ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
Reaqta MSXSL Spearphishing MAR 2018Admin. (2018, March 2). Spear-phishing campaign leveraging on MSXSL. Retrieved July 3, 2018.
Reaqta MavinjectReaqta. (2017, December 16). From False Positive to True Positive: the story of Mavinject.exe, the Microsoft Injector. Retrieved September 22, 2021.
Reaqta MuddyWater November 2017Reaqta. (2017, November 22). A dive into MuddyWater APT targeting Middle-East. Retrieved May 18, 2020.
ReasonLabsReasonLabs. (n.d.). What is Dead code insertion?. Retrieved March 4, 2025.
ReasonLabs Cyberpedia Junk CodeWhat is Junk Code?. (n.d.). ReasonLabs. Retrieved April 4, 2025.
Recorded Future APT3 May 2017Insikt Group (Recorded Future). (2017, May 17). Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3. Retrieved September 16, 2024.
Recorded Future Beacon 2019Recorded Future. (2019, June 20). Out of the Blue: How Recorded Future Identified Rogue Cobalt Strike Servers. Retrieved September 16, 2024.
Recorded Future Chinese Activity in Southeast Asia December 2021Insikt Group. (2021, December 8). Chinese State-Sponsored Cyber Espionage Activity Supports Expansion of Regional Power and Influence in Southeast Asia. Retrieved September 19, 2022.
Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Insikt Group. (2025, February 13). Inside the Scam: North Korea’s IT Worker Threat. Retrieved October 17, 2025.
Recorded Future ESXiArgs Ransomware 2023German Hoeffner, Aaron Soehnen and Gianni Perez. (2023, February 7). ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers. Retrieved March 26, 2025.
Recorded Future REDDELTA July 2020Insikt Group. (2020, July 28). CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS. Retrieved April 13, 2021.
Recorded Future RedDelta 2025Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.
Recorded Future RedEcho Feb 2021Insikt Group. (2021, February 28). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved March 22, 2021.
Recorded Future TAG-144 AUG 2025Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.
Recorded Future Turla Infra 2020Insikt Group. (2020, March 12). Swallowing the Snake’s Tail: Tracking Turla Infrastructure. Retrieved September 16, 2024.
RecordedFuture 2021 Ad InfraInsikt Group. (2022, January 18). 2021 Adversary Infrastructure Report. Retrieved March 25, 2022.
RecordedFuture RedEcho 2021Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024.
RecordedFuture RedEcho 2022Recorded Future Insikt Group. (2022, April 6). Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group. Retrieved November 21, 2024.
RecordedFuture WhisperGate Jan 2022Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.
Red Canary - Atomic Red TeamRed Canary - Atomic Red Team. (n.d.). T1053.005 - Scheduled Task/Job: Scheduled Task. Retrieved June 19, 2024.
Red Canary 2021 Threat Detection Report March 2021Red Canary. (2021, March 31). 2021 Threat Detection Report. Retrieved August 31, 2021.
Red Canary COR_PROFILER May 2020Brown, J. (2020, May 7). Detecting COR_PROFILER manipulation for persistence. Retrieved June 24, 2020.
Red Canary Dridex Threat Report 2021Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.
Red Canary Emotet Feb 2019Donohue, B.. (2019, February 13). https://redcanary.com/blog/stopping-emotet-before-it-moves-laterally/. Retrieved March 25, 2019.
Red Canary HTA Abuse Part DeuxMcCammon, K. (2015, August 14). Microsoft HTML Application (HTA) Abuse, Part Deux. Retrieved October 27, 2017.
Red Canary Hospital Thwarted Ryuk October 2020Brian Donohue, Katie Nickels, Paul Michaud, Adina Bodkins, Taylor Chapman, Tony Lambert, Jeff Felling, Kyle Rainey, Mike Haag, Matt Graeber, Aaron Didier.. (2020, October 29). A Bazar start: How one hospital thwarted a Ryuk ransomware outb…
Red Canary NETWIRE January 2020Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.
Red Canary Netwire Linux 2022TONY LAMBERT. (2022, June 7). Trapping the Netwire RAT on Linux. Retrieved September 28, 2023.
Red Canary QbotRainey, K. (n.d.). Qbot. Retrieved September 27, 2021.
Red Canary Silver Sparrow Feb2021Tony Lambert. (2021, February 18). Clipping Silver Sparrow’s wings: Outing macOS malware before it takes flight. Retrieved April 20, 2021.
Red Canary SocGholish March 2024Red Canary. (2024, March). Red Canary 2024 Threat Detection Report: SocGholish. Retrieved March 22, 2024.
Red Canary Verclsid.exeHaag, M., Levan, K. (2017, April 6). Old Phishing Attacks Deploy a New Methodology: Verclsid.exe. Retrieved August 10, 2020.
Red Hat Linux Disable or ModRed Hat. (n.d.). Retrieved April 15, 2026.
Red Hat PAMRed Hat. (n.d.). CHAPTER 2. USING PLUGGABLE AUTHENTICATION MODULES (PAM). Retrieved June 25, 2020.
Red Hat Systemctl 2022Damon Garn. (2022, May 17). How to use systemctl to manage Linux services. Retrieved March 18, 2025.
RedCanary June Insights 2024The Red Canary Team. (2024, June 20). Intelligence Insights: June 2024. Retrieved March 14, 2025.
RedCanary Mockingbird May 2020Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.
RedCanary RaspberryRobin 2022Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.
RedCanary Storm-1811 2024Red Canary Intelligence. (2024, December 2). Storm-1811 exploits RMM tools to drop Black Basta ransomware. Retrieved March 14, 2025.
RedHat WebhooksRedHat. (2022, June 1). What is a webhook?. Retrieved July 20, 2023.
RedLock Instance Metadata API 2018Higashi, Michael. (2018, May 15). Instance Metadata API: A Modern Day Trojan Horse. Retrieved July 16, 2019.
Redirectors_Domain_FrontingMudge, R. (2017, February 6). High-reputation Redirectors and Domain Fronting. Retrieved July 11, 2022.
Redops SyscallsFeichter, D. (2023, June 30). Direct Syscalls vs Indirect Syscalls. Retrieved September 27, 2023.
Redxorblue Remote Template InjectionHawkins, J. (2018, July 18). Executing Macros From a DOCX With Remote Template Injection. Retrieved October 12, 2018.
Reed thiefquest fake ransomThomas Reed. (2020, July 7). Mac ThiefQuest malware may not be ransomware after all. Retrieved March 18, 2021.
Register DeloitteThomson, I. (2017, September 26). Deloitte is a sitting duck: Key systems with RDP open, VPN and proxy 'login details leaked'. Retrieved October 19, 2020.
Register Robots TXT 2015Darren Pauli. (2015, May 19). Robots.txt tells hackers the places you don't want them to look. Retrieved July 18, 2024.
Register UberMcCarthy, K. (2015, February 28). FORK ME! Uber hauls GitHub into court to find who hacked database of 50,000 drivers. Retrieved October 19, 2020.
Registry Key SecurityMicrosoft. (2018, May 31). Registry Key Security and Access Rights. Retrieved March 16, 2017.
Reichert aon sedexp 2024Zachary Reichert. (2024, August 19). Unveiling "sedexp": A Stealthy Linux Malware Exploiting udev Rules. Retrieved September 26, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.