Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Twitter ItsReallyNick APT32 pubprn Masquerade | Carr, N.. (2017, December 26). Nick Carr Status Update APT32 pubprn. Retrieved September 12, 2024. |
| Twitter ItsReallyNick APT41 EK | Carr, N. (2019, October 30). Nick Carr Status Update APT41 Environmental Keying. Retrieved September 12, 2024. |
| Twitter ItsReallyNick Platinum Masquerade | Carr, N.. (2018, October 25). Nick Carr Status Update. Retrieved September 12, 2024. |
| Twitter ItsReallyNick Status Update APT32 PubPrn | Carr, N. (2017, December 22). ItsReallyNick Status Update. Retrieved September 12, 2024. |
| Twitter Richard WMIC | Ackroyd, R. (2023, March 24). Twitter. Retrieved September 12, 2024. |
| Two New Monero Malware Attacks Target Windows and Android Users | Douglas Bonderud. (2018, September 17). Two New Monero Malware Attacks Target Windows and Android Users. Retrieved June 5, 2023. |
| Tycoon2FA - Unicode | Rodel Mendrez. (2025, April 10). Tycoon2FA New Evasion Technique for 2025. Retrieved April 21, 2026. |
| UK GOV FSB Factsheet April 2022 | UK Gov. (2022, April 5). Russia's FSB malign activity: factsheet. Retrieved April 5, 2022. |
| UK Gov Malign RIS Activity April 2021 | UK Gov. (2021, April 15). UK and US expose global campaign of malign activity by Russian intelligence services . Retrieved April 16, 2021. |
| UK Gov UK Exposes Russia SolarWinds April 2021 | UK Gov. (2021, April 15). UK exposes Russian involvement in SolarWinds cyber compromise . Retrieved April 16, 2021. |
| UK NCSC Olympic Attacks October 2020 | UK NCSC. (2020, October 19). UK exposes series of Russian cyber attacks against Olympic and Paralympic Games . Retrieved November 30, 2020. |
| UK NSCS Russia SolarWinds April 2021 | UK NCSC. (2021, April 15). UK and US call out Russia for SolarWinds compromise. Retrieved April 16, 2021. |
| UNIT 42 LAPSUS Mar 2022 | UNIT 42. (2022, March 24). Threat Brief: Lapsus$ Group. Retrieved May 17, 2022. |
| URI | Michael Cobb. (2007, October 11). Preparing for uniform resource identifier (URI) exploits. Retrieved February 9, 2024. |
| URI Unique | Australian Cyber Security Centre. National Security Agency. (2020, April 21). Detect and Prevent Web Shell Malware. Retrieved February 9, 2024. |
| URI Use | Nathan McFeters. Billy Kim Rios. Rob Carter.. (2008). URI Use and Abuse. Retrieved February 9, 2024. |
| US Dept. of Treasury Salt Typhoon JAN 2025 | US Department of Treasury. (2025, January 17). Treasury Sanctions Company Associated with Salt Typhoon and Hacker Associated with Treasury Compromise. Retrieved February 24, 2025. |
| US District Court Indictment GRU Oct 2018 | Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020. |
| US District Court Indictment GRU Unit 74455 October 2020 | Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020. |
| US-CERT APT Energy Oct 2017 | US-CERT. (2017, October 20). Alert (TA17-293A): Advanced Persistent Threat Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved November 2, 2017. |
| US-CERT BADCALL | US-CERT. (2018, February 06). Malware Analysis Report (MAR) - 10135536-G. Retrieved June 7, 2018. |
| US-CERT BLINDINGCAN Aug 2020 | US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020. |
| US-CERT Bankshot Dec 2017 | US-CERT. (2017, December 13). Malware Analysis Report (MAR) - 10135536-B. Retrieved July 17, 2018. |
| US-CERT Emotet Jul 2018 | US-CERT. (2018, July 20). Alert (TA18-201A) Emotet Malware. Retrieved March 25, 2019. |
| US-CERT FALLCHILL Nov 2017 | US-CERT. (2017, November 22). Alert (TA17-318A): HIDDEN COBRA – North Korean Remote Administration Tool: FALLCHILL. Retrieved December 7, 2017. |
| US-CERT HARDRAIN March 2018 | US-CERT. (2018, February 05). Malware Analysis Report (MAR) - 10135536-F. Retrieved June 11, 2018. |
| US-CERT HIDDEN COBRA June 2017 | US-CERT. (2017, June 13). Alert (TA17-164A) HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructure. Retrieved July 13, 2017. |
| US-CERT HOPLIGHT Apr 2019 | US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019. |
| US-CERT HOTCROISSANT February 2020 | US-CERT. (2020, February 20). MAR-10271944-1.v1 – North Korean Trojan: HOTCROISSANT. Retrieved May 1, 2020. |
| US-CERT KEYMARBLE Aug 2018 | US-CERT. (2018, August 09). MAR-10135536-17 – North Korean Trojan: KEYMARBLE. Retrieved August 16, 2018. |
| US-CERT NotPetya 2017 | US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019. |
| US-CERT Ransomware 2016 | US-CERT. (2016, March 31). Alert (TA16-091A): Ransomware and Recent Variants. Retrieved March 15, 2019. |
| US-CERT SHARPKNOT June 2018 | US-CERT. (2018, March 09). Malware Analysis Report (MAR) - 10135536.11.WHITE. Retrieved June 13, 2018. |
| US-CERT SamSam 2018 | US-CERT. (2018, December 3). Alert (AA18-337A): SamSam Ransomware. Retrieved March 15, 2019. |
| US-CERT TA17-156A SNMP Abuse 2017 | US-CERT. (2017, June 5). Reducing the Risk of SNMP Abuse. Retrieved October 19, 2020. |
| US-CERT TA18-068A 2018 | US-CERT. (2018, March 27). TA18-068A Brute Force Attacks Conducted by Cyber Actors. Retrieved October 2, 2019. |
| US-CERT TA18-074A | US-CERT. (2018, March 16). Alert (TA18-074A): Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors. Retrieved June 6, 2018. |
| US-CERT TA18-106A Network Infrastructure Devices 2018 | US-CERT. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020. |
| US-CERT TYPEFRAME June 2018 | US-CERT. (2018, June 14). MAR-10135536-12 – North Korean Trojan: TYPEFRAME. Retrieved July 13, 2018. |
| US-CERT Ukraine Feb 2016 | US-CERT. (2016, February 25). ICS Alert (IR-ALERT-H-16-056-01) Cyber-Attack Against Ukrainian Critical Infrastructure. Retrieved June 10, 2020. |
| US-CERT Volgmer 2 Nov 2017 | US-CERT. (2017, November 01). Malware Analysis Report (MAR) - 10135536-D. Retrieved July 16, 2018. |
| US-CERT Volgmer Nov 2017 | US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017. |
| US-CERT WannaCry 2017 | US-CERT. (2017, May 12). Alert (TA17-132A): Indicators Associated With WannaCry Ransomware. Retrieved March 25, 2019. |
| US-CERT-TA18-106A | US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020. |
| USCYBERCOM SLOTHFULMEDIA October 2020 | USCYBERCOM. (2020, October 1). USCYBERCOM Cybersecurity Alert SLOTHFULMEDIA. Retrieved September 12, 2024. |
| USDOJ Sandworm Feb 2020 | Pompeo, M. (2020, February 20). The United States Condemns Russian Cyber Attack Against the Country of Georgia. Retrieved September 12, 2024. |
| USG Joint Statement SolarWinds January 2021 | FBI, CISA, ODNI, NSA. (2022, January 5). Joint Statement by the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Office of the Director of National Intelligence (ODNI), and the Nationa… |
| USNYAG IranianBotnet March 2016 | Preet Bharara, US Attorney. (2016, March 24). Retrieved April 23, 2019. |
| Ubuntu Manpage systemd rc | Canonical Ltd.. (n.d.). systemd-rc-local-generator - Compatibility generator for starting /etc/rc.local and /usr/sbin/halt.local during boot and shutdown. Retrieved February 23, 2021. |
| Ukraine15 - EISAC - 201603 | Electricity Information Sharing and Analysis Center; SANS Industrial Control Systems. (2016, March 18). Analysis of the Cyber Attack on the Ukranian Power Grid: Defense Use Case. Retrieved March 27, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.