ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Kaspersky ToddyCat June 2022Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.
Kaspersky Tomiris Sep 2021Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021.
Kaspersky Transparent Tribe August 2020Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.
Kaspersky TurlaKaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.
Kaspersky Turla Aug 2014Kaspersky Lab's Global Research & Analysis Team. (2014, August 06). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroboros. Retrieved November 7, 2018.
Kaspersky Turla Penquin December 2014Baumgartner, K. and Raiu, C. (2014, December 8). The ‘Penquin’ Turla. Retrieved March 11, 2021.
Kaspersky WIRTE November 2021Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.
Kaspersky Winnti April 2013Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.
Kaspersky Winnti June 2015Tarakanov, D. (2015, June 22). Games are over: Winnti is now targeting pharmaceutical companies. Retrieved January 14, 2016.
Kaspersky evil twinAO Kaspersky Lab. (n.d.). Evil twin attacks and how to prevent them. Retrieved September 17, 2024.
Kaspersky-maskingDedenok, Roman. (2023, December 12). How cybercriminals disguise URLs. Retrieved January 17, 2024.
KasperskyCarbanakKaspersky Lab's Global Research & Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved March 27, 2017.
KekeoBenjamin Delpy. (n.d.). Kekeo. Retrieved October 4, 2021.
Kerberos GNU/LinuxAdepts of 0xCC. (2021, January 28). The Kerberos Credential Thievery Compendium (GNU/Linux). Retrieved September 17, 2024.
Kersten Akira 2023Max Kersten & Alexandre Mundo. (2023, November 29). Akira Ransomware. Retrieved April 4, 2024.
Kettle CSV DDE Aug 2014Kettle, J. (2014, August 29). Comma Separated Vulnerabilities. Retrieved November 22, 2017.
Kevin Mandia Statement to US Senate Committee on IntelligenceKevin Mandia. (2017, March 30). Prepared Statement of Kevin Mandia, CEO of FireEye, Inc. before the United States Senate Select Committee on Intelligence. Retrieved April 19, 2019.
Keychain Decryption PasswareYana Gourenko. (n.d.). A Deep Dive into Apple Keychain Decryption. Retrieved April 13, 2022.
Keychain Services AppleApple. (n.d.). Keychain Services. Retrieved April 11, 2022.
Keyctl-unmaskMark Manning. (2020, July 23). Keyctl-unmask: "Going Florida" on The State Of Containerizing Linux Keyrings. Retrieved July 6, 2022.
Kickstart Apple Remote Desktop commandsApple. (n.d.). Use the kickstart command-line utility in Apple Remote Desktop. Retrieved September 23, 2021.
KillDisk RansomwareCatalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021.
Killing IOS diversity mythAng Cui, Jatin Kataria, Salvatore J. Stolfo. (2011, August). Killing the myth of Cisco IOS diversity: recent advances in reliable shellcode design. Retrieved October 20, 2020.
Killing the myth of Cisco IOS rootkitsSebastian 'topo' Muñiz. (2008, May). Killing the myth of Cisco IOS rootkits. Retrieved October 20, 2020.
Kimsuky MalwarebytesHossein Jazi. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved January 10, 2024.
Klein Active Setup 2010Klein, H. (2010, April 22). Active Setup Explained. Retrieved December 18, 2020.
Koi GlassWorm Rust December 2025Lotan Sery. (2025, December 10). GlassWorm Goes Native: Same Infrastructure, Hardened Delivery. Retrieved April 10, 2026.
Koi Glassworm Extensions November 2025Idan Dardikman, Yuval Ronen, Lotan Sery. (2025, November 6). GlassWorm Returns: New Wave Strikes as We Expose Attacker Infrastructure. Retrieved April 10, 2026.
Koi Glassworm InvisibleCode October 2025Idan Dardikman. (2025, October 18). GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace. Retrieved April 10, 2026.
Koi Glassworm New Tricks December 2025Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.
Korean FSI TA505 2020Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.
Krebs 3cx overview 2023Brian Krebs. (2023, April 20). 3CX Breach Was a Double Supply Chain Compromise. Retrieved May 22, 2025.
Krebs Access Brokers Fortune 500Brian Krebs. (2012, October 22). Service Sells Access to Fortune 500 Firms. Retrieved March 10, 2023.
Krebs AdobeBrian Krebs. (2013, October 3). Adobe To Announce Source Code, Customer Data Breach. Retrieved May 17, 2021.
Krebs Capital One August 2019Krebs, B.. (2019, August 19). What We Can Learn from the Capital One Hack. Retrieved March 25, 2020.
Krebs DNS Hijack 2019Brian Krebs. (2019, February 18). A Deep Dive on the Recent Widespread DNS Hijacking Attacks. Retrieved February 14, 2022.
Krebs Discord Bookmarks 2023Brian Krebs. (2023, May 30). Discord Admins Hacked by Malicious Bookmarks. Retrieved January 2, 2024.
Krebs-AnnaBrian Krebs. (2017, January 18). Who is Anna-Senpai, the Mirai Worm Author?. Retrieved May 15, 2017.
Krebs-BazaarBrian Krebs. (2016, October 31). Hackforums Shutters Booter Service Bazaar. Retrieved May 15, 2017.
Krebs-BooterBrian Krebs. (2016, October 27). Are the Days of “Booter” Services Numbered?. Retrieved May 15, 2017.
Kroll Qakbot June 2020Sette, N. et al. (2020, June 4). Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks. Retrieved September 27, 2021.
Kroll RawPOS Jan 2017Nesbit, B. and Ackerman, D. (2017, January). Malware Analysis Report - RawPOS Malware: Deconstructing an Intruder’s Toolkit. Retrieved October 4, 2017.
Kroll RedLine Stealer August 2024George Glass. (2024, August 14). REDLINESTEALER Malware Driving the Initial Access Broker Market. Retrieved September 17, 2025.
Kroll Royal Deep Dive February 2023Iacono, L. and Green, S. (2023, February 13). Royal Ransomware Deep Dive. Retrieved March 30, 2023.
Kubectl Exec Get ShellThe Kubernetes Authors. (n.d.). Get a Shell to a Running Container. Retrieved March 29, 2021.
Kubeflow PipelinesThe Kubeflow Authors. (n.d.). Overview of Kubeflow Pipelines. Retrieved March 29, 2021.
Kuberentes ABACKuberenets. (n.d.). Using ABAC Authorization. Retrieved July 14, 2023.
Kubernetes APIThe Kubernetes Authors. (n.d.). The Kubernetes API. Retrieved March 29, 2021.
Kubernetes Assigning Pods to NodesKubernetes. (n.d.). Assigning Pods to Nodes. Retrieved February 15, 2024.
Kubernetes CronJobThe Kubernetes Authors. (n.d.). Kubernetes CronJob. Retrieved March 29, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.