ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
VectorSec ForFiles Aug 2017vector_sec. (2017, August 11). Defenders watching launches of cmd? What about forfiles?. Retrieved September 12, 2024.
Venafi SSH Key AbuseBlachman, Y. (2020, April 22). Growing Abuse of SSH Keys: Commodity Malware Campaigns Now Equipped with SSH Capabilities. Retrieved June 24, 2020.
VenereCiscoTalos_Gamaredon_Mar2025Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.
Veriti RedLine Stealer MAAS April 2023Yair Herling. (2023, April 4). From ChatGPT to RedLine Stealer: The Dark Side of OpenAI and Google Bard. Retrieved September 17, 2025.
Villeneuve 2011Villeneuve, N., Sancho, D. (2011). THE “LURID” DOWNLOADER. Retrieved November 12, 2014.
Villeneuve 2014Villeneuve, N., Homan, J. (2014, July 31). Spy of the Tiger. Retrieved September 29, 2015.
Vincens AcidPour 2024A.J. Vincens, CyberScoop. (2024, March 18). Researchers spot updated version of malware that hit Viasat. Retrieved March 25, 2024.
Virtualization/Sandbox EvasionYUCEEL, Huseyin Can. Picus Labs. (2022, June 9). Virtualization/Sandbox Evasion - How Attackers Avoid Malware Analysis. Retrieved December 26, 2023.
Virus BulletinSuguru Ishimaru, Hajime Yanagishita, Yusuke Niwa. (2023, October 5). Unveiling activities of Tropic Trooper 2023: deep analysis of Xiangoop Loader and EntryShell payload. Retrieved October 3, 2025.
VirusBulletin Kimsuky October 2019Kim, J. et al. (2019, October). KIMSUKY GROUP: TRACKING THE KING OF THE SPEAR PHISHING. Retrieved November 2, 2020.
VirusTotal FAQVirusTotal. (n.d.). VirusTotal FAQ. Retrieved May 23, 2019.
Visa FIN6 Feb 2019Visa Public. (2019, February). FIN6 Cybercrime Group Expands Threat to eCommerce Merchants. Retrieved September 16, 2019.
Visa RawPOS March 2015Visa. (2015, March). Visa Security Alert: "RawPOS" Malware Targeting Lodging Merchants. Retrieved October 6, 2017.
Volatility Phalanx2Case, A. (2012, October 10). Phalanx 2 Revealed: Using Volatility to Analyze an Advanced Linux Rootkit. Retrieved April 9, 2018.
VolexityAnkur Saini, Charlie Gardner. (2023, June 28). Charming Kitten Updates POWERSTAR with an InterPlanetary Twist. Retrieved September 25, 2025.
Volexity 3CX Supply Chain Compromise AppleJeus IconicStealer March 2023Ankur Saini, Callum Roxan, Charlie Gardner, Paul Rascagneres, Steven Adair, Tom Lancaster. (2023, March 30). 3CX Supply Chain Compromise Leads to ICONIC Incident. Retrieved October 21, 2025.
Volexity Exchange Marauder March 2021Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021.
Volexity GlobalProtect CVE 2024Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved May 22, 2025.
Volexity InkySquid BLUELIGHT August 2021Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.
Volexity InkySquid RokRAT August 2021Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.
Volexity Ivanti Global Exploitation January 2024Gurkok, C. et al. (2024, January 15). Ivanti Connect Secure VPN Exploitation Goes Global. Retrieved February 27, 2024.
Volexity Ivanti Zero-Day Exploitation January 2024Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024.
Volexity Ocean Lotus November 2020Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.
Volexity OceanLotus Nov 2017Lassalle, D., et al. (2017, November 6). OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society. Retrieved November 6, 2017.
Volexity Patchwork June 2018Meltzer, M, et al. (2018, June 07). Patchwork APT Group Targets US Think Tanks. Retrieved July 16, 2018.
Volexity PowerDuke November 2016Adair, S.. (2016, November 9). PowerDuke: Widespread Post-Election Spear Phishing Campaigns Targeting Think Tanks and NGOs. Retrieved January 11, 2017.
Volexity SolarWindsCash, D. et al. (2020, December 14). Dark Halo Leverages SolarWinds Compromise to Breach Organizations. Retrieved December 29, 2020.
Volexity UPSTYLE 2024Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved November 20, 2024.
Volexity Virtual Private KeyloggingAdair, S. (2015, October 7). Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence. Retrieved March 20, 2017.
WHOISNTT America. (n.d.). Whois Lookup. Retrieved November 17, 2024.
WMI 1-3Microsoft. (2023, March 7). Retrieved February 13, 2024.
WMI 6Microsoft. (2022, June 13). BlackCat. Retrieved February 13, 2024.
WMI 7,8Microsoft. (2024, January 26). WMIC Deprecation. Retrieved February 13, 2024.
WSJ-Vishing-AI24Catherine Stupp. (2019, August 30). Fraudsters Used AI to Mimic CEO’s Voice in Unusual Cybercrime Case. Retrieved March 18, 2025.
Wald0 Guide to GPOsRobbins, A. (2018, April 2). A Red Teamer’s Guide to GPOs and OUs. Retrieved March 5, 2019.
Walmart Roberts Oct 2018Sayre, K., Ogden, H., Roberts, C. (2018, October 10). VBA Stomping — Advanced Maldoc Techniques. Retrieved September 17, 2020.
Wardle Dylib Hijack Vulnerable AppsPatrick Wardle. (2019, July 2). Getting Root with Benign AppStore Apps. Retrieved March 31, 2021.
Wardle Dylib Hijacking OSX 2015Patrick Wardle. (2015, March 1). Dylib Hijacking on OS X. Retrieved March 29, 2021.
Wardle Persistence ChapterPatrick Wardle. (n.d.). Chapter 0x2: Persistence. Retrieved April 13, 2022.
Washington Post WannaCry 2017Dwoskin, E. and Adam, K. (2017, May 14). More than 150 countries affected by massive cyberattack, Europol says. Retrieved March 25, 2019.
WeLiveSecurity Gapz and Redyms Mar 2013Matrosov, A. (2013, March 19). Gapz and Redyms droppers based on Power Loader code. Retrieved December 16, 2017.
Wevtutil Microsoft DocumentationMicrosoft. (n.d.). wevtutil. Retrieved September 14, 2021.
White House Imposing Costs RU Gov April 2021White House. (2021, April 15). Imposing Costs for Harmful Foreign Activities by the Russian Government. Retrieved April 16, 2021.
Wi-Fi Password of All Connected Networks in Windows/LinuxGeeks for Geeks. (n.d.). Wi-Fi Password of All Connected Networks in Windows/Linux. Retrieved September 8, 2023.
Wietze Beukema DLL HijackingWietze Beukema. (2020, June 22). Hijacking DLLs in Windows. Retrieved April 8, 2025.
Wikipedia Active DirectoryWikipedia. (2018, March 10). Active Directory. Retrieved April 11, 2018.
Wikipedia BIOSWikipedia. (n.d.). BIOS. Retrieved January 5, 2016.
Wikipedia Binary-to-text EncodingWikipedia. (2016, December 26). Binary-to-text encoding. Retrieved March 1, 2017.
Wikipedia BootingWikipedia. (n.d.). Booting. Retrieved November 13, 2019.
Wikipedia Browser ExtensionWikipedia. (2017, October 8). Browser Extension. Retrieved January 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.