ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
00sec Droppers0x00pico. (2017, September 25). Super-Stealthy Droppers. Retrieved October 4, 2021.
1 - appvSEONGSU PARK. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved February 6, 2024.
2 - appvMicrosoft. (2022, November 3). Getting started with App-V for Windows client. Retrieved February 6, 2024.
20 macOS Common Tools and TechniquesPhil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.
2022 November_TrendMicro_Earth Preta_Toneshell_PubloadNick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.
2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAGolo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.
3 - appvRaj Chandel. (2022, March 17). Indirect Command Execution: Defense Evasion (T1202). Retrieved February 6, 2024.
360 Machete Sep 2020kate. (2020, September 25). APT-C-43 steals Venezuelan military secrets to provide intelligence support for the reactionaries — HpReact campaign. Retrieved November 20, 2020.
3OHA double-fork 2022Juan Tapiador. (2022, April 11). UNIX daemonization and the double fork. Retrieved September 29, 2023.
3cx official statement 2023Agathocles Prodromou. (2023, April 20). Security Update Thursday 20 April 2023 – Initial Intrusion Vector Found. Retrieved August 25, 2025.
4 - appvJohn Fokker. (2022, March 17). Suspected DarkHotel APT activity update. Retrieved February 6, 2024.
401 TRG Winnti Umbrella May 2018Hegel, T. (2018, May 3). Burning Umbrella: An Intelligence Report on the Winnti Umbrella and Associated State-Sponsored Attackers. Retrieved July 8, 2018.
5 - appvNick Landers, Casey Smith. (n.d.). /Syncappvpublishingserver.vbs. Retrieved February 6, 2024.
6 - appvStrontic. (n.d.). SyncAppvPublishingServer.exe. Retrieved February 6, 2024.
7 - appvNick Landers. (2017, August 8). Need a signed alternative to Powershell.exe? SyncAppvPublishingServer in Win10 has got you covered.. Retrieved September 12, 2024.
7zip HomepageI. Pavlov. (2019). 7-Zip. Retrieved February 20, 2020.
AADInternalsDr. Nestori Syynimaa. (2018, October 25). AADInternals. Retrieved February 1, 2022.
AADInternals - BPRTDr. Nestori Syynimaa. (2021, January 31). BPRT unleashed: Joining multiple devices to Azure AD and Intune. Retrieved March 4, 2022.
AADInternals - Conditional Access BypassDr. Nestori Syynimaa. (2020, September 6). Bypassing conditional access by faking device compliance. Retrieved March 4, 2022.
AADInternals - Device RegistrationDr. Nestori Syynimaa. (2021, March 3). Deep-dive to Azure AD device join. Retrieved March 9, 2022.
AADInternals Azure AD Device IdentitiesDr. Nestori Syynimaa. (2022, February 15). Stealing and faking Azure AD device identities. Retrieved February 21, 2023.
AADInternals Azure AD On-Prem to CloudDr. Nestori Syynimaa. (2020, July 13). Unnoticed sidekick: Getting access to cloud as an on-prem admin. Retrieved September 28, 2022.
AADInternals DocumentationDr. Nestori Syynimaa. (2018, October 25). AADInternals. Retrieved February 18, 2022.
AADInternals GithubDr. Nestori Syynimaa. (2021, December 13). AADInternals. Retrieved February 1, 2022.
AADInternals Root Access to Azure VMsDr. Nestori Syynimaa. (2020, June 4). Getting root access to Azure VMs as a Azure AD Global Administrator. Retrieved March 13, 2023.
AADInternals zure AD Federated DomainDr. Nestori Syynimaa. (2017, November 16). Security vulnerability in Azure AD & Office 365 identity federation. Retrieved September 28, 2022.
ACSC BlackCat Apr 2022Australian Cyber Security Centre. (2022, April 14). 2022-004: ACSC Ransomware Profile - ALPHV (aka BlackCat). Retrieved December 20, 2022.
ADSecurity AD Kerberos AttacksMetcalf, S. (2014, November 22). Mimikatz and Active Directory Kerberos Attacks. Retrieved June 2, 2016.
ADSecurity Detecting Forged TicketsMetcalf, S. (2015, May 03). Detecting Forged Kerberos Ticket (Golden Ticket & Silver Ticket) Use in Active Directory. Retrieved December 23, 2015.
ADSecurity GPO Persistence 2016Metcalf, S. (2016, March 14). Sneaky Active Directory Persistence #17: Group Policy. Retrieved March 5, 2019.
ADSecurity Kerberos Ring DecoderSean Metcalf. (2014, September 12). Kerberos, Active Directory’s Secret Decoder Ring. Retrieved February 27, 2020.
ADSecurity Kerberos and KRBTGTSean Metcalf. (2014, November 10). Kerberos & KRBTGT: Active Directory’s Domain Kerberos Service Account. Retrieved January 30, 2020.
ADSecurity Mimikatz DCSyncMetcalf, S. (2015, September 25). Mimikatz DCSync Usage, Exploitation, and Detection. Retrieved August 7, 2017.
ADSecurity Silver TicketsSean Metcalf. (2015, November 17). How Attackers Use Kerberos Silver Tickets to Exploit Systems. Retrieved February 27, 2020.
AMD Magic PacketAMD. (1995, November 1). Magic Packet Technical White Paper. Retrieved February 17, 2021.
ANSSI Nobelium Phishing December 2021ANSSI. (2021, December 6). PHISHING CAMPAIGNS BY THE NOBELIUM INTRUSION SET. Retrieved April 13, 2022.
ANSSI RYUK RANSOMWAREANSSI. (2021, February 25). RYUK RANSOMWARE. Retrieved March 29, 2021.
ANSSI Sandworm January 2021ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.
ANY.RUN XLoader 2023ANY.RUN. (2023, February 28). XLoader/FormBook: Encryption Analysis and Malware Decryption . Retrieved March 11, 2025.
AP-NotPetyaFRANK BAJAK AND RAPHAEL SATTER. (2017, June 30). Companies still hobbled from fearsome cyberattack. Retrieved August 18, 2023.
APT15 Intezer June 2018Rosenberg, J. (2018, June 14). MirageFox: APT15 Resurfaces With New Tools Based On Old Ones. Retrieved September 21, 2018.
APT29 Deep Look at Credential RoamingThibault Van Geluwe De Berlaere. (2022, November 8). They See Me Roaming: Following APT29 by Taking a Deeper Look at Windows Credential Roaming. Retrieved November 9, 2022.
APT3 Adversary Emulation PlanKorban, C, et al. (2017, September). APT3 Adversary Emulation Plan. Retrieved January 16, 2018.
ARS Technica China Hack SK April 2017Sean Gallagher. (2017, April 21). Researchers claim China trying to hack South Korea missile defense efforts. Retrieved October 17, 2021.
ASEC Emotet 2017ASEC. (2017). ASEC REPORT VOL.88. Retrieved April 16, 2019.
ASEC Lazarus 2022AhnLab ASEC. (2022, October 6). Lazarus Group Uses the DLL Side-Loading Technique (mi.dll). Retrieved January 7, 2025.
ASEC Troll Stealer 2024AhnLab ASEC. (2024, February 16). TrollAgent That Infects Systems Upon Security Program Installation Process (Kimsuky Group). Retrieved January 17, 2025.
ASERT Donot March 2018Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.
ASERT InnaputRAT April 2018ASERT Team. (2018, April 04). Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files. Retrieved July 9, 2018.
ASERT Seven Pointed Dagger Aug 2015ASERT. (2015, August). ASERT Threat Intelligence Report – Uncovering the Seven Pointed Dagger. Retrieved March 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.