Topic
MITRE ATT&CK
35 reports tagged MITRE ATT&CK, spanning campaign, threat actor and malware coverage.
Articles tagged MITRE ATT&CK
-
Campaign2015 Ukraine Electric Power Attack
Sandworm Team's use of BlackEnergy3 and KillDisk to disrupt transmission and distribution substations within the Ukrainian power grid in December 2015 — the first major public cyberattack on a power grid.
-
Campaign2016 Ukraine Electric Power Attack
Sandworm Team's use of Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid in December 2016, the second major public attack Sandworm Team conducted against Ukraine.
-
CampaignAPT28 Nearest Neighbor Campaign
APT28's use of Wi-Fi daisy-chaining across nearby compromised organizations, combined with zero-day exploitation of CVE-2022-38028, to reach organizations and individuals with Ukraine expertise, February 2022 to November 2024.
-
CampaignAPT41 DUST
APT41's use of DUSTPAN and the newly observed DUSTTRAP malware, alongside Cobalt Strike and certutil, against shipping, logistics, and media entities in Europe, Asia, and the Middle East from 2023 to mid-2024.
-
Threat ActorAPT32
Suspected Vietnam-based threat group, per MITRE ATT&CK, active since at least 2014, targeting private industry, foreign governments, dissidents, and journalists across Southeast Asia.
-
MalwareQakBot
Modular banking trojan, per MITRE ATT&CK, used by financially motivated actors since at least 2007, evolved from an information stealer into a ransomware delivery agent.
-
Campaign2025 Poland Wiper Attacks
Russian state-sponsored destructive campaign against Polish energy infrastructure in December 2025, deploying two previously undocumented wiper tools against wind, photovoltaic, and CHP facilities.
-
CampaignCutting Edge
Campaign by suspected China-nexus espionage actors exploiting zero-day vulnerabilities in Ivanti Connect Secure VPN appliances beginning December 2023, targeting the US defense industrial base and multiple global sectors.
-
Threat ActorVolt Typhoon
PRC state-sponsored actor, per MITRE ATT&CK, active since at least 2021, pre-positioning within US critical infrastructure using living-off-the-land techniques rather than custom malware.
-
CampaignSolarWinds Compromise
Sophisticated supply-chain cyber operation conducted by APT29, discovered mid-December 2020, that injected malicious code into the SolarWinds Orion software build process and was formally attributed to Russia's SVR in April 2021.
-
Threat ActorKimsuky
North Korea-based cyber espionage group active since at least 2012, per MITRE ATT&CK, focused on foreign policy and nuclear-policy intelligence collection tied to the Korean Peninsula.
-
Threat ActorAPT29
Threat group attributed by MITRE ATT&CK to Russia's Foreign Intelligence Service (SVR), active since at least 2008 and linked to the 2015-16 DNC compromise and the 2020 SolarWinds supply-chain attack.
-
MalwareBazar
Downloader and backdoor, per MITRE ATT&CK, active since at least April 2020 against professional services, healthcare, manufacturing, IT, logistics, and travel companies, reportedly tied to TrickBot campaigns.
-
Threat ActorMustang Panda
China-based cyber espionage actor, per MITRE ATT&CK, conducting operations since at least 2012 using tailored phishing lures against government, diplomatic, and NGO targets.
-
CampaignOperation Honeybee
Campaign targeting humanitarian aid and inter-Korean affairs organizations from late 2017 through early 2018, initially in South Korea before expanding to six additional countries, assessed as likely Korean-speaking actors.
-
Threat ActorTurla
Cyber espionage group attributed by MITRE ATT&CK to Russia's Federal Security Service (FSB), active since at least 2004 with victims in over 50 countries.
-
CampaignOperation CuckooBees
Cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019, assessed by researchers as conducted by actors affiliated with Winnti Group, APT41, and BARIUM.
-
Threat ActorOilRig
Suspected Iranian threat group, per MITRE ATT&CK, targeting Middle Eastern and international victims since at least 2014 via supply-chain trust relationships.
-
CampaignOperation Wocao
Cyber espionage campaign by suspected China-based actors, per MITRE ATT&CK, that compromised government organizations, managed service providers, and multiple industries across ten countries from late 2017 to late 2019.
-
MalwarePlugX
Modular remote access tool with plugin architecture, per MITRE ATT&CK, used by multiple China-linked threat groups and the subject of a December 2024 US DOJ court-authorized disruption operation.
-
Threat ActorSandworm Team
Destructive threat group attributed by MITRE ATT&CK to Russia's GRU military unit 74455, active since at least 2009 and linked to Ukrainian power-grid attacks and the 2017 NotPetya worm.
-
MalwareMini Shai-Hulud
Self-replicating supply-chain worm and credential stealer, per MITRE ATT&CK, derived from Shai-Hulud and used by TeamPCP to target CI/CD workflows since at least 2026 via stolen npm and GitHub OIDC tokens.
-
CampaignNight Dragon
Cyber espionage campaign targeting oil, energy, and petrochemical companies and executives in Kazakhstan, Taiwan, Greece, and the United States, collecting SCADA and production data, assessed as China-based.
-
Threat ActorAPT41
Chinese state-sponsored espionage group, per MITRE ATT&CK, that also conducts financially motivated operations, active since at least 2012 across 14 countries and multiple industries.
-
MalwareCobalt Strike
Commercial "adversary simulation" remote access tool, per MITRE ATT&CK, whose interactive post-exploitation capabilities cover the full range of ATT&CK tactics and are widely repurposed by real threat actors.
-
MalwareMimikatz
Credential-dumping tool, per MITRE ATT&CK, capable of obtaining plaintext Windows account logins and passwords, among the most widely used post-exploitation utilities documented across threat groups.
-
CampaignSharePoint ToolShell Exploitation
July 2025 exploitation campaign against on-premises Microsoft SharePoint servers via incompletely patched spoofing and RCE vulnerabilities, later reissued as CVE-2025-53770/53771, exploited by a ransomware actor and two espionage groups.
-
Threat ActorLazarus Group
North Korean state-sponsored threat group attributed by MITRE ATT&CK to the Reconnaissance General Bureau (RGB), active since at least 2009 and linked to the 2014 Sony Pictures wiper attack.
-
MalwareInvisiMole
Modular spyware program, per MITRE ATT&CK, used by the InvisiMole Group since at least 2013 against victims in Ukraine and Russia, with two documented post-exploitation backdoor modules.
-
CampaignKV Botnet Activity
Volt Typhoon's exploitation of end-of-life SOHO routers from Cisco, NETGEAR, and DrayTek to obfuscate connectivity to US critical infrastructure victims, disrupted by US law enforcement in early 2024.
-
CampaignOperation AkaiRyū
Cyberespionage spearphishing campaign conducted by MirrorFace against entities in Japan and Central Europe, notable as the group's first reported targeting of a European entity and its first use of the UPPERCUT malware.
-
MalwareDarkGate
Initial-access and data-gathering tool, per MITRE ATT&CK, first emerging in 2018 and offered as Malware-as-a-Service since its use increased significantly starting in 2022.
-
MalwareEmpire
Open-source, cross-platform post-exploitation framework, per MITRE ATT&CK, written in Python with PowerShell-based Windows agents, singled out in a joint government report on widely abused public hacking tools.
-
MalwareTrickBot
Trojan spyware program written in C++, per MITRE ATT&CK, first emerging in September 2016 as a possible successor to Dyre, later repurposed for "big game hunting" ransomware campaigns worldwide.
-
CampaignOperation Dream Job
Cyber espionage operation likely conducted by Lazarus Group using fake job lures against defense, aerospace, and government sectors in the US, Israel, Australia, Russia, and India, 2019-2020.