Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Secure Team - Scriptrunner.exe | Secure Team - Information Assurance. (2023, January 8). Windows Error Reporting Tool Abused to Load Malware. Retrieved July 8, 2024. |
| SecureList BlueNoroff Device Cred Dev | Seongsu Park. (2022, December 27). BlueNoroff introduces new methods bypassing MoTW. Retrieved July 22, 2025. |
| SecureList Fileless | Legezo, D. (2022, May 4). A new secret stash for “fileless” malware. Retrieved March 23, 2023. |
| SecureList Griffon May 2019 | Namestnikov, Y. and Aime, F. (2019, May 8). FIN7.5: the infamous cybercrime rig “FIN7” continues its activities. Retrieved October 11, 2019. |
| SecureList Silence Nov 2017 | GReAT. (2017, November 1). Silence – a new Trojan attacking financial organizations. Retrieved May 24, 2019. |
| SecureList SynAck Doppelgänging May 2018 | Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018. |
| SecureListUbiedo_Tsundere_Nov2025 | Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026. |
| SecureWorks August 2019 | SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19 |
| SecureWorks BRONZE STARLIGHT Ransomware Operations June 2022 | Counter Threat Unit Research Team . (2022, June 23). BRONZE STARLIGHT RANSOMWARE OPERATIONS USE HUI LOADER. Retrieved December 7, 2023. |
| SecureWorks BRONZE UNION June 2017 | Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017. |
| SecureWorks Device Code Phishing 2021 | SecureWorks Counter Threat Unit Research Team. (2021, June 3). OAuth’S Device Code Flow Abused in Phishing Attacks. Retrieved March 19, 2024. |
| SecureWorks Infostealers 2023 | SecureWorks Counter Threat Unit Research Team. (2023, May 16). The Growing Threat from Infostealers. Retrieved October 10, 2024. |
| SecureWorks Mia Ash July 2017 | Counter Threat Unit Research Team. (2017, July 27). The Curious Case of Mia Ash: Fake Persona Lures Middle Eastern Targets. Retrieved February 26, 2018. |
| SecureWorks September 2019 | SecureWorks 2019, September 24 REvil/Sodinokibi Ransomware Retrieved. 2021/04/12 |
| SecureWorks TG-4127 | SecureWorks Counter Threat Unit Threat Intelligence. (2016, June 16). Threat Group-4127 Targets Hillary Clinton Presidential Campaign. Retrieved August 3, 2016. |
| SecureWorks WannaCry Analysis | Counter Threat Unit Research Team. (2017, May 18). WCry Ransomware Analysis. Retrieved March 26, 2019. |
| Securelist APT Trends April 2018 | Global Research and Analysis Team . (2018, April 12). APT Trends report Q1 2018. Retrieved January 27, 2021. |
| Securelist APT Trends Q2 2017 | Kaspersky Lab's Global Research & Analysis Team. (2017, August 8). APT Trends report Q2 2017. Retrieved February 15, 2018. |
| Securelist APT10 March 2021 | GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021. |
| Securelist Agent.btz | Gostev, A.. (2014, March 12). Agent.btz: a Source of Inspiration?. Retrieved April 8, 2016. |
| Securelist BlackEnergy Feb 2015 | Baumgartner, K. and Garnaeva, M.. (2015, February 17). BE2 extraordinary plugins, Siemens targeting, dev fails. Retrieved March 24, 2016. |
| Securelist BlackEnergy Nov 2014 | Baumgartner, K. and Garnaeva, M.. (2014, November 3). BE2 custom plugins, router abuse, and target profiles. Retrieved March 24, 2016. |
| Securelist BlackOasis Oct 2017 | Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018. |
| Securelist Brazilian Banking Malware July 2020 | GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020. |
| Securelist Calisto July 2018 | Kuzin, M., Zelensky S. (2018, July 20). Calisto Trojan for macOS. Retrieved September 7, 2018. |
| Securelist DarkVishnya Dec 2018 | Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020. |
| Securelist Darkhotel Aug 2015 | Kaspersky Lab's Global Research & Analysis Team. (2015, August 10). Darkhotel's attacks in 2015. Retrieved November 2, 2018. |
| Securelist Denis April 2017 | Shulmin, A., Yunakovsky, S. (2017, April 28). Use of DNS Tunneling for C&C Communications. Retrieved November 5, 2018. |
| Securelist Digital Certificates | Ladikov, A. (2015, January 29). Why You Shouldn’t Completely Trust Files Signed with Digital Certificates. Retrieved March 31, 2016. |
| Securelist Dropping Elephant | Kaspersky Lab's Global Research & Analysis Team. (2016, July 8). The Dropping Elephant – aggressive cyber-espionage in the Asian region. Retrieved August 3, 2016. |
| Securelist Dtrack | Konstantin Zykov. (2019, September 23). Hello! My name is Dtrack. Retrieved January 20, 2021. |
| Securelist Dtrack2 | KONSTANTIN ZYKOV. (2019, September 23). Hello! My name is Dtrack. Retrieved September 30, 2022. |
| Securelist GCMAN | Kaspersky Lab's Global Research & Analysis Team. (2016, February 8). APT-style bank robberies increase with Metel, GCMAN and Carbanak 2.0 attacks. Retrieved April 20, 2016. |
| Securelist JSWorm | Fedor Sinitsyn. (2021, May 25). Evolution of JSWorm Ransomware. Retrieved August 18, 2021. |
| Securelist Kimsuky Sept 2013 | Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019. |
| Securelist LuckyMouse June 2018 | Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018. |
| Securelist Machete Aug 2014 | Kaspersky Global Research and Analysis Team. (2014, August 20). El Machete. Retrieved September 13, 2019. |
| Securelist Malware Tricks April 2017 | Ishimaru, S.. (2017, April 13). Old Malware Tricks To Bypass Detection in the Age of Big Data. Retrieved May 30, 2019. |
| Securelist MiniDuke Feb 2013 | Kaspersky Lab's Global Research & Analysis Team. (2013, February 27). The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor. Retrieved November 17, 2024. |
| Securelist Minidionis July 2015 | Lozhkin, S.. (2015, July 16). Minidionis – one more APT with a usage of cloud drives. Retrieved April 5, 2017. |
| Securelist MuddyWater Oct 2018 | Kaspersky Lab's Global Research & Analysis Team. (2018, October 10). MuddyWater expands operations. Retrieved November 2, 2018. |
| Securelist Octopus Oct 2018 | Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018. |
| Securelist Remexi Jan 2019 | Legezo, D. (2019, January 30). Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities. Retrieved April 17, 2019. |
| Securelist ScarCruft Jun 2016 | Raiu, C., and Ivanov, A. (2016, June 17). Operation Daybreak. Retrieved February 15, 2018. |
| Securelist ScarCruft May 2019 | GReAT. (2019, May 13). ScarCruft continues to evolve, introduces Bluetooth harvester. Retrieved June 4, 2019. |
| Securelist ShadowPad Aug 2017 | GReAT. (2017, August 15). ShadowPad in corporate networks. Retrieved March 22, 2021. |
| Securelist Sofacy Feb 2018 | Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018. |
| Securelist Trasparent Tribe 2020 | Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved April 1, 2021. |
| Securelist Turla Oct 2018 | Kaspersky Lab's Global Research & Analysis Team. (2018, October 04). Shedding Skin – Turla’s Fresh Faces. Retrieved November 7, 2018. |
| Securelist Ventir | Mikhail, K. (2014, October 16). The Ventir Trojan: assemble your MacOS spy. Retrieved April 6, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.