Reports, blog posts and papers that MITRE cites as evidence.
3865 references
| Citation | Description |
|---|---|
| Wiz Ultralytics AI Library Hijack 2024 | Wiz Threat Research. (2024, December 9). Ultralytics AI Library Hacked via GitHub for Cryptomining. Retrieved May 22, 2025. |
| Writing Bad Malware for OSX | Patrick Wardle. (2015). Writing Bad @$$ Malware for OS X. Retrieved July 10, 2017. |
| XAgentOSX 2017 | Robert Falcone. (2017, February 14). XAgentOSX: Sofacy's Xagent macOS Tool. Retrieved July 12, 2017. |
| XPNSec PPID Nov 2017 | Chester, A. (2017, November 20). Alternative methods of becoming SYSTEM. Retrieved June 4, 2019. |
| XSL Bypass Mar 2019 | Singh, A. (2019, March 14). MSXSL.EXE and WMIC.EXE — A Way to Proxy Code Execution. Retrieved August 2, 2019. |
| Xpn Argue Like Cobalt 2019 | Chester, A. (2019, January 28). How to Argue like Cobalt Strike. Retrieved November 19, 2021. |
| ZDNET Selling Data | Cimpanu, C. (2020, May 9). A hacker group is selling more than 73 million user records on the dark web. Retrieved October 20, 2020. |
| ZDNet Dtrack | Catalin Cimpanu. (2019, October 30). Confirmed: North Korean malware found on Indian nuclear plant's network. Retrieved January 20, 2021. |
| ZDNet Ransomware Backups 2020 | Steve Ranger. (2020, February 27). Ransomware victims thought their backups were safe. They were wrong. Retrieved March 21, 2023. |
| ZScaler BitB 2020 | ZScaler. (2020, February 11). Fake Sites Stealing Steam Credentials. Retrieved March 8, 2023. |
| ZScaler Hacking Team | Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016. |
| ZScaler SEO | Wang, J. (2018, October 17). Ubiquitous SEO Poisoning URLs. Retrieved September 30, 2022. |
| ZScaler Squirrelwaffle Sep 2021 | Kumar, A., Stone-Gross, Brett. (2021, September 28). Squirrelwaffle: New Loader Delivering Cobalt Strike. Retrieved August 9, 2022. |
| Zdnet Kimsuky Dec 2018 | Cimpanu, C.. (2018, December 5). Cyber-espionage group uses Chrome extension to infect victims. Retrieved August 26, 2019. |
| Zdnet Kimsuky Group September 2020 | Cimpanu, C. (2020, September 30). North Korea has tried to hack 11 officials of the UN Security Council. Retrieved November 4, 2020. |
| Zdnet Ngrok September 2018 | Cimpanu, C. (2018, September 13). Sly malware author hides cryptomining botnet behind ever-shifting proxy service. Retrieved September 15, 2020. |
| Zimbra Preauth | Zimbra. (2023, March 16). Preauth. Retrieved May 31, 2023. |
| Zlib Github | madler. (2017). zlib. Retrieved February 20, 2020. |
| Zscaler | Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025. |
| Zscaler APT31 Covid-19 October 2020 | Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021. |
| Zscaler Bazar September 2020 | Sadique, M. and Singh, A. (2020, September 29). Spear Phishing Campaign Delivers Buer and Bazar Malware. Retrieved November 19, 2020. |
| Zscaler BlindEagle DEC 2025 | Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026. |
| Zscaler Cobian Aug 2017 | Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018. |
| Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 | Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025. |
| Zscaler Havoc FEB 2023 | Shivtarkar, N. and Jain, S. (2023, February 14). Havoc Across the Cyberspace. Retrieved August 4, 2025. |
| Zscaler Higaisa 2020 | Singh, S. Singh, A. (2020, June 11). The Return on the Higaisa APT. Retrieved March 2, 2021. |
| Zscaler Kasidet | Yadav, A., et al. (2016, January 29). Malicious Office files dropping Kasidet and Dridex. Retrieved March 24, 2016. |
| Zscaler Kimsuky TRANSLATEXT | Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024. |
| Zscaler Lyceum DnsSystem June 2022 | Shivtarkar, N. and Kumar, A. (2022, June 9). Lyceum .NET DNS Backdoor. Retrieved June 23, 2022. |
| Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 | Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025. |
| Zscaler Pikabot 2023 | Brett Stone-Gross & Nikolaos Pantazopoulos. (2023, May 24). Technical Analysis of Pikabot. Retrieved July 12, 2024. |
| Zscaler Pikabot 2024 | Nikolaos Pantazopoulos. (2024, February 12). The (D)Evolution of Pikabot. Retrieved July 17, 2024. |
| Zscaler PureCrypter JUN 2022 | Dumont, R. (2022, June 13). Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Retrieved April 16, 2026. |
| Zscaler XLoader 2025 | Zscaler Threatlabz. (2025, January 27). Technical Analysis of Xloader Versions 6 and 7 | Part 1. Retrieved March 11, 2025. |
| abusing_com_reg | bohops. (2018, August 18). ABUSING THE COM REGISTRY STRUCTURE (PART 2): HIJACKING & LOADING TECHNIQUES. Retrieved September 20, 2021. |
| acroread package compromised Arch Linux Mail 8JUL2018 | Eli Schwartz. (2018, June 8). acroread package compromised. Retrieved April 23, 2019. |
| ad_blocker_with_miner | Kuzmenko, A.. (2021, March 10). Ad blocker with miner included. Retrieved October 28, 2021. |
| airwalk backdoor unix systems | airwalk. (2023, January 1). A guide to backdooring Unix systems. Retrieved May 31, 2023. |
| alert_TA18_106A | CISA. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved February 14, 2022. |
| alientvault macspy | PETER EWANE. (2017, June 9). MacSpy: OS X RAT as a Service. Retrieved September 21, 2018. |
| amnesia malware | Claud Xiao, Cong Zheng, Yanhui Jia. (2017, April 6). New IoT/Linux Malware Targets DVRs, Forms Botnet. Retrieved February 19, 2018. |
| amnesty_nso_pegasus | Amnesty International Security Lab. (2021, July 18). Forensic Methodology Report: How to catch NSO Group’s Pegasus. Retrieved February 22, 2022. |
| anomali-linux-rabbit | Anomali Threat Research. (2018, December 6). Pulling Linux Rabbit/Rabbot Malware Out of a Hat. Retrieved December 17, 2020. |
| anomali-rocke-tactics | Anomali Threat Research. (2019, October 15). Illicit Cryptomining Threat Actor Rocke Changes Tactics, Now More Difficult to Detect. Retrieved December 17, 2020. |
| apple doco bonjour description | Apple Inc. (2013, April 23). Bonjour Overview. Retrieved October 11, 2021. |
| apt41_dcsocytec_dec2022 | DCSO CyTec Blog. (2022, December 24). APT41 — The spy who failed to encrypt me. Retrieved June 13, 2024. |
| apt41_mandiant | Mandiant. (n.d.). APT41, A DUAL ESPIONAGE AND CYBER CRIME OPERATION. Retrieved June 11, 2024. |
| aptsim | valsmith. (2012, September 21). More on APTSim. Retrieved September 28, 2017. |
| aquasec | Ofek Itach, Assaf Morag. (2023, July 13). TeamTNT Reemerged with New Aggressive Cloud Campaign. Retrieved June 15, 2025. |
| aquasec-postgres-processes | Assaf Morag. (2024, August 19). PG_MEM: A Malware Hidden in the Postgres Processes. Retrieved January 31, 2025. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.