Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Backtrace VDSO | backtrace. (2016, April 22). ELF SHARED LIBRARY INJECTION FORENSICS. Retrieved November 17, 2024. |
| Baeldung LD_PRELOAD | baeldung. (2020, August 9). What Is the LD_PRELOAD Trick?. Retrieved March 24, 2021. |
| BaltimoreSun RobbinHood May 2019 | Duncan, I., Campbell, C. (2019, May 7). Baltimore city government computer network hit by ransomware attack. Retrieved July 29, 2019. |
| Banker Google Chrome Extension Steals Creds | Marinho, R. (n.d.). (Banker(GoogleChromeExtension)).targeting. Retrieved November 18, 2017. |
| Barnea DirectSend | Tom Barnea. (2025, September 9). Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails. Retrieved September 24, 2025. |
| Bashfuscator Command Obfuscators | LeFevre, A. (n.d.). Bashfuscator Command Obfuscators. Retrieved March 17, 2023. |
| Baumgartner Golovkin Naikon 2015 | Baumgartner, K., Golovkin, M.. (2015, May 14). The Naikon APT. Retrieved January 14, 2015. |
| Baumgartner Naikon 2015 | Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019. |
| Beek Use of VHD Dec 2020 | Beek, C. (2020, December 3). Investigating the Use of VHD Files By Cybercriminals. Retrieved November 17, 2024. |
| BiZone Lizar May 2021 | BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022. |
| Bienstock, D. - Defending O365 - 2019 | Bienstock, D.. (2019). BECS and Beyond: Investigating and Defending O365. Retrieved November 17, 2024. |
| Binary Defense Emotes Wi-Fi Spreader | Binary Defense. (n.d.). Emotet Evolves With new Wi-Fi Spreader. Retrieved September 8, 2023. |
| Binary Defense Kerberos Linux | ARC Labs, Dwyer, John. Gonzalez, Eric. Hudak, Tyler. (2024, October 1). Shining a Light in the Dark – How Binary Defense Uncovered an APT Lurking in Shadows of IT. Retrieved October 7, 2024. |
| Bishop Fox Sliver Framework August 2019 | Kervella, R. (2019, August 4). Cross-platform General Purpose Implant Framework Written in Golang. Retrieved July 30, 2021. |
| BitDefender BADHATCH Mar 2021 | Vrabie, V., et al. (2021, March 10). FIN8 Returns with Improved BADHATCH Toolkit. Retrieved September 8, 2021. |
| BitDefender Chafer May 2020 | Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020. |
| Bitdefender APT28 Dec 2015 | Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017. |
| Bitdefender Agent Tesla April 2020 | Arsene, L. (2020, April 21). Oil & Gas Spearphishing Campaigns Drop Agent Tesla Spyware in Advance of Historic OPEC+ Deal. Retrieved May 19, 2020. |
| Bitdefender FIN8 July 2021 | Martin Zugec. (2021, July 27). Deep Dive Into a FIN8 Attack - A Forensic Investigation. Retrieved September 1, 2021. |
| Bitdefender FunnyDream Campaign November 2020 | Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022. |
| Bitdefender LuminousMoth July 2021 | Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022. |
| Bitdefender NPM Repositories Compromised 2021 | Silviu Stahie. (2021, November 8). Popular NPM Repositories Compromised in Man-in-the-Middle Attack. Retrieved May 22, 2025. |
| Bitdefender Naikon April 2021 | Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021. |
| Bitdefender Sardonic Aug 2021 | Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023. |
| Bitdefender StrongPity June 2020 | Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020. |
| Bitdefender Trickbot C2 infra Nov 2020 | Liviu Arsene, Radu Tudorica. (2020, November 23). TrickBot is Dead. Long Live TrickBot!. Retrieved September 28, 2021. |
| Bitdefender Trickbot March 2020 | Tudorica, R., Maximciuc, A., Vatamanu, C. (2020, March 18). New TrickBot Module Bruteforces RDP Connections, Targets Select Telecommunication Services in US and Hong Kong. Retrieved March 15, 2021. |
| Bitdefender Trickbot VNC module Whitepaper 2021 | Radu Tudorica. (2021, July 12). A Fresh Look at Trickbot’s Ever-Improving VNC Module. Retrieved September 28, 2021. |
| Bitsight 7777 Botnet | Batista, João. Gi7w0rm. (2024, August 27). Retrieved June 5, 2025. |
| Bitsight Latrodectus June 2024 | Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024. |
| Bizeul 2014 | Bizeul, D., Fontarensky, I., Mouchoux, R., Perigaud, F., Pernet, C. (2014, July 11). Eye of the Tiger. Retrieved September 29, 2015. |
| Black Hills Attacking Exchange MailSniper, 2016 | Bullock, B.. (2016, October 3). Attacking Exchange with MailSniper. Retrieved October 6, 2019. |
| Black Hills Information Security TruffleHog January 2024 | Chris Traynor. (2024, January 18). Rooting For Secrets with TruffleHog. Retrieved April 15, 2026. |
| Black Hills Red Teaming MS AD Azure, 2018 | Felch, M.. (2018, August 31). Red Teaming Microsoft Part 1 Active Directory Leaks via Azure. Retrieved October 6, 2019. |
| BlackBasta | Antonio Cocomazzi and Antonio Pirozzi. (2022, November 3). Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor. Retrieved March 14, 2023. |
| BlackBerry Amadey 2020 | Kasuya, M. (2020, January 8). Threat Spotlight: Amadey Bot Targets Non-Russian Users. Retrieved July 14, 2022. |
| BlackBerry Bahamut | The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021. |
| BlackBerry Black Basta May 2022 | Ballmer, D. (2022, May 6). Black Basta: Rebrand of Conti or Something New?. Retrieved March 7, 2023. |
| BlackBerry CostaRicto November 2020 | The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021. |
| BlackBerry MUSTANG PANDA October 2022 | The BlackBerry Research and Intelligence Team. (2022, October 6). Mustang Panda Abuses Legitimate Apps to Target Myanmar Based Victims. Retrieved October 14, 2025. |
| BlackBerry_FIN7_April2024 | The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025. |
| BlackCat ransomware | Lucas Silva, Leandro Froes. (2022, April 18). An Investigation of the BlackCat Ransomware via Trend Micro Vision One. Retrieved February 2, 2026. |
| BlackHat API Packers | Choi, S. (2015, August 6). Obfuscated API Functions in Modern Packers. Retrieved August 22, 2022. |
| BlackHat Mac OSX Rootkit | Pan, M., Tsai, S. (2014). You can’t see me: A Mac OS X Rootkit uses the tricks you haven't known yet. Retrieved December 21, 2017. |
| BlackHat Process Doppelgänging Dec 2017 | Liberman, T. & Kogan, E. (2017, December 7). Lost in Transaction: Process Doppelgänging. Retrieved December 20, 2017. |
| BlackHatRobinSage | Ryan, T. (2010). “Getting In Bed with Robin Sage.”. Retrieved March 6, 2017. |
| BlackHillsInfosec Password Spraying | Thyer, J. (2015, October 30). Password Spraying & Other Fun with RPCCLIENT. Retrieved April 25, 2017. |
| BlackWater Malware Cloudflare Workers | Lawrence Abrams. (2020, March 14). BlackWater Malware Abuses Cloudflare Workers for C2 Communication. Retrieved July 8, 2022. |
| Blasco 2013 | Blasco, J. (2013, March 21). New Sykipot developments [Blog]. Retrieved November 12, 2014. |
| Bleeping Computer - Ryuk WoL | Abrams, L. (2021, January 14). Ryuk Ransomware Uses Wake-on-Lan To Encrypt Offline Devices. Retrieved February 11, 2021. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.