T1195: T1195
Essential information
- MITRE technique ID
T1195- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:37
- Modified
- 27/03/2026 01:09
- Author / Source
- The MITRE Corporation
Aliases
Supply Chain Compromise
Platforms
windows macos linux SaaS
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | initial-access |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (53)
-
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
The MITRE Corporation Confidence 100
[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Gamaredon Group](https://attack.mitre.org/groups/G0047) is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
UAC-0006 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:55 · Modified 21/12/2025 12:11
-
The MITRE Corporation Confidence 100
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Unfurling Hemlock usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:40 · Modified 21/12/2025 05:40
-
Phoenix Hyena usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:35 · Modified 21/12/2025 13:35
-
StormBamboo usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:17 · Modified 21/12/2025 06:17
-
TeamPCP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/03/2026 22:18 · Modified 20/03/2026 22:18
-
Diplomatic Orbiter usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:13 · Modified 21/12/2025 02:13
-
Kimsuky and Andariel usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:20 · Modified 21/12/2025 05:20
-
FAMOUS CHOLLIMA usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:18 · Modified 13/05/2026 17:36
-
The MITRE Corporation Confidence 100
[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Agenda usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:26 · Modified 21/12/2025 03:26
-
NullBulge usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:59 · Modified 21/12/2025 05:59
-
Muddled Libra usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:53 · Modified 21/12/2025 00:53
-
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:17 · Modified 29/05/2026 12:20
-
SneakyChef usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:59 · Modified 21/12/2025 04:59
-
PikaBot usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:44 · Modified 21/12/2025 04:02
-
The MITRE Corporation Confidence 100
[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
AlienVault Confidence 100
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active …
First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:51 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 11/03/2026 11:36 · Modified 11/03/2026 11:36
-
Funnull usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 09:41 · Modified 03/03/2026 18:14
-
GrewApacha usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:58 · Modified 21/12/2025 05:58
-
The MITRE Corporation Confidence 100
[AppleJeus](https://attack.mitre.org/groups/G1049) is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader [Lazarus Group](https://attack.mitre.org/groups/G0032) umbrella of actors, [AppleJeus](https://attack.mitre.org/groups/G1049) has been active since …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:59 -
Ping3r and Rodrigo usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:04 · Modified 21/12/2025 07:04
-
Juiceledger usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 22:03 · Modified 20/12/2025 22:03
-
The MITRE Corporation Confidence 100
[BRONZE BUTLER](https://attack.mitre.org/groups/G0060) is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Knight usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 01:34 · Modified 21/12/2025 01:34
-
TA423 APT40 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 22:01 · Modified 20/12/2025 22:01
-
Socgholish usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:07 · Modified 21/12/2025 07:54
-
The MITRE Corporation Confidence 100
[Daggerfly](https://attack.mitre.org/groups/G1034) is a People's Republic of China-linked APT entity active since at least 2012. [Daggerfly](https://attack.mitre.org/groups/G1034) has targeted individuals, government and NGO entities, and telecommunication companies in Asia and …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
APT45 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:37 · Modified 21/12/2025 05:37
-
The MITRE Corporation Confidence 100
[Saint Bear](https://attack.mitre.org/groups/G1031) is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
DPRK usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:19 · Modified 20/12/2025 23:19
-
8220 Mining Gang relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:44 · Modified 21/12/2025 05:44
-
APT-C-26 (Lazarus) relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:49 · Modified 21/12/2025 00:49
-
APT-C-35 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:55 · Modified 20/12/2025 21:55
-
APT42 relatedThe MITRE Corporation Confidence 100
[APT42](https://attack.mitre.org/groups/G1044) is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.(Citation: Mandiant APT42-charms) The group primarily focuses on targets in the Middle East region, but has targeted …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Agrius](https://attack.mitre.org/groups/G1030) is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation: …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Blackwood relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:55 · Modified 21/12/2025 02:55
-
Earth Kapre relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:38 · Modified 21/12/2025 03:38
-
Eugenfest relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:41 · Modified 21/12/2025 05:41
-
Fighting Ursa relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:47 · Modified 21/12/2025 05:47
-
GlassWorm relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 18:54 · Modified 21/12/2025 18:54
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 07/05/2026 10:42 · Modified 07/05/2026 10:42
-
Manic Menagerie relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:49 · Modified 21/12/2025 00:49
-
The MITRE Corporation Confidence 100
[Moonstone Sleet](https://attack.mitre.org/groups/G1036) is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, [Lazarus Group](https://attack.mitre.org/groups/G0032), …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
PlushDaemon relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 10:10 · Modified 21/12/2025 10:10
-
Shai-Hulud relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 19:07 · Modified 21/12/2025 19:18
-
The MITRE Corporation Confidence 100
[Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
The MITRE Corporation Confidence 100
[Thrip](https://attack.mitre.org/groups/G0076) is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
Malware (123)
-
SHATTEREDGLASS usesFamilyPublished 26/07/2024 08:51 · Modified 26/07/2024 08:51
- Buhti
-
XMRig usesFamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
- Trojan.XML.CRUDLER.A
- SentinelSneak
-
K4Spreader usesFamilyPublished 01/10/2024 10:08 · Modified 01/10/2024 10:08
-
TeaBot usesFamilyPublished 13/04/2026 14:27 · Modified 13/04/2026 14:27
-
YCollection usesFamilyPublished 26/08/2024 12:43 · Modified 26/08/2024 12:43
- BlackCat
-
EugenLoader usesFamilyPublished 11/07/2024 11:51 · Modified 11/07/2024 11:51
- VSingle
- Fantasy wiper
-
RedLine Stealer usesFamilyPublished 14/12/2024 07:04 · Modified 14/12/2024 07:04
-
StealC usesFamilyPublished 27/03/2026 08:46 · Modified 27/03/2026 08:46
- BLINDINGCAN
-
CastleLoader usesFamilyPublished 04/06/2026 22:52 · Modified 04/06/2026 22:52
-
FamilyPublished 06/06/2024 07:22 · Modified 06/06/2024 07:22
-
CXCLNT usesFamilyPublished 13/05/2025 18:41 · Modified 13/05/2025 18:41
- StealthMutant
-
FakeBat usesFamilyPublished 11/11/2024 09:50 · Modified 11/11/2024 09:50
-
QakBot usesFamilyPublished 30/05/2024 14:20 · Modified 30/05/2024 14:20
- Dtrack
- Exodus Wallet
-
Cerberus usesFamilyPublished 19/03/2026 11:00 · Modified 19/03/2026 11:00
-
TrollAgent usesFamilyPublished 06/08/2024 14:12 · Modified 06/08/2024 14:12
-
LemonDuck usesFamilyPublished 14/10/2024 10:41 · Modified 14/10/2024 10:41
-
Remcos usesFamilyPublished 05/05/2026 18:45 · Modified 05/05/2026 18:45
- Poseidon Mythic
-
PlugX - S0013 usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
Comebacker usesFamilyPublished 10/11/2025 11:12 · Modified 10/11/2025 11:12
- Maui
- Tick
-
DanaBot usesFamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
- Luna Grabber
-
LockBit Black usesFamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
- Roaming Mantis
-
BlackCat - S1068 usesFamilyPublished 06/11/2025 14:16 · Modified 06/11/2025 14:16
- Ryuk
-
Havoc usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
- SVR Cyber
-
AsyncRAT usesFamilyPublished 11/06/2026 16:31 · Modified 11/06/2026 16:31
-
FakeSet usesFamilyPublished 10/03/2026 21:10 · Modified 10/03/2026 21:10
-
Kimsuky usesFamilyPublished 11/06/2025 22:07 · Modified 11/06/2025 22:07
- ReVBShell
-
Hydraq - S0203 usesFamilyPublished 20/05/2026 17:45 · Modified 20/05/2026 17:45
-
POCOSTICK usesFamilyPublished 05/08/2024 11:29 · Modified 05/08/2024 11:29
-
Lorem Ipsum usesFamilyPublished 04/05/2026 23:46 · Modified 04/05/2026 23:46
-
Kaolin usesFamilyPublished 02/09/2024 20:46 · Modified 02/09/2024 20:46
-
PaykLoader usesFamilyPublished 02/07/2024 08:33 · Modified 02/07/2024 08:33
-
Async RAT usesFamilyPublished 01/03/2026 05:26 · Modified 01/03/2026 05:26
-
DeTankWar usesFamilyPublished 29/05/2024 11:12 · Modified 29/05/2024 11:12
- MacMa
- Netboy
-
DoraRAT usesFamilyPublished 06/08/2024 14:12 · Modified 06/08/2024 14:12
-
RIFLE usesFamilyPublished 26/07/2024 08:51 · Modified 26/07/2024 08:51
- Cryptonite
-
TellYouThePass usesFamilyPublished 11/07/2024 13:06 · Modified 11/07/2024 13:06
-
Chrysalis backdoor usesFamilyPublished 03/02/2026 12:08 · Modified 03/02/2026 12:08
-
BiBi wiper usesFamilyPublished 02/06/2026 14:38 · Modified 02/06/2026 14:38
- Trojan.Win64.CRUDLER.A
- TutClient
- W4SP
- Juicestealer
- Trojan:MSIL/RedLineStealer
-
Mystic Stealer usesFamilyPublished 01/07/2024 10:54 · Modified 01/07/2024 10:54
- Sidewinder
-
NetSupport usesFamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
- Cahnadr
-
Redline usesFamilyPublished 08/05/2026 11:31 · Modified 08/05/2026 11:31
-
YouieLoad usesFamilyPublished 29/05/2024 11:12 · Modified 29/05/2024 11:12
-
Chalubo usesFamilyPublished 04/06/2024 15:58 · Modified 04/06/2024 15:58
- Elephant
-
Tsundere Botnet usesFamilyPublished 23/04/2026 14:16 · Modified 23/04/2026 14:16
-
CloudSorcerer usesFamilyPublished 05/05/2026 14:07 · Modified 05/05/2026 14:07
- VMConnect
-
Warp AV Killer usesFamilyPublished 11/07/2024 13:06 · Modified 11/07/2024 13:06
-
Meduza Stealer usesFamilyPublished 20/08/2025 18:39 · Modified 20/08/2025 18:39
-
SectopRAT usesFamilyPublished 26/05/2026 15:20 · Modified 26/05/2026 15:20
-
3PROXY usesFamilyPublished 26/07/2024 08:51 · Modified 26/07/2024 08:51
-
SpiceRAT usesFamilyPublished 28/06/2024 07:35 · Modified 28/06/2024 07:35
-
BlackSuit usesFamilyPublished 07/08/2025 18:57 · Modified 07/08/2025 18:57
-
SmokeLoader usesFamilyPublished 16/09/2025 08:02 · Modified 16/09/2025 08:02
-
CobaltStrike usesFamilyPublished 31/10/2025 09:30 · Modified 31/10/2025 09:30
-
Nitrogen usesFamilyPublished 20/05/2025 19:27 · Modified 20/05/2025 19:27
-
UAC-0006 usesFamilyPublished 10/02/2025 20:44 · Modified 10/02/2025 20:44
- Slingshot
- Sandals
-
Trash Panda usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 01:03 · Modified 21/12/2025 01:03
- Operation DreamJob
-
Sha1-Hulud usesFamilyPublished 27/11/2025 14:13 · Modified 27/11/2025 14:13
-
ROGUEEYE usesFamilyPublished 26/07/2024 08:51 · Modified 26/07/2024 08:51
- Pupy
-
PUBLOAD usesFamilyPublished 07/04/2026 11:11 · Modified 07/04/2026 11:11
-
Roarur usesFamilyPublished 20/05/2026 17:45 · Modified 20/05/2026 17:45
-
FamilyPublished 24/03/2026 08:49 · Modified 24/03/2026 08:49
-
Qilin usesFamilyPublished 09/06/2026 15:50 · Modified 09/06/2026 15:50
-
Muhstik usesFamilyPublished 11/07/2024 20:35 · Modified 11/07/2024 20:35
- Pennywise
-
BeaverTail usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
-
Atera Agent usesFamilyPublished 18/09/2024 08:29 · Modified 18/09/2024 08:29
-
Badredis2s usesFamilyPublished 02/03/2026 17:39 · Modified 02/03/2026 17:39
- GREASE
- ShadowPy
-
Maui Ransomware usesFamilyPublished 26/07/2024 08:51 · Modified 26/07/2024 08:51
-
LPEClient usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:41 · Modified 29/05/2026 12:20
-
BianLian usesFamilyPublished 14/11/2024 11:57 · Modified 14/11/2024 11:57
-
RELOADEXT usesFamilyPublished 05/08/2024 11:29 · Modified 05/08/2024 11:29
-
Chrysalis usesFamilyPublished 16/02/2026 14:28 · Modified 16/02/2026 14:28
- Popping Eagle
-
dbgpkg usesFamilyPublished 15/05/2025 20:12 · Modified 15/05/2025 20:12
-
SugarGh0st usesFamilyPublished 28/06/2024 07:35 · Modified 28/06/2024 07:35
- ETERNALBLUE
-
Vidar Stealer usesFamilyPublished 07/04/2025 19:41 · Modified 07/04/2025 19:41
-
Akira usesFamilyPublished 12/06/2026 16:57 · Modified 12/06/2026 16:57
- RA World
-
Cobalt Strike usesFamilyPublished 16/12/2024 14:25 · Modified 16/12/2024 14:25
-
Cthulu usesFamilyPublished 13/09/2024 08:59 · Modified 13/09/2024 08:59
- Going Eagle
- JokerSpy
- scanbox
-
Pikabot usesFamilyPublished 21/10/2024 10:59 · Modified 21/10/2024 10:59
-
Dridex - S0384 usesFamilyPublished 08/08/2025 07:53 · Modified 08/08/2025 07:53
-
QRLog usesFamilyPublished 21/01/2025 22:17 · Modified 21/01/2025 22:17
Reports (50)
-
20 MITREs 1 Malware 1 APTPublished 02/06/2026 14:38 · Modified 03/06/2026 09:34
-
Threat landscape — insurance relatedConfidence 100 199 MITREs 11 APTsPublished 27/05/2026 15:46 · threat-report
-
AlienVault Confidence 100 20 MITREs 3 IOCs 3 Observables 1 APTPublished 18/05/2026 21:29 · Modified 18/05/2026 19:56 · threat-report
-
20 MITREs 8 ObservablesPublished 11/05/2026 11:49 · Modified 11/05/2026 19:27
-
20 MITREs 2 Malwares 2 Observables 1 APTPublished 06/05/2026 10:26 · Modified 07/05/2026 08:42
-
AlienVault Confidence 100 20 MITREs 1 Malware 13 IOCs 13 ObservablesPublished 05/05/2026 01:46 · Modified 05/05/2026 10:36 · threat-report
-
15 MITREs 4 ObservablesPublished 31/03/2026 16:35 · Modified 31/03/2026 18:49
-
AlienVault Confidence 100 16 MITREs 4 IOCs 4 Observables 1 APTPublished 27/03/2026 19:59 · Modified 27/03/2026 19:31 · threat-report
-
12 MITREs 1 Observable 1 APTPublished 25/03/2026 10:38 · Modified 27/03/2026 00:08
-
AlienVault Confidence 100 10 MITREs 4 IOCs 4 Observables 1 APTPublished 24/03/2026 09:49 · Modified 27/03/2026 00:05 · threat-report
-
19 MITREs 1 Malware 2 Observables 1 APTPublished 20/03/2026 09:51 · Modified 20/03/2026 21:18
-
16 MITREs 7 Malwares 14 Observables 1 APTPublished 10/03/2026 21:10 · Modified 11/03/2026 10:36
-
14 MITREs 5 Malwares 40 Observables 1 APTPublished 02/03/2026 17:39 · Modified 03/03/2026 17:15
-
8 MITREs 1 ObservablePublished 04/02/2026 11:13 · Modified 05/02/2026 11:22
-
12 MITREs 3 Malwares 36 ObservablesPublished 03/02/2026 12:08 · Modified 03/02/2026 16:33
-
1 CVE 7 MITREs 2 ObservablesPublished 03/12/2025 20:19 · Modified 21/12/2025 18:24
-
14 MITREs 1 Malware 3 Observables 1 APTPublished 03/12/2025 08:47 · Modified 21/12/2025 18:18
-
17 MITREs 1 Malware 3 ObservablesPublished 27/11/2025 14:13 · Modified 21/12/2025 18:08
-
1 CVE 9 MITREsPublished 24/11/2025 21:10 · Modified 25/11/2025 09:14
-
12 MITREs 2 Malwares 1 APTPublished 15/05/2025 20:12 · Modified 21/05/2025 20:35
-
19 MITREs 3 Malwares 29 ObservablesPublished 13/05/2025 18:41 · Modified 21/05/2025 19:31
-
11 MITREs 1 Malware 1 APTPublished 27/03/2025 21:47 · Modified 27/03/2025 21:54
-
13 MITREs 3 Malwares 62 Observables 1 APTPublished 10/02/2025 20:44 · Modified 10/02/2025 20:57
-
13 MITREs 13 Observables 1 APTPublished 30/01/2025 16:13 · Modified 30/01/2025 16:33
-
32 MITREs 1 Malware 1 APTPublished 22/01/2025 14:41 · Modified 22/01/2025 19:17
-
9 MITREs 1 Malware 1 ObservablePublished 20/12/2024 15:25 · Modified 20/12/2024 16:42
-
14 MITREs 1 MalwarePublished 07/12/2024 12:25 · Modified 09/12/2024 11:31
-
4 MITREs 4 ObservablesPublished 26/11/2024 20:53 · Modified 26/11/2024 21:35
-
5 MITREs 22 ObservablesPublished 31/10/2024 19:46 · Modified 01/11/2024 00:26
-
A Website Attacked related4 MITREs 1 Malware 72 Observables 1 APTPublished 16/10/2024 09:29 · Modified 16/10/2024 09:49
-
20 MITREs 5 Malwares 3 Observables 1 APTPublished 13/09/2024 08:59 · Modified 13/09/2024 09:26
-
22 MITREs 7 Malwares 12 Observables 1 APTPublished 11/09/2024 20:18 · Modified 11/09/2024 20:30
-
15 MITREs 10 Malwares 15 ObservablesPublished 10/09/2024 08:11 · Modified 10/09/2024 08:24
-
7 CVEs 7 MITREs 1 Malware 2 Observables 1 APTPublished 02/09/2024 20:46 · Modified 02/09/2024 21:12
-
9 MITREs 9 Observables 1 APTPublished 26/08/2024 13:09 · Modified 26/08/2024 13:34
-
19 MITREs 4 Malwares 38 Observables 1 APTPublished 26/08/2024 12:43 · Modified 26/08/2024 13:06
-
20 MITREs 3 Malwares 42 Observables 1 APTPublished 21/08/2024 13:02 · Modified 21/08/2024 13:29
-
16 MITREs 2 Malwares 68 ObservablesPublished 16/08/2024 08:21 · Modified 16/08/2024 08:53
-
11 MITREs 2 Malwares 5 Observables 1 APTPublished 14/08/2024 15:32 · Modified 14/08/2024 15:45
-
14 MITREs 2 Malwares 16 Observables 1 APTPublished 06/08/2024 14:12 · Modified 06/08/2024 14:35
-
1 CVE 15 MITREs 5 Malwares 2 Observables 1 APTPublished 05/08/2024 11:29 · Modified 05/08/2024 11:35
-
1 CVE 8 MITREs 1 Malware 6 Observables 1 APTPublished 05/08/2024 08:30 · Modified 05/08/2024 08:34
-
16 MITREs 5 Malwares 37 Observables 1 APTPublished 26/07/2024 08:51 · Modified 26/07/2024 09:03
-
1 CVE 16 MITREs 2 Malwares 27 ObservablesPublished 24/07/2024 08:02 · Modified 24/07/2024 08:16
-
18 MITREs 3 Malwares 9 Observables 1 APTPublished 16/07/2024 14:51 · Modified 16/07/2024 14:56
-
20 MITREs 3 Malwares 4 ObservablesPublished 16/07/2024 13:03 · Modified 16/07/2024 13:26
-
1 CVE 16 MITREs 12 Malwares 27 ObservablesPublished 11/07/2024 13:06 · Modified 11/07/2024 13:35
-
6 MITREs 67 ObservablesPublished 10/07/2024 09:36 · Modified 10/07/2024 10:02
-
10 MITREs 1 Malware 28 Observables 1 APTPublished 08/07/2024 10:50 · Modified 08/07/2024 10:56
-
10 MITREs 3 Malwares 200 Observables 1 APTPublished 02/07/2024 08:33 · Modified 02/07/2024 09:28
Vulnerabilities (CVE) (35)
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma …
- Attack vector
- NETWORK
- Published
- 29/03/2024
- Modified
- 21/12/2025
Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.
- Attack vector
- Network
- Published
- 23/01/2023
- Modified
- 20/12/2025
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
- Published
- 10/01/2022
- Modified
- 20/12/2025
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
- Attack vector
- LOCAL
- Published
- 14/01/2025
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an …
- Attack vector
- Network
- Published
- 07/11/2023
- Modified
- 21/12/2025
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
- Published
- 18/01/2022
- Modified
- 20/12/2025
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
- Published
- 03/11/2021
- Modified
- 20/12/2025
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file …
- Attack vector
- Local
- Published
- 24/08/2023
- Modified
- 27/05/2026
TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.
- Attack vector
- Network
- Published
- 10/02/2023
- Modified
- 20/12/2025
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
- Attack vector
- Network
- Published
- 04/10/2023
- Modified
- 29/05/2026
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system …
- Attack vector
- Network
- Published
- 12/06/2024
- Modified
- 21/12/2025
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
- Attack vector
- Network
- Published
- 10/12/2021
- Modified
- 27/05/2026
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/05/2017
- Modified
- 22/04/2026
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
- Published
- 28/01/2022
- Modified
- 20/12/2025
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
- Attack vector
- Network
- Published
- 30/09/2022
- Modified
- 20/12/2025
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This …
- Attack vector
- Network
- Published
- 28/05/2024
- Modified
- 21/12/2025
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code …
- Published
- 03/11/2021
- Modified
- 20/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
- Attack vector
- Network
- Published
- 13/02/2024
- Modified
- 27/05/2026
Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation …
- Attack vector
- Local
- Published
- 13/08/2024
- Modified
- 21/12/2025
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code …
- Published
- 03/11/2021
- Modified
- 27/05/2026
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
- Published
- 15/03/2022
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
- Attack vector
- Local
- Complexity
- Low
- Published
- 15/11/2017
- Modified
- 29/05/2026
Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain …
- Attack vector
- Local
- Published
- 13/08/2024
- Modified
- 21/12/2025
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.
- Attack vector
- Network
- Published
- 15/03/2023
- Modified
- 21/12/2025
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. …
- Attack vector
- Network
- Published
- 26/08/2024
- Modified
- 21/12/2025
Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys …
- Attack vector
- Local
- Published
- 04/03/2024
- Modified
- 21/12/2025
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Attack patterns (MITRE) (2)
-
Compromise Hardware Supply Chain subtechnique-of
-
T1195.001 subtechnique-ofCompromise Software Dependencies and Development Tools
Course Of Action (4)
- Limit Software Installation mitigates
- Vulnerability Scanning mitigates
- User Account Management mitigates
- Boot Integrity mitigates