ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Nearest Neighbor VolexityKoessel, Sean. Adair, Steven. Lancaster, Tom. (2024, November 22). The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access. Retrieved February 25, 2025.
NetSPI ClickOnceRyan Gandrud. (2015, March 23). All You Need Is One – A ClickOnce Love Story. Retrieved September 9, 2024.
NetSPI SQL Server CLRSutherland, S. (2017, July 13). Attacking SQL Server CLR Assemblies. Retrieved September 12, 2024.
NetSPI Startup Stored ProceduresSutherland, S. (2016, March 7). Maintaining Persistence via SQL Server – Part 1: Startup Stored Procedures. Retrieved September 12, 2024.
Netcraft SendGrid 2024Graham Edgecombe. (2024, February 7). Phishception – SendGrid is abused to host phishing attacks impersonating itself. Retrieved October 15, 2024.
Netscout Stolen Pencil Dec 2018ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.
Netskope Cloud PhishingAshwin Vamshi. (2020, August 12). A Big Catch: Cloud Phishing from Google App Engine and Azure App Service. Retrieved August 18, 2022.
Netskope Device Code Phishing 2021Jenko Hwong. (2021, August 10). New Phishing Attacks Exploiting OAuth Authorization Flows (Part 1). Retrieved March 19, 2024.
Netskope GCP RedirectionAshwin Vamshi. (2019, January 24). Targeted Attacks Abusing Google Cloud Platform Open Redirection. Retrieved August 18, 2022.
Netskope LummaStealer 2025Leandro Fróes, Netskope. (2025, January 23). Lumma Stealer: Fake CAPTCHAs & New Techniques to Evade Detection. Retrieved March 22, 2025.
Netskope NitolMalik, A. (2016, October 14). Nitol Botnet makes a resurgence with evasive sandbox analysis technique. Retrieved September 30, 2021.
Netskope Shai-Hulud November 2025Gianpietro Cutolo. (2025, November 26). Shai-Hulud 2.0: Aggressive, Automated, and Fast Spreading. Retrieved April 9, 2026.
Netskope Squirrelwaffle Oct 2021Palazolo, G. (2021, October 7). SquirrelWaffle: New Malware Loader Delivering Cobalt Strike and QakBot. Retrieved August 9, 2022.
Netskope XLoader 2022Gustavo Palazolo, Netskope. (2022, March 11). New Formbook Campaign Delivered Through Phishing Emails. Retrieved March 11, 2025.
Network Provider APIMicrosoft. (2021, January 7). Network Provider API. Retrieved March 30, 2023.
New DragonOKMiller-Osborn, J., Grunzweig, J.. (2015, April). Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese Targets. Retrieved November 4, 2015.
Nick Tyrer GitHubTyrer, N. (n.d.). Instructions. Retrieved August 10, 2020.
Nicolas Falliere, Liam O Murchu, Eric Chien February 2011Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.
Nltest Manualss64. (n.d.). NLTEST.exe - Network Location Test. Retrieved February 14, 2019.
Nmap Firewalls NIDSNmap. (n.d.). Chapter 10. Detecting and Subverting Firewalls and Intrusion Detection Systems. Retrieved October 20, 2020.
NodeJSOpenJS Foundation. (n.d.). Node.js. Retrieved June 23, 2020.
NorthSec 2015 GData Uroburos ToolsRascagneres, P. (2015, May). Tools used by the Uroburos actors. Retrieved August 18, 2016.
Norton BotnetNorton. (n.d.). What is a botnet?. Retrieved October 4, 2020.
NotMe-BSODlzcapp. (n.d.). Retrieved September 22, 2025.
Nov AI Threat TrackerGoogle Threat Intelligence Group. (2025, November 5). GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools. Retrieved March 31, 2026.
Novetta BlockbusterNovetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.
Novetta Blockbuster Destructive MalwareNovetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.
Novetta Blockbuster LoadersNovetta Threat Research Group. (2016, February 24). Operation Blockbuster: Loaders, Installers and Uninstallers Report. Retrieved November 17, 2024.
Novetta Blockbuster RATsNovetta Threat Research Group. (2016, February 24). Operation Blockbuster: Remote Administration Tools & Content Staging Malware Report. Retrieved March 16, 2016.
Novetta Blockbuster ToolsNovetta Threat Research Group. (2016, February 24). Operation Blockbuster: Tools Report. Retrieved March 10, 2016.
Novetta Winnti April 2015Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.
Novetta-AxiomNovetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.
Nozomi BUSTLEBERM 2024Nozomi Networks Labs. (2024, July 24). Cyberwarfare Targeting OT: Protecting Against FrostyGoop/BUSTLEBERM Malware. Retrieved November 20, 2024.
NtQueryInformationProcessMicrosoft. (2021, November 23). NtQueryInformationProcess function (winternl.h). Retrieved February 4, 2022.
NtRaiseHardErrorNtDoc. (n.d.). NtRaiseHardError - NtDoc. Retrieved September 22, 2025.
Nviso Spoof Command Line 2020Daman, R. (2020, February 4). The return of the spoof part 2: Command line spoofing. Retrieved November 19, 2021.
O365 Blog Azure AD Device IDsSyynimaa, N. (2022, February 15). Stealing and faking Azure AD device identities. Retrieved August 3, 2022.
OPM LeakCybersecurity Resource Center. (n.d.). CYBERSECURITY INCIDENTS. Retrieved September 16, 2024.
ORB APT31Cimpanu, Catalin. (2021, July 20). Chinese hacking group APT31 uses mesh of home routers to disguise attacks. Retrieved July 8, 2024.
ORB MandiantRaggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.
OS X KeychainJuuso Salonen. (2012, September 5). Breaking into the OS X keychain. Retrieved November 17, 2024.
OSX Coldroot RATPatrick Wardle. (2018, February 17). Tearing Apart the Undetected (OSX)Coldroot RAT. Retrieved August 8, 2019.
OSX Keychain SchaumannJan Schaumann. (2015, November 5). Using the OS X Keychain to store and retrieve passwords. Retrieved March 31, 2022.
OSX Keydnap malwareMarc-Etienne M.Leveille. (2016, July 6). New OSX/Keydnap malware is hungry for credentials. Retrieved July 3, 2017.
OSX Malware DetectionPatrick Wardle. (2016, February 29). Let's Play Doctor: Practical OS X Malware Detection & Analysis. Retrieved November 17, 2024.
OSX Malware Exploits MacKeeperSergei Shevchenko. (2015, June 4). New Mac OS Malware Exploits Mackeeper. Retrieved July 3, 2017.
OSX.Dok MalwareThomas Reed. (2017, July 7). New OSX.Dok malware intercepts web traffic. Retrieved July 10, 2017.
OSX.FairyTalePhile Stokes. (2018, September 20). On the Trail of OSX.FairyTale | Adware Playing at Malware. Retrieved August 24, 2021.
OWASP CICD-SEC-4OWASP. (n.d.). CICD-SEC-4: Poisoned Pipeline Execution (PPE). Retrieved May 22, 2025.
OWASP CSV Injection Albinowax Timo Goosen. (n.d.). CSV Injection. Retrieved February 7, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.