ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Cylance Redirect to SMBCylance. (2015, April 13). Redirect to SMB. Retrieved December 21, 2017.
Cylance Reg Persistence Sept 2013Langendorf, S. (2013, September 24). Windows Registry Persistence, Part 2: The Run Keys and Search-Order. Retrieved November 17, 2024.
Cylance Shaheen Nov 2018Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.
Cylance Shell Crew Feb 2017Cylance SPEAR Team. (2017, February 9). Shell Crew Variants Continue to Fly Under Big AV’s Radar. Retrieved February 15, 2017.
Cylance Sodinokibi July 2019Cylance. (2019, July 3). hreat Spotlight: Sodinokibi Ransomware. Retrieved August 4, 2020.
Cylera Kwampirs 2022Pablo Rincón Crespo. (2022, January). The link between Kwampirs (Orangeworm) and Shamoon APTs. Retrieved February 8, 2024.
Cymmetria PatchworkCymmetria. (2016). Unveiling Patchwork - The Copy-Paste APT. Retrieved November 17, 2024.
Cynet Ragnar Apr 2020Gold, B. (2020, April 27). Cynet Detection Report: Ragnar Locker Ransomware. Retrieved June 29, 2020.
Cyphort EvilBunnyMarschalek, Marion. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved August 5, 2024.
Cyphort EvilBunny Dec 2014Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.
Cyware Ngrok May 2019Cyware. (2019, May 29). Cyber attackers leverage tunneling service to drop Lokibot onto victims’ systems. Retrieved September 15, 2020.
Cyware Social MediaCyware Hacker News. (2019, October 2). How Hackers Exploit Social Media To Break Into Your Company. Retrieved October 20, 2020.
D3Secutrity CTI FeedsBanerd, W. (2019, April 30). 10 of the Best Open Source Threat Intelligence Feeds. Retrieved October 20, 2020.
DBAPPSecurity BITTER zero-day Feb 2021JinQuan, MaDongZe, TuXiaoYi, and LiHao. (2021, February 10). Windows kernel zero-day exploit (CVE-2021-1732) is used by BITTER APT in targeted attack. Retrieved June 1, 2022.
DCSO StrelaStealer 2022DCSO CyTec Blog. (2022, November 8). #ShortAndMalicious: StrelaStealer aims for mail credentials. Retrieved December 31, 2024.
DCShadow BlogDelpy, B. & LE TOUX, V. (n.d.). DCShadow. Retrieved March 20, 2018.
DD ManKerrisk, M. (2020, February 2). DD(1) User Commands. Retrieved February 21, 2020.
DEFCON2016 Sticky KeysMaldonado, D., McGuffin, T. (2016, August 6). Sticky Keys to the Kingdom. Retrieved July 5, 2017.
DFIR Conti Bazar Nov 2021DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.
DFIR Diavol Ransomware December 2021DFIR Report. (2021, December 13). Diavol Ransomware. Retrieved March 9, 2022.
DFIR Phosphorus November 2021DFIR Report. (2021, November 15). Exchange Exploit Leads to Domain Wide Ransomware. Retrieved January 5, 2023.
DFIR Python Persistence 2025Stephan Berger. (2025, January 14). Analysis of Python's .pth files as a persistence mechanism. Retrieved May 22, 2025.
DFIR Report APT35 ProxyShell March 2022DFIR Report. (2022, March 21). APT35 Automates Initial Access Using ProxyShell. Retrieved May 25, 2022.
DFIR Report GootloaderThe DFIR Report. (2022, May 9). SEO Poisoning – A Gootloader Story. Retrieved September 30, 2022.
DFIR Report Trickbot June 2023The DFIR Report. (2023, June 12). A Truly Graceful Wipe Out. Retrieved May 31, 2024.
DFIR Ryuk 2 Hour Speed Run November 2020The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.
DFIR Ryuk in 5 Hours October 2020The DFIR Report. (2020, October 18). Ryuk in 5 Hours. Retrieved October 19, 2020.
DFIR Ryuk's Return October 2020The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.
DFIR_Quantum_RansomwareDFIR. (2022, April 25). Quantum Ransomware. Retrieved July 26, 2024.
DFIR_Sodinokibi_RansomwareDFIR. (2021, March 29). Sodinokibi (aka REvil) Ransomware. Retrieved July 22, 2024.
DHS CISA AA22-055A MuddyWater February 2022FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.
DHS/CISA Ransomware Targeting Healthcare October 2020DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.
DMARC-overviewDMARC. (n.d.). Retrieved March 24, 2025.
DNS BeaconsVercara. (n.d.). Retrieved July 21, 2025.
DNS DumpsterHacker Target. (n.d.). DNS Dumpster. Retrieved October 20, 2020.
DNS-CISACISA. (2016, September 29). DNS Zone Transfer AXFR Requests May Leak Domain Information. Retrieved June 5, 2024.
DOJ - Cisco InsiderDOJ. (2020, August 26). San Jose Man Pleads Guilty To Damaging Cisco’s Network. Retrieved December 15, 2020.
DOJ APT10 Dec 2018United States District Court Southern District of New York (USDC SDNY) . (2018, December 17). United States of America v. Zhu Hua and Zhang Shilong. Retrieved April 17, 2019.
DOJ Affidavit Search and Seizure PlugX December 2024DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrie…
DOJ FBI Handala Hack March 2026DOJ/FBI. (2026, March 19). Case 1:26-mj-00683-CDA: Affidavit in Support of Seizure Warrant: In the Matter of the Seizure of Domain Names Justicehomeland[.]org; karmabelow80[.]org; handala-hack[.]to; and handala-redwatned[.]to. Retrieved Ap…
DOJ FIN7 Aug 2018Department of Justice. (2018, August 01). HOW FIN7 ATTACKED AND STOLE DATA. Retrieved August 24, 2018.
DOJ GRU Charges 2018U.S. Department of Justice. (2018, October 4). U.S. Charges Russian GRU Officers with International Hacking and Related Influence and Disinformation Operations. Retrieved February 25, 2025.
DOJ GRU Indictment Jul 2018Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.
DOJ Iran Indictments March 2018DOJ. (2018, March 23). U.S. v. Rafatnejad et al . Retrieved February 3, 2021.
DOJ Iran Indictments September 2020DOJ. (2020, September 17). Department of Justice and Partner Departments and Agencies Conduct Coordinated Actions to Disrupt and Deter Iranian Malicious Cyber Activities Targeting the United States and the Broader International Community. …
DOJ KVBotnet 2024US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.
DOJ Lazarus Sony 2018Department of Justice. (2018, September 6). Criminal Complaint - United States of America v. PARK JIN HYOK. Retrieved March 29, 2019.
DOJ North Korea Indictment Feb 2021Department of Justice. (2021, February 17). Three North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyberattacks and Financial Crimes Across the Globe. Retrieved June 9, 2021.
DOJ Russia Targeting Critical Infrastructure March 2022Department of Justice. (2022, March 24). Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide. Retrieved April 5, 2022.
DOJ-DPRK HeistDepartment of Justice. (2021). 3 North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyber-attacks and Financial Crimes Across the Globe. Retrieved August 18, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.