Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Google Election Threats October 2020 | Huntley, S. (2020, October 16). How We're Tackling Evolving Online Threats. Retrieved March 24, 2021. |
| Google Ensuring Your Information is Safe | Google. (2011, June 1). Ensuring your information is safe online. Retrieved April 1, 2022. |
| Google Federating GC | Google. (n.d.). Federating Google Cloud with Active Directory. Retrieved March 13, 2020. |
| Google Instances Resource | Google. (n.d.). Rest Resource: instance. Retrieved March 3, 2020. |
| Google Iran Threats October 2021 | Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023. |
| Google Mandiant Storm-0501 Sabbath Ransomware November 2021 | Tyler McLellan, Brandan Schondorfer. (2021, November 29). Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again. Retrieved October 19, 2025. |
| Google Salesforce JUN 2025 | Google Threat Intelligence Group. (2025, June 4). The Cost of a Call: From Voice Phishing to Data Extortion. Retrieved October 22, 2025. |
| Google TAG COLDRIVER January 2024 | Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024. |
| Google TAG Lazarus Jan 2021 | Weidemann, A. (2021, January 25). New campaign targeting security researchers. Retrieved December 20, 2021. |
| Google TAG Ukraine Threat Landscape March 2022 | Huntley, S. (2022, March 7). An update on the threat landscape. Retrieved March 16, 2022. |
| Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025 | Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025. |
| Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024 | Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Explo… |
| Google UNC5221 Ivanti April 2025 | John Wolfram, Michael Edie, Jacob Thompson, Matt Lin, Josh Murchie. (2025, April 3). Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457). Retrieved April 13, 2026. |
| Google UNC5221 Ivanti January 2025 | John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026. |
| Google VPC Overview | Google. (2019, September 23). Virtual Private Cloud (VPC) network overview. Retrieved October 6, 2019. |
| Google Workspace Global Access List | Google. (n.d.). Retrieved March 16, 2021. |
| Google XLoader 2017 | Nart Villeneuve, Randi Eitzman, Sandor Nemes & Tyler Dean, Google Cloud. (2017, October 5). Significant FormBook Distribution Campaigns Impacting the U.S. and South Korea. Retrieved March 11, 2025. |
| Google-Vishing24 | Emily Astranova, Pascal Issa. (2024, July 23). Whose Voice Is It Anyway? AI-Powered Voice Spoofing for Next-Gen Vishing Attacks. Retrieved March 18, 2025. |
| Google_SHOracle_Jun2026 | Mandiant, Google Threat Intelligence Group. (2026, June 11). ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit. Retrieved June 11, 2026. |
| Google_WinRAR_vuln_2023 | Morgan, K. (2023, October 18). Government-backed actors exploiting WinRAR vulnerability. Retrieved July 19, 2024. |
| GovCERT Carbon May 2016 | GovCERT. (2016, May 23). Technical Report about the Espionage Case at RUAG. Retrieved November 7, 2018. |
| Graeber 2014 | Graeber, M. (2014, October). Analysis of Malicious Security Support Provider DLLs. Retrieved March 1, 2017. |
| GrimBlog UsernameEnum | GrimHacker. (2017, July 24). Office365 ActiveSync Username Enumeration. Retrieved December 9, 2021. |
| Group IB APT 41 June 2021 | Rostovcev, N. (2021, June 10). Big airline heist APT41 likely behind a third-party attack on Air India. Retrieved August 26, 2021. |
| Group IB Cobalt Aug 2017 | Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018. |
| Group IB GrimAgent July 2021 | Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024. |
| Group IB RTM August 2019 | Skulkin, O. (2019, August 5). Following the RTM Forensic examination of a computer infected with a banking trojan. Retrieved May 11, 2020. |
| Group IB Ransomware May 2020 | Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020. |
| Group IB Ransomware September 2020 | Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024. |
| Group IB Silence Aug 2019 | Group-IB. (2019, August). Silence 2.0: Going Global. Retrieved May 5, 2020. |
| Group IB Silence Sept 2018 | Group-IB. (2018, September). Silence: Moving Into the Darkside. Retrieved May 5, 2020. |
| Group-IB Anunak | Group-IB and Fox-IT. (2014, December). Anunak: APT against financial institutions. Retrieved April 20, 2016. |
| Group-IB RansomHub FEB 2025 | Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025. |
| Guardian Grand Theft Auto Leak 2022 | Keza MacDonald, Keith Stuart and Alex Hern. (2022, September 19). Grand Theft Auto 6 leak: who hacked Rockstar and what was stolen?. Retrieved August 30, 2024. |
| Guardio Etherhiding 2023 | Nati Tal and Oleg Zaytsev. (2023, October 13). “EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts. Retrieved May 22, 2025. |
| Guidepoint SUPERNOVA Dec 2020 | Riley, W. (2020, December 1). SUPERNOVA SolarWinds .NET Webshell Analysis. Retrieved February 18, 2021. |
| Gummy Browsers Targeted Browser Spoofing against State-of-the-Art Fingerprinting Techniques | Zengrui Liu, Prakash Shrestha, and Nitesh Saxena. (2021, October 19). Retrieved April 15, 2026. |
| HC3 Qilin Threat Profile JUN 2024 | Health Sector Cybersecurity Coordination Center. (2024, June 18). Qilin, aka Agenda Ransomware. Retrieved September 26, 2025. |
| HIPAA Journal S3 Breach, 2017 | HIPAA Journal. (2017, October 11). 47GB of Medical Records and Test Results Found in Unsecured Amazon S3 Bucket. Retrieved October 4, 2019. |
| HP RaspberryRobin 2024 | Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024. |
| HP SVCReady Jun 2022 | Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022. |
| HTML Smuggling Menlo Security 2020 | Subramanian, K. (2020, August 18). New HTML Smuggling Attack Alert: Duri. Retrieved May 20, 2021. |
| Hacker News GitHub Abuse 2024 | Dvir Sasson. (2024, May 13). GitHub Abuse Flaw Shows Why We Can't Shrug Off Abuse Vulnerabilities in Security. Retrieved March 31, 2025. |
| Hacker News LuckyMouse June 2018 | Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018. |
| HackerNews IndigoZebra July 2021 | Lakshmanan, R.. (2021, July 1). IndigoZebra APT Hacking Campaign Targets the Afghan Government. Retrieved September 24, 2021. |
| HackersArise Email | Hackers Arise. (n.d.). Email Scraping and Maltego. Retrieved October 20, 2020. |
| Hakobyan 2009 | Hakobyan, A. (2009, January 8). FDump - Dumping File Sectors Directly from Disk using Logical Offsets. Retrieved November 12, 2014. |
| Halcyon AWS Ransomware 2025 | Halcyon RISE Team. (2025, January 13). Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C. Retrieved March 18, 2025. |
| Halcyon Qilin.B OCT 2024 | Halcyon RISE Team. (2024, October 24). New Qilin.B Ransomware Variant Boasts Enhanced Encryption and Defense Evasion. Retrieved September 26, 2025. |
| Halcyon_CloakRansomware_Dec2024 | Halcyon RISE Team. (2024, December 12). Cloak Ransomware Variant Exhibits Advanced Persistence, Evasion and VHD Extraction Capabilities. Retrieved December 23, 2025. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.