LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1685: Disable or Modify Tools

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.[1]

In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing for Windows (ETW), modifying event log configurations (e.g., redirecting Security logs), or interfering with logging pipelines and forwarding mechanisms (e.g., SIEM ingestion).[2][3]

More advanced techniques include leveraging legitimate drivers or debugging mechanisms to render tools non-functional, bypassing anti-tampering protections, and targeting specific defenses such as Sysmon or cloud monitoring agents. Adversaries may also disrupt broader defensive operations, including update mechanisms, logging infrastructure (e.g., syslog), or event aggregation, further degrading an organization’s ability to detect and respond to malicious activity.[4]

EnterpriseT1685TechniqueObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Disable or Modify Tools is a defense-impairment technique: adversaries tamper with security tooling, logging, sensors, update mechanisms, or telemetry pipelines so responders lose visibility at the moment they need it most. For leaders, the practical issue is not only whether EDR, IDS, cloud logs, or SIEM forwarding exist, but whether the organization can prove they remain trustworthy during an intrusion.

Executive priority

Prioritize this as an operational resilience and audit-evidence risk. If security tools, event logs, cloud logging, or SIEM ingestion can be stopped or altered by compromised accounts or local administrators without rapid detection, incident response timelines, regulatory evidence, and recovery decisions become less reliable. The ATT&CK relationships also connect this behavior to campaigns involving energy, supply chain compromise, VPN appliances, and critical infrastructure contexts, making it relevant to both enterprise and cyber-physical risk discussions where those environments exist.

Technical view

Validate coverage across the listed platforms: Windows, Linux, macOS, ESXi, IaaS, containers, and network devices. SOC and IR teams should test whether they can detect service stops, killed security processes, configuration or registry changes, logging changes, update disruption, ETW or event-log tampering, syslog or SIEM forwarding failure, cloud monitoring-agent changes, and mismatches between security-tool UI health and underlying telemetry. Because ATT&CK provides no official detection text for this technique, use the related detection strategy DET0497 as a pointer and map validation to the sub-techniques for Windows Event Log, cloud logs, Linux audit logs, log clearing, and tool UI manipulation.

Likely telemetry

  • Endpoint security tool health and tamper events
  • Process creation, process termination, and service-control events
  • File integrity and permission changes for security-tool configurations and logging paths
  • Windows Registry changes for security, logging, and startup-related keys
  • Windows Event Log, ETW, and audit policy configuration events

Detection direction

  • Alert on unexpected disabling, stopping, deletion, or configuration changes to defensive tools and logging components.
  • Monitor for gaps: missing heartbeats, sudden ingestion drops, log-source silence, or telemetry redirection can be as important as explicit tamper alerts.
  • Correlate tool-health events with privileged account activity because several mitigations depend on limiting who can change tools, files, directories, registry keys, and logging settings.
  • Tune for authorized maintenance windows, software upgrades, and administrator troubleshooting to reduce false positives while preserving high-severity handling for unscheduled or multi-system impairment.
  • Validate sub-technique coverage separately for Windows Event Log changes, cloud log changes, Linux audit changes, Windows log clearing, Linux/macOS log clearing, and security-tool UI spoofing or inconsistency.

Mitigation priorities

  • Enforce least privilege and strong user account management for accounts able to administer security tools, logging, cloud monitoring, and SIEM integrations.
  • Restrict file, directory, and registry permissions around security tooling, logging configurations, startup locations, and audit settings.
  • Use execution prevention to limit unauthorized code, scripts, drivers, or tooling that could impair defenses.
  • Remove or disable unnecessary software, features, or services that increase the number of components defenders must protect and monitor.
  • Harden software configurations for endpoint, cloud, network, and logging tools, including update and tamper-resistance settings where available.
Additional notes and limits

This object consolidates older ATT&CK coverage for disabling security tools, indicator blocking, and broader impair-defense behavior. The sub-techniques provide the most useful scoping for engineering work: Windows logs, cloud logs, Linux audit logs, log clearing on Windows/Linux/macOS, and tool UI manipulation. The campaign relationships show this behavior has appeared in notable ATT&CK-documented campaigns, but local relevance depends on the organization’s platforms, logging architecture, and administrative model.

ATT&CK does not provide official detection analytics for this object in the supplied fields. The guidance above is derived from the official description, listed platforms, tactic, mitigations, detection-strategy relationship, and related sub-techniques; it does not prove any environment has detection coverage or exposure. Local validation is required to determine which tools, logs, accounts, and pipelines can be modified and whether independent monitoring would catch impairment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Disable or Modify Tools

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.[1]

In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing for Windows (ETW), modifying event log configurations (e.g., redirecting Security logs), or interfering with logging pipelines and forwarding mechanisms (e.g., SIEM ingestion).[2][3]

More advanced techniques include leveraging legitimate drivers or debugging mechanisms to render tools non-functional, bypassing anti-tampering protections, and targeting specific defenses such as Sysmon or cloud monitoring agents. Adversaries may also disrupt broader defensive operations, including update mechanisms, logging infrastructure (e.g., syslog), or event aggregation, further degrading an organization’s ability to detect and respond to malicious activity.[4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

6 rows
DomainIDNameRelationship / procedure
EnterpriseT1685.002Disable or Modify Cloud LogSub-techniqueDisable or Modify Cloud Log subtechnique of this object.
EnterpriseT1562.001Disable or Modify ToolsSub-techniqueDisable or Modify Tools revoked by this object.
EnterpriseT1685.001Disable or Modify Windows Event LogSub-techniqueDisable or Modify Windows Event Log subtechnique of this object.
EnterpriseT1562.006Indicator BlockingSub-techniqueIndicator Blocking revoked by this object.
EnterpriseT1685.006Clear Linux or Mac System LogsSub-techniqueClear Linux or Mac System Logs subtechnique of this object.
EnterpriseT1685.005Clear Windows Event LogsSub-techniqueClear Windows Event Logs subtechnique of this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G1015: Scattered Spider

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. [1] [2] The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. [2] Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. [3] [4] [5] Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. [6]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0078: Gorgon Group

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. [1]

GroupEnterprise

G0037: FIN6

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.[1][2]

GroupEnterprise

G1054: MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]

GroupEnterprise

G1030: Agrius

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.[1][2] Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).[3]

GroupEnterprise

G1023: APT5

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.[1][2][3][4][5][6]

GroupEnterprise

G1018: TA2541

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.[1][2]

GroupEnterprise

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

GroupEnterprise

G0082: APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

MalwareEnterprise

S1048: macOS.OSAMiner

macOS.OSAMiner is a Monero mining trojan that was first observed in 2018; security researchers assessed macOS.OSAMiner may have been circulating since at least 2015. macOS.OSAMiner is known for embedding one run-only AppleScript into another, which helped the malware evade full analysis for five years due to a lack of Apple event (AEVT) analysis tools.[1][2]

macOS
MalwareEnterprise

S0638: Babuk

Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021. The operators of Babuk employ a "Big Game Hunting" approach to targeting major enterprises and operate a leak site to post stolen data as part of their extortion scheme.[1][2][3]

WindowsLinux
MalwareEnterprise

S1130: Raspberry Robin

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.[1][2][3] The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."[4] The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.[5]

Windows
MalwareEnterprise

S0697: HermeticWiper

HermeticWiper is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in Latvia and Lithuania. Some sectors targeted include government, financial, defense, aviation, and IT services.[1][2][3][4][5]

Windows
MalwareEnterprise

S0689: WhisperGate

WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.[1][2][3]

Windows
MalwareEnterprise

S0670: WarzoneRAT

WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.[1][2]

Windows
CampaignEnterprise

C0055: Quad7 Activity

Quad7 Activity, also known as CovertNetwork-1658 or the 7777 Botnet, is a network of compromised small office/home office (SOHO) routers. [1] [2] The botnet was initially composed primarily of TP-Link routers and was named Quad7 due to compromised devices exposing TCP port 7777 with the distinctive banner xlogin. Later activity showed a significant increase in compromised Asus routers and the addition of new ports and banners, including TCP port 63256 displaying alogin. Quad7 infrastructure functions as a collection of egress IPs that various China-affiliated threat actors have used to conduct password-spraying and brute-force operations. [1][3] Microsoft has reported that Storm-0940 leveraged credentials obtained through Quad7 Activity to target organizations in North America and Europe, including government agencies, non-governmental organizations, think tanks, law firms, energy firms, IT providers, and defense industrial base entities. [2]

CampaignEnterprise

C0029: Cutting Edge

Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.[1][2][3][4][5]

CampaignEnterprise

C0035: KV Botnet Activity

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.[1] This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.[2]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
79447f4605264fdd...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle79447f460526…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SCADAfence_ransomware

    Shaked, O. (2020, January 20). Anatomy of a Targeted Ransomware Attack. Retrieved June 18, 2022.

    Open source URL
  2. [2]
    Microsoft Lamin Sept 2017

    Microsoft. (2009, May 17). Backdoor:Win32/Lamin.A. Retrieved September 6, 2018.

    Open source URL
  3. [3]
    ETW Palantir

    Palantir. (2018, December 24). Tampering with Windows Event Tracing: Background, Offense, and Defense. Retrieved April 15, 2026.

    Open source URL
  4. [4]
    Cocomazzi FIN7 Reboot

    Cocomazzi, Antonio. (2024, July 17). FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks. Retrieved September 24, 2025.

    Open source URL
  5. [5]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  6. [6]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  7. [7]
    Sekoia 7777 Botnet JUL 2024

    Aime, F. et al. (n.d.). Solving the 7777 Botnet enigma: A cybersecurity quest. Retrieved July 23, 2024.

    Open source URL
  8. [8]
    Microsoft Storm-0940

    Microsoft Threat Intelligence. (2024, October 31). Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network. Retrieved June 4, 2025.

    Open source URL
  9. [9]
    Bitsight 7777 Botnet

    Batista, João. Gi7w0rm. (2024, August 27). Retrieved June 5, 2025.

    Open source URL
  10. [10]
    SentinelLabs reversing run-only applescripts 2021

    Phil Stokes. (2021, January 11). FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts. Retrieved September 29, 2022.

    Open source URL
  11. [11]
    IBM MegaCortex

    Del Fierro, C. Kessem, L.. (2020, January 8). From Mega to Giga: Cross-Version Comparison of Top MegaCortex Modifications. Retrieved February 15, 2021.

    Open source URL
  12. [12]
    Mandiant UNC3944 May 2025

    Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.

    Open source URL
  13. [13]
    Microsoft PLATINUM April 2016

    Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

    Open source URL
  14. [14]
    Securelist Kimsuky Sept 2013

    Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.

    Open source URL
  15. [15]
    Talos Kimsuky Nov 2021

    An, J and Malhotra, A. (2021, November 10). North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets. Retrieved December 29, 2021.

    Open source URL
  16. [16]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  17. [17]
    HP RaspberryRobin 2024

    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.

    Open source URL
  18. [18]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  19. [19]
    SentinelOne Hermetic Wiper February 2022

    Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022.

    Open source URL
  20. [20]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  21. [21]
    Qualys Hermetic Wiper March 2022

    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

    Open source URL
  22. [22]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  23. [23]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  24. [24]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  25. [25]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  26. [26]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  27. [27]
    TrendMicro Netwalker May 2020

    Victor, K.. (2020, May 18). Netwalker Fileless Ransomware Injected via Reflective Loading . Retrieved May 26, 2020.

    Open source URL
  28. [28]
    Sophos Netwalker May 2020

    Szappanos, G., Brandt, A.. (2020, May 27). Netwalker ransomware tools give insight into threat actor. Retrieved May 27, 2020.

    Open source URL
  29. [29]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  30. [30]
    Zscaler XLoader 2025

    Zscaler Threatlabz. (2025, January 27). Technical Analysis of Xloader Versions 6 and 7 | Part 1. Retrieved March 11, 2025.

    Open source URL
  31. [31]
    Netskope XLoader 2022

    Gustavo Palazolo, Netskope. (2022, March 11). New Formbook Campaign Delivered Through Phishing Emails. Retrieved March 11, 2025.

    Open source URL
  32. [32]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  33. [33]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  34. [34]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  35. [35]
    Mandiant Cutting Edge Part 2 January 2024

    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  36. [36]
    Volexity Ivanti Zero-Day Exploitation January 2024

    Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024.

    Open source URL
  37. [37]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  38. [38]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  39. [39]
    Booz Allen Hamilton

    Booz Allen Hamilton. (2016). When The Lights Went Out. Retrieved December 18, 2024.

    Open source URL
  40. [40]
    Lumen KVBotnet 2023

    Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

    Open source URL
  41. [41]
    Group IB Ransomware September 2020

    Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.

    Open source URL
  42. [42]
    CERT Polska

    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

    Open source URL
  43. [43]
    Cylance Cleaver

    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

    Open source URL
  44. [44]
    FBI Lockbit 2.0 FEB 2022

    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

    Open source URL
  45. [45]
    Palo Alto Lockbit 2.0 JUN 2022

    Elsad, A. et al. (2022, June 9). LockBit 2.0: How This RaaS Operates and How to Protect Against It. Retrieved January 24, 2025.

    Open source URL
  46. [46]
    Mandiant Pulse Secure Update May 2021

    Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.

    Open source URL
  47. [47]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  48. [48]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  49. [49]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  50. [50]
    Trend Micro Skidmap

    Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020.

    Open source URL
  51. [51]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  52. [52]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  53. [53]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  54. [54]
    Cisco Salt Typhoon FEB 2025

    Cisco Talos. (2025, February 20). Weathering the storm: In the midst of a Typhoon. Retrieved February 24, 2025.

    Open source URL
  55. [55]
    Socket Shai-Hulud November 2025

    Socket Research Team. (2025, November 24). Shai Hulud Strikes Again (v2). Retrieved April 9, 2026.

    Open source URL
  56. [56]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  57. [57]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  58. [58]
    Fortinet Diavol July 2021

    Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.

    Open source URL
  59. [59]
    CodeX Microsoft Defender 2021

    Christopher Brumm. (2021, August 4). My learnings on Microsoft Defender for Endpoint and Exclusions. Retrieved March 18, 2025.

    Open source URL
  60. [60]
    Symantec WastedLocker June 2020

    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

    Open source URL
  61. [61]
    Mandiant_UNC2165

    Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.

    Open source URL
  62. [62]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  63. [63]
    Arxiv Avaddon Feb 2021

    Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021.

    Open source URL
  64. [64]
    1 - appv

    SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.

    Open source URL
  65. [65]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  66. [66]
    CrowdStrike Putter Panda

    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

  67. [67]
    Joint Cybersecurity Advisory LockBit JUN 2023

    CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.

    Open source URL
  68. [68]
    Joint Cybersecurity Advisory LockBit 3.0 MAR 2023

    FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.

    Open source URL
  69. [69]
    INCIBE-CERT LockBit MAR 2024

    INCIBE-CERT. (2024, March 14). LockBit: response and recovery actions. Retrieved February 5, 2025.

    Open source URL
  70. [70]
    DigiTrust NanoCore Jan 2017

    The DigiTrust Group. (2017, January 01). NanoCore Is Not Your Average RAT. Retrieved November 9, 2018.

    Open source URL
  71. [71]
    PaloAlto NanoCore Feb 2016

    Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.

    Open source URL
  72. [72]
    CERT-FR PYSA April 2020

    CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021.

    Open source URL
  73. [73]
    wardle evilquest parti

    Patrick Wardle. (2020, June 29). OSX.EvilQuest Uncovered part i: infection, persistence, and more!. Retrieved March 18, 2021.

    Open source URL
  74. [74]
    DHS/CISA Ransomware Targeting Healthcare October 2020

    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

    Open source URL
  75. [75]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  76. [76]
    DFIR Ryuk's Return October 2020

    The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

    Open source URL
  77. [77]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  78. [78]
    Rostovcev APT41 2021

    Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.

    Open source URL
  79. [79]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  80. [80]
    FireEye SUNBURST Additional Details Dec 2020

    Stephen Eckels, Jay Smith, William Ballenthin. (2020, December 24). SUNBURST Additional Technical Details. Retrieved January 6, 2021.

    Open source URL
  81. [81]
    Check Point Meteor Aug 2021

    Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.

    Open source URL
  82. [82]
    Imminent Unit42 Dec2019

    Unit 42. (2019, December 2). Imminent Monitor – a RAT Down Under. Retrieved May 5, 2020.

    Open source URL
  83. [83]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  84. [84]
    ESET Turla PowerShell May 2019

    Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.

    Open source URL
  85. [85]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  86. [86]
    Novetta Blockbuster Loaders

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024.

    Open source URL
  87. [87]
    Novetta Blockbuster Tools

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Tools Report. Retrieved March 10, 2016.

    Open source URL
  88. [88]
    US-CERT SHARPKNOT June 2018

    US-CERT. (2018, March 09). Malware Analysis Report (MAR) - 10135536.11.WHITE. Retrieved June 13, 2018.

    Open source URL
  89. [89]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  90. [90]
    objsee mac malware 2017

    Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

    Open source URL
  91. [91]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  92. [92]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  93. [93]
    Netskope LummaStealer 2025

    Leandro Fróes, Netskope. (2025, January 23). Lumma Stealer: Fake CAPTCHAs & New Techniques to Evade Detection. Retrieved March 22, 2025.

    Open source URL
  94. [94]
    Wired Lockergoga 2019

    Greenberg, A. (2019, March 25). A Guide to LockerGoga, the Ransomware Crippling Industrial Firms. Retrieved July 17, 2019.

    Open source URL
  95. [95]
    Trend Micro Muddy Water March 2021

    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

    Open source URL
  96. [96]
    ESET Gamaredon June 2020

    Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.

    Open source URL
  97. [97]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
  98. [98]
    Cocomazzi FIN7 Reboot

    Cocomazzi, Antonio. (2024, July 17). FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks. Retrieved September 24, 2025.

    Open source URL
  99. [99]
    Cocomazzi FIN7 Reboot

    Cocomazzi, Antonio. (2024, July 17). FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks. Retrieved September 24, 2025.

    Open source URL
  100. [100]
    ETW Palantir

    Palantir. (2018, December 24). Tampering with Windows Event Tracing: Background, Offense, and Defense. Retrieved April 15, 2026.

    Open source URL
  101. [101]
    ETW Palantir

    Palantir. (2018, December 24). Tampering with Windows Event Tracing: Background, Offense, and Defense. Retrieved April 15, 2026.

    Open source URL
  102. [102]
    Microsoft Lamin Sept 2017

    Microsoft. (2009, May 17). Backdoor:Win32/Lamin.A. Retrieved September 6, 2018.

    Open source URL
  103. [103]
    Microsoft Lamin Sept 2017

    Microsoft. (2009, May 17). Backdoor:Win32/Lamin.A. Retrieved September 6, 2018.

    Open source URL
  104. [104]
    SCADAfence_ransomware

    Shaked, O. (2020, January 20). Anatomy of a Targeted Ransomware Attack. Retrieved June 18, 2022.

    Open source URL
  105. [105]
    SCADAfence_ransomware

    Shaked, O. (2020, January 20). Anatomy of a Targeted Ransomware Attack. Retrieved June 18, 2022.

    Open source URL
  106. [106]
    mitre-attackT1685
    Open source URL
  107. [107]
    mitre-attackT1685
    Open source URL
  108. [108]
    mitre-attackT1685
    Open source URL
  109. [109]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  110. [110]
    Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

    Open source URL
  111. [111]
    Bitsight 7777 Botnet

    Batista, João. Gi7w0rm. (2024, August 27). Retrieved June 5, 2025.

    Open source URL
  112. [112]
    Microsoft Storm-0940

    Microsoft Threat Intelligence. (2024, October 31). Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network. Retrieved June 4, 2025.

    Open source URL
  113. [113]
    Sekoia 7777 Botnet JUL 2024

    Aime, F. et al. (n.d.). Solving the 7777 Botnet enigma: A cybersecurity quest. Retrieved July 23, 2024.

    Open source URL
  114. [114]
    SentinelLabs reversing run-only applescripts 2021

    Phil Stokes. (2021, January 11). FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts. Retrieved September 29, 2022.

    Open source URL
  115. [115]
    IBM MegaCortex

    Del Fierro, C. Kessem, L.. (2020, January 8). From Mega to Giga: Cross-Version Comparison of Top MegaCortex Modifications. Retrieved February 15, 2021.

    Open source URL
  116. [116]
    Mandiant UNC3944 May 2025

    Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025.

    Open source URL
  117. [117]
    Microsoft PLATINUM April 2016

    Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018.

    Open source URL
  118. [118]
    Securelist Kimsuky Sept 2013

    Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.

    Open source URL
  119. [119]
    Talos Kimsuky Nov 2021

    An, J and Malhotra, A. (2021, November 10). North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets. Retrieved December 29, 2021.

    Open source URL
  120. [120]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  121. [121]
    HP RaspberryRobin 2024

    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.

    Open source URL
  122. [122]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  123. [123]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  124. [124]
    Qualys Hermetic Wiper March 2022

    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

    Open source URL
  125. [125]
    SentinelOne Hermetic Wiper February 2022

    Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022.

    Open source URL
  126. [126]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  127. [127]
    FireEye FIN6 Apr 2019

    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

    Open source URL
  128. [128]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  129. [129]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  130. [130]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  131. [131]
    Sophos Netwalker May 2020

    Szappanos, G., Brandt, A.. (2020, May 27). Netwalker ransomware tools give insight into threat actor. Retrieved May 27, 2020.

    Open source URL
  132. [132]
    TrendMicro Netwalker May 2020

    Victor, K.. (2020, May 18). Netwalker Fileless Ransomware Injected via Reflective Loading . Retrieved May 26, 2020.

    Open source URL
  133. [133]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  134. [134]
    Netskope XLoader 2022

    Gustavo Palazolo, Netskope. (2022, March 11). New Formbook Campaign Delivered Through Phishing Emails. Retrieved March 11, 2025.

    Open source URL
  135. [135]
    Zscaler XLoader 2025

    Zscaler Threatlabz. (2025, January 27). Technical Analysis of Xloader Versions 6 and 7 | Part 1. Retrieved March 11, 2025.

    Open source URL
  136. [136]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  137. [137]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  138. [138]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  139. [139]
    Mandiant Cutting Edge Part 2 January 2024

    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

    Open source URL
  140. [140]
    Volexity Ivanti Zero-Day Exploitation January 2024

    Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024.

    Open source URL
  141. [141]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  142. [142]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  143. [143]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  144. [144]
    Ensilo Darkgate 2018

    Adi Zeligson & Rotem Kerner. (2018, November 13). Enter The DarkGate - New Cryptocurrency Mining and Ransomware Campaign. Retrieved February 9, 2024.

    Open source URL
  145. [145]
    Booz Allen Hamilton

    Booz Allen Hamilton. (2016). When The Lights Went Out. Retrieved December 18, 2024.

    Open source URL
  146. [146]
    Lumen KVBotnet 2023

    Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

    Open source URL
  147. [147]
    Group IB Ransomware September 2020

    Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.

    Open source URL
  148. [148]
    CERT Polska

    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

    Open source URL
  149. [149]
    Cylance Cleaver

    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

    Open source URL
  150. [150]
    FBI Lockbit 2.0 FEB 2022

    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

    Open source URL
  151. [151]
    Palo Alto Lockbit 2.0 JUN 2022

    Elsad, A. et al. (2022, June 9). LockBit 2.0: How This RaaS Operates and How to Protect Against It. Retrieved January 24, 2025.

    Open source URL
  152. [152]
    Mandiant Pulse Secure Update May 2021

    Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.

    Open source URL
  153. [153]
    Proofpoint Leviathan Oct 2017

    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

    Open source URL
  154. [154]
    Proofpoint TA2541 February 2022

    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

    Open source URL
  155. [155]
    Zscaler PureCrypter JUN 2022

    Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026.

    Open source URL
  156. [156]
    Trend Micro Skidmap

    Remillano, A., Urbanec, J. (2019, September 19). Skidmap Linux Malware Uses Rootkit Capabilities to Hide Cryptocurrency-Mining Payload. Retrieved June 4, 2020.

    Open source URL
  157. [157]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  158. [158]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  159. [159]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  160. [160]
    Cisco Salt Typhoon FEB 2025

    Cisco Talos. (2025, February 20). Weathering the storm: In the midst of a Typhoon. Retrieved February 24, 2025.

    Open source URL
  161. [161]
    Socket Shai-Hulud November 2025

    Socket Research Team. (2025, November 24). Shai Hulud Strikes Again (v2). Retrieved April 9, 2026.

    Open source URL
  162. [162]
    GitHub SILENTTRINITY Modules July 2019

    Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

    Open source URL
  163. [163]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  164. [164]
    Fortinet Diavol July 2021

    Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.

    Open source URL
  165. [165]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  166. [166]
    McAfee Gold Dragon

    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

    Open source URL
  167. [167]
    CodeX Microsoft Defender 2021

    Christopher Brumm. (2021, August 4). My learnings on Microsoft Defender for Endpoint and Exclusions. Retrieved March 18, 2025.

    Open source URL
  168. [168]
    Mandiant_UNC2165

    Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.

    Open source URL
  169. [169]
    Symantec WastedLocker June 2020

    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

    Open source URL
  170. [170]
    Socket HexEval BeaverTail Contagious Interview June 2025

    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

    Open source URL
  171. [171]
    Arxiv Avaddon Feb 2021

    Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021.

    Open source URL
  172. [172]
    1 - appv

    SEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.

    Open source URL
  173. [173]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  174. [174]
    CrowdStrike Putter Panda

    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

  175. [175]
    INCIBE-CERT LockBit MAR 2024

    INCIBE-CERT. (2024, March 14). LockBit: response and recovery actions. Retrieved February 5, 2025.

    Open source URL
  176. [176]
    Joint Cybersecurity Advisory LockBit 3.0 MAR 2023

    FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.

    Open source URL
  177. [177]
    Joint Cybersecurity Advisory LockBit JUN 2023

    CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.

    Open source URL
  178. [178]
    DigiTrust NanoCore Jan 2017

    The DigiTrust Group. (2017, January 01). NanoCore Is Not Your Average RAT. Retrieved November 9, 2018.

    Open source URL
  179. [179]
    PaloAlto NanoCore Feb 2016

    Kasza, A., Halfpop, T. (2016, February 09). NanoCoreRAT Behind an Increase in Tax-Themed Phishing E-mails. Retrieved November 9, 2018.

    Open source URL
  180. [180]
    CERT-FR PYSA April 2020

    CERT-FR. (2020, April 1). ATTACKS INVOLVING THE MESPINOZA/PYSA RANSOMWARE. Retrieved March 1, 2021.

    Open source URL
  181. [181]
    wardle evilquest parti

    Patrick Wardle. (2020, June 29). OSX.EvilQuest Uncovered part i: infection, persistence, and more!. Retrieved March 18, 2021.

    Open source URL
  182. [182]
    DFIR Ryuk's Return October 2020

    The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

    Open source URL
  183. [183]
    DHS/CISA Ransomware Targeting Healthcare October 2020

    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

    Open source URL
  184. [184]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  185. [185]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  186. [186]
    Rostovcev APT41 2021

    Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.

    Open source URL
  187. [187]
    Trend Micro Tick November 2019

    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

    Open source URL
  188. [188]
    FireEye SUNBURST Additional Details Dec 2020

    Stephen Eckels, Jay Smith, William Ballenthin. (2020, December 24). SUNBURST Additional Technical Details. Retrieved January 6, 2021.

    Open source URL
  189. [189]
    Check Point Meteor Aug 2021

    Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.

    Open source URL
  190. [190]
    Imminent Unit42 Dec2019

    Unit 42. (2019, December 2). Imminent Monitor – a RAT Down Under. Retrieved May 5, 2020.

    Open source URL
  191. [191]
    Cylance Sodinokibi July 2019

    Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.

    Open source URL
  192. [192]
    ESET Turla PowerShell May 2019

    Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.

    Open source URL
  193. [193]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  194. [194]
    Novetta Blockbuster Loaders

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024.

    Open source URL
  195. [195]
    Novetta Blockbuster Tools

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Tools Report. Retrieved March 10, 2016.

    Open source URL
  196. [196]
    US-CERT SHARPKNOT June 2018

    US-CERT. (2018, March 09). Malware Analysis Report (MAR) - 10135536.11.WHITE. Retrieved June 13, 2018.

    Open source URL
  197. [197]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  198. [198]
    objsee mac malware 2017

    Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.

    Open source URL
  199. [199]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  200. [200]
    MacKeeper Bundlore Apr 2019

    Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.

    Open source URL
  201. [201]
    Netskope LummaStealer 2025

    Leandro Fróes, Netskope. (2025, January 23). Lumma Stealer: Fake CAPTCHAs & New Techniques to Evade Detection. Retrieved March 22, 2025.

    Open source URL
  202. [202]
    Wired Lockergoga 2019

    Greenberg, A. (2019, March 25). A Guide to LockerGoga, the Ransomware Crippling Industrial Firms. Retrieved July 17, 2019.

    Open source URL
  203. [203]
    Trend Micro Muddy Water March 2021

    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

    Open source URL
  204. [204]
    ESET Gamaredon June 2020

    Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.

    Open source URL
  205. [205]
    ESET Gamaredon Sept2024

    Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.