ATT&CKReferences

References

Reports, blog posts and papers that MITRE cites as evidence.

3865 references

CitationDescription
ReliaQuest Health Care Social Engineering Campaign 2024Hayden Evans. (2024, April 4). Health Care Social Engineering Campaign. Retrieved May 22, 2025.
Reliaquest CAPTCHA 2024Alex Capraro. (2024, December 17). Using CAPTCHA for Compromise: Hackers Flip the Script. Retrieved March 18, 2025.
Reliaquest-executionReliaquest. (2024, May 31). New Execution Technique in ClearFake Campaign. Retrieved August 2, 2024.
Remote Management MDM macOSApple. (n.d.). Use MDM to enable Remote Management in macOS. Retrieved September 23, 2021.
Remote Shell Execution in PythonAbdou Rockikz. (2020, July). How to Execute Shell Commands in a Remote Machine in Python. Retrieved July 26, 2021.
Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025Resecurity Threat Intelligence & Incident Analysis. (2025, October 22). F5 BIG-IP Source Code Leak Tied to State-Linked Campaigns Using BRICKSTORM Backdoor. Retrieved April 16, 2026.
Resource and Data ForksFlylib. (n.d.). Identifying Resource and Data Forks. Retrieved October 12, 2021.
Retwin Directory Share PivotRoutin, D. (2017, November 13). Abusing network shares for efficient lateral movements and privesc (DirSharePivot). Retrieved April 12, 2018.
Reuters Taiwan BlackTech August 2020Lee, Y. (2020, August 19). Taiwan says China behind cyberattacks on government agencies, emails. Retrieved April 6, 2022.
Revil Independence DayLoman, M. et al. (2021, July 4). Independence Day: REvil uses supply chain exploit to attack hundreds of businesses. Retrieved September 30, 2021.
Rewterz Sidewinder APT April 2020Rewterz. (2020, April 20). Sidewinder APT Group Campaign Analysis. Retrieved January 29, 2021.
Rewterz Sidewinder COVID-19 June 2020Rewterz. (2020, June 22). Analysis on Sidewinder APT Group – COVID-19. Retrieved January 29, 2021.
Rhingo Security Labs GCP Privilege EscalationSpencer Gietzen. (n.d.). Privilege Escalation in Google Cloud Platform – Part 1 (IAM). Retrieved May 27, 2022.
Rhino Google Cloud Privilege EscalationSpencer Gietzen. (n.d.). Privilege Escalation in Google Cloud Platform – Part 1 (IAM). Retrieved September 21, 2023.
Rhino Labs Cloud Backdoor September 2019Rhino Labs. (2019, September). Cloud Container Attack Tool (CCAT). Retrieved September 12, 2019.
Rhino Labs Cloud Image Backdoor Technique Sept 2019Rhino Labs. (2019, August). Exploiting AWS ECR and ECS with the Cloud Container Attack Tool (CCAT). Retrieved September 12, 2019.
Rhino S3 Ransomware Part 1Gietzen, S. (n.d.). S3 Ransomware Part 1: Attack Vector. Retrieved April 14, 2021.
Rhino Security Labs AWS Privilege EscalationSpencer Gietzen. (n.d.). AWS IAM Privilege Escalation – Methods and Mitigation. Retrieved May 27, 2022.
Rhino Security Labs AWS S3 RansomwareSpencer Gietzen. (n.d.). AWS Simple Storage Service S3 Ransomware Part 2: Prevention and Defense. Retrieved March 21, 2023.
Rhino Security Labs AWS VPC Traffic MirroringSpencer Gietzen. (2019, September 17). Abusing VPC Traffic Mirroring in AWS. Retrieved March 17, 2022.
Rhino Security Labs Enumerating AWS RolesSpencer Gietzen. (2018, August 8). Assume the Worst: Enumerating AWS Roles through ‘AssumeRole’. Retrieved April 1, 2022.
RiskIQ British Airways September 2018Klijnsma, Y. (2018, September 11). Inside the Magecart Breach of British Airways: How 22 Lines of Code Claimed 380,000 Victims. Retrieved September 9, 2020.
RiskIQ Cobalt Jan 2018Klijnsma, Y.. (2018, January 16). First Activities of Cobalt Group in 2018: Spear Phishing Russian Banks. Retrieved October 10, 2018.
RiskIQ Cobalt Nov 2017Klijnsma, Y.. (2017, November 28). Gaffe Reveals Full List of Targets in Spear Phishing Attack Using Cobalt Strike Against Financial Institutions. Retrieved October 10, 2018.
RiskIQ Newegg September 2018Klijnsma, Y. (2018, September 19). Another Victim of the Magecart Assault Emerges: Newegg. Retrieved September 9, 2020.
Riskiq Remcos Jan 2018Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.
Risky Bulletin Threat actor impersonates FSB APTCatalin Cimpanu. (2025, January 22). Risky Bulletin: Threat actor impersonates FSB APT for months to target Russian orgs. Retrieved June 14, 2025.
RoadtoolsDirk-jan Mollema. (2020, April 16). Introducing ROADtools - The Azure AD exploration framework. Retrieved January 31, 2022.
RootDSE AD Detection 2022Scarred Monk. (2022, May 6). Real-time detection scenarios in Active Directory environments. Retrieved August 5, 2024.
Rostovcev APT41 2021Nikita Rostovcev. (2022, August 18). APT41 World Tour 2021 on a tight schedule. Retrieved February 22, 2024.
RotaJakiro 2021 netlab360 analysis Alex Turing, Hui Wang. (2021, April 28). RotaJakiro: A long live secret backdoor with 0 VT detection. Retrieved June 14, 2023.
Russian 2FA Push Annoyance - CimpanuCatalin Cimpanu. (2021, December 9). Russian hackers bypass 2FA by annoying victims with repeated push notifications. Retrieved March 31, 2022.
Russian threat actors dig in, prepare to seize on war fatigueMicrosoft Threat Intelligence. (2023, December 7). Russian threat actors dig in, prepare to seize on war fatigue. Retrieved June 18, 2025.
Russians Exploit Default MFA Protocol - CISA March 2022Cyber Security Infrastructure Agency. (2022, March 15). Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and “PrintNightmare” Vulnerability. Retrieved May 31, 2022.
Russinovich SysinternalsRussinovich, M. (2014, May 2). Windows Sysinternals PsExec v2.11. Retrieved May 13, 2015.
Ryte WikiRyte Wiki. (n.d.). Retrieved November 17, 2024.
S1 Custom Shellcode ToolBunce, D. (2019, October 31). Building A Custom Tool For Shellcode Analysis. Retrieved October 4, 2021.
S1 Old Rat New TricksLandry, J. (2016, April 21). Teaching an old RAT new tricks. Retrieved October 4, 2021.
S1 macOs PersistenceStokes, P. (2019, July 17). How Malware Persists on macOS. Retrieved March 27, 2020.
S2 Grupo TrickBot June 2017Salinas, M., Holguin, J. (2017, June). Evolution of Trickbot. Retrieved July 31, 2018.
S2W Racoon 2022S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.
S2W Troll Stealer 2024Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.
S3Recon GitHubTravis Clarke. (2020, March 21). S3Recon GitHub. Retrieved March 4, 2022.
SANS 1Joshua Wright. (2020, October 13). Retrieved March 22, 2024.
SANS 2Joshua Wright. (2020, October 14). Retrieved March 22, 2024.
SANS Attacking Kerberos Nov 2014Medin, T. (2014, November). Attacking Kerberos - Kicking the Guard Dog of Hades. Retrieved March 22, 2018.
SANS Brian Wiltse Template InjectionWiltse, B.. (2018, November 7). Template Injection Attacks - Bypassing Security Controls by Living off the Land. Retrieved April 10, 2019.
SANS Brute Ratel October 2022Thomas, W. (2022, October 5). Cracked Brute Ratel C4 framework proliferates across the cybercriminal underground. Retrieved February 6, 2023.
SANS ConfickerBurton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.
SANS Information Security Reading Room Securing SNMP Securing SNMPMichael Stump. (2003). Information Security Reading Room Securing SNMP: A Look atNet-SNMP (SNMPv3). Retrieved October 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.