Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Kaspersky ToddyCat June 2022 | Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024. |
| Kaspersky Tomiris Sep 2021 | Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021. |
| Kaspersky Transparent Tribe August 2020 | Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021. |
| Kaspersky Turla | Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014. |
| Kaspersky Turla Aug 2014 | Kaspersky Lab's Global Research & Analysis Team. (2014, August 06). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroboros. Retrieved November 7, 2018. |
| Kaspersky Turla Penquin December 2014 | Baumgartner, K. and Raiu, C. (2014, December 8). The ‘Penquin’ Turla. Retrieved March 11, 2021. |
| Kaspersky WIRTE November 2021 | Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022. |
| Kaspersky Winnti April 2013 | Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017. |
| Kaspersky Winnti June 2015 | Tarakanov, D. (2015, June 22). Games are over: Winnti is now targeting pharmaceutical companies. Retrieved January 14, 2016. |
| Kaspersky evil twin | AO Kaspersky Lab. (n.d.). Evil twin attacks and how to prevent them. Retrieved September 17, 2024. |
| Kaspersky-masking | Dedenok, Roman. (2023, December 12). How cybercriminals disguise URLs. Retrieved January 17, 2024. |
| KasperskyCarbanak | Kaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017. |
| Kekeo | Benjamin Delpy. (n.d.). Kekeo. Retrieved October 4, 2021. |
| Kerberos GNU/Linux | Adepts of 0xCC. (2021, January 28). The Kerberos Credential Thievery Compendium (GNU/Linux). Retrieved September 17, 2024. |
| Kersten Akira 2023 | Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024. |
| Kettle CSV DDE Aug 2014 | Kettle, J. (2014, August 29). Comma Separated Vulnerabilities. Retrieved November 22, 2017. |
| Kevin Mandia Statement to US Senate Committee on Intelligence | Kevin Mandia. (2017, March 30). Prepared Statement of Kevin Mandia, CEO of FireEye, Inc. before the United States Senate Select Committee on Intelligence. Retrieved April 19, 2019. |
| Keychain Decryption Passware | Yana Gourenko. (n.d.). A Deep Dive into Apple Keychain Decryption. Retrieved April 13, 2022. |
| Keychain Services Apple | Apple. (n.d.). Keychain Services. Retrieved April 11, 2022. |
| Keyctl-unmask | Mark Manning. (2020, July 23). Keyctl-unmask: "Going Florida" on The State Of Containerizing Linux Keyrings. Retrieved July 6, 2022. |
| Kickstart Apple Remote Desktop commands | Apple. (n.d.). Use the kickstart command-line utility in Apple Remote Desktop. Retrieved September 23, 2021. |
| KillDisk Ransomware | Catalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021. |
| Killing IOS diversity myth | Ang Cui, Jatin Kataria, Salvatore J. Stolfo. (2011, August). Killing the myth of Cisco IOS diversity: recent advances in reliable shellcode design. Retrieved October 20, 2020. |
| Killing the myth of Cisco IOS rootkits | Sebastian 'topo' Muñiz. (2008, May). Killing the myth of Cisco IOS rootkits. Retrieved October 20, 2020. |
| Kimsuky Malwarebytes | Hossein Jazi. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved January 10, 2024. |
| Klein Active Setup 2010 | Klein, H. (2010, April 22). Active Setup Explained. Retrieved December 18, 2020. |
| Koi GlassWorm Rust December 2025 | Lotan Sery. (2025, December 10). GlassWorm Goes Native: Same Infrastructure, Hardened Delivery. Retrieved April 10, 2026. |
| Koi Glassworm Extensions November 2025 | Idan Dardikman, Yuval Ronen, Lotan Sery. (2025, November 6). GlassWorm Returns: New Wave Strikes as We Expose Attacker Infrastructure. Retrieved April 10, 2026. |
| Koi Glassworm InvisibleCode October 2025 | Idan Dardikman. (2025, October 18). GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace. Retrieved April 10, 2026. |
| Koi Glassworm New Tricks December 2025 | Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026. |
| Korean FSI TA505 2020 | Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022. |
| Krebs 3cx overview 2023 | Brian Krebs. (2023, April 20). 3CX Breach Was a Double Supply Chain Compromise. Retrieved May 22, 2025. |
| Krebs Access Brokers Fortune 500 | Brian Krebs. (2012, October 22). Service Sells Access to Fortune 500 Firms. Retrieved March 10, 2023. |
| Krebs Adobe | Brian Krebs. (2013, October 3). Adobe To Announce Source Code, Customer Data Breach. Retrieved May 17, 2021. |
| Krebs Capital One August 2019 | Krebs, B.. (2019, August 19). What We Can Learn from the Capital One Hack. Retrieved March 25, 2020. |
| Krebs DNS Hijack 2019 | Brian Krebs. (2019, February 18). A Deep Dive on the Recent Widespread DNS Hijacking Attacks. Retrieved February 14, 2022. |
| Krebs Discord Bookmarks 2023 | Brian Krebs. (2023, May 30). Discord Admins Hacked by Malicious Bookmarks. Retrieved January 2, 2024. |
| Krebs-Anna | Brian Krebs. (2017, January 18). Who is Anna-Senpai, the Mirai Worm Author?. Retrieved May 15, 2017. |
| Krebs-Bazaar | Brian Krebs. (2016, October 31). Hackforums Shutters Booter Service Bazaar. Retrieved May 15, 2017. |
| Krebs-Booter | Brian Krebs. (2016, October 27). Are the Days of “Booter” Services Numbered?. Retrieved May 15, 2017. |
| Kroll Qakbot June 2020 | Sette, N. et al. (2020, June 4). Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks. Retrieved September 27, 2021. |
| Kroll RawPOS Jan 2017 | Nesbit, B. and Ackerman, D. (2017, January). Malware Analysis Report - RawPOS Malware: Deconstructing an Intruder’s Toolkit. Retrieved October 4, 2017. |
| Kroll RedLine Stealer August 2024 | George Glass. (2024, August 14). REDLINESTEALER Malware Driving the Initial Access Broker Market. Retrieved September 17, 2025. |
| Kroll Royal Deep Dive February 2023 | Iacono, L. and Green, S. (2023, February 13). Royal Ransomware Deep Dive. Retrieved March 30, 2023. |
| Kubectl Exec Get Shell | The Kubernetes Authors. (n.d.). Get a Shell to a Running Container. Retrieved March 29, 2021. |
| Kubeflow Pipelines | The Kubeflow Authors. (n.d.). Overview of Kubeflow Pipelines. Retrieved March 29, 2021. |
| Kuberentes ABAC | Kuberenets. (n.d.). Using ABAC Authorization. Retrieved July 14, 2023. |
| Kubernetes API | The Kubernetes Authors. (n.d.). The Kubernetes API. Retrieved March 29, 2021. |
| Kubernetes Assigning Pods to Nodes | Kubernetes. (n.d.). Assigning Pods to Nodes. Retrieved February 15, 2024. |
| Kubernetes CronJob | The Kubernetes Authors. (n.d.). Kubernetes CronJob. Retrieved March 29, 2021. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.