ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
NCC Group Black Basta June 2022Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.
NCC Group Chimera January 2021Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.
NCC Group Fivehands June 2021Matthews, M. and Backhouse, W. (2021, June 15). Handy guide to a new Fivehands ransomware variant. Retrieved June 24, 2021.
NCC Group LAPSUS Apr 2022Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.
NCC Group TA505Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022.
NCC Group Team9 June 2020Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.
NCC Group WastedLocker June 2020Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021.
NCCGroup RokRat Nov 2018Pantazopoulos, N.. (2018, November 8). RokRat Analysis. Retrieved May 21, 2020.
NCSC APT29 July 2020National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.
NCSC CISA Cyclops Blink Advisory February 2022NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022.
NCSC Cyclops Blink February 2022NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.
NCSC GCHQ Small Sieve Jan 2022NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022.
NCSC Joint Report Public ToolsThe Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cyb…
NCSC Sandworm Feb 2020NCSC. (2020, February 20). NCSC supports US advisory regarding GRU intrusion set Sandworm. Retrieved June 10, 2020.
NCSC et al APT29 2024UK National Cyber Security Center et al. (2024, February). SVR cyber actors adapt tactics for initial cloud access. Retrieved March 1, 2024.
NCSC-NL COATHANGER Feb 2024Dutch Military Intelligence and Security Service (MIVD) & Dutch General Intelligence and Security Service (AIVD). (2024, February 6). Ministry of Defense of the Netherlands uncovers COATHANGER, a stealthy Chinese FortiGate RAT. Retrieved F…
NEWSCASTER2014Lennon, M. (2014, May 29). Iranian Hackers Targeted US Officials in Elaborate Social Media Attack Operation. Retrieved March 1, 2017.
NGLite TrojanRobert Falcone, Jeff White, and Peter Renals. (2021, November 7). Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer. Retrieved February 8, 2024.
NHS Digital Egregor Nov 2020NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
NHS UK BLINDINGCAN Aug 2020NHS Digital . (2020, August 20). BLINDINGCAN Remote Access Trojan. Retrieved August 20, 2020.
NIST AuthenticationNIST. (n.d.). Authentication. Retrieved January 30, 2020.
NIST MFANIST. (n.d.). Multi-Factor Authentication (MFA). Retrieved September 25, 2024.
NIST Web BugNIST Information Technology Laboratory. (n.d.). web bug. Retrieved March 22, 2023.
NJCCIC Ursnif Sept 2016NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
NKAbuse BCBill Toulas. (2023, December 14). New NKAbuse malware abuses NKN blockchain for stealthy comms. Retrieved February 8, 2024.
NKAbuse SLKASPERSKY GERT. (2023, December 14). Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocol. Retrieved February 8, 2024.
NPLogonNotifyMicrosoft. (2021, October 21). NPLogonNotify function (npapi.h). Retrieved March 30, 2023.
NPPSPYGrzegorz Tworek. (2021, December 15). NPPSpy. Retrieved March 30, 2023.
NPPSPY - Huntress Dray Agha. (2022, August 16). Cleartext Shenanigans: Gifting User Passwords to Adversaries With NPPSPY. Retrieved March 30, 2023.
NPPSPY VideoGrzegorz Tworek. (2021, December 14). How winlogon.exe shares the cleartext password with custom DLLs. Retrieved March 30, 2023.
NSA APT5 Citrix Threat Hunting December 2022National Security Agency. (2022, December). APT5: Citrix ADC Threat Hunting Guidance. Retrieved February 5, 2024.
NSA Joint Advisory SVR SolarWinds April 2021NSA, FBI, DHS. (2021, April 15). Russian SVR Targets U.S. and Allied Networks. Retrieved April 16, 2021.
NSA NCSC Turla OilRigNSA/NCSC. (2019, October 21). Cybersecurity Advisory: Turla Group Exploits Iranian APT To Expand Coverage Of Victims. Retrieved October 16, 2020.
NSA Sandworm 2020National Security Agency. (2020, March 28). Sandworm Actors Exploiting Vulnerability In EXIM Mail Transfer Agent. Retrieved March 1, 2024.
NSA/FBI Drovorub August 2020NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.
NT API WindowsThe NTinterlnals.net team. (n.d.). Nowak, T. Retrieved June 25, 2020.
NTT Security Flagpro new December 2021Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.
NVD CVE-2014-7169National Vulnerability Database. (2017, September 24). CVE-2014-7169 Detail. Retrieved April 3, 2018.
NVD CVE-2016-6662National Vulnerability Database. (2017, February 2). CVE-2016-6662 Detail. Retrieved April 3, 2018.
NVD CVE-2017-0176National Vulnerability Database. (2017, June 22). CVE-2017-0176 Detail. Retrieved April 3, 2018.
NVD CVE-2019-3610National Vulnerability Database. (2019, October 9). CVE-2019-3610 Detail. Retrieved April 14, 2021.
NVISO BRICKSTORM April 2025NVISO Incident Response. (2025, April 1). BRICKSTORM Backdoor Analysis: A Persistent Espionage Threat to European Industries. Retrieved April 16, 2026.
NYT-ColonialNicole Perlroth. (2021, May 13). Colonial Pipeline paid 75 Bitcoin, or roughly $5 million, to hackers.. Retrieved August 18, 2023.
NYTStuxnetWilliam J. Broad, John Markoff, and David E. Sanger. (2011, January 15). Israeli Test on Worm Called Crucial in Iran Nuclear Delay. Retrieved March 1, 2017.
Narrator Accessibility AbuseComi, G. (2019, October 19). Abusing Windows 10 Narrator's 'Feedback-Hub' URI for Fileless Persistence. Retrieved April 28, 2020.
National Vulnerability DatabaseNational Vulnerability Database. (n.d.). National Vulnerability Database. Retrieved October 15, 2020.
NationsBuyingNicole Perlroth and David E. Sanger. (2013, July 12). Nations Buying as Hackers Sell Flaws in Computer Code. Retrieved March 9, 2017.
NaumaanProofpoint_GlobalClickFix_April2025Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026.
Nccgroup Emissary Panda May 2018Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.
Nccgroup Gh0st April 2018Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.