Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Catch All Chrome Extension | Marinho, R. (n.d.). "Catch-All" Google Chrome Malicious Extension Steals All Posted Data. Retrieved November 16, 2017. |
| Categorisation_not_boundary | MDSec Research. (2017, July). Categorisation is not a Security Boundary. Retrieved September 20, 2019. |
| Cato LAMEHUG JUL 2025 | Simonovich, V. (2025, July 23). Cato CTRL™ Threat Research: Analyzing LAMEHUG – First Known LLM-Powered Malware with Links to APT28 (Fancy Bear) . Retrieved April 21, 2026. |
| Censys RedPenguin MAR 2025 | Censys Research Team. (2025, March 14). JunOS and RedPenguin. Retrieved June 24, 2025. |
| Certfa Charming Kitten January 2021 | Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021. |
| Chaos Stolen Backdoor | Sebastian Feldmann. (2018, February 14). Chaos: a Stolen Backdoor Rising Again. Retrieved March 5, 2018. |
| Charles McLellan March 2016 | Charles McLellan. (2016, March 4). How hackers attacked Ukraine's power grid: Implications for Industrial IoT security. Retrieved September 27, 2023. |
| Check Point APT31 February 2021 | Itkin, E. and Cohen, I. (2021, February 22). The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day. Retrieved March 24, 2021. |
| Check Point APT34 April 2021 | Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021. |
| Check Point APT35 CharmPower January 2022 | Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022. |
| Check Point Black Basta October 2022 | Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023. |
| Check Point Blind Eagle MAR 2025 | Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026. |
| Check Point Havij Analysis | Ganani, M. (2015, May 14). Analysis of the Havij SQL Injection tool. Retrieved March 19, 2018. |
| Check Point Medusa Ransomware April 2025 | Check Point. (2025, April 16). The 2025 Ransomware Surge: Context for Medusa’s Rise. Retrieved October 15, 2025. |
| Check Point Meteor Aug 2021 | Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022. |
| Check Point Pay2Key November 2020 | Check Point. (2020, November 6). Ransomware Alert: Pay2Key. Retrieved January 4, 2021. |
| Check Point Rocket Kitten | Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018. |
| Check Point Scattered Spider JUL 2025 | Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025. |
| Check Point Sunburst Teardrop December 2020 | Check Point Research. (2020, December 22). SUNBURST, TEARDROP and the NetSec New Normal. Retrieved January 6, 2021. |
| Check Point VOID MANTICORE Handala Hack March 2026 | Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026. |
| Check Point Warzone Feb 2020 | Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021. |
| Check Point Wirte NOV 2024 | Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026. |
| CheckPoint Agrius 2023 | Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024. |
| CheckPoint Bandook Nov 2020 | Check Point. (2020, November 26). Bandook: Signed & Delivered. Retrieved May 31, 2021. |
| CheckPoint Dok | Ofer Caspi. (2017, May 4). OSX Malware is Catching Up, and it wants to Read Your HTTPS Traffic. Retrieved October 5, 2021. |
| CheckPoint Naikon May 2020 | CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020. |
| CheckPoint Redaman October 2019 | Eisenkraft, K., Olshtein, A. (2019, October 17). Pony’s C&C servers hidden inside the Bitcoin blockchain. Retrieved June 15, 2020. |
| CheckPoint SpeakUp Feb 2019 | Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019. |
| CheckPoint Volatile Cedar March 2015 | Threat Intelligence and Research. (2015, March 30). VOLATILE CEDAR. Retrieved February 8, 2021. |
| CheckPoint XLoader 2022 | Alexey Bukhteyev & Raman Ladutska, Check Point Research. (2022, May 31). XLoader Botnet: Find Me If You Can. Retrieved March 11, 2025. |
| Checkmarx Webhooks | Jossef Harush Kadouri. (2022, March 7). Webhook Party — Malicious packages caught exfiltrating data via legit webhook services. Retrieved July 20, 2023. |
| Checkmarx-oss-seo | Yehuda Gelb. (2024, April 10). New Technique to Trick Developers Detected in an Open Source Supply Chain Attack. Retrieved June 18, 2024. |
| Checkpoint Dridex Jan 2021 | Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021. |
| Checkpoint IndigoZebra July 2021 | CheckPoint Research. (2021, July 1). IndigoZebra APT continues to attack Central Asia with evolving tools. Retrieved September 24, 2021. |
| Checkpoint MosesStaff Nov 2021 | Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022. |
| Checkpoint WannaCry 2017 | Pal, P. (2017, May 16). CRYING IS FUTILE: SandBlast Forensic Analysis of WannaCry. Retrieved November 22, 2024. |
| Checkpoint_MOISCyberCrime_Mar2026 | CheckPoint Research. (2026, March 10). Iranian MOIS Actors & the Cyber Crime Connection. Retrieved March 12, 2026. |
| Chexmarx-seo | Yehuda Gelb. (2023, November 30). The GitHub Black Market: Gaming the Star Ranking Game. Retrieved June 18, 2024. |
| Chrome Extension C2 Malware | Kjaer, M. (2016, July 18). Malware in the browser: how you might get hacked by a Chrome extension. Retrieved September 12, 2024. |
| Chrome Extension Crypto Miner | Brinkmann, M. (2017, September 19). First Chrome extension with JavaScript Crypto Miner detected. Retrieved November 16, 2017. |
| Chrome Extensions Definition | Chrome. (n.d.). What are Extensions?. Retrieved November 16, 2017. |
| Chrome Remote Desktop | Huntress. (n.d.). Retrieved March 14, 2024. |
| Chrome Roaming Profiles | Chrome Enterprise and Education Help. (n.d.). Use Chrome Browser with Roaming User Profiles. Retrieved March 28, 2023. |
| Chronicle Winnti for Linux May 2019 | Chronicle Blog. (2019, May 15). Winnti: More than just Windows and Gates. Retrieved April 29, 2020. |
| Ciberseguridad Decoding malicious RTF files | Pedrero, R.. (2021, July). Decoding malicious RTF files. Retrieved November 16, 2021. |
| Cider Security Top 10 CICD Security Risks | Daniel Krivelevich and Omer Gil. (n.d.). Top 10 CI/CD Security Risks. Retrieved November 17, 2024. |
| Circl Passive DNS | CIRCL Computer Incident Response Center. (n.d.). Passive DNS. Retrieved October 20, 2020. |
| Cisco Akira Ransomware OCT 2024 | Nutland, J. and Szeliga, M. (2024, October 21). Akira ransomware continues to evolve. Retrieved December 10, 2024. |
| Cisco ArcaneDoor 2024 | Cisco Talos. (2024, April 24). ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices. Retrieved January 6, 2025. |
| Cisco BlackByte 2024 | James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.