ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
MITRE VMware Abuse 2024Lex Crumpton. (2024, May 22). Infiltrating Defenses: Abusing VMware in MITRE’s Cyber Intrusion. Retrieved March 26, 2025.
MMPC ISAPI Filter 2012MMPC. (2012, October 3). Malware signed with the Adobe code signing certificate. Retrieved June 3, 2021.
MRWLabs Office Persistence Add-insKnowles, W. (2017, April 21). Add-In Opportunities for Office Persistence. Retrieved November 17, 2024.
MS17-010 March 2017Microsoft. (2017, March 14). Microsoft Security Bulletin MS17-010 - Critical. Retrieved August 17, 2017.
MSDN Authentication PackagesMicrosoft. (n.d.). Authentication Packages. Retrieved March 1, 2017.
MSDN COM ElevationMicrosoft. (n.d.). The COM Elevation Moniker. Retrieved July 26, 2016.
MSDN ClipboardMicrosoft. (n.d.). About the Clipboard. Retrieved March 29, 2016.
MSDN HTML ApplicationsMicrosoft. (n.d.). HTML Applications. Retrieved October 27, 2017.
MSDN InstallUtilMicrosoft. (n.d.). Installutil.exe (Installer Tool). Retrieved July 1, 2016.
MSDN MSBuildMicrosoft. (n.d.). MSBuild1. Retrieved November 30, 2016.
MSDN RegasmMicrosoft. (n.d.). Regasm.exe (Assembly Registration Tool). Retrieved July 1, 2016.
MSDN RegsvcsMicrosoft. (n.d.). Regsvcs.exe (.NET Services Installation Tool). Retrieved July 1, 2016.
MSDN System TimeMicrosoft. (n.d.). System Time. Retrieved November 25, 2016.
MSDN VBA in OfficeAustin, J. (2017, June 6). Getting Started with VBA in Office. Retrieved July 3, 2017.
MSDN WMIMicrosoft. (n.d.). Windows Management Instrumentation. Retrieved April 27, 2016.
MSFT-AIMicrosoft Threat Intelligence. (2024, February 14). Staying ahead of threat actors in the age of AI. Retrieved March 11, 2024.
MSRC Nobelium June 2021MSRC. (2021, June 25). New Nobelium activity. Retrieved August 4, 2021.
MSTIC DEV-0537 Mar 2022MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.
MSTIC FoggyWeb September 2021Ramin Nafisi. (2021, September 27). FoggyWeb: Targeted NOBELIUM malware leads to persistent backdoor. Retrieved October 4, 2021.
MSTIC NOBELIUM Mar 2021Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021.
MSTIC NOBELIUM May 2021Microsoft Threat Intelligence Center (MSTIC). (2021, May 27). New sophisticated email-based attack from NOBELIUM. Retrieved May 28, 2021.
MSTIC Nobelium Oct 2021Microsoft Threat Intelligence Center. (2021, October 25). NOBELIUM targeting delegated administrative privileges to facilitate broader attacks. Retrieved March 25, 2022.
MSTIC Nobelium Toolset May 2021MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.
MSTIC Octo Tempest Operations October 2023Microsoft. (2023, October 25). Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction. Retrieved March 18, 2024.
MSitPros CMSTP Aug 2017Moe, O. (2017, August 15). Research on CMSTP.exe. Retrieved April 11, 2018.
MWRInfoSecurity Dynamic Hooking 2015Hillman, M. (2015, August 8). Dynamic Hooking Techniques: User Mode. Retrieved December 20, 2017.
Mac Backdoors are backDan Goodin. (2016, July 6). After hiatus, in-the-wild Mac backdoors are suddenly back. Retrieved July 8, 2017.
Mac Forwarding RulesApple. (n.d.). Reply to, forward, or redirect emails in Mail on Mac. Retrieved June 22, 2021.
Mac Time SyncCone, Matt. (2021, January 14). Synchronize your Mac's Clock with a Time Server. Retrieved March 27, 2024.
MacKeeper Bundlore Apr 2019Sushko, O. (2019, April 17). macOS Bundlore: Mac Virus Bypassing macOS Security Features. Retrieved June 30, 2020.
MacOS Email RulesApple. (n.d.). Use rules to manage emails you receive in Mail on Mac. Retrieved June 14, 2021.
MacOS VNC software for Remote DesktopApple Support. (n.d.). Set up a computer running VNC software for Remote Desktop. Retrieved August 18, 2021.
Macro Malware Targets MacsYerko Grbic. (2017, February 14). Macro Malware Targets Macs. Retrieved July 8, 2017.
MagentoCesar Anjos. (2018, May 31). Shell Logins as a Magento Reinfection Vector. Retrieved December 17, 2020.
MagicWebMicrosoft Threat Intelligence Center, Microsoft Detection and Response Team, Microsoft 365 Defender Research Team . (2022, August 24). MagicWeb: NOBELIUM’s post-compromise trick to authenticate as anyone. Retrieved September 28, 2022.
Magnet ForensicsMagnet Forensics. (2020, August 24). Expose Evidence of Timestomping with the NTFS Timestamp Mismatch Artifact. Retrieved June 20, 2024.
Malicious Chrome Extension NumbersJagpal, N., et al. (2015, August). Trends and Lessons from Three Years Fighting Malicious Extensions. Retrieved November 17, 2017.
Malicious Life by CybereasonPhilip Tsukerman. (n.d.). No Win32 Process Needed | Expanding the WMI Lateral Movement Arsenal. Retrieved June 19, 2024.
Malleable-C2-U42Chris Navarrete Durgesh Sangvikar Andrew Guan Yu Fu Yanhui Jia Siddhart Shibiraj. (2022, March 16). Cobalt Strike Analysis and Tutorial: How Malleable C2 Profiles Make Cobalt Strike Difficult to Detect. Retrieved September 24, 2024.
Malware Analysis Report 10135536-GUS-CERT. (2018, February 6). Malware Analysis Report 10135536-G. Retrieved August 15, 2024.
Malware Analysis Report ComRATCISA. (2020, October 29). Malware Analysis Report (AR20-303A) MAR-10310246-2.v1 – PowerShell Script: ComRAT. Retrieved September 30, 2022.
Malware Bytes New AgentTesla variant steals WiFi credentialsHossein Jazi. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved September 8, 2023.
Malware Monday VBEBromiley, M. (2016, December 27). Malware Monday: VBScript and VBE Files. Retrieved March 17, 2023.
Malware Persistence on OS XPatrick Wardle. (2015). Malware Persistence on OS X Yosemite. Retrieved July 10, 2017.
Malware System Language CheckPierre-Marc Bureau. (2009, January 15). Malware Trying to Avoid Some Countries. Retrieved August 18, 2021.
MalwareBytes ADS July 2015Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.
MalwareBytes Lazarus-Andariel Conceals Code April 2021Jazi, H. (2021, April 19). Lazarus APT conceals malicious code within BMP image to drop its RAT . Retrieved September 29, 2021.
MalwareBytes LazyScripter Feb 2021Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.
MalwareBytes Ngrok February 2020Segura, J. (2020, February 26). Fraudsters cloak credit card skimmer with fake content delivery network, ngrok server. Retrieved September 15, 2020.
MalwareBytes SEOArntz, P. (2018, May 29). SEO poisoning: Is it worth it?. Retrieved September 30, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.