ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Proofpoint ZeroT Feb 2017Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.
Proofpoint-DMARCProofpoint. (n.d.). Retrieved March 24, 2025.
Proofpoint-spoofProofpoint. (n.d.). What Is Email Spoofing?. Retrieved February 24, 2023.
PsExec RussinovichRussinovich, M. (2004, June 28). PsExec. Retrieved December 17, 2015.
Pulsedive Pulsedive Threat Research. (2025, March 21). Rilide - An Information Stealing Browser Extension. Retrieved September 22, 2025.
Push Security SaaS Attacks Repository WebhooksPush Security. (2023, July 31). Webhooks. Retrieved August 4, 2023.
Push Security SaaS Persistence 2022Luke Jennings. (2022, November 29). Maintaining persistent access in a SaaS-first world. Retrieved March 20, 2025.
Push Security Slack Persistence 2023Luke Jennings. (2023, October 24). Slack Attack: A phisher's guide to persistence and lateral movement. Retrieved March 20, 2025.
Push notifications - viruspositiveGaurav Sethi. (2021, December 14). The Dark Side of Web Push Notifications. Retrieved March 14, 2025.
PwC Yellow LidercPwC Threat Intelligence. (2023, October 25). Yellow Liderc ships its scripts and delivers IMAPLoader malware. Retrieved March 29, 2024.
PyPI RARmkz. (2020). rarfile 3.1. Retrieved February 20, 2020.
Python Site Configuration HookPython. (n.d.). site — Site-specific configuration hook. Retrieved May 22, 2025.
QR-campaign-energy-firmJonathan Greig. (2023, August 16). Phishing campaign used QR codes to target large energy company. Retrieved November 27, 2023.
QR-cofenseNathaniel Raymond. (2023, August 16). Major Energy Company Targeted in Large QR Code Phishing Campaign. Retrieved February 13, 2024.
QiAnXin APT-C-36 Feb2019QiAnXin Threat Intelligence Center. (2019, February 18). APT-C-36: Continuous Attacks Targeting Colombian Government Institutions and Corporations. Retrieved May 5, 2020.
Qualys Hermetic Wiper March 2022Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.
Qualys LolZarusPradhan, A. (2022, February 8). LolZarus: Lazarus Group Incorporating Lolbins into Campaigns. Retrieved March 22, 2022.
Qualys LummaStealer 2024Vishwajeet Kumar, Qualys. (2024, October 20). Unmasking Lumma Stealer: Analyzing Deceptive Tactics with Fake CAPTCHA. Retrieved March 22, 2025.
RATANKBATrend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.
RC PowerShellRed Canary. (n.d.). 2022 Threat Detection Report: PowerShell. Retrieved March 17, 2023.
RDP Hijacking KorznikovKorznikov, A. (2017, March 17). Passwordless RDP Session Hijacking Feature All Windows versions. Retrieved December 11, 2017.
RDP Hijacking MediumBeaumont, K. (2017, March 19). RDP hijacking — how to hijack RDS and RemoteApp sessions transparently to move through an organisation. Retrieved December 11, 2017.
RDPWrap GithubStas'M Corp. (2014, October 22). RDP Wrapper Library by Stas'M. Retrieved March 28, 2022.
RELIAQUESTRELIAQUEST THREAT RESEARCH TEAM. (2025, April 11). Threat Spotlight: Hijacked and Hidden: New Backdoor and Persistence Technique. Retrieved June 27, 2025.
RFC1918IETF Network Working Group. (1996, February). Address Allocation for Private Internets. Retrieved October 20, 2020.
RFC826 ARPPlummer, D. (1982, November). An Ethernet Address Resolution Protocol. Retrieved October 15, 2020.
ROADtools GithubDirk-jan Mollema. (2022, January 31). ROADtools. Retrieved January 31, 2022.
RSA Carbanak November 2017RSA. (2017, November 21). THE CARBANAK/FIN7 SYNDICATE A HISTORICAL OVERVIEW OF AN EVOLVING THREAT. Retrieved July 29, 2020.
RSA EU12 They're InsideRivner, U., Schwartz, E. (2012). They’re Inside… Now What?. Retrieved November 25, 2016.
RSA Shell CrewRSA Incident Response. (2014, January). RSA Incident Response Emerging Threat Profile: Shell Crew. Retrieved January 14, 2016.
RSA2017 Detect and Respond AdairAdair, S. (2017, February 17). Detecting and Responding to Advanced Threats within Exchange Environments. Retrieved November 17, 2024.
RSAC 2015 Abu Dhabi Stefano MaccagliaMaccaglia, S. (2015, November 4). Evolving Threats: dissection of a CyberEspionage attack. Retrieved April 4, 2018.
RSAC 2015 San Francisco Patrick WardleWardle, P. (2015, April). Malware Persistence on OS X Yosemite. Retrieved April 6, 2018.
Radware Micropsia July 2018Tsarfaty, Y. (2018, July 25). Micropsia Malware. Retrieved November 13, 2018.
Rancor Unit42 June 2018Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.
Rancor WMIJen Miller-Osborn and Mike Harbison. (2019, December 17). Rancor: Cyber Espionage Group Uses New Custom Malware to Attack Southeast Asia. Retrieved February 9, 2024.
Rapid7Condon, Caitlin. (2022, April 24). PetitPotam: Novel Attack Chain Can Fully Compromise Windows Domains. Retrieved May 30, 2025.
Rapid7 AppDomain Manager InjectionSpagnola, N. (2023, May 5). AppDomain Manager Injection: New Techniques For Red Teams. Retrieved March 29, 2024.
Rapid7 BlackBasta 2024McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.
Rapid7 Fake W2 July 2024Elkins, T. (2024, July 24). Malware Campaign Lures Users With Fake W2 Form. Retrieved September 13, 2024.
Rapid7 HAFNIUM Mar 2021Eoin Miller. (2021, March 23). Defending Against the Zero Day: Analyzing Attacker Behavior Post-Exploitation of Microsoft Exchange. Retrieved October 27, 2022.
Rapid7 KeyBoy Jun 2013Guarnieri, C., Schloesser M. (2013, June 7). KeyBoy, Targeted Attacks against Vietnam and India. Retrieved June 14, 2019.
Rapid7 LLMNR SpooferFrancois, R. (n.d.). LLMNR Spoofer. Retrieved November 17, 2017.
Rapid7 MiTM BasicsRapid7. (n.d.). Man-in-the-Middle (MITM) Attacks. Retrieved March 2, 2020.
Rapid7 Service Persistence 22JUNE2016Rapid7. (2016, June 22). Service Persistence. Retrieved April 23, 2019.
Rapid7G20EspionageRapid7. (2013, August 26). Upcoming G20 Summit Fuels Espionage Operations. Retrieved March 6, 2017.
RcloneNick Craig-Wood. (n.d.). Rclone syncs your files to cloud storage. Retrieved August 30, 2022.
Rclone WarsJustin Schoenfeld and Aaron Didier. (2021, May 4). Rclone Wars: Transferring leverage in a ransomware attack. Retrieved August 30, 2022.
Rclone-mega-extortion_05_2021Justin Schoenfeld, Aaron Didier. (2021, May 4). Transferring leverage in a ransomware attack. Retrieved July 14, 2022.
Re-Open windows on MacApple. (2016, December 6). Automatically re-open windows, apps, and documents on your Mac. Retrieved July 11, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.