ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
sentinellabs resource named fork 2020Phil Stokes. (2020, November 5). Resourceful macOS Malware Hides in Named Fork. Retrieved October 12, 2021.
sentinelone apt32 macOS backdoor 2020Phil Stokes. (2020, December 2). APT32 Multi-stage macOS Trojan Innovates on Crimeware Scripting Technique. Retrieved September 13, 2021.
sentinelone macos persist Jun 2019Stokes, Phil. (2019, June 17). HOW MALWARE PERSISTS ON MACOS. Retrieved September 10, 2019.
sentinelone operationDigitalEye Dec 2024Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.
sentinelone shlayer to zshlayerPhil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.
sentinelone-malvertisingHegel, Tom. (2023, January 19). Breaking Down the SEO Poisoning Attack | How Attackers Are Hijacking Search Results. Retrieved February 21, 2023.
setuid man pageMichael Kerrisk. (2017, September 15). Linux Programmer's Manual. Retrieved September 21, 2018.
show_clock_detail_cisco_cmdCisco. (2023, March 6). show clock detail - Cisco IOS Security Command Reference: Commands S to Z . Retrieved July 13, 2022.
show_processes_cisco_cmdCisco. (2022, August 16). show processes - . Retrieved July 13, 2022.
show_run_config_cmd_ciscoCisco. (2022, August 16). show running-config - Cisco IOS Configuration Fundamentals Command Reference . Retrieved July 13, 2022.
show_ssh_users_cmd_ciscoCisco. (2023, March 7). Cisco IOS Security Command Reference: Commands S to Z . Retrieved July 13, 2022.
sophos-bombingMark Parsons, Colin Cowie, Daniel Souter, Hunter Neal, Anthony Bradshaw, Sean Gallagher. (2025, January 21). Sophos MDR tracks two ransomware campaigns using “email bombing,” Microsoft Teams “vishing”. Retrieved January 31, 2025.
sophos-multiple-attackersMatt Wixey. (2022, August 9). Multiple attackers increase pressure on victims, complicate incident response. Retrieved January 31, 2025.
spamhaus-malvertisingMiller, Sarah. (2023, February 2). A surge of malvertising across Google Ads is distributing dangerous malware. Retrieved February 21, 2023.
specter ops evil twinRyan, Gabriel. (2019, October 28). Modern Wireless Tradecraft Pt I — Basic Rogue AP Theory — Evil Twin and Karma Attacks. Retrieved September 17, 2024.
split man pageTorbjorn Granlund, Richard M. Stallman. (2020, March null). split(1) — Linux manual page. Retrieved March 25, 2022.
sqlmap IntroductionDamele, B., Stampar, M. (n.d.). sqlmap. Retrieved March 19, 2018.
store_pwd_rev_encMicrosoft. (2021, October 28). Store passwords using reversible encryption. Retrieved January 3, 2022.
subTee .NET Profilers May 2017Smith, C. (2017, May 18). Subvert CLR Process Listing With .NET Profilers. Retrieved June 24, 2020.
sudo man page 2018Todd C. Miller. (2018). Sudo Man Page. Retrieved March 19, 2018.
sygnia Luna MonthOren Biderman, Tomer Lahiyani, Noam Lifshitz, Ori Porag. (n.d.). LUNA MOTH: THE THREAT ACTORS BEHIND RECENT FALSE SUBSCRIPTION SCAMS. Retrieved February 2, 2023.
symantec_mantisSymantec Threat Hunter Team. (2023, April 4). Mantis: New Tooling Used in Attacks Against Palestinian Targets. Retrieved March 4, 2024.
synack 2016 reviewPatrick Wardle. (2017, January 1). Mac Malware of 2016. Retrieved September 21, 2018.
sysdigSysdig. (2023). Sysdig Global Cloud Threat Report. Retrieved March 1, 2024.
systemdsleep LinuxMan7. (n.d.). systemd-sleep.conf(5) — Linux manual page. Retrieved June 7, 2023.
systemsetup mac timeApple Support. (n.d.). About systemsetup in Remote Desktop. Retrieved March 27, 2024.
t1105_lolbasLOLBAS. (n.d.). LOLBAS Mapped to T1105. Retrieved March 11, 2022.
tau bundlore erika noerenberg 2020Erika Noerenberg. (2020, June 29). TAU Threat Analysis: Bundlore (macOS) mm-install-macos. Retrieved October 12, 2021.
taxonomy_downgrade_att_tlsAlashwali, E. S., Rasmussen, K. (2019, January 26). What's in a Downgrade? A Taxonomy of Downgrade Attacks in the TLS Protocol and Application Protocols Using TLS. Retrieved December 7, 2021.
theevilbit gatekeeper bypass 2021Csaba Fitzl. (2021, June 29). GateKeeper - Not a Bypass (Again). Retrieved September 22, 2021.
therecord_redcurlAntoniuk, D. (2023, July 17). RedCurl hackers return to spy on 'major Russian bank,' Australian company. Retrieved August 9, 2024.
tlseminar_downgrade_attTeam Cinnamon. (2017, February 3). Downgrade Attacks. Retrieved December 9, 2021.
trendmicro xcsset xcode project 2020Mac Threat Response, Mobile Research Team. (2020, August 13). The XCSSET Malware: Inserts Malicious Code Into Xcode Projects, Performs UXSS Backdoor Planting in Safari, and Leverages Two Zero-day Exploits. Retrieved October 5, 2021.
trendmicro_redcurlTancio et al. (2024, March 6). Unveiling Earth Kapre aka RedCurl’s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence. Retrieved August 9, 2024.
tt_httrack_fake_domainsMalhotra, A., Thattil, J. et al. (2022, March 29). Transparent Tribe campaign uses new bespoke malware to target Indian government officials . Retrieved September 6, 2022.
tt_obliqueRATMalhotra, A., McKay, K. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal . Retrieved July 29, 2022.
ttint_ratTu, L. Ma, Y. Ye, G. (2020, October 1). Ttint: An IoT Remote Access Trojan spread through 2 0-day vulnerabilities. Retrieved October 28, 2021.
unit 42Tom Fakterman, Chen Erlich, & Assaf Dahan. (2024, February 22). Intruders in the Library: Exploring DLL Hijacking. Retrieved January 30, 2025.
unit42_gamaredon_dec2022Unit 42. (2022, December 20). Russia’s Trident Ursa (aka Gamaredon APT) Cyber Conflict Operations Unwavering Since Invasion of Ukraine. Retrieved September 12, 2024.
uptycs Fake POC linux malware 2023Nischay Hegde and Siddartha Malladi. (2023, July 12). PoC Exploit: Fake Proof of Concept with Backdoor Malware. Retrieved September 28, 2023.
vNinja Rogue VMs 2024Christian Mohn. (2024, November 11). Beware Of The Rogue VMs!. Retrieved March 26, 2025.
volexity_0day_sophos_FWAdair, S., Lancaster, T., Volexity Threat Research. (2022, June 15). DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach. Retrieved July 1, 2022.
vxunderground debugvxunderground. (2021, June 30). VX-API. Retrieved April 1, 2022.
w32.tidserv.gSymantec. (2009, March 22). W32.Tidserv.G. Retrieved January 14, 2022.
wailing crab sub/pubHammond, Charlotte. Villadsen, Ole. Metrick, Kat.. (2023, November 21). Stealthy WailingCrab Malware misuses MQTT Messaging Protocol. Retrieved August 28, 2024.
wardle artofmalware volume1Patrick Wardle. (2020, August 5). The Art of Mac Malware Volume 0x1: Analysis. Retrieved November 17, 2024.
wardle chp2 persistencePatrick Wardle. (2022, January 1). The Art of Mac Malware Volume 0x1:Analysis. Retrieved April 19, 2022.
wardle evilquest partiPatrick Wardle. (2020, June 29). OSX.EvilQuest Uncovered part i: infection, persistence, and more!. Retrieved March 18, 2021.
wardle evilquest partiiPatrick Wardle. (2020, July 3). OSX.EvilQuest Uncovered part ii: insidious capabilities. Retrieved March 21, 2021.
welivesec_strongpityStefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.