Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| VectorSec ForFiles Aug 2017 | vector_sec. (2017, August 11). Defenders watching launches of cmd? What about forfiles?. Retrieved September 12, 2024. |
| Venafi SSH Key Abuse | Blachman, Y. (2020, April 22). Growing Abuse of SSH Keys: Commodity Malware Campaigns Now Equipped with SSH Capabilities. Retrieved June 24, 2020. |
| VenereCiscoTalos_Gamaredon_Mar2025 | Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025. |
| Veriti RedLine Stealer MAAS April 2023 | Yair Herling. (2023, April 4). From ChatGPT to RedLine Stealer: The Dark Side of OpenAI and Google Bard. Retrieved September 17, 2025. |
| Villeneuve 2011 | Villeneuve, N., Sancho, D. (2011). THE “LURID” DOWNLOADER. Retrieved November 12, 2014. |
| Villeneuve 2014 | Villeneuve, N., Homan, J. (2014, July 31). Spy of the Tiger. Retrieved September 29, 2015. |
| Vincens AcidPour 2024 | A.J. Vincens, CyberScoop. (2024, March 18). Researchers spot updated version of malware that hit Viasat. Retrieved March 25, 2024. |
| Virtualization/Sandbox Evasion | YUCEEL, Huseyin Can. Picus Labs. (2022, June 9). Virtualization/Sandbox Evasion - How Attackers Avoid Malware Analysis. Retrieved December 26, 2023. |
| Virus Bulletin | Suguru Ishimaru, Hajime Yanagishita, Yusuke Niwa. (2023, October 5). Unveiling activities of Tropic Trooper 2023: deep analysis of Xiangoop Loader and EntryShell payload. Retrieved October 3, 2025. |
| VirusBulletin Kimsuky October 2019 | Kim, J. et al. (2019, October). KIMSUKY GROUP: TRACKING THE KING OF THE SPEAR PHISHING. Retrieved November 2, 2020. |
| VirusTotal FAQ | VirusTotal. (n.d.). VirusTotal FAQ. Retrieved May 23, 2019. |
| Visa FIN6 Feb 2019 | Visa Public. (2019, February). FIN6 Cybercrime Group Expands Threat to eCommerce Merchants. Retrieved September 16, 2019. |
| Visa RawPOS March 2015 | Visa. (2015, March). Visa Security Alert: "RawPOS" Malware Targeting Lodging Merchants. Retrieved October 6, 2017. |
| Volatility Phalanx2 | Case, A. (2012, October 10). Phalanx 2 Revealed: Using Volatility to Analyze an Advanced Linux Rootkit. Retrieved April 9, 2018. |
| Volexity | Ankur Saini, Charlie Gardner. (2023, June 28). Charming Kitten Updates POWERSTAR with an InterPlanetary Twist. Retrieved September 25, 2025. |
| Volexity 3CX Supply Chain Compromise AppleJeus IconicStealer March 2023 | Ankur Saini, Callum Roxan, Charlie Gardner, Paul Rascagneres, Steven Adair, Tom Lancaster. (2023, March 30). 3CX Supply Chain Compromise Leads to ICONIC Incident. Retrieved October 21, 2025. |
| Volexity Exchange Marauder March 2021 | Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021. |
| Volexity GlobalProtect CVE 2024 | Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved May 22, 2025. |
| Volexity InkySquid BLUELIGHT August 2021 | Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021. |
| Volexity InkySquid RokRAT August 2021 | Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021. |
| Volexity Ivanti Global Exploitation January 2024 | Gurkok, C. et al. (2024, January 15). Ivanti Connect Secure VPN Exploitation Goes Global. Retrieved February 27, 2024. |
| Volexity Ivanti Zero-Day Exploitation January 2024 | Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024. |
| Volexity Ocean Lotus November 2020 | Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020. |
| Volexity OceanLotus Nov 2017 | Lassalle, D., et al. (2017, November 6). OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society. Retrieved November 6, 2017. |
| Volexity Patchwork June 2018 | Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018. |
| Volexity PowerDuke November 2016 | Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017. |
| Volexity SolarWinds | Cash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020. |
| Volexity UPSTYLE 2024 | Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved November 20, 2024. |
| Volexity Virtual Private Keylogging | Adair, S. (2015, October 7). Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence. Retrieved March 20, 2017. |
| WHOIS | NTT America. (n.d.). Whois Lookup. Retrieved November 17, 2024. |
| WMI 1-3 | Microsoft. (2023, March 7). Retrieved February 13, 2024. |
| WMI 6 | Microsoft. (2022, June 13). BlackCat. Retrieved February 13, 2024. |
| WMI 7,8 | Microsoft. (2024, January 26). WMIC Deprecation. Retrieved February 13, 2024. |
| WSJ-Vishing-AI24 | Catherine Stupp. (2019, August 30). Fraudsters Used AI to Mimic CEO’s Voice in Unusual Cybercrime Case. Retrieved March 18, 2025. |
| Wald0 Guide to GPOs | Robbins, A. (2018, April 2). A Red Teamer’s Guide to GPOs and OUs. Retrieved March 5, 2019. |
| Walmart Roberts Oct 2018 | Sayre, K., Ogden, H., Roberts, C. (2018, October 10). VBA Stomping — Advanced Maldoc Techniques. Retrieved September 17, 2020. |
| Wardle Dylib Hijack Vulnerable Apps | Patrick Wardle. (2019, July 2). Getting Root with Benign AppStore Apps. Retrieved March 31, 2021. |
| Wardle Dylib Hijacking OSX 2015 | Patrick Wardle. (2015, March 1). Dylib Hijacking on OS X. Retrieved March 29, 2021. |
| Wardle Persistence Chapter | Patrick Wardle. (n.d.). Chapter 0x2: Persistence. Retrieved April 13, 2022. |
| Washington Post WannaCry 2017 | Dwoskin, E. and Adam, K. (2017, May 14). More than 150 countries affected by massive cyberattack, Europol says. Retrieved March 25, 2019. |
| WeLiveSecurity Gapz and Redyms Mar 2013 | Matrosov, A. (2013, March 19). Gapz and Redyms droppers based on Power Loader code. Retrieved December 16, 2017. |
| Wevtutil Microsoft Documentation | Microsoft. (n.d.). wevtutil. Retrieved September 14, 2021. |
| White House Imposing Costs RU Gov April 2021 | White House. (2021, April 15). Imposing Costs for Harmful Foreign Activities by the Russian Government. Retrieved April 16, 2021. |
| Wi-Fi Password of All Connected Networks in Windows/Linux | Geeks for Geeks. (n.d.). Wi-Fi Password of All Connected Networks in Windows/Linux. Retrieved September 8, 2023. |
| Wietze Beukema DLL Hijacking | Wietze Beukema. (2020, June 22). Hijacking DLLs in Windows. Retrieved April 8, 2025. |
| Wikipedia Active Directory | Wikipedia. (2018, March 10). Active Directory. Retrieved April 11, 2018. |
| Wikipedia BIOS | Wikipedia. (n.d.). BIOS. Retrieved January 5, 2016. |
| Wikipedia Binary-to-text Encoding | Wikipedia. (2016, December 26). Binary-to-text encoding. Retrieved March 1, 2017. |
| Wikipedia Booting | Wikipedia. (n.d.). Booting. Retrieved November 13, 2019. |
| Wikipedia Browser Extension | Wikipedia. (2017, October 8). Browser Extension. Retrieved January 11, 2018. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.