ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Bleeping Computer - Scriptrunner.exeBill Toulas. (2023, January 4). Hackers abuse Windows error reporting tool to deploy malware. Retrieved July 8, 2024.
Bleeping Computer 2easy 2021Bill Toulas. (2021, December 21). 2easy now a significant dark web marketplace for stolen data. Retrieved October 7, 2024.
Bleeping Computer Bank Hack 2020Ionut Ilascu. (2020, January 16). Customer-Owned Bank Informs 100k of Breach Exposing Account Balance, PII. Retrieved July 1, 2024.
Bleeping Computer Binance Smart Chain 2023Bill Toulas. (2023, October 13). Hackers use Binance Smart Chain contracts to store malicious scripts. Retrieved May 22, 2025.
Bleeping Computer INC Ransomware March 2024Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Bleeping Computer Latrodectus April 2024Abrams, L. (2024, April 30). New Latrodectus malware attacks use Microsoft, Cloudflare themes. Retrieved September 13, 2024.
Bleeping Computer Mint Mobile Hack 2021Lawrence Abrams. (2021, July 10). Mint Mobile hit by a data breach after numbers ported, data accessed. Retrieved July 1, 2024.
Bleeping Computer Op Sharpshooter March 2019I. Ilascu. (2019, March 3). Op 'Sharpshooter' Connected to North Korea's Lazarus Group. Retrieved September 26, 2022.
Bleeping Computer SVG Smuggling 2024Lawrence Abrams. (2024, November 17). Phishing emails increasingly use SVG attachments to evade detection. Retrieved March 25, 2025.
Bleeping Computer Stealer Logs 2023Flare. (2023, June 6). Dissecting the Dark Web Supply Chain: Stealer Logs in Context. Retrieved October 10, 2024.
Bleeping Computer US Cellular Hack 2022Sergiu Gatlan. (2022, January 4). UScellular discloses data breach after billing system hack. Retrieved July 1, 2024.
BleepingComp Godlua JUL19Gatlan, S. (2019, July 3). New Godlua Malware Evades Traffic Monitoring via DNS over HTTPS. Retrieved March 15, 2020.
BleepingComputer Agent Tesla steal wifi passwordsSergiu Gatlan. (2020, April 16). Hackers steal WiFi passwords using upgraded Agent Tesla malware. Retrieved September 8, 2023.
BleepingComputer BackSwapCatalin Cimpanu. (2018, May 25). BackSwap Banking Trojan Uses Never-Before-Seen Techniques. Retrieved March 27, 2025.
BleepingComputer DDE Disabled in Word Dec 2017Cimpanu, C. (2017, December 15). Microsoft Disables DDE Feature in Word to Prevent Further Malware Attacks. Retrieved December 19, 2017.
BleepingComputer Ebury March 2017Cimpanu, C.. (2017, March 29). Russian Hacker Pleads Guilty for Role in Infamous Linux Ebury Malware. Retrieved April 23, 2019.
BleepingComputer Molerats Dec 2020Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.
BleepingComputer REvil 2021Abrams, L. (2021, March 19). REvil ransomware has a new ‘Windows Safe Mode’ encryption mode. Retrieved June 23, 2021.
BleepingComputer USBIonut Ilascu. (2020, March 27). FBI: Hackers Sending Malicious USB Drives & Teddy Bears via USPS. Retrieved March 27, 2025.
Bleepingcomputer Gamardeon FSB November 2021Toulas, B. (2018, November 4). Ukraine links members of Gamaredon hacker group to Russian FSB. Retrieved April 15, 2022.
Bleepingcomputer RAT malware 2020Abrams, L. (2020, October 23). New RAT malware gets commands via Discord, has ransomware feature. Retrieved April 1, 2021.
BloxhamBloxham, B. (n.d.). Getting Windows to Play with Itself [PowerPoint slides]. Retrieved November 12, 2014.
Blue Cloud of DeathKunz, Bryce. (2018, May 11). Blue Cloud of Death: Red Teaming Azure. Retrieved October 23, 2019.
Blue Cloud of Death VideoKunz, Bruce. (2018, October 14). Blue Cloud of Death: Red Teaming Azure. Retrieved November 21, 2019.
Booby Trap Shortcut 2017Weyne, F. (2017, April). Booby trap a shortcut with a backdoor. Retrieved October 3, 2023.
Booz Allen HamiltonBooz Allen Hamilton. (2016). When The Lights Went Out. Retrieved December 18, 2024.
Botnet ScanDainotti, A. et al. (2012). Analysis of a “/0” Stealth Scan from a Botnet. Retrieved October 20, 2020.
Brazking-WebsocketsShahar Tavor. (n.d.). BrazKing Android Malware Upgraded and Targeting Brazilian Banks. Retrieved March 24, 2023.
Breach Post-mortem SSH HijackHodgson, M. (2019, May 8). Post-mortem and remediations for Apr 11 security incident. Retrieved November 17, 2024.
Breakdev Evilginx 2.1 SEP 2018Gretzky, K. (2018, September 10). Evilginx 2.1 - The First Post-Release Update. Retrieved January 27, 2026.
Breakdev Evilginx 2.2 NOV 2018Gretzky, K. (2018, November 22). Evilginx 2.2 - Jolly Winter Update. Retrieved January 27, 2026.
Breakdev Evilginx 2.3 JAN 2019Gretzky, K. (2019, January 18). Evilginx 2.3 - Phisherman's Dream. Retrieved January 27, 2026.
Breakdev Evilginx 2.4 SEP 2020Gretzky, K. (2020, September 14). Evilginx 2.4 - Gone Phishing. Retrieved January 27, 2026.
Breakdev Evilginx 3.0 May 2023Gretzky, K. (2023, May 10). Evilginx 3.0 + Evilginx Mastery. Retrieved January 27, 2026.
Breakdev Evilginx 3.2 AUG 2023Gretzky, K. (2023, August 24). Evilginx 3.2 - Swimming With The Phishes. Retrieved January 27, 2026.
Breakdev Evilginx 3.3 APR 2024Gretzky, K. (2024, April 2). Evilginx 3.3 - Go & Phish. Retrieved January 27, 2026.
Brining MimiKatz to UnixTim Wadhwa-Brown. (2018, November). Where 2 worlds collide Bringing Mimikatz et al to UNIX. Retrieved October 13, 2021.
BroadcomBroadcom Protection Bulletins. (2025, February 20). Bookworm malware linked to Fireant (aka Stately Tarurus) activity observed in Southeast Asia. Retrieved July 21, 2025.
Broadcom BirdyClient Microsoft Graph API 2024Broadcom. (2024, May 2). BirdyClient malware leverages Microsoft Graph API for C&C communication. Retrieved July 1, 2024.
Broadcom ESXCLI ReferenceBroadcom. (n.d.). ESXCLI Reference. Retrieved March 27, 2025.
Broadcom ESXi FirewallBroadcom. (2025, March 24). Add Allowed IP Addresses for an ESXi Host by Using the VMware Host Client. Retrieved March 26, 2025.
Broadcom ESXi SSHBroadcom. (2024, December 12). Allowing SSH access to VMware vSphere ESXi/ESX hosts with public/private key authentication. Retrieved March 26, 2025.
Broadcom ESXi Shell AuditBroadcom. (2025, February 20). Auditing ESXi Shell logins and commands. Retrieved March 26, 2025.
Broadcom Medusa Ransomware Medusa Group March 2025Threat Hunter Team Symantec and Carbon Black. (2025, March 6). Medusa Ransomware Activity Continues to Increase. Retrieved October 15, 2025.
Broadcom Running Guest OS OperationsBroadcom. (n.d.). Running Guest OS Operations. Retrieved March 28, 2025.
Broadcom VMSA-2024-0019Broadcom. (2024, September 17). VMSA-2024-0019: Questions & Answers. Retrieved April 8, 2025.
Broadcom VMSA-2025-004Broadcom. (2025, March 6). VMSA-2025-0004: Questions & Answers. Retrieved March 26, 2025.
Broadcom VMware Tools ServicesBroadcom. (n.d.). VMware Tools Services. Retrieved March 28, 2025.
Bromium Ursnif Mar 2017Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Browers FriarFoxRaggi, Michael. Proofpoint Threat Research Team. (2021, February 25). TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.