CISA AA20-301A Kimsuky

    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

    Open source URL
  65. [65]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  66. [66]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  67. [67]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  68. [68]
    Mandiant APT43 March 2024

    Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024.

    Open source URL
  69. [69]
    Check Point Scattered Spider JUL 2025

    Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.

    Open source URL
  70. [70]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  71. [71]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  72. [72]
    Cisco Operation Layover September 2021

    Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.

    Open source URL
  73. [73]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  74. [74]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  75. [75]
    Talos Transparent Tribe May 2021

    Malhotra, A. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal. Retrieved September 2, 2021.

    Open source URL
  76. [76]
    Microsoft Targeting Elections September 2020

    Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.

    Open source URL
  77. [77]
    RedCanary RaspberryRobin 2022

    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

    Open source URL
  78. [78]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  79. [79]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  80. [80]
    Palo Alto Ashen Lepus DEC 2025

    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

    Open source URL
  81. [81]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  82. [82]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  83. [83]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  84. [84]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  85. [85]
    ClearSky OilRig Jan 2017

    ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.

  86. [86]
    Secureworks BRONZE PRESIDENT December 2019

    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

    Open source URL
  87. [87]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  88. [88]
    Lab52 MUSTANG PANDA PUBLOAD MAY 2023

    Dex. (n.d.). New Mustang Panda’s campaing against Australia. Retrieved August 4, 2025.

    Open source URL
  89. [89]
    Recorded Future REDDELTA July 2020

    Insikt Group. (2020, July 28). CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS. Retrieved April 13, 2021.

    Open source URL
  90. [90]
    Trend Micro Mustang Panda Earth Preta Toneshell February 2025

    Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.

    Open source URL
  91. [91]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  92. [92]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  93. [93]
    Palo Alto Networks, Unit 42

    Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.

    Open source URL
  94. [94]
    McAfee Dianxun March 2021

    Roccia, T., Seret, T., Fokker, J. (2021, March 16). Technical Analysis of Operation Dianxun. Retrieved April 13, 2021.

    Open source URL
  95. [95]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  96. [96]
    CISA AppleJeus Feb 2021

    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

    Open source URL
  97. [97]
    Google TAG Lazarus Jan 2021

    Weidemann, A. (2021, January 25). New campaign targeting security researchers. Retrieved December 20, 2021.

    Open source URL
  98. [98]
    Google EXOTIC LILY March 2022

    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

    Open source URL
  99. [99]
    DOJ Iran Indictments March 2018

    DOJ. (2018, March 23). U.S. v. Rafatnejad et al . Retrieved February 3, 2021.

    Open source URL
  100. [100]
    Phish Labs Silent Librarian

    Hassold, Crane. (2018, March 26). Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment. Retrieved February 3, 2021.

    Open source URL
  101. [101]
    Secureworks COBALT DICKENS August 2018

    Counter Threat Unit Research Team. (2018, August 24). Back to School: COBALT DICKENS Targets Universities. Retrieved February 3, 2021.

    Open source URL
  102. [102]
    Proofpoint TA407 September 2019

    Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021.

    Open source URL
  103. [103]
    Secureworks COBALT DICKENS September 2019

    Counter Threat Unit Research Team. (2019, September 11). COBALT DICKENS Goes Back to School…Again. Retrieved February 3, 2021.

    Open source URL
  104. [104]
    Malwarebytes Silent Librarian October 2020

    Malwarebytes Threat Intelligence Team. (2020, October 14). Silent Librarian APT right on schedule for 20/21 academic year. Retrieved February 3, 2021.

    Open source URL
  105. [105]
    eSentire FIN7 July 2021

    eSentire. (2021, July 21). Notorious Cybercrime Gang, FIN7, Lands Malware in Law Firm Using Fake Legal Complaint Against Jack Daniels’ Owner, Brown-Forman Inc.. Retrieved September 20, 2021.

    Open source URL
  106. [106]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  107. [107]
    Cisco Talos Transparent Tribe Education Campaign July 2022

    N. Baisini. (2022, July 13). Transparent Tribe begins targeting education sector in latest campaign. Retrieved September 22, 2022.

    Open source URL
  108. [108]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  109. [109]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  110. [110]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  111. [111]
    Certfa Charming Kitten January 2021

    Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021.

    Open source URL
  112. [112]
    1 - appv

    SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.

    Open source URL
  113. [113]
    CheckPoint XLoader 2022

    Alexey Bukhteyev & Raman Ladutska, Check Point Research. (2022, May 31). XLoader Botnet: Find Me If You Can. Retrieved March 11, 2025.

    Open source URL
  114. [114]
    Microsoft Actinium February 2022

    Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.

    Open source URL
  115. [115]
    Unit 42 Gamaredon February 2022

    Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

    Open source URL
  116. [116]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
  117. [117]
    SymantecCarbonBlack_ShuckwormUSB_Apr2025

    Threat Hunter Team, Symantec and Carbon Black. (2025, April 10). Shuckworm Targets Foreign Military Mission Based in Ukraine. Retrieved July 23, 2025.

    Open source URL
  118. [118]
    DomainTools WinterVivern 2021

    Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.

    Open source URL
  119. [119]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  120. [120]
    Forcepoint BITTER Pakistan Oct 2016

    Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.

    Open source URL
  121. [121]
    Palo Alto Black-T October 2020

    Quist, N. (2020, October 5). Black-T: New Cryptojacking Variant from TeamTNT. Retrieved September 22, 2021.

    Open source URL
  122. [122]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  123. [123]
    Slowik Sandworm 2021

    Joseph Slowik, DomainTools. (2021, March 3). Centreon to Exim and Back: On the Trail of Sandworm. Retrieved April 6, 2024.

    Open source URL
  124. [124]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  125. [125]
    Kaspersky Winnti April 2013

    Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.

    Open source URL
  126. [126]
    Kaspersky Ferocious Kitten Jun 2021

    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

    Open source URL
  127. [127]
    PWC Yellow Liderc 2023

    PwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved August 14, 2024.

    Open source URL
  128. [128]
    MSTIC NOBELIUM Mar 2021

    Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.

    Open source URL
  129. [129]
    FireEye SUNSHUTTLE Mar 2021

    Smith, L., Leathery, J., Read, B. (2021, March 4). New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452. Retrieved March 12, 2021.

    Open source URL
  130. [130]
    DOJ APT10 Dec 2018

    United States District Court Southern District of New York (USDC SDNY) . (2018, December 17). United States of America v. Zhu Hua and Zhang Shilong. Retrieved April 17, 2019.

    Open source URL
  131. [131]
    District Court of NY APT10 Indictment December 2018

    US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020.

    Open source URL
  132. [132]
    CISA IDN ST05-016

    CISA. (2019, September 27). Security Tip (ST05-016): Understanding Internationalized Domain Names. Retrieved October 20, 2020.

    Open source URL
  133. [133]
    CISA IDN ST05-016

    CISA. (2019, September 27). Security Tip (ST05-016): Understanding Internationalized Domain Names. Retrieved October 20, 2020.

    Open source URL
  134. [134]
    CISA MSS Sep 2020

    CISA. (2020, September 14). Alert (AA20-258A): Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity. Retrieved October 1, 2020.

    Open source URL
  135. [135]
    CISA MSS Sep 2020

    CISA. (2020, September 14). Alert (AA20-258A): Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity. Retrieved October 1, 2020.

    Open source URL
  136. [136]
    Categorisation_not_boundary

    MDSec Research. (2017, July). Categorisation is not a Security Boundary. Retrieved September 20, 2019.

    Open source URL
  137. [137]
    Categorisation_not_boundary

    MDSec Research. (2017, July). Categorisation is not a Security Boundary. Retrieved September 20, 2019.

    Open source URL
  138. [138]
    Domain_Steal_CC

    Krebs, B. (2018, November 13). That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards. Retrieved September 20, 2019.

    Open source URL
  139. [139]
    Domain_Steal_CC

    Krebs, B. (2018, November 13). That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards. Retrieved September 20, 2019.

    Open source URL
  140. [140]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  141. [141]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  142. [142]
    Invictus IR DangerDev 2024

    Invictus Incident Response. (2024, January 31). The curious case of DangerDev@protonmail.me. Retrieved March 19, 2024.

    Open source URL
  143. [143]
    Invictus IR DangerDev 2024

    Invictus Incident Response. (2024, January 31). The curious case of DangerDev@protonmail.me. Retrieved March 19, 2024.

    Open source URL
  144. [144]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  145. [145]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  146. [146]
    PaypalScam

    Bob Sullivan. (2000, July 24). PayPal alert! Beware the 'PaypaI' scam. Retrieved March 2, 2017.

    Open source URL
  147. [147]
    PaypalScam

    Bob Sullivan. (2000, July 24). PayPal alert! Beware the 'PaypaI' scam. Retrieved March 2, 2017.

    Open source URL
  148. [148]
    Redirectors_Domain_Fronting

    Mudge, R. (2017, February 6). High-reputation Redirectors and Domain Fronting. Retrieved July 11, 2022.

    Open source URL
  149. [149]
    Redirectors_Domain_Fronting

    Mudge, R. (2017, February 6). High-reputation Redirectors and Domain Fronting. Retrieved July 11, 2022.

    Open source URL
  150. [150]
    ThreatConnect Infrastructure Dec 2020

    ThreatConnect. (2020, December 15). Infrastructure Research and Hunting: Boiling the Domain Ocean. Retrieved October 12, 2021.

    Open source URL
  151. [151]
    ThreatConnect Infrastructure Dec 2020

    ThreatConnect. (2020, December 15). Infrastructure Research and Hunting: Boiling the Domain Ocean. Retrieved October 12, 2021.

    Open source URL
  152. [152]
    ThreatConnect Infrastructure Dec 2020

    ThreatConnect. (2020, December 15). Infrastructure Research and Hunting: Boiling the Domain Ocean. Retrieved October 12, 2021.

    Open source URL
  153. [153]
    URI

    Michael Cobb. (2007, October 11). Preparing for uniform resource identifier (URI) exploits. Retrieved February 9, 2024.

    Open source URL
  154. [154]
    URI

    Michael Cobb. (2007, October 11). Preparing for uniform resource identifier (URI) exploits. Retrieved February 9, 2024.

    Open source URL
  155. [155]
    URI Unique

    Australian Cyber Security Centre. National Security Agency. (2020, April 21). Detect and Prevent Web Shell Malware. Retrieved February 9, 2024.

    Open source URL
  156. [156]
    URI Unique

    Australian Cyber Security Centre. National Security Agency. (2020, April 21). Detect and Prevent Web Shell Malware. Retrieved February 9, 2024.

    Open source URL
  157. [157]
    URI Use

    Nathan McFeters. Billy Kim Rios. Rob Carter.. (2008). URI Use and Abuse. Retrieved February 9, 2024.

    Open source URL
  158. [158]
    URI Use

    Nathan McFeters. Billy Kim Rios. Rob Carter.. (2008). URI Use and Abuse. Retrieved February 9, 2024.

    Open source URL
  159. [159]
    bypass_webproxy_filtering

    Fehrman, B. (2017, April 13). How to Bypass Web-Proxy Filtering. Retrieved September 20, 2019.

    Open source URL
  160. [160]
    bypass_webproxy_filtering

    Fehrman, B. (2017, April 13). How to Bypass Web-Proxy Filtering. Retrieved September 20, 2019.

    Open source URL
  161. [161]
    httrack_unhcr

    RISKIQ. (2022, March 15). RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure. Retrieved July 29, 2022.

    Open source URL
  162. [162]
    httrack_unhcr

    RISKIQ. (2022, March 15). RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure. Retrieved July 29, 2022.

    Open source URL
  163. [163]
    iOS URL Scheme

    Ostorlab. (n.d.). iOS URL Scheme Hijacking. Retrieved February 9, 2024.

    Open source URL
  164. [164]
    iOS URL Scheme

    Ostorlab. (n.d.). iOS URL Scheme Hijacking. Retrieved February 9, 2024.

    Open source URL
  165. [165]
    lazgroup_idn_phishing

    RISKIQ. (2017, December 20). Mining Insights: Infrastructure Analysis of Lazarus Group Cyber Attacks on the Cryptocurrency Industry. Retrieved July 29, 2022.

    Open source URL
  166. [166]
    lazgroup_idn_phishing

    RISKIQ. (2017, December 20). Mining Insights: Infrastructure Analysis of Lazarus Group Cyber Attacks on the Cryptocurrency Industry. Retrieved July 29, 2022.

    Open source URL
  167. [167]
    mitre-attackT1583.001
    Open source URL
  168. [168]
    mitre-attackT1583.001
    Open source URL
  169. [169]
    mitre-attackT1583.001
    Open source URL
  170. [170]
    tt_httrack_fake_domains

    Malhotra, A., Thattil, J. et al. (2022, March 29). Transparent Tribe campaign uses new bespoke malware to target Indian government officials . Retrieved September 6, 2022.

    Open source URL
  171. [171]
    tt_httrack_fake_domains

    Malhotra, A., Thattil, J. et al. (2022, March 29). Transparent Tribe campaign uses new bespoke malware to target Indian government officials . Retrieved September 6, 2022.

    Open source URL
  172. [172]
    tt_obliqueRAT

    Malhotra, A., McKay, K. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal . Retrieved July 29, 2022.

    Open source URL
  173. [173]
    tt_obliqueRAT

    Malhotra, A., McKay, K. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal . Retrieved July 29, 2022.

    Open source URL
  174. [174]
    FireEye APT29 Nov 2018

    Dunwoody, M., et al. (2018, November 19). Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign. Retrieved November 27, 2018.

    Open source URL
  175. [175]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  176. [176]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  177. [177]
    Google TAG Ukraine Threat Landscape March 2022

    Huntley, S. (2022, March 7). An update on the threat landscape. Retrieved March 16, 2022.

    Open source URL
  178. [178]
    US District Court Indictment GRU Oct 2018

    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

    Open source URL
  179. [179]
    Korean FSI TA505 2020

    Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.

    Open source URL
  180. [180]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  181. [181]
    Kaspersky BlindEagle AUG 2024

    Global Research & Analysis Team, Kaspersky. (2024, August 19). BlindEagle flying high in Latin America. Retrieved April 16, 2026.

    Open source URL
  182. [182]
    LevelBlue Blind Eagle Proton66 JUN 2025

    Melnyk, S. (2025, June 27). Tracing Blind Eagle to Proton66. Retrieved April 16, 2026.

    Open source URL
  183. [183]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  184. [184]
    Zscaler BlindEagle DEC 2025

    Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

    Open source URL
  185. [185]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  186. [186]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  187. [187]
    NaumaanProofpoint_GlobalClickFix_April2025

    Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.

    Open source URL
  188. [188]
    ClearSky Siamesekitten August 2021

    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

    Open source URL
  189. [189]
    Dragos Hexane

    Dragos. (n.d.). Hexane. Retrieved October 27, 2019.

    Open source URL
  190. [190]
    SecureWorks August 2019

    SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

    Open source URL
  191. [191]
    DOJ FBI Handala Hack March 2026

    DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved April 20, 2026.

    Open source URL
  192. [192]
    Domain Tools Handala Hack Karma Homeland Justice MOIS April 2026

    DomainTools Investigations. (2026, April 6). Handala: MOIS Linked Cyber Influence Ecosystem Threat Intelligence Assessment. Retrieved April 20, 2026.

    Open source URL
  193. [193]
    FBI IC3 Flash VOID MANTICORE Handala Hack March 2026

    FBI. (2026, March 20). FBI Flash: FLASH-20260320-001:Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targets. Retrieved April 20, 2026.

    Open source URL
  194. [194]
    SPECOPS Outpost24 Handala Hack Stryker March 2026

    David Ketler. (2026, March 30). Stryker Cyber-Attack: What we Know so Far About the Remote Wipe Attack. Retrieved April 20, 2026.

    Open source URL
  195. [195]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  196. [196]
    StarBlizzard

    Microsoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.

    Open source URL
  197. [197]
    RecordedFuture RedEcho 2021

    Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.

    Open source URL
  198. [198]
    Mandiant APT42-charms

    Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.

    Open source URL
  199. [199]
    TAG APT42

    Google Threat Analysis Group. (2024, August 14). Iranian backed group steps up phishing campaigns against Israel, U.S.. Retrieved October 9, 2024.

    Open source URL
  200. [200]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  201. [201]
    PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024

    Unit42. (2024, October 9). Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware. Retrieved October 17, 2025.

    Open source URL
  202. [202]
    Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025

    Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.

    Open source URL
  203. [203]
    Sekoia ClickFake 2025

    Amaury G., Coline Chavane, Felix Aimé and Sekoia TDR. (2025, March 31). From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic. Retrieved April 1, 2025.

    Open source URL
  204. [204]
    Sentinel One Contagious Interview ClickFix September 2025

    Aleksandar Milenkoski, Sreekar Madabushi, Kenneth Kinion. (2025, September 4). Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms. Retrieved October 20, 2025.

    Open source URL
  205. [205]
    Socket BeaverTail XORIndex HexEval Contagious Interview July 2025

    Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.

    Open source URL
  206. [206]
    Socket Contagious Interview NPM April 2025

    Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.

    Open source URL
  207. [207]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  208. [208]
    Validin Contagious Interview North Korea ClickFix January 2025

    Efstratios Lontzetidis. (2025, January 16). Lazarus APT: Techniques for Hunting Contagious Interview. Retrieved October 20, 2025.

    Open source URL
  209. [209]
    Microsoft SharePoint Exploit JUL 2025

    Microsoft Threat Intelligence. (2025, July 22). Disrupting active exploitation of on-premises SharePoint vulnerabilities. Retrieved October 15, 2025.

    Open source URL
  210. [210]
    Palo Alto SharePoint Vulnerabilities JUL 2025

    Unit 42. (2025, July 31). Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated). Retrieved October 15, 2025.

    Open source URL
  211. [211]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  212. [212]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  213. [213]
    McAfee Honeybee

    Sherstobitoff, R. (2018, March 02). McAfee Uncovers Operation Honeybee, a Malicious Document Campaign Targeting Humanitarian Aid Groups. Retrieved May 16, 2018.

    Open source URL
  214. [214]
    Volexity Ocean Lotus November 2020

    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

    Open source URL
  215. [215]
    Checkpoint IndigoZebra July 2021

    CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021.

    Open source URL
  216. [216]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  217. [217]
    Accenture MUDCARP March 2019

    Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.

    Open source URL
  218. [218]
    CISA AA21-200A APT40 July 2021

    CISA. (2021, July 19). (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department. Retrieved August 12, 2021.

    Open source URL
  219. [219]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  220. [220]
    TrendMicro EarthLusca 2022

    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

    Open source URL
  221. [221]
    CISA AA20-301A Kimsuky

    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

    Open source URL
  222. [222]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  223. [223]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  224. [224]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  225. [225]
    Mandiant APT43 March 2024

    Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024.

    Open source URL
  226. [226]
    ThreatConnect Kimsuky September 2020

    ThreatConnect. (2020, September 28). Kimsuky Phishing Operations Putting In Work. Retrieved October 30, 2020.

    Open source URL
  227. [227]
    Zdnet Kimsuky Group September 2020

    Cimpanu, C. (2020, September 30). North Korea has tried to hack 11 officials of the UN Security Council. Retrieved November 4, 2020.

    Open source URL
  228. [228]
    Check Point Scattered Spider JUL 2025

    Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025.

    Open source URL
  229. [229]
    CISA AA20-296A Berserk Bear December 2020

    CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.

    Open source URL
  230. [230]
    Cisco Operation Layover September 2021

    Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.

    Open source URL
  231. [231]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  232. [232]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  233. [233]
    Proofpoint Operation Transparent Tribe March 2016

    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

    Open source URL
  234. [234]
    Talos Transparent Tribe May 2021

    Malhotra, A. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal. Retrieved September 2, 2021.

    Open source URL
  235. [235]
    Microsoft Targeting Elections September 2020

    Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.

    Open source URL
  236. [236]
    RedCanary RaspberryRobin 2022

    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

    Open source URL
  237. [237]
    ESET Dukes October 2019

    Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020.

    Open source URL
  238. [238]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  239. [239]
    Palo Alto Ashen Lepus DEC 2025

    Unit 42. (2025, December 11). Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite. Retrieved April 20, 2026.

    Open source URL
  240. [240]
    Lunghi Iron Tiger Linux

    Daniel Lunghi. (2023, March 1). Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting. Retrieved March 20, 2023.

    Open source URL
  241. [241]
    Trellix Darkgate 2023

    Ernesto Fernández Provecho, Pham Duy Phuc, Ciana Driscoll & Vinoo Thomas. (2023, November 21). The Continued Evolution of the DarkGate Malware-as-a-Service. Retrieved February 9, 2024.

    Open source URL
  242. [242]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  243. [243]
    BlackBerry CostaRicto November 2020

    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

    Open source URL
  244. [244]
    RecordedFuture RedEcho 2021

    Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.

    Open source URL
  245. [245]
    RecordedFuture RedEcho 2021

    Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.

    Open source URL
  246. [246]
    ClearSky OilRig Jan 2017

    ClearSky Cybersecurity. (2017, January 5). Iranian Threat Agent OilRig Delivers Digitally Signed Malware, Impersonates University of Oxford. Retrieved May 3, 2017.

  247. [247]
    CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024

    CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.

    Open source URL
  248. [248]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  249. [249]
    Lab52 MUSTANG PANDA PUBLOAD MAY 2023

    Dex. (n.d.). New Mustang Panda’s campaing against Australia. Retrieved August 4, 2025.

    Open source URL
  250. [250]
    McAfee Dianxun March 2021

    Roccia, T., Seret, T., Fokker, J. (2021, March 16). Technical Analysis of Operation Dianxun. Retrieved April 13, 2021.

    Open source URL
  251. [251]
    Palo Alto Networks, Unit 42

    Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.

    Open source URL
  252. [252]
    Recorded Future REDDELTA July 2020

    Insikt Group. (2020, July 28). CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS. Retrieved April 13, 2021.

    Open source URL
  253. [253]
    Secureworks BRONZE PRESIDENT December 2019

    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

    Open source URL
  254. [254]
    Trend Micro Mustang Panda Earth Preta Toneshell February 2025

    Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.

    Open source URL
  255. [255]
    Unit42 Bookworm Nov2015

    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

    Open source URL
  256. [256]
    Mandiant UNC3890 Aug 2022

    Mandiant Israel Research Team. (2022, August 17). Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors. Retrieved September 21, 2022.

    Open source URL
  257. [257]
    CISA AppleJeus Feb 2021

    Cybersecurity and Infrastructure Security Agency. (2021, February 21). AppleJeus: Analysis of North Korea’s Cryptocurrency Malware. Retrieved March 1, 2021.

    Open source URL
  258. [258]
    Google TAG Lazarus Jan 2021

    Weidemann, A. (2021, January 25). New campaign targeting security researchers. Retrieved December 20, 2021.

    Open source URL
  259. [259]
    Google EXOTIC LILY March 2022

    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

    Open source URL
  260. [260]
    DOJ Iran Indictments March 2018

    DOJ. (2018, March 23). U.S. v. Rafatnejad et al . Retrieved February 3, 2021.

    Open source URL
  261. [261]
    Malwarebytes Silent Librarian October 2020

    Malwarebytes Threat Intelligence Team. (2020, October 14). Silent Librarian APT right on schedule for 20/21 academic year. Retrieved February 3, 2021.

    Open source URL
  262. [262]
    Phish Labs Silent Librarian

    Hassold, Crane. (2018, March 26). Silent Librarian: More to the Story of the Iranian Mabna Institute Indictment. Retrieved February 3, 2021.

    Open source URL
  263. [263]
    Proofpoint TA407 September 2019

    Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021.

    Open source URL
  264. [264]
    Secureworks COBALT DICKENS August 2018

    Counter Threat Unit Research Team. (2018, August 24). Back to School: COBALT DICKENS Targets Universities. Retrieved February 3, 2021.

    Open source URL
  265. [265]
    Secureworks COBALT DICKENS September 2019

    Counter Threat Unit Research Team. (2019, September 11). COBALT DICKENS Goes Back to School…Again. Retrieved February 3, 2021.

    Open source URL
  266. [266]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  267. [267]
    eSentire FIN7 July 2021

    eSentire. (2021, July 21). Notorious Cybercrime Gang, FIN7, Lands Malware in Law Firm Using Fake Legal Complaint Against Jack Daniels’ Owner, Brown-Forman Inc.. Retrieved September 20, 2021.

    Open source URL
  268. [268]
    Cisco Talos Transparent Tribe Education Campaign July 2022

    N. Baisini. (2022, July 13). Transparent Tribe begins targeting education sector in latest campaign. Retrieved September 22, 2022.

    Open source URL
  269. [269]
    Bitdefender FunnyDream Campaign November 2020

    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

    Open source URL
  270. [270]
    Hunt Sea Turtle 2024

    Hunt & Hackett Research Team. (2024, January 5). Turkish espionage campaigns in the Netherlands. Retrieved November 20, 2024.

    Open source URL
  271. [271]
    Talos Sea Turtle 2019_2

    Paul Rascagneres. (2019, July 9). Sea Turtle keeps on swimming, finds new victims, DNS hijacking techniques. Retrieved November 20, 2024.

    Open source URL
  272. [272]
    Certfa Charming Kitten January 2021

    Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021.

    Open source URL
  273. [273]
    1 - appv

    SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.

    Open source URL
  274. [274]
    CheckPoint XLoader 2022

    Alexey Bukhteyev & Raman Ladutska, Check Point Research. (2022, May 31). XLoader Botnet: Find Me If You Can. Retrieved March 11, 2025.

    Open source URL
  275. [275]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
  276. [276]
    Microsoft Actinium February 2022

    Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.

    Open source URL
  277. [277]
    SymantecCarbonBlack_ShuckwormUSB_Apr2025

    Threat Hunter Team, Symantec and Carbon Black. (2025, April 10). Shuckworm Targets Foreign Military Mission Based in Ukraine. Retrieved July 23, 2025.

    Open source URL
  278. [278]
    Unit 42 Gamaredon February 2022

    Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022.

    Open source URL
  279. [279]
    DomainTools WinterVivern 2021

    Chad Anderson. (2021, April 27). Winter Vivern: A Look At Re-Crafted Government MalDocs Targeting Multiple Languages. Retrieved July 29, 2024.

    Open source URL
  280. [280]
    Microsoft Moonstone Sleet 2024

    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

    Open source URL
  281. [281]
    Forcepoint BITTER Pakistan Oct 2016

    Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.

    Open source URL
  282. [282]
    Palo Alto Black-T October 2020

    Quist, N. (2020, October 5). Black-T: New Cryptojacking Variant from TeamTNT. Retrieved September 22, 2021.

    Open source URL
  283. [283]
    Slowik Sandworm 2021

    Joseph Slowik, DomainTools. (2021, March 3). Centreon to Exim and Back: On the Trail of Sandworm. Retrieved April 6, 2024.

    Open source URL
  284. [284]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.