Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| MalwareBytes SideCopy Dec 2021 | Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022. |
| MalwareBytes Template Injection OCT 2017 | Segura, J. (2017, October 13). Decoy Microsoft Word document delivers malware through a RAT. Retrieved July 21, 2018. |
| MalwareBytes WoodyRAT Aug 2022 | MalwareBytes Threat Intelligence Team. (2022, August 3). Woody RAT: A new feature-rich malware spotted in the wild. Retrieved December 6, 2022. |
| MalwareTech Power Loader Aug 2013 | MalwareTech. (2013, August 13). PowerLoader Injection – Something truly amazing. Retrieved December 16, 2017. |
| MalwareTech VFS Nov 2014 | Hutchins, M. (2014, November 28). Virtual File Systems for Beginners. Retrieved June 22, 2020. |
| MalwareUnicorn macOS Dylib Injection MachO | Amanda Rousseau. (2020, April 4). MacOS Dylib Injection Workshop. Retrieved March 29, 2021. |
| Malwarebytes Agent Tesla April 2020 | Jazi, H. (2020, April 16). New AgentTesla variant steals WiFi credentials. Retrieved May 19, 2020. |
| Malwarebytes AvosLocker Jul 2021 | Hasherezade. (2021, July 23). AvosLocker enters the ransomware scene, asks for partners. Retrieved January 11, 2023. |
| Malwarebytes Crossrider Apr 2018 | Reed, Thomas. (2018, April 24). New Crossrider variant installs configuration profiles on Macs. Retrieved September 6, 2019. |
| Malwarebytes DarkComet March 2018 | Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018. |
| Malwarebytes Dyreza November 2015 | hasherezade. (2015, November 4). A Technical Look At Dyreza. Retrieved June 15, 2020. |
| Malwarebytes Emotet Dec 2017 | Smith, A.. (2017, December 22). Protect your network from Emotet Trojan with Malwarebytes Endpoint Security. Retrieved January 17, 2019. |
| Malwarebytes Heroku Skimmers | Jérôme Segura. (2019, December 4). There's an app for that: web skimmers found on PaaS Heroku. Retrieved August 18, 2022. |
| Malwarebytes Higaisa 2020 | Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021. |
| Malwarebytes IssacWiper CaddyWiper March 2022 | Threat Intelligence Team. (2022, March 18). Double header: IsaacWiper and CaddyWiper . Retrieved April 11, 2022. |
| Malwarebytes KONNI Evolves Jan 2022 | Santos, R. (2022, January 26). KONNI evolves into stealthier RAT. Retrieved April 13, 2022. |
| Malwarebytes Kimsuky June 2021 | Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021. |
| Malwarebytes Konni Aug 2021 | Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022. |
| Malwarebytes OSINT Leaky Buckets - Hioureas | Vasilios Hioureas. (2019, September 13). Hacking with AWS: incorporating leaky buckets into your OSINT workflow. Retrieved February 14, 2022. |
| Malwarebytes Pony April 2016 | hasherezade. (2016, April 11). No money, but Pony! From a mail to a trojan horse. Retrieved May 21, 2020. |
| Malwarebytes RokRAT VBA January 2021 | Jazi, Hossein. (2021, January 6). Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat. Retrieved March 22, 2022. |
| Malwarebytes Saint Bot April 2021 | Hasherezade. (2021, April 6). A deep dive into Saint Bot, a new downloader. Retrieved June 9, 2022. |
| Malwarebytes Silent Librarian October 2020 | Malwarebytes Threat Intelligence Team. (2020, October 14). Silent Librarian APT right on schedule for 20/21 academic year. Retrieved February 3, 2021. |
| Malwarebytes SmokeLoader 2016 | Hasherezade. (2016, September 12). Smoke Loader – downloader with a smokescreen still alive. Retrieved March 20, 2018. |
| Malwarebytes Targeted Attack against Saudi Arabia | Malwarebytes Labs. (2017, March 27). New targeted attack against Saudi Arabia Government. Retrieved July 3, 2017. |
| Malwarebytes The Windows Vault | Arntz, P. (2016, March 30). The Windows Vault . Retrieved November 23, 2020. |
| Malwarebytes Wow6432Node 2016 | Arntz, P. (2016, March 30). Hiding in Plain Sight. Retrieved August 3, 2020. |
| Man LD.SO | Kerrisk, M. (2020, June 13). Linux Programmer's Manual. Retrieved June 15, 2020. |
| Man Pam_Unix | die.net. (n.d.). pam_unix(8) - Linux man page. Retrieved June 25, 2020. |
| Mandiant - Synful Knock | Bill Hau, Tony Lee, Josh Homan. (2015, September 15). SYNful Knock - A Cisco router implant - Part I. Retrieved November 17, 2024. |
| Mandiant 3cx UNC4736 2023 | Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodoreanu, Daniel Scott. (2023, April 20). 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspecte… |
| Mandiant APT1 | Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016. |
| Mandiant APT1 Appendix | Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016. |
| Mandiant APT29 Eye Spy Email Nov 22 | Mandiant. (2022, May 2). UNC3524: Eye Spy on Your Email. Retrieved August 17, 2023. |
| Mandiant APT29 Microsoft 365 2022 | Douglas Bienstock. (2022, August 18). You Can’t Audit Me: APT29 Continues Targeting Microsoft 365. Retrieved February 23, 2023. |
| Mandiant APT29 Trello | Wolfram, J. et al. (2022, April 28). Trello From the Other Side: Tracking APT29 Phishing Campaigns. Retrieved August 3, 2022. |
| Mandiant APT41 | Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022. |
| Mandiant APT41 Global Intrusion | Gyler, C.,Perez D.,Jones, S.,Miller, S.. (2021, February 25). This is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved February 17, 2022. |
| Mandiant APT42 | Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromise. Retrieved September 16, 2022. |
| Mandiant APT42 Operations 2024 | Ofir Rozmann, Asli Koksal, Adrian Hernandez, Sarah Bock, and Jonathan Leathery. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved May 28, 2024. |
| Mandiant APT42-charms | Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024. |
| Mandiant APT42-untangling | Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024. |
| Mandiant APT43 March 2024 | Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024. |
| Mandiant Advanced Persistent Threats | Mandiant. (n.d.). Advanced Persistent Threats (APTs). Retrieved February 14, 2024. |
| Mandiant Azure AD Backdoors | Mike Burns. (2020, September 30). Detecting Microsoft 365 and Azure Active Directory Backdoors. Retrieved September 28, 2022. |
| Mandiant BYOL | Kirk, N. (2018, June 18). Bring Your Own Land (BYOL) – A Novel Red Teaming Technique. Retrieved October 4, 2021. |
| Mandiant Cutting Edge January 2024 | McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024. |
| Mandiant Cutting Edge Part 2 January 2024 | Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024. |
| Mandiant Cutting Edge Part 3 February 2024 | Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024. |
| Mandiant DPRK Groups 2023 | Michael Barnhart, Austin Larsen, Jeff Johnson, Taylor Long, Michelle Cantos, Adrian Hernandez. (2023, October 10). Assessed Cyber Structure and Alignments of North Korea in 2023. Retrieved August 25, 2025. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.