ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Securelist WhiteBear Aug 2017Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.
Securelist fileless attacks Feb 2017Kaspersky Lab's Global Research and Analysis Team. (2017, February 8). Fileless attacks against enterprise networks. Retrieved February 8, 2017.
Secureworks BRONZE BUTLER Oct 2017Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.
Secureworks BRONZE PRESIDENT December 2019Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.
Secureworks BRONZE SILHOUETTE May 2023Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.
Secureworks BRONZEUNION Feb 2019Counter Threat Unit Research Team. (2019, February 27). A Peek into BRONZE UNION’s Toolbox. Retrieved September 24, 2019.
Secureworks COBALT DICKENS August 2018Counter Threat Unit Research Team. (2018, August 24). Back to School: COBALT DICKENS Targets Universities. Retrieved February 3, 2021.
Secureworks COBALT DICKENS September 2019Counter Threat Unit Research Team. (2019, September 11). COBALT DICKENS Goes Back to School…Again. Retrieved February 3, 2021.
Secureworks COBALT ILLUSION Threat ProfileSecureworks. (n.d.). COBALT ILLUSION Threat Profile. Retrieved April 14, 2021.
Secureworks Cobalt Gypsy Feb 2017Counter Threat Unit Research Team. (2017, February 15). Iranian PupyRAT Bites Middle Eastern Organizations. Retrieved December 27, 2017.
Secureworks DarkTortilla Aug 2022Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.
Secureworks Emotet Nov 2018Mclellan, M.. (2018, November 19). Lazy Passwords Become Rocket Fuel for Emotet SMB Spreader. Retrieved March 25, 2019.
Secureworks GOLD CABINSecureworks. (n.d.). GOLD CABIN Threat Profile. Retrieved March 17, 2021.
Secureworks GOLD IONIC April 2024Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Secureworks GOLD KINGSWOOD September 2018CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.
Secureworks GOLD KINGSWOOD Threat ProfileSecureworks. (n.d.). GOLD KINGSWOOD. Retrieved October 18, 2021.
Secureworks GOLD NIAGARA Threat ProfileCTU. (n.d.). GOLD NIAGARA. Retrieved September 21, 2021.
Secureworks GOLD SAHARASecureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.
Secureworks GOLD SOUTHFIELDSecureworks. (n.d.). GOLD SOUTHFIELD. Retrieved October 6, 2020.
Secureworks GandCrab and REvil September 2019Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.
Secureworks Gold Prelude ProfileSecureworks. (n.d.). GOLD PRELUDE . Retrieved March 22, 2024.
Secureworks IRON HEMLOCK ProfileSecureworks CTU. (n.d.). IRON HEMLOCK. Retrieved February 22, 2022.
Secureworks IRON HUNTER ProfileSecureworks CTU. (n.d.). IRON HUNTER. Retrieved February 22, 2022.
Secureworks IRON LIBERTY July 2019Secureworks. (2019, July 24). Resurgent Iron Liberty Targeting Energy Sector. Retrieved August 12, 2020.
Secureworks IRON RITUAL ProfileSecureworks CTU. (n.d.). IRON RITUAL. Retrieved February 24, 2022.
Secureworks IRON RITUAL USAID Phish May 2021Secureworks CTU. (2021, May 28). USAID-Themed Phishing Campaign Leverages U.S. Elections Lure. Retrieved February 24, 2022.
Secureworks IRON TILDEN ProfileSecureworks CTU. (n.d.). IRON TILDEN. Retrieved February 24, 2022.
Secureworks IRON TWILIGHT Active Measures March 2017Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.
Secureworks Karagany July 2019Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.
Secureworks MCMD July 2019Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.
Secureworks NotPetya June 2017Counter Threat Research Team. (2017, June 28). NotPetya Campaign: What We Know About the Latest Global Ransomware Attack. Retrieved June 11, 2020.
Secureworks REvil September 2019Counter Threat Unit Research Team. (2019, September 24). REvil/Sodinokibi Ransomware. Retrieved August 4, 2020.
Security Affairs DustSquad Oct 2018Paganini, P. (2018, October 16). Russia-linked APT group DustSquad targets diplomatic entities in Central Asia. Retrieved August 24, 2021.
Security Affairs Elderwood Sept 2012Paganini, P. (2012, September 9). Elderwood project, who is behind Op. Aurora and ongoing attacks?. Retrieved February 13, 2018.
Security Affairs SILENTTRINITY July 2019Paganini, P. (2019, July 7). Croatia government agencies targeted with news SilentTrinity malware. Retrieved March 23, 2022.
Security Boulevard Egregor Oct 2020Meskauskas, T.. (2020, October 29). Egregor: Sekhmet’s Cousin. Retrieved January 6, 2021.
Security Intelligence More Eggs Aug 2019Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.
Security Scorecard Medusa Ransomware January 2024Vlad Pasca. (2024, January 1). A Deep Dive into Medusa Ransomware. Retrieved October 15, 2025.
SecurityScorecard Contagious Interview FamousChollima October 2024Steve Cobb. (2024, October 29). The Job Offer That Wasn’t: How We Stopped an Espionage Plot. Retrieved October 20, 2025.
SecurityScorecard Contagious Interview October 2024Ryan Sherstobitoff. (2024, October 29). Inside a North Korean Phishing Operation Targeting DevOps Employees. Retrieved October 20, 2025.
SecurityTrails Google HackingBorges, E. (2019, March 5). Exploring Google Hacking Techniques. Retrieved September 12, 2024.
Securonix Contagious Interview DEVPOPPER April 2024Securonix Threat Research, D.Iuzvyk, T. Peck, O.Kolesnikov. (2024, April 24). Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors. Retrieved October 20, 2025.
Securonix CronTrap 2024Den Iuzvyk and Tim Peck. (2024, November 4). CRON#TRAP: Emulated Linux Environments as the Latest Tactic in Malware Staging. Retrieved May 22, 2025.
Securonix Kimsuky February 2025Den Iuzvyk, Tim Peck. (2025, February 13). Analyzing DEEP#DRIVE: North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks. Retrieved August 19, 2025.
Segurança Informática URSA Sophisticated Loader 2020Pedro Tavares (Segurança Informática). (2020, September 15). Threat analysis: The emergent URSA trojan impacts many countries using a sophisticated loader. Retrieved March 13, 2024.
Sekoia 7777 Botnet JUL 2024Aime, F. et al. (n.d.). Solving the 7777 Botnet enigma: A cybersecurity quest. Retrieved July 23, 2024.
Sekoia ClickFake 2025Amaury G., Coline Chavane, Felix Aimé and Sekoia TDR. (2025, March 31). From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic. Retrieved April 1, 2025.
Sekoia HideDRV Oct 2016Rascagnères, P.. (2016, October 27). Rootkit analysis: Use case on HideDRV. Retrieved November 17, 2024.
Sekoia Raccoon1 2022Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.
Sekoia Raccoon2 2022Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.