T1573.002 Asymmetric Cryptography
Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Asymmetric cryptography, also known as public key cryptography, uses a keypair per party: one public that can be freely distributed, and one private. Due to how the keys are generated, the sender encrypts data with the receiver’s public key and the receiver decrypts the data with their private key. This ensures that only the intended recipient can read the encrypted data. Common public key encryption algorithms include RSA and ElGamal.
For efficiency, many protocols (including SSL/TLS) use symmetric cryptography once a connection is established, but use asymmetric cryptography to establish or transmit a key. As such, these protocols are classified as Asymmetric Cryptography.
| Item | Value |
|---|---|
| ID | T1573.002 |
| Sub-techniques | T1573.001, T1573.002 |
| Tactics | TA0011 |
| Platforms | ESXi, Linux, Network Devices, Windows, macOS |
| Version | 1.2 |
| Created | 16 March 2020 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| S0202 | adbupd | adbupd contains a copy of the OpenSSL library to encrypt C2 traffic.83 |
| S0045 | ADVSTORESHELL | A variant of ADVSTORESHELL encrypts some C2 with RSA.77 |
| C0040 | APT41 DUST | APT41 DUST used HTTPS for command and control.106 |
| G1044 | APT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.76 |
| S0438 | Attor | Attor’s Blowfish key is encrypted with a public RSA key.39 |
| S1081 | BADHATCH | BADHATCH can beacon to a hardcoded C2 IP address using TLS encryption every 5 minutes.55 |
| S0534 | Bazar | Bazar can use TLS in C2 communications.26 |
| S0017 | BISCUIT | BISCUIT uses SSL for encrypting C2 communications.82 |
| S1184 | BOLDMOVE | BOLDMOVE uses the WolfSSL library to implement SSL encryption for command and control communication.51 |
| C0021 | C0021 | During C0021, the threat actors used SSL via TCP port 443 for C2 communications.105 |
| S0335 | Carbon | Carbon has used RSA encryption for C2 communications.49 |
| S1224 | CASTLETAP | CASTLETAP can initiate a C2 connection over an SSL socket.22 |
| S0023 | CHOPSTICK | CHOPSTICK encrypts C2 communications with TLS.68 |
| S1105 | COATHANGER | COATHANGER connects to command and control infrastructure using SSL.57 |
| G0080 | Cobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels.100 |
| S0154 | Cobalt Strike | Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server.61 |
| S0126 | ComRAT | ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel.3031 |
| S1155 | Covenant | Covenant can utilize SSL to encrypt command and control traffic.15 |
| S0687 | Cyclops Blink | Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key.20 |
| S0673 | DarkWatchman | DarkWatchman can use TLS to encrypt its C2 channel.56 |
| S0600 | Doki | Doki has used the embedTLS library for network communications.40 |
| S0384 | Dridex | Dridex has encrypted traffic with RSA.43 |
| S0363 | Empire | Empire can use TLS to encrypt its C2 channel.14 |
| G0037 | FIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.101 |
| G0061 | FIN8 | FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure.102 |
| S1144 | FRP | FRP can be configured to only accept TLS connections.7 |
| S0168 | Gazer | Gazer uses custom encryption for C2 that uses RSA.3334 |
| S0588 | GoldMax | GoldMax has RSA-encrypted its communication with the C2 server.50 |
| S1198 | Gomir | Gomir uses reverse proxy functionality that employs SSL to encrypt communications.90 |
| S0531 | Grandoreiro | Grandoreiro can use SSL in C2 communication.36 |
| S0342 | GreyEnergy | GreyEnergy encrypts communications using RSA-2048.54 |
| S0632 | GrimAgent | GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2.38 |
| S0087 | Hi-Zor | Hi-Zor encrypts C2 traffic with TLS.63 |
| S0483 | IcedID | IcedID has used SSL and TLS in communications with C2.8889 |
| C0043 | Indian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication.98 |
| S1203 | J-magic | J-magic can communicate back to send a challenge to C2 infrastructure over SSL.42 |
| S1051 | KEYPLUG | KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2.70 |
| S0250 | Koadic | Koadic can use SSL and TLS for communications.13 |
| S0641 | Kobalos | Kobalos’s authentication and key exchange is performed using RSA-512.8485 |
| S1121 | LITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server.23 |
| S1213 | Lumma Stealer | Lumma Stealer has used HTTPS for command and control purposes.81 |
| S1141 | LunarWeb | LunarWeb can send short C2 commands, up to 512 bytes, encrypted with RSA-4096.28 |
| S0409 | Machete | Machete has used TLS-encrypted FTP to exfiltrate data.60 |
| S1169 | Mango | Mango can use TLS to encrypt C2 communications.41 |
| G1051 | Medusa Group | Medusa Group has used HTTPS for command and control.97 |
| S0455 | Metamorfo | Metamorfo’s C2 communication has been encrypted using OpenSSL.24 |
| S1122 | Mispadu | Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic.78 |
| S0699 | Mythic | Mythic supports SSL encrypted C2.5 |
| S1192 | NICECURL | NICECURL has used HTTPS for C2 communications.76 |
| S1172 | OilBooster | OilBooster can use the OpenSSL library to encrypt C2 communications.87 |
| G0049 | OilRig | OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers.99 |
| C0014 | Operation Wocao | During Operation Wocao, threat actors’ proxy implementation “Agent” upgraded the socket in use to a TLS socket.103 |
| S0556 | Pay2Key | Pay2Key has used RSA encrypted communications with C2.35 |
| S0587 | Penquin | Penquin can encrypt communications using the BlowFish algorithm and a symmetric key exchanged with Diffie Hellman.59 |
| S1123 | PITSTOP | PITSTOP has the ability to communicate over TLS.23 |
| S0428 | PoetRAT | PoetRAT used TLS to encrypt command and control (C2) communications.75 |
| S0150 | POSHSPY | POSHSPY encrypts C2 traffic with AES and RSA.66 |
| S0223 | POWERSTATS | POWERSTATS has encrypted C2 traffic with RSA.71 |
| S0192 | Pupy | Pupy’s default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES.4 |
| G1039 | RedCurl | RedCurl has used HTTPS for C2 communication.9596 |
| G1042 | RedEcho | RedEcho uses SSL for network communication.98 |
| S1219 | REPTILE | REPTILE can use TLS over raw TCP for secure C2.2122 |
| S0496 | REvil | REvil has encrypted C2 communications with the ECIES algorithm.32 |
| S0448 | Rising Sun | Rising Sun variants can use SSL for encrypting C2 communications.65 |
| S1210 | Sagerunex | Sagerunex uses HTTPS for command and control communication.69 |
| S1085 | Sardonic | Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key.79 |
| S0382 | ServHelper | ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP.37 |
| S0633 | Sliver | Sliver can use mutual TLS and RSA cryptography to exchange a session key.12108911 |
| S1035 | Small Sieve | Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel.48 |
| S1163 | SnappyTCP | SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic.53 |
| S0627 | SodaMaster | SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic.29 |
| S0615 | SombRAT | SombRAT can SSL encrypt C2 traffic.161718 |
| S0491 | StrongPity | StrongPity has encrypted C2 traffic using SSL/TLS.64 |
| S0018 | Sykipot | Sykipot uses SSL for encrypting C2 communications.25 |
| G1018 | TA2541 | TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT.91 |
| S0668 | TinyTurla | TinyTurla has the ability to encrypt C2 traffic with SSL/TLS.27 |
| S0183 | Tor | Tor encapsulates traffic in multiple layers of encryption, using TLS by default.6 |
| S0094 | Trojan.Karagany | Trojan.Karagany can secure C2 communications with SSL and TLS.58 |
| G0081 | Tropic Trooper | Tropic Trooper has used SSL to connect to C2 servers.9394 |
| S0022 | Uroburos | Uroburos has used a combination of a Diffie-Hellman key exchange mixed with a pre-shared key (PSK) to encrypt its top layer of C2 communications.19 |
| G1047 | Velvet Ant | Velvet Ant has used a reverse SSH shell to securely communicate with victim devices.92 |
| C0039 | Versa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used HTTPS for command and control of compromised Versa Director servers.104 |
| S0180 | Volgmer | Some Volgmer variants use SSL to encrypt C2 communications.62 |
| S0366 | WannaCry | WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit.80 |
| S0515 | WellMail | WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS.8647 |
| S0514 | WellMess | WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.44454647 |
| S1065 | Woody RAT | Woody RAT can use RSA-4096 to encrypt data sent to its C2 server.52 |
| S0117 | XTunnel | XTunnel uses SSL/TLS and RC4 to encrypt traffic.6768 |
| S0251 | Zebrocy | Zebrocy uses SSL and AES ECB for encrypting C2 communications.727374 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1031 | Network Intrusion Prevention | Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware can be used to mitigate activity at the network level. |
| M1020 | SSL/TLS Inspection | SSL/TLS inspection can be used to see the contents of encrypted sessions to look for network-based indicators of malware communication protocols. |
References
-
Butler, M. (2013, November). Finding Hidden Threats by Decrypting SSL. Retrieved April 5, 2016. ↩
-
Dormann, W. (2015, March 13). The Risks of SSL Inspection. Retrieved April 5, 2016. ↩
-
Gardiner, J., Cova, M., Nagaraja, S. (2014, February). Command & Control Understanding, Denying and Detecting. Retrieved April 20, 2016. ↩
-
Thomas, C. (n.d.). Mythc Documentation. Retrieved March 25, 2022. ↩
-
Roger Dingledine, Nick Mathewson and Paul Syverson. (2004). Tor: The Second-Generation Onion Router. Retrieved December 21, 2017. ↩
-
BishopFox. (n.d.). Sliver Transport Encryption. Retrieved September 16, 2021. ↩
-
Cybereason Global SOC and Incident Response Team. (n.d.). Sliver C2 Leveraged by Many Threat Actors. Retrieved March 24, 2025. ↩
-
Kervella, R. (2019, August 4). Cross-platform General Purpose Implant Framework Written in Golang. Retrieved July 30, 2021. ↩
-
Microsoft Security Experts. (2022, August 24). Looking for the ‘Sliver’ lining: Hunting for emerging command-and-control frameworks. Retrieved March 24, 2025. ↩
-
NCSC, CISA, FBI, NSA. (2021, May 7). Further TTPs associated with SVR cyber actors. Retrieved July 29, 2021. ↩
-
Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024. ↩
-
Schroeder, W., Warner, J., Nelson, M. (n.d.). Github PowerShellEmpire. Retrieved April 28, 2016. ↩
-
cobbr. (2021, April 21). Covenant. Retrieved September 4, 2024. ↩
-
The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021. ↩
-
McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021. ↩
-
CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021. ↩
-
FBI et al. (2023, May 9). Hunting Russian Intelligence “Snake” Malware. Retrieved June 8, 2023. ↩
-
NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022. ↩
-
Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024. ↩
-
Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023. ↩↩
-
Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024. ↩↩
-
Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020. ↩
-
Blasco, J. (2013, March 21). New Sykipot developments [Blog]. Retrieved November 12, 2014. ↩
-
Sadique, M. and Singh, A. (2020, September 29). Spear Phishing Campaign Delivers Buer and Bazar Malware. Retrieved November 19, 2020. ↩
-
Cisco Talos. (2021, September 21). TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines. Retrieved December 2, 2021. ↩
-
Jurčacko, F. (2024, May 15). To the Moon and back(doors): Lunar landing in diplomatic missions. Retrieved June 26, 2024. ↩
-
GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021. ↩
-
Faou, M. (2020, May). From Agent.btz to ComRAT v4: A ten-year journey. Retrieved June 15, 2020. ↩
-
CISA. (2020, October 29). Malware Analysis Report (AR20-303A). Retrieved December 9, 2020. ↩
-
Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020. ↩
-
ESET. (2017, August). Gazing at Gazer: Turla’s new second stage backdoor. Retrieved September 14, 2017. ↩
-
Kaspersky Lab’s Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017. ↩
-
Check Point. (2020, November 6). Ransomware Alert: Pay2Key. Retrieved January 4, 2021. ↩
-
Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020. ↩
-
Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019. ↩
-
Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024. ↩
-
Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020. ↩
-
Fishbein, N., Kajiloti, M.. (2020, July 28). Watch Your Containers: Doki Infecting Docker Servers in the Cloud. Retrieved March 30, 2021. ↩
-
Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024. ↩
-
Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025. ↩
-
Slepogin, N. (2017, May 25). Dridex: A History of Evolution. Retrieved May 31, 2019. ↩
-
PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020. ↩
-
PWC. (2020, August 17). WellMess malware: analysis of its Command and Control (C2) server. Retrieved September 29, 2020. ↩
-
CISA. (2020, July 16). MAR-10296782-2.v1 – WELLMESS. Retrieved September 24, 2020. ↩
-
National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020. ↩↩
-
FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022. ↩
-
Accenture. (2020, October). Turla uses HyperStack, Carbon, and Kazuar to compromise government entity. Retrieved December 2, 2020. ↩
-
Nafisi, R., Lelli, A. (2021, March 4). GoldMax, GoldFinder, and Sibot: Analyzing NOBELIUM’s layered persistence. Retrieved March 8, 2021. ↩
-
Scott Henderson, Cristiana Kittner, Sarah Hawley & Mark Lechtik, Google Cloud. (2023, January 19). Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475). Retrieved December 31, 2024. ↩
-
MalwareBytes Threat Intelligence Team. (2022, August 3). Woody RAT: A new feature-rich malware spotted in the wild. Retrieved December 6, 2022. ↩
-
PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024. ↩
-
Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018. ↩
-
Savelesky, K., et al. (2019, July 23). ABADBABE 8BADFOOD: Discovering BADHATCH and a Detailed Look at FIN8’s Tooling. Retrieved September 8, 2021. ↩
-
Smith, S., Stafford, M. (2021, December 14). DarkWatchman: A new evolution in fileless techniques. Retrieved January 10, 2022. ↩
-
Dutch Military Intelligence and Security Service (MIVD) & Dutch General Intelligence and Security Service (AIVD). (2024, February 6). Ministry of Defense of the Netherlands uncovers COATHANGER, a stealthy Chinese FortiGate RAT. Retrieved February 7, 2024. ↩
-
Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020. ↩
-
Leonardo. (2020, May 29). MALWARE TECHNICAL INSIGHT TURLA “Penquin_x64”. Retrieved March 11, 2021. ↩
-
The Cylance Threat Research Team. (2017, March 22). El Machete’s Malware Attacks Cut Through LATAM. Retrieved September 13, 2019. ↩
-
Mavis, N. (2020, September 21). The Art and Science of Detecting Cobalt Strike. Retrieved September 12, 2024. ↩
-
US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017. ↩
-
Fidelis Threat Research Team. (2016, January 27). Introducing Hi-Zor RAT. Retrieved March 24, 2016. ↩
-
Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020. ↩
-
I. Ilascu. (2019, March 3). Op ‘Sharpshooter’ Connected to North Korea’s Lazarus Group. Retrieved September 26, 2022. ↩
-
Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017. ↩
-
Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016. ↩
-
ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016. ↩↩
-
Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025. ↩
-
Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022. ↩
-
Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018. ↩
-
ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019. ↩
-
ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019. ↩
-
CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020. ↩
-
Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020. ↩
-
Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran’s APT42 Operations. Retrieved October 9, 2024. ↩↩
-
Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017. ↩
-
Pedro Tavares (Segurança Informática). (2020, September 15). Threat analysis: The emergent URSA trojan impacts many countries using a sophisticated loader. Retrieved March 13, 2024. ↩
-
Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023. ↩
-
Counter Threat Unit Research Team. (2017, May 18). WCry Ransomware Analysis. Retrieved March 26, 2019. ↩
-
Cara Lin, Fortinet. (2024, January 8). Deceptive Cracked Software Spreads Lumma Variant on YouTube. Retrieved March 22, 2025. ↩
-
Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016. ↩
-
Windows Defender Advanced Threat Hunting Team. (2016, April 29). PLATINUM: Targeted attacks in South and Southeast Asia. Retrieved February 15, 2018. ↩
-
M.Leveille, M., Sanmillan, I. (2021, February 2). Kobalos – A complex Linux threat to high performance computing infrastructure. Retrieved August 24, 2021. ↩
-
M.Leveille, M., Sanmillan, I. (2021, January). A WILD KOBALOS APPEARS Tricksy Linux malware goes after HPCs. Retrieved August 24, 2021. ↩
-
CISA. (2020, July 16). MAR-10296782-3.v1 – WELLMAIL. Retrieved September 29, 2020. ↩
-
Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024. ↩
-
Kessem, L., et al. (2017, November 13). New Banking Trojan IcedID Discovered by IBM X-Force Research. Retrieved July 14, 2020. ↩
-
Kimayong, P. (2020, June 18). COVID-19 and FMLA Campaigns used to install new IcedID banking malware. Retrieved July 14, 2020. ↩
-
Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025. ↩
-
Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023. ↩
-
Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025. ↩
-
Horejsi, J., et al. (2018, March 14). Tropic Trooper’s New Strategy. Retrieved November 9, 2018. ↩
-
Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020. ↩
-
Group-IB. (2020, August). RedCurl: The Pentest You Didn’t Know About. Retrieved August 9, 2024. ↩
-
Group-IB. (2021, November). RedCurl: The Awakening. Retrieved August 14, 2024. ↩
-
Cybersecurity and Infrastructure Security Agency. (2025, March 12). AA25-071A #StopRansomware: Medusa Ransomware. Retrieved October 15, 2025. ↩
-
Recorded Future Insikt Group. (2021, February). China-Linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions. Retrieved November 21, 2024. ↩↩
-
Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017. ↩
-
Matveeva, V. (2017, August 15). Secrets of Cobalt. Retrieved October 10, 2018. ↩
-
FireEye Threat Intelligence. (2016, April). Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6. Retrieved November 17, 2024. ↩
-
Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018. ↩
-
Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020. ↩
-
Black Lotus Labs. (2024, August 27). Taking The Crossroads: The Versa Director Zero-Day Exploitaiton. Retrieved August 27, 2024. ↩
-
Dunwoody, M., et al. (2018, November 19). Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign. Retrieved November 27, 2018. ↩
-
Mike Stokkel et al. (2024, July 18). APT41 Has Arisen From the DUST. Retrieved September 16, 2024. ↩