ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Inversecos Timestomping 2022Lina Lau. (2022, April 28). Defence Evasion Technique: Timestomping Detection – NTFS Forensics. Retrieved September 30, 2024.
Invictus IR Cloud Ransomware 2024Invictus IR. (2024, January 11). Ransomware in the cloud. Retrieved August 5, 2024.
Invictus IR DangerDev 2024Invictus Incident Response. (2024, January 31). The curious case of [email protected]. Retrieved March 19, 2024.
Invincea XTunnelBelcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.
Invisible Prompt Injection - Trend MicroIan Ch Lui. (2025, January 22). Invisible Prompt Injection: A Threat to AI Security. Retrieved April 21, 2026.
Invoke-DOSfuscationBohannon, D. (2018, March 19). Invoke-DOSfuscation. Retrieved March 17, 2023.
Invoke-ObfuscationBohannon, D. (2016, September 24). Invoke-Obfuscation. Retrieved March 17, 2023.
IranThreats Kittens Dec 2017Iran Threats . (2017, December 5). Flying Kitten to Rocket Kitten, A Case of Ambiguity and Shared Code. Retrieved May 28, 2020.
IronNet BlackTech Oct 2021Demboski, M., et al. (2021, October 26). China cyber attacks: the current threat landscape. Retrieved March 25, 2022.
Irongeek Sims BSides 2017Stephen Sims. (2017, April 30). Microsoft Patch Analysis for Exploitation. Retrieved October 16, 2020.
IssueMakersLab Andariel GoldenAxe May 2017IssueMakersLab. (2017, May 1). Operation GoldenAxe. Retrieved September 12, 2024.
IzyKnows auditd threat detection 2022IzySec. (2022, January 26). Linux auditd for Threat Detection. Retrieved September 29, 2023.
JPCERT ChChes Feb 2017Nakamura, Y.. (2017, February 17). ChChes - Malware that Communicates with C&C Servers Using Cookie Headers. Retrieved November 17, 2024.
JPCERT MirrorFace JUL 2024Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
JPCERT SPAWNCHIMERA Ivanti February 2025Yuma Masubuchi. (2025, February 20). SPAWNCHIMERA Malware: The Chimera Spawning from Ivanti Connect Secure Vulnerability. Retrieved April 17, 2026.
JPCert BlackTech Malware September 2019Tomonaga, S.. (2019, September 18). Malware Used by BlackTech after Network Intrusion. Retrieved May 6, 2020.
JPCert Blog Laz Subgroups 2025佐々木勇人 Hayato Sasaki. (2025, March 25). Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup. Retrieved August 25, 2025.
JPCert PLEAD Downloader June 2018Tomonaga, S. (2018, June 8). PLEAD Downloader Used by BlackTech. Retrieved May 6, 2020.
JPCert TSCookie March 2018Tomonaga, S. (2018, March 6). Malware “TSCookie”. Retrieved May 6, 2020.
JScrip May 2018Microsoft. (2018, May 31). Translating to JScript. Retrieved June 23, 2020.
Jacobsen 2014Jacobsen, K. (2014, May 16). Lateral Movement with PowerShell[slides]. Retrieved November 12, 2014.
JamPlus manualPerforce Software, Inc.. (n.d.). JamPlus manual: Quick Start Guide. Retrieved March 21, 2025.
James TermServ DLLJames. (2019, July 14). @James_inthe_box. Retrieved September 12, 2024.
Jamf User Password PoliciesHolland, J. (2016, January 25). User password policies on non AD machines. Retrieved April 5, 2018.
JanicabThomas. (2013, July 15). New signed malware called Janicab. Retrieved July 17, 2017.
Joe Sec NymaimJoe Security. (2016, April 21). Nymaim - evading Sandboxes with API hammering. Retrieved September 30, 2021.
Joe Sec TrickbotJoe Security. (2020, July 13). TrickBot's new API-Hammering explained. Retrieved September 30, 2021.
JoeSecurity Egregor 2020Joe Security. (n.d.). Analysis Report fasm.dll. Retrieved November 17, 2024.
John Stawinski PyTorch Supply Chain Attack 2024John Stawinski IV. (2024, January 11). Playing with Fire – How We Executed a Critical Supply Chain Attack on PyTorch. Retrieved May 22, 2025.
Joint CSA AvosLocker Mar 2022FBI, FinCEN, Treasury. (2022, March 17). Indicators of Compromise Associated with AvosLocker Ransomware. Retrieved January 11, 2023.
Joint Cybersecurity Advisory AA23-129A Snake Malware May 2023FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023.
Joint Cybersecurity Advisory LockBit 3.0 MAR 2023FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.
Joint Cybersecurity Advisory LockBit JUN 2023CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.
Joint Cybersecurity Advisory Volt Typhoon June 2023NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.
Journey into IR ZeroAccess NTFS EAHarrell, C. (2012, December 11). Extracting ZeroAccess from NTFS Extended Attributes. Retrieved June 3, 2016.
JumpCloud Conditional Access PoliciesJumpCloud. (n.d.). Get Started: Conditional Access Policies. Retrieved January 2, 2024.
Juniper IcedID June 2020Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020.
Juniper Netscreen of the DeadGraeme Neilson . (2009, August). Juniper Netscreen of the Dead. Retrieved October 20, 2020.
Juniper Networks ESXi Backdoor 2022Asher Langton. (2022, December 9). A Custom Python Backdoor for VMWare ESXi Servers. Retrieved March 26, 2025.
Juniper RedPenguin MAR 2025Juniper Networks, Cybersecurity R&D. (2025, March 11). The RedPenguin Malware Incident. Retrieved June 24, 2025.
Juniper Traffic MirroringJuniper. (n.d.). Understanding Port Mirroring on EX2200, EX3200, EX3300, EX4200, EX4500, EX4550, EX6200, and EX8200 Series Switches. Retrieved October 19, 2020.
Justice GRU 2024Office of Public Affairs. (2024, February 15). Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the General Staff (GRU). Retrieved March 28, 2024.
KISA Operation MuzabiKISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.
Kali HydraKali. (2014, February 18). THC-Hydra. Retrieved November 2, 2017.
Kali RedsnarfNCC Group PLC. (2016, November 1). Kali Redsnarf. Retrieved December 11, 2017.
Kandji Cuckoo April 2024Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024.
Kansa Service related collectorsHull, D.. (2014, May 3). Kansa: Service related collectors and analysis. Retrieved October 10, 2019.
Kaspersky 3CX Gopuram 2023Georgy Kucherin, Vasily Berdnikov, Vilen Kamalov. (2023, April 3). Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack. Retrieved August 25, 2025.
Kaspersky APT Trends Q1 2020Global Research and Analysis Team. (2020, April 30). APT trends report Q1 2020. Retrieved September 19, 2022.
Kaspersky APT Trends Q1 April 2021GReAT . (2021, April 27). APT trends report Q1 2021. Retrieved June 6, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.