TA0004: TA0004
Essential information
- MITRE technique ID
TA0004- Confidence
- 100/100
- Revoked
- No
- Published
- 20/12/2025 19:36
- Modified
- 20/12/2025 22:21
- Author / Source
- AlienVault
Description
No description.
Marking (TLP)
TLP:CLEAR
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (3)
-
Phobos usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 · -
gunra usesAlienVault Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (21)
-
Cobalt Strike usesFamily
-
BlackMoon uses
-
Gunra Ransomware usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
CherryLoader uses
-
AgentTesla usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Linux usesFamily
-
Phobos usesFamily
-
Foxblade uses
-
DoNoT Loader usesFamily
-
Redline usesFamily
-
SmokeLoader usesFamily
-
theAgentTesla uses
Reports (2)
-
22 MITREs 3 Malwares 1 APT
-
2 CVEs 6 MITREs 37 Observables
Vulnerabilities (CVE) (4)
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma …
- Attack vector
- NETWORK
- Published
- 29/03/2024
- Modified
- 21/12/2025
A signal handler race condition was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by …
- Published
- 01/07/2024
- Modified
- 01/07/2024
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
- Attack vector
- Network
- Published
- 21/02/2023
- Modified
- 21/12/2025
PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context …
- Attack vector
- Network
- Published
- 21/04/2023
- Modified
- 21/12/2025