Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| ELC Extended Attributes | Howard Oakley. (2020, October 24). There's more to files than data: Extended Attributes. Retrieved October 12, 2021. |
| ELC Running at startup | hoakley. (2018, May 22). Running at startup: when to use a Login Item or a LaunchAgent/LaunchDaemon. Retrieved October 5, 2021. |
| ELF Injection May 2009 | O'Neill, R. (2009, May). Modern Day ELF Runtime infection via GOT poisoning. Retrieved March 15, 2020. |
| ENSIL AtomBombing Oct 2016 | Liberman, T. (2016, October 27). ATOMBOMBING: BRAND NEW CODE INJECTION FOR WINDOWS. Retrieved December 8, 2017. |
| ESEST Black Energy Jan 2016 | Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016. |
| ESET Attor Oct 2019 | Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020. |
| ESET BackdoorDiplomacy Jun 2021 | Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021 |
| ESET Bad Rabbit | M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021. |
| ESET BlackEnergy Jan 2016 | Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry . Retrieved June 10, 2020. |
| ESET Buhtrap and Buran April 2019 | ESET Research. (2019, April 30). Buhtrap backdoor and Buran ransomware distributed via major advertising platform. Retrieved May 11, 2020. |
| ESET CaddyWiper March 2022 | ESET. (2022, March 15). CaddyWiper: New wiper malware discovered in Ukraine. Retrieved March 23, 2022. |
| ESET Carberp March 2012 | Matrosov, A., Rodionov, E., Volkov, D., Harley, D. (2012, March 2). Win32/Carberp When You’re in a Black Hole, Stop Digging. Retrieved July 15, 2020. |
| ESET Carbon Mar 2017 | ESET. (2017, March 30). Carbon Paper: Peering into Turla’s second stage backdoor. Retrieved November 7, 2018. |
| ESET Casbaneiro Oct 2019 | ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021. |
| ESET ComRAT May 2020 | Faou, M. (2020, May). From Agent.btz to ComRAT v4: A ten-year journey. Retrieved June 15, 2020. |
| ESET Contagious Interview BeaverTail InvisibleFerret February 2025 | Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025. |
| ESET Crutch December 2020 | Faou, M. (2020, December 2). Turla Crutch: Keeping the “back door” open. Retrieved December 4, 2020. |
| ESET DazzleSpy Jan 2022 | M.Léveillé, M., Cherepanov, A.. (2022, January 25). Watering hole deploys new macOS malware, DazzleSpy, in Asia. Retrieved May 6, 2022. |
| ESET Dukes October 2019 | Faou, M., Tartare, M., Dupuy, T. (2019, October). OPERATION GHOST. Retrieved September 23, 2020. |
| ESET DynoWiper JAN 2026 | ESET. (2026, January 30). Russian Sandworm group attacks energy company in Poland with DynoWiper, ESET Research discovers. Retrieved April 22, 2026. |
| ESET DynoWiper Update JAN 2026 | ESET. (2026, January 30). DynoWiper update: Technical analysis and attribution. Retrieved April 22, 2026. |
| ESET Ebury Feb 2014 | M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019. |
| ESET Ebury May 2024 | Marc-Etienne M.Léveillé. (2024, May 1). Ebury is alive but unseen. Retrieved May 21, 2024. |
| ESET Ebury Oct 2017 | Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021. |
| ESET Embargo Ransomware October 2024 | Jan Holman, Tomas Zvara. (2024, October 23). Embargo ransomware: Rock’n’Rust. Retrieved October 19, 2025. |
| ESET Emotet Dec 2018 | Perez, D.. (2018, December 28). Analysis of the latest Emotet propagation campaign. Retrieved April 16, 2019. |
| ESET EvasivePanda 2023 | Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024. |
| ESET EvasivePanda 2024 | Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024. |
| ESET EvilNum July 2020 | Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021. |
| ESET Exchange Mar 2021 | Faou, M., Tartare, M., Dupuy, T. (2021, March 10). Exchange servers under siege from at least 10 APT groups. Retrieved May 21, 2021. |
| ESET FinFisher Jan 2018 | Kafka, F. (2018, January). ESET's Guide to Deobfuscating and Devirtualizing FinFisher. Retrieved August 12, 2019. |
| ESET FontOnLake Analysis 2021 | Vladislav Hrčka. (2021, January 1). FontOnLake. Retrieved September 27, 2023. |
| ESET ForSSHe December 2018 | Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020. |
| ESET Gamaredon June 2020 | Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020. |
| ESET Gamaredon Sept2024 | Rusnák, Z. (2024, September 26). Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023. Retrieved October 30, 2024. |
| ESET Gazer Aug 2017 | ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017. |
| ESET Gelsemium June 2021 | Dupuy, T. and Faou, M. (2021, June). Gelsemium. Retrieved November 30, 2021. |
| ESET Grandoreiro April 2020 | ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020. |
| ESET GreyEnergy Oct 2018 | Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018. |
| ESET Hermetic Wiper February 2022 | ESET. (2022, February 24). HermeticWiper: New data wiping malware hits Ukraine. Retrieved March 25, 2022. |
| ESET Hermetic Wizard March 2022 | ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022. |
| ESET HiddenFace 2024 | Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026. |
| ESET IIS Malware 2021 | Hromcová, Z., Cherepanov, A. (2021). Anatomy of Native IIS Malware. Retrieved September 9, 2021. |
| ESET Industroyer | Anton Cherepanov. (2017, June 12). Win32/Industroyer: A new threat for industrial controls systems. Retrieved December 18, 2020. |
| ESET InvisiMole June 2018 | Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018. |
| ESET InvisiMole June 2020 | Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020. |
| ESET Kobalos Feb 2021 | M.Leveille, M., Sanmillan, I. (2021, February 2). Kobalos – A complex Linux threat to high performance computing infrastructure. Retrieved August 24, 2021. |
| ESET Kobalos Jan 2021 | M.Leveille, M., Sanmillan, I. (2021, January). A WILD KOBALOS APPEARS Tricksy Linux malware goes after HPCs. Retrieved August 24, 2021. |
| ESET Lazarus Jun 2020 | Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021. |
| ESET Lazarus KillDisk April 2018 | Kálnai, P., Cherepanov A. (2018, April 03). Lazarus KillDisks Central American casino. Retrieved May 17, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.