ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
SpectorOps Medium ClickOnceNick Powers. (2023, June 7). Less SmartScreen More Caffeine: (Ab)Using ClickOnce for Trusted Code Execution. Retrieved September 9, 2024.
SpectorOps Subverting Trust Sept 2017Graeber, M. (2017, September). Subverting Trust in Windows. Retrieved January 31, 2018.
Splunk DarkGateSplunk Threat Research Team. (2024, January 17). Enter The Gates: An Analysis of the DarkGate AutoIt Loader. Retrieved March 29, 2024.
Splunk Detect Renamed PSExecSplunk. (2025, February 24). Detection: Detect Renamed PSExec. Retrieved April 3, 2025.
Splunk LAMEHUG SEP 2025Conteras, T., Splunk Research Team. (2025, September 25). From Prompt to Payload: LAMEHUG’s LLM-Driven Cyber Intrusion. Retrieved April 21, 2026.
Splunk Linux Gormir 2024Splunk Threat Research Team , Teoderick Contreras. (2024, July 15). Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs. Retrieved May 22, 2025.
Splunk RedLine Stealer June 2023Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.
Splunk ShrinkLocker 2024Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.
Splunk Supernova Jan 2021Stoner, J. (2021, January 21). Detecting Supernova Malware: SolarWinds Continued. Retrieved February 22, 2021.
Spoofing credential dialogsJohann Rehberger. (2021, April 18). Spoofing credential dialogs on macOS Linux and Windows. Retrieved August 19, 2021.
SpyCloud Kali365 June 2026Trevor Hilligoss. (2026, June 11). Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit – From Telegram Hype to FBI Takedown Theater. Retrieved July 30, 2026.
Staaldraad Phishing with OAuth 2017Stalmans, E.. (2017, August 2). Phishing with OAuth and o365/Azure. Retrieved October 4, 2019.
Stack OverflowStack Overflow. (n.d.). How to find the location of the Scheduled Tasks folder. Retrieved June 19, 2024.
Stantinko BotnetVachon, F., Faou, M. (2017, July 20). Stantinko: A massive adware campaign operating covertly since 2012. Retrieved November 16, 2017.
StarBlizzardMicrosoft Threat Intelligence. (2023, December 7). Star Blizzard increases sophistication and evasion in ongoing attacks. Retrieved February 13, 2024.
Startup ItemsApple. (2016, September 13). Startup Items. Retrieved July 11, 2017.
Startup Items Eclectichoakley. (2021, September 16). How to run an app or tool at startup. Retrieved October 5, 2021.
Stealthbits Cracking AS-REP Roasting Jun 2019Jeff Warren. (2019, June 27). Cracking Active Directory Passwords with AS-REP Roasting. Retrieved August 24, 2020.
Stealthbits Overpass-the-HashWarren, J. (2019, February 26). How to Detect Overpass-the-Hash Attacks. Retrieved February 4, 2021.
Stewart 2014Stewart, A. (2014). DLL SIDE-LOADING: A Thorn in the Side of the Anti-Virus Industry. Retrieved November 12, 2014.
Storm-0558 techniques for unauthorized email accessMicrosoft Threat Intelligence. (2023, July 14). Analysis of Storm-0558 techniques for unauthorized email access. Retrieved September 18, 2023.
Stuart ELF MemoryStuart. (2018, March 31). In-Memory-Only ELF Execution (Without tmpfs). Retrieved October 4, 2021.
Sucuri BIND9 August 2015Cid, D.. (2015, August 2). BIND9 – Denial of Service Exploit in the Wild. Retrieved April 26, 2019.
Summit Route Malicious AMIsPiper, S.. (2018, September 24). Investigating Malicious AMIs. Retrieved March 30, 2021.
Superuser Linux Password PoliciesMatutiae, M. (2014, August 6). How to display password policy information for a user (Ubuntu)?. Retrieved April 5, 2018.
Suspected Russian Activity Targeting Government and Business Entities Around the GlobeLuke Jenkins, Sarah Hawley, Parnian Najafi, Doug Bienstock. (2021, December 6). Suspected Russian Activity Targeting Government and Business Entities Around the Globe. Retrieved April 15, 2022.
Sygnia Abyss Locker 2025Abigail See, Zhongyuan (Aaron) Hau, Ren Jie Yow, Yoav Mazor, Omer Kidron, and Oren Biderman. (2025, February 4). The Anatomy of Abyss Locker Ransomware Attack. Retrieved April 4, 2025.
Sygnia ESXi Ransomware 2025Zhongyuan Hau (Aaron), Ren Jie Yow, and Yoav Mazor. (2025, January 21). ESXi Ransomware Attacks: Stealthy Persistence through. Retrieved March 27, 2025.
Sygnia Elephant Beetle Jan 2022Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.
Sygnia Emperor Dragonfly October 2022Biderman, O. et al. (2022, October 3). REVEALING EMPEROR DRAGONFLY: NIGHT SKY AND CHEERSCRYPT - A SINGLE RANSOMWARE GROUP. Retrieved December 6, 2023.
Sygnia VelvetAnt 2024ASygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.
Sygnia VelvetAnt 2024BSygnia Team. (2024, July 1). China-Nexus Threat Group ‘Velvet Ant’ Exploits Cisco Zero-Day (CVE-2024-20399) to Compromise Nexus Switch Devices – Advisory for Mitigation and Response. Retrieved March 14, 2025.
Symantec APT28 Oct 2018Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.
Symantec Attacks Against Government SectorSymantec. (2021, June 10). Attacks Against the Government Sector. Retrieved September 28, 2021.
Symantec BITS May 2007Florio, E. (2007, May 9). Malware Update with Windows Update. Retrieved January 12, 2018.
Symantec Backdoor.MivastStama, D.. (2015, February 6). Backdoor.Mivast. Retrieved February 15, 2016.
Symantec Backdoor.NidiranSponchioni, R.. (2016, March 11). Backdoor.Nidiran. Retrieved August 3, 2016.
Symantec BeetlejuiceSymantec Security Response. (2012, May 31). Flamer: A Recipe for Bluetoothache. Retrieved February 25, 2017.
Symantec Bilbug 2022Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.
Symantec Black VineDiMaggio, J.. (2015, August 6). The Black Vine cyberespionage group. Retrieved January 26, 2016.
Symantec BlackByte 2022Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.
Symantec Briba May 2012Ladley, F. (2012, May 15). Backdoor.Briba. Retrieved February 21, 2018.
Symantec BuckeyeSymantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.
Symantec Bumblebee June 2022Kamble, V. (2022, June 28). Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem. Retrieved August 24, 2022.
Symantec Calisto July 2018Pantig, J. (2018, July 30). OSX.Calisto. Retrieved September 7, 2018.
Symantec Catchamas April 2018Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.
Symantec Chafer Dec 2015Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.
Symantec Chafer February 2018Symantec. (2018, February 28). Chafer: Latest Attacks Reveal Heightened Ambitions. Retrieved May 22, 2020.
Symantec Chernobyl W95.CIHYamamura, M. (2002, April 25). W95.CIH. Retrieved April 12, 2019.
Symantec Cicada November 2020Symantec. (2020, November 17). Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. Retrieved December 17, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.