Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| NCC Group Black Basta June 2022 | Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023. |
| NCC Group Chimera January 2021 | Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024. |
| NCC Group Fivehands June 2021 | Matthews, M. and Backhouse, W. (2021, June 15). Handy guide to a new Fivehands ransomware variant. Retrieved June 24, 2021. |
| NCC Group LAPSUS Apr 2022 | Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022. |
| NCC Group TA505 | Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022. |
| NCC Group Team9 June 2020 | Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020. |
| NCC Group WastedLocker June 2020 | Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021. |
| NCCGroup RokRat Nov 2018 | Pantazopoulos, N.. (2018, November 8). RokRat Analysis. Retrieved May 21, 2020. |
| NCSC APT29 July 2020 | National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020. |
| NCSC CISA Cyclops Blink Advisory February 2022 | NCSC, CISA, FBI, NSA. (2022, February 23). New Sandworm malware Cyclops Blink replaces VPNFilter. Retrieved March 3, 2022. |
| NCSC Cyclops Blink February 2022 | NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022. |
| NCSC GCHQ Small Sieve Jan 2022 | NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022. |
| NCSC Joint Report Public Tools | The Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), CERT New Zealand, the UK National Cyber Security Centre (UK NCSC) and the US National Cyb… |
| NCSC Sandworm Feb 2020 | NCSC. (2020, February 20). NCSC supports US advisory regarding GRU intrusion set Sandworm. Retrieved June 10, 2020. |
| NCSC et al APT29 2024 | UK National Cyber Security Center et al. (2024, February). SVR cyber actors adapt tactics for initial cloud access. Retrieved March 1, 2024. |
| NCSC-NL COATHANGER Feb 2024 | Dutch Military Intelligence and Security Service (MIVD) & Dutch General Intelligence and Security Service (AIVD). (2024, February 6). Ministry of Defense of the Netherlands uncovers COATHANGER, a stealthy Chinese FortiGate RAT. Retrieved F… |
| NEWSCASTER2014 | Lennon, M. (2014, May 29). Iranian Hackers Targeted US Officials in Elaborate Social Media Attack Operation. Retrieved March 1, 2017. |
| NGLite Trojan | Robert Falcone, Jeff White, and Peter Renals. (2021, November 7). Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer. Retrieved February 8, 2024. |
| NHS Digital Egregor Nov 2020 | NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020. |
| NHS UK BLINDINGCAN Aug 2020 | NHS Digital . (2020, August 20). BLINDINGCAN Remote Access Trojan. Retrieved August 20, 2020. |
| NIST Authentication | NIST. (n.d.). Authentication. Retrieved January 30, 2020. |
| NIST MFA | NIST. (n.d.). Multi-Factor Authentication (MFA). Retrieved September 25, 2024. |
| NIST Web Bug | NIST Information Technology Laboratory. (n.d.). web bug. Retrieved March 22, 2023. |
| NJCCIC Ursnif Sept 2016 | NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024. |
| NKAbuse BC | Bill Toulas. (2023, December 14). New NKAbuse malware abuses NKN blockchain for stealthy comms. Retrieved February 8, 2024. |
| NKAbuse SL | KASPERSKY GERT. (2023, December 14). Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocol. Retrieved February 8, 2024. |
| NPLogonNotify | Microsoft. (2021, October 21). NPLogonNotify function (npapi.h). Retrieved March 30, 2023. |
| NPPSPY | Grzegorz Tworek. (2021, December 15). NPPSpy. Retrieved March 30, 2023. |
| NPPSPY - Huntress | Dray Agha. (2022, August 16). Cleartext Shenanigans: Gifting User Passwords to Adversaries With NPPSPY. Retrieved March 30, 2023. |
| NPPSPY Video | Grzegorz Tworek. (2021, December 14). How winlogon.exe shares the cleartext password with custom DLLs. Retrieved March 30, 2023. |
| NSA APT5 Citrix Threat Hunting December 2022 | National Security Agency. (2022, December). APT5: Citrix ADC Threat Hunting Guidance. Retrieved February 5, 2024. |
| NSA Joint Advisory SVR SolarWinds April 2021 | NSA, FBI, DHS. (2021, April 15). Russian SVR Targets U.S. and Allied Networks. Retrieved April 16, 2021. |
| NSA NCSC Turla OilRig | NSA/NCSC. (2019, October 21). Cybersecurity Advisory: Turla Group Exploits Iranian APT To Expand Coverage Of Victims. Retrieved October 16, 2020. |
| NSA Sandworm 2020 | National Security Agency. (2020, March 28). Sandworm Actors Exploiting Vulnerability In EXIM Mail Transfer Agent. Retrieved March 1, 2024. |
| NSA/FBI Drovorub August 2020 | NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020. |
| NT API Windows | The NTinterlnals.net team. (n.d.). Nowak, T. Retrieved June 25, 2020. |
| NTT Security Flagpro new December 2021 | Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022. |
| NVD CVE-2014-7169 | National Vulnerability Database. (2017, September 24). CVE-2014-7169 Detail. Retrieved April 3, 2018. |
| NVD CVE-2016-6662 | National Vulnerability Database. (2017, February 2). CVE-2016-6662 Detail. Retrieved April 3, 2018. |
| NVD CVE-2017-0176 | National Vulnerability Database. (2017, June 22). CVE-2017-0176 Detail. Retrieved April 3, 2018. |
| NVD CVE-2019-3610 | National Vulnerability Database. (2019, October 9). CVE-2019-3610 Detail. Retrieved April 14, 2021. |
| NVISO BRICKSTORM April 2025 | NVISO Incident Response. (2025, April 1). BRICKSTORM Backdoor Analysis: A Persistent Espionage Threat to European Industries. Retrieved April 16, 2026. |
| NYT-Colonial | Nicole Perlroth. (2021, May 13). Colonial Pipeline paid 75 Bitcoin, or roughly $5 million, to hackers.. Retrieved August 18, 2023. |
| NYTStuxnet | William J. Broad, John Markoff, and David E. Sanger. (2011, January 15). Israeli Test on Worm Called Crucial in Iran Nuclear Delay. Retrieved March 1, 2017. |
| Narrator Accessibility Abuse | Comi, G. (2019, October 19). Abusing Windows 10 Narrator's 'Feedback-Hub' URI for Fileless Persistence. Retrieved April 28, 2020. |
| National Vulnerability Database | National Vulnerability Database. (n.d.). National Vulnerability Database. Retrieved October 15, 2020. |
| NationsBuying | Nicole Perlroth and David E. Sanger. (2013, July 12). Nations Buying as Hackers Sell Flaws in Computer Code. Retrieved March 9, 2017. |
| NaumaanProofpoint_GlobalClickFix_April2025 | Naumaan, S., et al. (2025, April 17). Around the World in 90 Days: State-Sponsored Actors Try ClickFix . Retrieved January 21, 2026. |
| Nccgroup Emissary Panda May 2018 | Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018. |
| Nccgroup Gh0st April 2018 | Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.