ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Ars Technica GRU indictment Jul 2018Gallagher, S. (2018, July 27). How they did it (and will likely try again): GRU hackers vs. US elections. Retrieved September 13, 2018.
Ars Technica VMWare Code Execution Vulnerability 2021Dan Goodin . (2021, February 25). Code-execution flaw in VMware has a severity rating of 9.8 out of 10. Retrieved April 8, 2025.
ArsTechnica Great Firewall of ChinaGoodin, D.. (2015, March 31). Massive denial-of-service attack on GitHub tied to Chinese government. Retrieved April 19, 2019.
ArsTechnica IntelGoodin, D. & Salter, J. (2020, August 6). More than 20GB of Intel source code and proprietary data dumped online. Retrieved October 20, 2020.
Artic Wolf Kali365 Device Code OAuth June 2026Artic Wolf Labs. (2026, June 2). Retrieved July 30, 2026.
Artic Wolf Labs Kali365 Device Code April 2026Artic Wolf Labs. (2026, April 24). Token Bingo: Don’t Let Your Code be the Winner. Retrieved July 30, 2026.
Arxiv Avaddon Feb 2021Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021.
Aryaka Kimsuky July 2025Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026.
AsyncRAT GitHubNyan-x-Cat. (n.d.). NYAN-x-CAT / AsyncRAT-C-Sharp. Retrieved October 3, 2023.
Atlas SEOAtlas Cybersecurity. (2021, April 19). Threat Actors use Search-Engine-Optimization Tactics to Redirect Traffic and Install Malware. Retrieved September 30, 2022.
Attackify Rundll32.exe ObscurityAttackify. (n.d.). Rundll32.exe Obscurity. Retrieved August 23, 2021.
Attacking VNC Servers PentestLabAdministrator, Penetration Testing Lab. (2012, October 30). Attacking VNC Servers. Retrieved October 6, 2021.
Australia ‘Evil Twin’Toulas, Bill. (2024, July 1). Australian charged for ‘Evil Twin’ WiFi attack on plane. Retrieved September 17, 2024.
Auth0 - Why You Should Always Use Access Tokens to Secure APIs Sept 2019Auth0. (n.d.). Why You Should Always Use Access Tokens to Secure APIs. Retrieved September 12, 2019.
Auth0 Understanding Refresh TokensAuth0 Inc.. (n.d.). Understanding Refresh Tokens. Retrieved November 17, 2024.
AutoHotKeyAutoHotkey Foundation LLC. (n.d.). Using the Program. Retrieved March 29, 2024.
AutoITAutoIT. (n.d.). Running Scripts. Retrieved March 29, 2024.
Avaddon Ransomware 2021Javier Yuste and Sergio Pastrana. (2021). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved March 24, 2025.
Avast CCleaner3 2018Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.
Avast RaspberryRobin 2022Jan Vojtěšek. (2022, September 22). Raspberry Robin’s Roshtyak: A Little Lesson in Trickery. Retrieved May 17, 2024.
Avertium Black Basta June 2022Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.
Avertium Storm-0501 Sabbath Ransomware Arcane January 2022Avertium. (2022, January 11). An In-Depth Look at Ransomware Gang, Sabbath. Retrieved October 19, 2025.
Avertium callback phishingAvertium. (n.d.). EVERYTHING YOU NEED TO KNOW ABOUT CALLBACK PHISHING. Retrieved February 2, 2023.
Avira Mustang Panda January 2020Hamzeloofard, S. (2020, January 31). New wave of PlugX targets Hong Kong | Avira Blog. Retrieved April 13, 2021.
Awake Security AvaddonGahlot, A. (n.d.). Threat Hunting for Avaddon Ransomware. Retrieved August 19, 2021.
Awake Security C2 CloudGary Golomb and Tory Kei. (n.d.). Threat Hunting Series: Detecting Command & Control in the Cloud. Retrieved May 27, 2022.
Awesome Executable PackingAlexandre D'Hondt. (n.d.). Awesome Executable Packing. Retrieved March 11, 2022.
Azure - Resource Manager APIMicrosoft. (2019, May 20). Azure Resource Manager. Retrieved June 17, 2020.
Azure - StormspotterMicrosoft. (2020). Azure Stormspotter GitHub. Retrieved June 17, 2020.
Azure AD Conditional Access ExclusionsMicrosoft. (2022, August 26). Use Azure AD access reviews to manage users excluded from Conditional Access policies. Retrieved August 30, 2022.
Azure AD Connect for Read TeamersAdam Chester. (2019, February 18). Azure AD Connect for Red Teamers. Retrieved September 28, 2022.
Azure AD Federation VulnerabilityDr. Nestori Syynimaa.. (2017, November 16). Security vulnerability in Azure AD & Office 365 identity federation. Retrieved February 1, 2022.
Azure AD Graph APIMicrosoft. (2016, March 26). Operations overview | Graph API concepts. Retrieved June 18, 2020.
Azure AD Hybrid IdentityMicrosoft. (2022, August 26). Choose the right authentication method for your Azure Active Directory hybrid identity solution. Retrieved September 28, 2022.
Azure AD ReconDr. Nestori Syynimaa. (2020, June 13). Just looking: Azure Active Directory reconnaissance as an outsider. Retrieved February 1, 2022.
Azure Active Directory ReconnaisanceDr. Nestori Syynimaa. (2020, June 13). Just looking: Azure Active Directory reconnaissance as an outsider. Retrieved May 27, 2022.
Azure Just in Time Access 2023Microsoft. (2023, August 29). Configure and approve just-in-time access for Azure Managed Applications. Retrieved September 21, 2023.
Azure Serial ConsoleMicrosoft. (2022, October 17). Azure Serial Console. Retrieved June 2, 2023.
Azure Storage LifecyclesMicrosoft Azure. (2024, July 3). Configure a lifecycle management policy. Retrieved September 25, 2024.
Azure Update Virtual MachinesMicrosoft. (n.d.). Virtual Machines - Update. Retrieved April 1, 2022.
Azure Virtual Network TAPMicrosoft. (2022, February 9). Virtual network TAP. Retrieved March 17, 2022.
BATLOADER: The Evasive Downloader MalwareBethany Hardin, Lavine Oluoch, Tatiana Vollbrecht. (2022, November 14). BATLOADER: The Evasive Downloader Malware. Retrieved June 5, 2023.
BBC LAPSUS Apr 2022BBC. (2022, April 1). LAPSUS: Two UK Teenagers Charged with Hacking for Gang. Retrieved June 9, 2022.
BBC-RoninJoe Tidy. (2022, March 30). Ronin Network: What a $600m hack says about the state of crypto. Retrieved August 18, 2023.
BBC-malvertisingBBC. (2011, March 29). Spotify ads hit by malware attack. Retrieved February 21, 2023.
BH Linux InjectColgan, T. (2015, August 15). Linux-Inject. Retrieved February 21, 2020.
BH Manul Aug 2016Galperin, E., Et al.. (2016, August 4). When Governments Attack: State Sponsored Malware Attacks Against Activists, Lawyers, and Journalists. Retrieved May 23, 2018.
BOA Telephone ScamsBank of America. (n.d.). How to avoid telephone scams. Retrieved September 8, 2023.
BOHOPS Abusing the COM RegistryBOHOPS. (2018, August 18). Abusing the COM Registry Structure (Part 2): Hijacking & Loading Techniques. Retrieved August 10, 2020.
Backdooring an AWS accountDaniel Grzelak. (2016, July 9). Backdooring an AWS account. Retrieved May 27, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.