ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Google Election Threats October 2020Huntley, S. (2020, October 16). How We're Tackling Evolving Online Threats. Retrieved March 24, 2021.
Google Ensuring Your Information is SafeGoogle. (2011, June 1). Ensuring your information is safe online. Retrieved April 1, 2022.
Google Federating GCGoogle. (n.d.). Federating Google Cloud with Active Directory. Retrieved March 13, 2020.
Google Instances ResourceGoogle. (n.d.). Rest Resource: instance. Retrieved March 3, 2020.
Google Iran Threats October 2021Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023.
Google Mandiant Storm-0501 Sabbath Ransomware November 2021Tyler McLellan, Brandan Schondorfer. (2021, November 29). Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again. Retrieved October 19, 2025.
Google Salesforce JUN 2025Google Threat Intelligence Group. (2025, June 4). The Cost of a Call: From Voice Phishing to Data Extortion. Retrieved October 22, 2025.
Google TAG COLDRIVER January 2024Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.
Google TAG Lazarus Jan 2021Weidemann, A. (2021, January 25). New campaign targeting security researchers. Retrieved December 20, 2021.
Google TAG Ukraine Threat Landscape March 2022Huntley, S. (2022, March 7). An update on the threat landscape. Retrieved March 16, 2022.
Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.
Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Explo…
Google UNC5221 Ivanti April 2025John Wolfram, Michael Edie, Jacob Thompson, Matt Lin, Josh Murchie. (2025, April 3). Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457). Retrieved April 13, 2026.
Google UNC5221 Ivanti January 2025John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.
Google VPC OverviewGoogle. (2019, September 23). Virtual Private Cloud (VPC) network overview. Retrieved October 6, 2019.
Google Workspace Global Access ListGoogle. (n.d.). Retrieved March 16, 2021.
Google XLoader 2017Nart Villeneuve, Randi Eitzman, Sandor Nemes & Tyler Dean, Google Cloud. (2017, October 5). Significant FormBook Distribution Campaigns Impacting the U.S. and South Korea. Retrieved March 11, 2025.
Google-Vishing24Emily Astranova, Pascal Issa. (2024, July 23). Whose Voice Is It Anyway? AI-Powered Voice Spoofing for Next-Gen Vishing Attacks. Retrieved March 18, 2025.
Google_SHOracle_Jun2026Mandiant, Google Threat Intelligence Group. (2026, June 11). ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit. Retrieved June 11, 2026.
Google_WinRAR_vuln_2023Morgan, K. (2023, October 18). Government-backed actors exploiting WinRAR vulnerability. Retrieved July 19, 2024.
GovCERT Carbon May 2016GovCERT. (2016, May 23). Technical Report about the Espionage Case at RUAG. Retrieved November 7, 2018.
Graeber 2014Graeber, M. (2014, October). Analysis of Malicious Security Support Provider DLLs. Retrieved March 1, 2017.
GrimBlog UsernameEnumGrimHacker. (2017, July 24). Office365 ActiveSync Username Enumeration. Retrieved December 9, 2021.
Group IB APT 41 June 2021Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021.
Group IB Cobalt Aug 2017Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018.
Group IB GrimAgent July 2021Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.
Group IB RTM August 2019Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020.
Group IB Ransomware May 2020Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.
Group IB Ransomware September 2020Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.
Group IB Silence Aug 2019Group-IB. (2019, August). Silence 2.0: Going Global. Retrieved May 5, 2020.
Group IB Silence Sept 2018Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020.
Group-IB AnunakGroup-IB and Fox-IT. (2014, December). Anunak: APT against financial institutions. Retrieved April 20, 2016.
Group-IB RansomHub FEB 2025Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.
Guardian Grand Theft Auto Leak 2022Keza MacDonald, Keith Stuart and Alex Hern. (2022, September 19). Grand Theft Auto 6 leak: who hacked Rockstar and what was stolen?. Retrieved August 30, 2024.
Guardio Etherhiding 2023Nati Tal and Oleg Zaytsev. (2023, October 13). “EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts. Retrieved May 22, 2025.
Guidepoint SUPERNOVA Dec 2020Riley, W. (2020, December 1). SUPERNOVA SolarWinds .NET Webshell Analysis. Retrieved February 18, 2021.
Gummy Browsers Targeted Browser Spoofing against State-of-the-Art Fingerprinting TechniquesZengrui Liu, Prakash Shrestha, and Nitesh Saxena. (2021, October 19). Retrieved April 15, 2026.
HC3 Qilin Threat Profile JUN 2024Health Sector Cybersecurity Coordination Center. (2024, June 18). Qilin, aka Agenda Ransomware. Retrieved September 26, 2025.
HIPAA Journal S3 Breach, 2017HIPAA Journal. (2017, October 11). 47GB of Medical Records and Test Results Found in Unsecured Amazon S3 Bucket. Retrieved October 4, 2019.
HP RaspberryRobin 2024Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.
HP SVCReady Jun 2022Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.
HTML Smuggling Menlo Security 2020Subramanian, K. (2020, August 18). New HTML Smuggling Attack Alert: Duri. Retrieved May 20, 2021.
Hacker News GitHub Abuse 2024Dvir Sasson. (2024, May 13). GitHub Abuse Flaw Shows Why We Can't Shrug Off Abuse Vulnerabilities in Security. Retrieved March 31, 2025.
Hacker News LuckyMouse June 2018Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.
HackerNews IndigoZebra July 2021Lakshmanan, R.. (2021, July 1). IndigoZebra APT Hacking Campaign Targets the Afghan Government. Retrieved September 24, 2021.
HackersArise EmailHackers Arise. (n.d.). Email Scraping and Maltego. Retrieved October 20, 2020.
Hakobyan 2009Hakobyan, A. (2009, January 8). FDump - Dumping File Sectors Directly from Disk using Logical Offsets. Retrieved November 12, 2014.
Halcyon AWS Ransomware 2025Halcyon RISE Team. (2025, January 13). Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C. Retrieved March 18, 2025.
Halcyon Qilin.B OCT 2024Halcyon RISE Team. (2024, October 24). New Qilin.B Ransomware Variant Boasts Enhanced Encryption and Defense Evasion. Retrieved September 26, 2025.
Halcyon_CloakRansomware_Dec2024Halcyon RISE Team. (2024, December 12). Cloak Ransomware Variant Exhibits Advanced Persistence, Evasion and VHD Extraction Capabilities. Retrieved December 23, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.