Pith. sign in

REVIEW 4 major objections 5 minor 1 cited by

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures

T0 review · 4 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read APTs cannot operate without C&C servers, and HTTP(S) is the evasion channel in 81% of campaigns.

desk verdict A useful, messy consolidation of APT C&C TTPs whose headline percentages rest on a convenience sample; worth refereeing, but the numbers need re-framing. read the letter →

arxiv 2502.08830 v1 pith:ILVUB3JT submitted 2025-02-12 cs.CR cs.NIcs.OS

classification cs.CRcs.NIcs.OS
keywords AdvancedpersistentthreatscommandandcontrolevasiontechniquesDNStunnelingHTTPSC&CfallbackchannelsnetworkintrusiondetectionTTPanalysis
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper tries to establish what advanced persistent threats actually do at the network layer, from the adversary's point of view, by reading 22 years of industry reports and real traffic artifacts. The central claim is that APT operations are impossible without command-and-control (C&C) servers, that those servers are mostly reached through DNS, and that HTTP(S) is the dominant vehicle for evading detection, used by 81% of campaigns. A sympathetic reader should care because the percentages point at specific design priorities for next-generation network intrusion detection systems (NIDS): inspect HTTP(S) and DNS in context, treat fallback channels and multi-hop proxies as first-class signals, and stop relying on traffic volume alone.

What carries the argument

The carrying object is a network-level TTP (tactics, techniques, and procedures) taxonomy with three branches: DNS-based techniques (DGA, dynamic DNS, FQDN hijacking, DNS tunneling), traffic-based techniques (web-protocol misuse, data obfuscation through protocol impersonation, non-application protocols such as raw TCP or ICMP, stealthy bursts, low profile), and channel-based techniques (multi-layer encrypted channels and fallback channels). The taxonomy is filled in by reading the vendor reports into per-campaign feature tables and then validating selected techniques against collected traffic and domain datasets, so the percentage claims come from campaign-level binary features rather than from individual packet labels.

What would settle it

Compile a fresh sample of every APT campaign disclosed by several major vendors between 2023 and 2025, code the same TTP features without excluding any campaign, and compare the HTTPS share (81%), DNS share (45%), fallback-channel share (60.6%), and multi-hop proxy share (51.5%); a substantial shortfall would show that the paper's percentages are artifacts of its campaign-selection rule.

Watch

Extended reading notes

Core claim

The paper claims that no APT can function without C&C infrastructure, and that infrastructure is reachable mostly through DNS-addressed servers. Across 33 campaigns drawn from 118 industry technical reports spanning 22 years, HTTP(S) is the workhorse evasion protocol: 81% of campaigns use HTTPS, essentially all use HTTP at some point, and 45% use DNS for resolution or tunneling. The defensive consequence is that fallback channels are not an edge case: 60.6% of campaigns split traffic across multiple C&C servers to defeat volume-based detection, 54.5% layer encryption so that decrypting one layer still leaves another, and 51.5% use domain fronting or multi-hop proxies. The paper also reports that 84.8% of campaigns use backdoors and 78.7% use remote-access trojans, with botnets rare, and it frames these findings as requirements for the next generation of network-based APT detection.

Load-bearing premise

The headline percentages rest on the assumption that the 33 selected campaigns and the 118 vendor reports used to code them are representative of all APTs, and that techniques missing from a report were not actually used.

Editorial extensions

If this is right

  • A network intrusion detection system that does not treat HTTP(S) payloads and DNS queries as primary detection surfaces will miss the two channels that carry most APT C&C traffic.
  • Any volume-based detector can be evaded by the 60.6% of campaigns that divide traffic across multiple C&C servers, so detector features should be per-flow or per-context rather than aggregate-volume.
  • Decrypting TLS at the perimeter is insufficient when 54.5% of campaigns wrap command traffic in additional encoding or cipher layers underneath the session.
  • Detection of malicious domains has to cover dynamic DNS, typosquatting, TLD squatting, FQDN hijacking, and DGA, because 45% of campaigns use DNS beyond simple resolution.
  • Because 24.2% of campaigns deliver malware through spearphishing links, domain and URL reputation belongs inside the network-detection loop, not only at the mail gateway.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The 81% and 60.6% figures are best read as lower bounds: a campaign counted as not using a technique may simply be one whose vendor report omitted it, so true prevalence could be higher.
  • The selection rule of choosing one high-damage campaign per timeframe skews the sample toward well-resourced, well-documented actors, so the trend that fallback channels are increasing may be stronger for prominent campaigns than for the general APT population.
  • A direct test of the paper's generalization would be to repeat the same campaign-level feature extraction on a sample built from all reports released in a fixed later window, without impact-based preselection, and check whether the HTTPS and fallback-channel shares are reproduced.
  • The taxonomy could be extended to protocols the paper flags but does not fully count, such as DNS over HTTPS, cloud APIs, and P2P SMB, where the same evasion logic is likely migrating.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. This paper surveys 33 APT campaigns documented in 118 industry reports, supplemented by the authors' own traffic datasets, with the goal of characterizing network-based tactics, techniques, and procedures (TTPs) for command-and-control (C&C) communication. It presents quantitative claims about protocol usage (81% HTTPS, 45% DNS), channel-based evasion (60.6% fallback channels, 54.5% multi-level encryption), and DNS-based TTPs (27.2% dynamic DNS, 24.2% DGA/DNS tunneling), and it develops a taxonomy of 13 network-based TTPs. The paper concludes with recommendations for next-generation NIDS, emphasizing HTTP(S) and DNS inspection and the need to treat fallback channels and multi-hop proxies as first-class detection signals.

Significance. The qualitative contribution is valuable: the TTP taxonomy (Figure 5), the per-campaign tables, and the real-traffic examples of domain fronting, protocol impersonation, fallback channels, and raw-TCP/ICMP channels give concrete, actionable evidence for detection research. The paper also draws on a large corpus of industry reports and the authors' own datasets, and several figures (Figures 8–13) provide traffic-level grounding that is often missing in survey papers. If the quantitative claims were properly scoped, they would provide useful evidence for prioritizing HTTP(S) and DNS inspection. However, the headline percentages are load-bearing and currently rest on an unstated representativeness assumption, and at least one internal inconsistency affects the paper's central protocol claim.

major comments (4)
  1. [Section III] The selection of the 33 campaigns is non-random: the methodology states that campaigns are chosen for 'fair distribution' over 22 years, 'availability of data from industry vendors,' and 'the one that causes major damage' (Section III). This is a damage-maximizing, availability-biased sample, yet the abstract and Section X present the resulting percentages (81% HTTPS, 45% DNS, 60.6% fallback channels, 54.5% multi-level encryption) as facts about APTs generally. The authors should either reframe these numbers as descriptive statistics of the selected sample with an explicit limitations paragraph, or justify representativeness and provide uncertainty estimates. As written, the central quantitative claims overgeneralize.
  2. [Abstract vs. Section X] The abstract states that 'the most popular protocol to deploy evasion techniques is using HTTP(S) with 81% of APT campaigns,' but Section X and Figure 14.b state that all campaigns use HTTP and that 81% rely on HTTPS to bypass NIDS. These statements conflict: if HTTP is used by all campaigns, then the 81% figure cannot refer to HTTP(S) as a combined category. This internal inconsistency affects the paper's most prominent protocol claim and must be corrected.
  3. [Sections V and X] The analysis treats a TTP as absent when no vendor report mentions it, effectively assuming that the 118 reports are complete descriptions of each campaign. This assumption is never stated or defended; the paper acknowledges only that industry is the primary information source. Because the abstract frames the numbers as facts about APT campaigns, the authors should explicitly state that the percentages describe what is documented in the selected reports, not necessarily what occurred, and discuss the implications of report incompleteness.
  4. [Figure 14 and Table III] The percentages in Figure 14 are said to be based on the 33 campaigns in Table III, but the paper does not provide the per-campaign counts that map Table III's checkmarks to the reported figures. A reader cannot verify 60.6%, 54.5%, 51.5%, 27.2%, or 24.2% from the material as presented. Please include the underlying counts (e.g., a supplementary table listing, for each campaign, which TTPs were counted) or a machine-readable version of Table III.
minor comments (5)
  1. [Section III] In the HEALP dataset description, the text reads 'we collect xxx domains'; the placeholder 'xxx' should be replaced with the actual number of domains collected, as this is part of the dataset description needed for reproducibility.
  2. [Figure 11] The caption describes 'Stealthy malicious APT StringPity' while the surrounding text refers to njRAT; the mismatch should be resolved.
  3. [Figure 13] The caption uses 'GRIFFON' while the text and Section II use 'Griffon'; please standardize the spelling.
  4. [Section X] The sentence 'Figure 14.b shows that all APT campaigns have continued using HTTP since 2001' should be checked against Table III, since some rows appear to have no HTTP checkmark; if those rows do use HTTP, the claim should be clarified to avoid overstatement.
  5. [References] The dataset references [4], [25], and [127] point to prior work and a GitHub repository, but the paper does not clearly state how the reader can access the APTracePlus and MCFP datasets used for the traffic figures; consider adding a data-availability note.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the paper's headline percentages are transcriptions of external industry reports, and its self-cited datasets are illustrative, not the fitted source of the claims.

full rationale

The paper is an empirical survey, not a derivation. Section III defines the dataset: 33 APT campaigns are selected from 118 industry reports based on 'fair distribution' and 'availability of data from industry vendors'. Section V tabulates protocol and TTP presence per campaign in Tables I-III, and Section X computes percentages such as 81% HTTPS and 60.6% fallback channels by simple arithmetic over those tables. No equation maps a fitted parameter to a predicted quantity, and no claim is defined in terms of the quantity it purports to explain. The authors' self-citations [4], [25], [127] supply traffic datasets and domain artifacts used to illustrate TTPs (e.g., Zebrocy, Mivast/Sakula, GRIFFON), but those artifacts are not the source of the headline percentages and are not fitted to the survey conclusions. The acknowledged reliance on industry reporting is a data-validity limitation, not a circularity: the percentages describe what vendor reports document, but the paper does not disguise that as a model output. No load-bearing step reduces to its own input, so no circularity is present.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The central claims (protocol usage rates, TTP frequencies) rest on three external premises: that vendor reports are complete, that the non-random campaign selection is representative, and that unreported techniques are absent. These are data-quality assumptions, not derivable results. No invented entities or fitted parameters are introduced.

assumptions (3)
  • domain assumption Industry vendor reports accurately and completely describe each APT campaign's C&C behavior.
    The entire survey in Sections V and X relies on 118 reports from vendors such as FireEye, Symantec, Kaspersky, and ESET; if these reports omit or misreport TTPs, the derived percentages are wrong. Stated in Section III and Section V.
  • ad hoc to paper The 33 selected campaigns are representative of the population of APTs.
    Campaigns were chosen for 'fair distribution over 22 years', 'availability of data', and 'major damage', all subjective criteria; this is not a random or systematic sample. Section III.
  • domain assumption A TTP not mentioned in a campaign's industry reports was not used by that campaign.
    The percentage calculations treat unreported techniques as absent, which is a strong completeness assumption given that vendors often describe only some artifacts. Used throughout Tables II and III.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures." pith.science (2026). https://pith.science/paper/ILVUB3JT

@misc{pith2026250208830,
  author       = {Pith},
  title        = {Pith review of: Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ILVUB3JT}},
  note         = {Machine review of arXiv:2502.08830}
}
read the original abstract

The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques. To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to take into account the specific context of the attack explained in this paper. In this study, we select 33 APT campaigns based on the fair distribution over the past 22 years to observe the evolution of APTs over time. We focus on their evasion techniques and how they stay undetected for months or years. We found that APTs cannot continue their operations without C&C servers, which are mostly addressed by Domain Name System (DNS). We identify several TTPs used for DNS, such as Dynamic DNS, typosquatting, and TLD squatting. The next step for APT operators is to start communicating with a victim. We found that the most popular protocol to deploy evasion techniques is using HTTP(S) with 81% of APT campaigns. HTTP(S) can evade firewall filtering and pose as legitimate web-based traffic. DNS protocol is also widely used by 45% of APTs for DNS resolution and tunneling. We identify and analyze the TTPs associated with using HTTP(S) based on real artifacts.

Figures

Figures reproduced from arXiv: 2502.08830 by the authors.

Figure 14
Figure 14. c with the example of Mivast and Skula malware [PITH_FULL_IMAGE:figures/full_fig_p002_14.png] view at source ↗
Figure 1
Figure 1. Methodology. • APT, Botnets and Legitimate traffic (APTracePluse): in this dataset, we extend the dataset based on [4] to include protocols used beyond HTTP(S) such as Raw TCP and UDP, which are popular as we found in Section V. IV. APT LIFECYCLE Understanding how an APT campaign behaves from the first day until the mission is accomplished can be crucial in identifying the attack surface at each stage and provide de… view at source ↗
Figure 2
Figure 2. Lockheed Martin Cyber Kill Chain detective controls [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figures from the paper (11 more)
Figure 3
Figure 3. Figure 3: Mandiant attack model [3]. C. ATT&CK TM Model While Cyber Kill Chain and Mandiant APT attack models are presented in an abstract view and are focused on the lifecy￾cle of an APT campaign, MITRE ATT&CK presents a matrix for enterprise to describe Tactics, Techniques and…
Figure 5
Figure 5. Figure 5: Network-based TTPs taxonomy. VI. TAXONOMY OF NETWORK-BASED TTPS USED BY APTS [PITH_FULL_IMAGE:figures/full_fig_p019_5.png]
Figure 6
Figure 6. Figure 6: Campaigns are sorted by median length. APT and legitimate domain campaigns are interleaved. The upper and [PITH_FULL_IMAGE:figures/full_fig_p020_6.png]
Figure 7
Figure 7. Figure 7: An example of domain fronting [117]. VIII. TRAFFIC-BASED TTPS After APT operators successfully evade the defenses and locate the C&C server, they deploy several traffic-based TTPs to continue undetected. This section discusses the TTPs related to the traffic itself. A.…
Figure 8
Figure 8. Figure 8: Zebrocy pushes collected information of the infected [PITH_FULL_IMAGE:figures/full_fig_p021_8.png]
Figure 11
Figure 11. Figure 11: Stealthy malicious APT StringPity compared legit [PITH_FULL_IMAGE:figures/full_fig_p022_11.png]
Figure 10
Figure 10. Figure 10: NanoCore executes remote commands and collects [PITH_FULL_IMAGE:figures/full_fig_p022_10.png]
Figure 12
Figure 12. Figure 12: Remcos transfers the collected data of the infected [PITH_FULL_IMAGE:figures/full_fig_p022_12.png]
Figure 13
Figure 13. Figure 13: GRIFFON divides its communication with its C&C [PITH_FULL_IMAGE:figures/full_fig_p023_13.png]
Figure 14
Figure 14. Figure 14: b shows that all APT campaigns have continued [PITH_FULL_IMAGE:figures/full_fig_p023_14.png]
Figure 14
Figure 14. Figure 14: Investigation summary based on 33 APT campaigns. [PITH_FULL_IMAGE:figures/full_fig_p024_14.png]

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations

    cs.CR 2025-09 conditional novelty 6.0 of 10

    An intermittent observer can recover DSSE search queries with up to about 90% accuracy by linking query groups across observation rounds via co-occurrence graph matching.

Reference graph

Works this paper leans on

129 extracted references · 79 canonical work pages · cited by 1 Pith paper

  1. [1]

    Computer security incident handling guide,

    P. Cichonski, T. Millar, T. Grance, and K. Scarfone, “Computer security incident handling guide,” NIST Special Publication , vol. 800, no. 61, pp. 1–147, 2012

  2. [2]

    Advanced persistent threats and how to monitor and deter them,

    C. Tankard, “Advanced persistent threats and how to monitor and deter them,” Network security, vol. 2011, no. 8, pp. 16–19, 2011

  3. [3]

    APT 1: Exposing one of china’s cyber espionage units,

    D. McWhorter, “APT 1: Exposing one of china’s cyber espionage units,” Feb 2013. FireEye Mandiant Lab

  4. [4]

    E ARLYCROW: Detecting APT malware command and control over HTTP(S) using contextual summaries,

    A. Alageel and S. Maffeis, “E ARLYCROW: Detecting APT malware command and control over HTTP(S) using contextual summaries,” in 25th International Information Security Conference (ISC 22) , pp. 290– 316, Springer, 2022

  5. [5]

    Apt beaconing detection: A systematic review,

    M. A. Talib, Q. Nasir, A. B. Nassif, T. Mokhamed, N. Ahmed, and B. Mahfood, “Apt beaconing detection: A systematic review,” Computers & Security , p. 102875, 2022

  6. [6]

    Survey of publicly available reports on advanced persistent threat actors,

    A. Lemay, J. Calvet, F. Menet, and J. M. Fernandez, “Survey of publicly available reports on advanced persistent threat actors,” Computers & Security, vol. 72, pp. 26–59, 2018

  7. [7]

    Apt datasets and attack modeling for automated detection methods: A review,

    B. Stojanovi ´c, K. Hofer-Schmitz, and U. Kleb, “Apt datasets and attack modeling for automated detection methods: A review,” Computers & Security, vol. 92, p. 101734, 2020

  8. [8]

    A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,

    A. Alshamrani, S. Myneni, A. Chowdhary, and D. Huang, “A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,” IEEE Communications Surveys & Tutorials , 2019

Show all 129 references
  1. [9]

    Finding cyber threats with att&ck™-based analytics,

    B. E. Strom, J. A. Battaglia, M. S. Kemmerer, W. Kupersanin, D. P. Miller, C. Wampler, S. M. Whitley, and R. D. Wolf, “Finding cyber threats with att&ck™-based analytics,” tech. rep., The MITRE Corporation, 2017

  2. [10]

    APT 28 under the scope a journey into exfiltrating intelligence and government information,

    R. Benchea, C. Vatamanu, A. Maximciuc, and V . Lunca¸ su, “APT 28 under the scope a journey into exfiltrating intelligence and government information,” 2015

  3. [11]

    Sednit update: How fancy bear spent the year

    E. Research, “Sednit update: How fancy bear spent the year.” https://www.welivesecurity.com/2017/12/21/sednit-update-fancy-bear- spent-year/, December 2017. Accessed: 2019-04-10

  4. [12]

    Operation cobalt kitty: A large-scale APT in asia carried out by the oceanlotus group

    A. Dahan, “Operation cobalt kitty: A large-scale APT in asia carried out by the oceanlotus group.” https://www.cybereason.com/blog/operation- cobalt-kitty-apt. Accessed: 2019-04-14

  5. [13]

    Operation cobalt kitty cybereason labs analysis,

    C. Labs and A. Dahan, “Operation cobalt kitty cybereason labs analysis,” 2017

  6. [14]

    The dukes 7 years of russian cyberespionage,

    F.-S. L. T. Intelligence, “The dukes 7 years of russian cyberespionage,” 2016

  7. [15]

    Bears in the midst: Intrusion into the democratic national committee

    D. Alperovitch, “Bears in the midst: Intrusion into the democratic national committee.” https://www .crowdstrike.com/blog/bears-midst- intrusion-democratic-national-committee/. Accessed: 2019-04-14

  8. [16]

    Buckeye cyberespionage group shifts gaze from us to hong kong

    S. S. Response, “Buckeye cyberespionage group shifts gaze from us to hong kong.” https://www .symantec.com/connect/blogs/ buckeye-cyberespionage-group-shifts-gaze-us-hong-kong, September

  9. [17]

    Where you at?: Indicators of lateral movement using at.exe on windows 7 systems

    H. Carvey, “Where you at?: Indicators of lateral movement using at.exe on windows 7 systems.” https://www .secureworks.com/blog/ where-you-at-indicators-of-lateral-movement-using-at-exe- on-windows-7-systems, September 2014. Accessed: 2019-04-14

  10. [18]

    Evasive maneuvers by the wekby group with custom rop-packing and dns covert channels

    A. Shelmire, “Evasive maneuvers by the wekby group with custom rop-packing and dns covert channels.” https://www .anomali.com/blog/ evasive-maneuvers-the-wekby-group-attempts-to-evade- analysis-via-custom-rop, July 2015. Accessed: 2019-04-14

  11. [19]

    APT 37 (reaper) the overlooked north korean actor, special report,

    F. Lab, “APT 37 (reaper) the overlooked north korean actor, special report,” 2018

  12. [20]

    A taxonomy of botnet behavior, detection, and defense,

    S. Khattak, N. R. Ramay, K. R. Khan, A. A. Syed, and S. A. Khayam, “A taxonomy of botnet behavior, detection, and defense,” IEEE communications surveys & tutorials , vol. 16, no. 2, pp. 898– 924, 2013

  13. [21]

    Detecting APT malware infections based on malicious dns and traffic analysis,

    G. Zhao, K. Xu, L. Xu, and B. Wu, “Detecting APT malware infections based on malicious dns and traffic analysis,” IEEE access , vol. 3, pp. 1132–1142, 2015

  14. [22]

    Botnet communication patterns,

    G. V ormayr, T. Zseby, and J. Fabini, “Botnet communication patterns,” IEEE Communications Surveys & Tutorials , vol. 19, no. 4, pp. 2768– 2796, 2017

  15. [23]

    Advanced persistent threats: Behind the scenes,

    M. Ussath, D. Jaeger, F. Cheng, and C. Meinel, “Advanced persistent threats: Behind the scenes,” in Annual Conference on Information Science and Systems (CISS 16) , pp. 181–186, IEEE, 2016

  16. [24]

    A study on advanced persistent threats,

    P. Chen, L. Desmet, and C. Huygens, “A study on advanced persistent threats,” in IFIP International Conference on Communications and Multimedia Security, pp. 63–72, Springer, 2014

  17. [25]

    H AWK-E YE: Holistic detection of APT command and control domains,

    A. Alageel and S. Maffeis, “H AWK-E YE: Holistic detection of APT command and control domains,” in In The 36th ACM/SIGAPP Sympo- sium on Applied Computing (SAC 21) , pp. 1664–1673, ACM, 2021

  18. [26]

    Intelligence- driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,

    E. M. Hutchins, M. J. Cloppert, and R. M. Amin, “Intelligence- driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,” Leading Issues in Information Warfare & Security Research, vol. 1, no. 1, p. 80, 2011

  19. [27]

    Sys- tems for detecting advanced persistent threats: A development roadmap using intelligent data analysis,

    J. de Vries, H. Hoogstraaten, J. van den Berg, and S. Daskapan, “Sys- tems for detecting advanced persistent threats: A development roadmap using intelligent data analysis,” in 2012 International Conference on Cyber Security, pp. 54–61, IEEE, 2012

  20. [28]

    A context-based detection framework for advanced persistent threats,

    P. Giura and W. Wang, “A context-based detection framework for advanced persistent threats,” in International Conference on Cyber Security, pp. 69–74, IEEE, 2012

  21. [29]

    Technical aspects of cyber kill chain,

    T. Yadav and A. M. Rao, “Technical aspects of cyber kill chain,” in In- ternational Symposium on Security in Computing and Communication , pp. 438–452, Springer, 2015

  22. [30]

    A cyber kill chain based taxonomy of banking trojans for evolutionary computational intelligence,

    D. Kiwia, A. Dehghantanha, K.-K. R. Choo, and J. Slaughter, “A cyber kill chain based taxonomy of banking trojans for evolutionary computational intelligence,” Journal of computational science , vol. 27, pp. 394–409, 2018

  23. [31]

    A markov multi- phase transferable belief model: An application for predicting data exfiltration apts,

    G. Ioannou, P. Louvieris, N. Clewley, and G. Powell, “A markov multi- phase transferable belief model: An application for predicting data exfiltration apts,” in Proceedings of the 16th International Conference on Information Fusion , pp. 842–849, IEEE, 2013

  24. [32]

    Holmes: real-time APT detection through correlation of sus- picious information flows,

    S. M. Milajerdi, R. Gjomemo, B. Eshete, R. Sekar, and V . Venkatakr- ishnan, “Holmes: real-time APT detection through correlation of sus- picious information flows,” arXiv preprint arXiv:1810.01594 , 2018

  25. [33]

    Situation awareness of multistage cyber attacks by semantic event fusion,

    S. Mathew, S. Upadhyaya, M. Sudit, and A. Stotz, “Situation awareness of multistage cyber attacks by semantic event fusion,” in Military Communications Conference (MILCOM 10) , pp. 1286–1291, IEEE, 2010

  26. [34]

    Dark matter: Uncovering the darkcomet rat ecosystem,

    B. Farinholt, M. Rezaeirad, D. McCoy, and K. Levchenko, “Dark matter: Uncovering the darkcomet rat ecosystem,” in Proceedings of The Web Conference (WWW 20) , pp. 2109–2120, 2020

  27. [35]

    Schrödinger’s RAT: Profiling the stakeholders in the remote access trojan ecosystem,

    M. Rezaeirad, B. Farinholt, H. Dharmdasani, P. Pearce, K. Levchenko, and D. McCoy, “Schrödinger’s RAT: Profiling the stakeholders in the remote access trojan ecosystem,” in 27th USENIX Security Symposium (USENIX Security 18) , pp. 1043–1060, 2018

  28. [36]

    To catch a ratter: Monitoring the behavior of amateur darkcomet rat operators in the wild,

    B. Farinholt, M. Rezaeirad, P. Pearce, H. Dharmdasani, H. Yin, S. Le Blond, D. McCoy, and K. Levchenko, “To catch a ratter: Monitoring the behavior of amateur darkcomet rat operators in the wild,” in IEEE Symposium on Security and Privacy (S&P 17), pp. 770– 787, IEEE, 2017. 25

  29. [37]

    Fin7.5: the infamous cybercrime rig “fin7

    M. Heinemeyer, “Fin7.5: the infamous cybercrime rig “fin7” continues its activities.” https://securelist .com/fin7-5-the-infamous-cybercrime- rig-fin7-continues-its-activities/90703//. Accessed: 2021-07-18

  30. [38]

    The elderwood project,

    G. O’Gorman and G. McDonald, “The elderwood project,” September 2012

  31. [39]

    C. G. I. Team, CrowdStrike Intelligence Report: Putter Panda. Crowd- Strike, June 2014

  32. [40]

    APT 3 adversary emulation plan,

    C. A. Korban, D. P. Miller, A. Pennington, C. B. Thomas, and T. M. Corporation, “APT 3 adversary emulation plan,” September 2017

  33. [41]

    Opera- tion double tap

    N. Moran, M. Scott, M. Oppenheim, and J. Homan, “Opera- tion double tap.” https://www .fireeye.com/blog/threat-research/2014/ 11/operation_doubletap.html, November 2014. Accessed: 2019-04-23

  34. [42]

    Yates, APT 3 Uncovered: The code evolution of Pirpi

    M. Yates, APT 3 Uncovered: The code evolution of Pirpi . Palo Alto Networks, June 2017

  35. [43]

    Operation cloud hopper,

    PwC and B. Systems, “Operation cloud hopper,” April 2017

  36. [44]

    Operation cloud hopper technical annex,

    PwC and B. Systems, “Operation cloud hopper technical annex,” April 2017

  37. [45]

    Darwin’s favorite APT group

    N. Moran and M. Oppenheim, “Darwin’s favorite APT group.” https://www.fireeye.com/blog/threat-research/2014/09/darwins- favorite-apt-group-2 .html. Accessed: 2019-04-18

  38. [46]

    Operation “ke3chang

    N. Villeneuve, J. T. Bennett, N. Moran, T. Haq, M. Scott, and K. Geers, “Operation “ke3chang”: Targeted attacks against ministries of foreign affairs,” 2014

  39. [47]

    Apt15 is alive and strong: An analysis of royalcli and royaldns

    N. Group, “Apt15 is alive and strong: An analysis of royalcli and royaldns.” https://www .nccgroup.trust/uk/about-us/newsroom-and- events/blogs/2018/march/apt15-is-alive-and-strong-an-analysis-of- royalcli-and- royaldns/. Accessed: 2019-04-18

  40. [48]

    The eps awakens - part 2

    R. Winters, “The eps awakens - part 2.” https://www .fireeye.com/ blog/threat-research/2015/12/the-eps-awakens-part-two .html, Decem- ber 2015. Accessed: 2019-04-18

  41. [49]

    The eps awakens

    G. Jiang, D. Caselden, and R. Winters, “The eps awakens.” https:// www.fireeye.com/blog/threat-research/2015/12/the_eps_awakens.html, December 2015. Accessed: 2019-04-18

  42. [50]

    Hiding in plain sight: Fireeye and microsoft expose,

    F. L. . F. T. Intelligence, “Hiding in plain sight: Fireeye and microsoft expose,” May 2015

  43. [51]

    New attacks linked to c0d0so0 group

    J. Grunzweig and B. Lee, “New attacks linked to c0d0so0 group.” https: //unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group/. Accessed: 2019-04-10

  44. [52]

    Privileges and credentials: Phished at the request of counsel

    I. Ahl, “Privileges and credentials: Phished at the request of counsel.” https://www.fireeye.com/blog/threat-research/2017/06/phished-at-the- request-of-counsel .html. Accessed: 2019-04-10

  45. [53]

    Threat group 3390 cyberespionage

    D. S. C. T. U. T. Intelligence, “Threat group 3390 cyberespionage.” https://www.secureworks.com/research/threat-group-3390-targets- organizations-for-cyberespionage, August 2015. Accessed: 2019-04- 23

  46. [54]

    Bronze union cyberespionage persists despite dis- closures

    C. T. U. R. Team, “Bronze union cyberespionage persists despite dis- closures.” https://www .secureworks.com/research/bronze-union, June

  47. [55]

    Luckymouse hits national data center to organize country- level waterholing campaign

    D. Legezo, “Luckymouse hits national data center to organize country- level waterholing campaign.” https://securelist .com/luckymouse-hits- national-data-center/86083/, June 2018. Accessed: 2019-04-23

  48. [56]

    APT 28: A window into russia’s cyber espionage operations and a special report,

    F. Lab, “APT 28: A window into russia’s cyber espionage operations and a special report,” 2014

  49. [57]

    Anthe, P

    C. Anthe, P. Chrzan, E. Florio, C. Foster, P. Henry, J. Jones, N. Ng, N. O’Sullivan, D. Pecelj, A. Penta, I. Ragragio, T. Rains, and P. Rebriy, Microsoft Security Intelligence Report , vol. 19. Microsoft, June 2015

  50. [58]

    APT 28: New espionage operations target mili- tary and government organizations

    S. R. A. I. Team, “APT 28: New espionage operations target mili- tary and government organizations.” https://www.symantec.com/blogs/ election-security/apt28-espionage-military-government, October 2018. Accessed: 2019-04-10

  51. [59]

    Lab, En Route with Sednit Part 2: Observing the Comings and Goings, vol

    E. Lab, En Route with Sednit Part 2: Observing the Comings and Goings, vol. 1. ESET, October 2016

  52. [60]

    Grizzly steppe – russian malicious cyber activity,

    D. of Homeland Security and F. B. of Investigation, “Grizzly steppe – russian malicious cyber activity,” December 2016

  53. [61]

    Not so cozy: An uncomfortable examination of a suspected apt29 phishing campaign

    M. Dunwoody, A. Thompson, B. Withnell, J. Leathery, M. Matonis, and N. Carr, “Not so cozy: An uncomfortable examination of a suspected apt29 phishing campaign.” https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy- an-uncomfortable-examination-of-a-suspected- apt29...

  54. [62]

    Labs, APT 30 and the mechanics of a long-running cyber espionage operation

    F. Labs, APT 30 and the mechanics of a long-running cyber espionage operation. FireEye, April 2015

  55. [63]

    Fake or fake: Keeping up with oceanlotus decoys

    R. Dumont, “Fake or fake: Keeping up with oceanlotus decoys.” https://www.welivesecurity.com/2019/03/20/fake-or-fake-keeping-up- with-oceanlotus-decoys/. Accessed: 2019-04-14

  56. [64]

    Cyber espionage is alive and well: APT 32 and the threat to global corporations

    N. Carr, “Cyber espionage is alive and well: APT 32 and the threat to global corporations.” https://www .fireeye.com/blog/threat-research/ 2017/05/cyber-espionage-apt32.html, May 2017. Accessed: 2019-06- 10

  57. [65]

    Insights into iranian cyber espionage: APT 33 targets aerospace and energy sectors and has ties to destructive malware

    J. O’Leary, J. Kimble, K. Vanderlee, and N. Fraser, “Insights into iranian cyber espionage: APT 33 targets aerospace and energy sectors and has ties to destructive malware.” https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights- into-iranian-cyber-espionage .html...

  58. [66]

    Elfin: Relentless espionage group targets multiple organizations in saudi arabia and u.s

    S. R. A. I. T. at Symantec, “Elfin: Relentless espionage group targets multiple organizations in saudi arabia and u.s..” https: //www.symantec.com/blogs/threat-intelligence/elfin-apt33-espionage. Accessed: 2019-04-20

  59. [67]

    Overruled: Containing a potentially destructive adversary

    G. Ackerman, R. Cole, A. Thompson, A. Orleans, and N. Carr, “Overruled: Containing a potentially destructive adversary.” https://www.fireeye.com/blog/threat-research/2018/12/overruled- containing-a-potentially-destructive-adversary .html. Accessed: 2019-04-20

  60. [68]

    New targeted attack in the middle east by apt34, a suspected iranian threat group, using cve-2017-11882 ex- ploit

    M. Sardiwal, V . Cannon, N. Fraser, Y . Londhe, N. Richard, and J. O’Leary, “New targeted attack in the middle east by apt34, a suspected iranian threat group, using cve-2017-11882 ex- ploit.” https://www .fireeye.com/blog/threat-research/2017/12/targeted- attack-in-middle-eas...

  61. [69]

    Oilrig uses ismdoor variant; possibly linked to greenbug threat group

    R. Falcone and B. Lee, “Oilrig uses ismdoor variant; possibly linked to greenbug threat group.” https://unit42 .paloaltonetworks.com/unit42- oilrig-uses-ismdoor-variant-possibly-linked- greenbug-threat-group/. Accessed: 2019-04-21

  62. [70]

    Rocket kitten: A campaign with 9 lives,

    T. Intelligence and C. P. Research, “Rocket kitten: A campaign with 9 lives,” 2015

  63. [71]

    China-based cyber threat group uses drop- box for malware communications and targets hong kong media outlets

    F. T. Intelligence, “China-based cyber threat group uses drop- box for malware communications and targets hong kong media outlets.” https://www .fireeye.com/blog/threat-research/2015/11/china- based-threat.html. Accessed: 2019-04-20

  64. [72]

    Operation blockbuster: Unraveling the long thread of the sony attack,

    Novetta, “Operation blockbuster: Unraveling the long thread of the sony attack,” August 2017

  65. [73]

    Operation blockbuster: Remote administration tools and content staging malware report,

    Novetta, “Operation blockbuster: Remote administration tools and content staging malware report,” August 2017

  66. [74]

    Colbat snatch,

    P. Technologies, “Colbat snatch,” December 2016

  67. [75]

    Multiple cobalt personality disorder

    V . Svajcer, “Multiple cobalt personality disorder.” https: //blog.talosintelligence.com/2018/07/multiple-cobalt-personality- disorder.html, July 2018. Accessed: 2019-04-05

  68. [76]

    S. S. Response, Dragonfly: Cyberespionage AttacksAgainst Energy Suppliers. Symantec, July 2014

  69. [77]

    Lab, The Duqu 2.0 technical details

    K. Lab, The Duqu 2.0 technical details . Kaspersky, June 2015

  70. [78]

    On the hunt for fin7: Pursuing an enigmatic and evasive global crimi- nal operation

    N. Carr, K. Goody, S. Miller, and B. Vengerik, “On the hunt for fin7: Pursuing an enigmatic and evasive global crimi- nal operation.” https://www .fireeye.com/blog/threat-research/2018/08/ fin7-pursuing-an-enigmatic-and-evasive-global-criminal- operation.html, August 2018. Acc...

  71. [79]

    Apt40: Examining a china-nexus espionage actor

    F. Plan, N. Fraser, J. O’Leary, V . Cannon, and B. Read, “Apt40: Examining a china-nexus espionage actor.” https: //www.fireeye.com/blog/threat-research/2019/03/apt40-examining- a-china-nexus-espionage-actor .html, March 2019. Accessed: 2019- 05-04

  72. [80]

    Suspected chinese cyber espionage group (temp.periscope) targeting u.s. engineering and maritime industries

    F. Lab, “Suspected chinese cyber espionage group (temp.periscope) targeting u.s. engineering and maritime industries.” https: //www.fireeye.com/blog/threat-research/2018/03/suspected-chinese- espionage-group-targeting-maritime-and- engineering-industries.html, March 2018. Acce...

  73. [81]

    The msnmm campaigns the earliest naikon APT campaigns,

    K. Baumgartner and M. Golovkin, “The msnmm campaigns the earliest naikon APT campaigns,” May 2015

  74. [82]

    Camerashy closing the aperture on china’s unit 78020,

    T. Inc. and D. G. Inc, “Camerashy closing the aperture on china’s unit 78020,” 2015. Accessed: 2019-01-25

  75. [83]

    Untangling the patchwork cyberespionage group,

    D. Lunghi, J. Horejsi, and C. Pernet, “Untangling the patchwork cyberespionage group,” October 2018

  76. [84]

    Patchwork APT group targets us think tanks

    M. Meltzer, S. Koessel, and S. Adair, “Patchwork APT group targets us think tanks.” https://www.volexity.com/blog/2018/06/07/patchwork- apt-group-targets-us-think-tanks/, June 2018. Accessed: 2019-04-02

  77. [85]

    N. G. Andy Settle and A. Toro, Monsoon – analysis of an APT campaign espionage and data loss under the cover of current affairs , vol. 1. Raytheon - Forcepoint Security Labs, September 2016

  78. [86]

    F.-S. L. S. Response, Blackenergy and Quedagh. F-Secure, 2014

  79. [87]

    Research and A

    G. Research and A. Team, The ProjectSauron APT. Technical analysis. Kaspersky, August 2016

  80. [88]

    Backdoor.remsec indicators of compromise,

    S. S. Response, “Backdoor.remsec indicators of compromise,” August 2016. 26

  81. [89]

    S. S. Response, Regin: Top-tier espionage tool enables stealthy surveil- lance. Symantec, Auguest 2014

  82. [90]

    Research and A

    G. Research and A. Team, Cloud Atlas: RedOctober APT is back in style. Kaspersky, December 2014. Accessed: 2019-05-04

  83. [91]

    Research and A

    G. Research and A. Team, Red October” Diplomatic Cyber Attacks Investigation. Kaspersky, January 2013. Accessed: 2019-05-04

  84. [92]

    Research and A

    G. Research and A. Team, Red October” – Part Two, the Modules . Kaspersky, January 2013. Accessed: 2019-05-04

  85. [93]

    Puttering into the future

    J. Gross and J. Walter, “Puttering into the future. . . .” https: //threatvector.cylance.com/en_us/home/puttering-into-the-future .html, January 2016. Accessed: 2019-04-23

  86. [94]

    Decoding network data from a gh0st rat variant

    N. Pantazopoulos, “Decoding network data from a gh0st rat variant.” https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/ 2018/april/decoding-network-data-from-a-gh0st-rat-variant/, April

  87. [95]

    New wekby attacks use dns requests as command and control mechanism

    J. Grunzweig, M. Scott, and B. Lee, “New wekby attacks use dns requests as command and control mechanism.” https://unit42.paloaltonetworks.com/unit42-new-wekby-attacks- use-dns-requests-as-command- and-control-mechanism/, September 2014. Accessed: 2019-04-14

  88. [96]

    Emissary panda – a potential new malicious tool

    N. Group, “Emissary panda – a potential new malicious tool.” https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/ 2018/may/emissary-panda-a-potential-new-malicious-tool/, May

  89. [97]

    Apt29 domain fronting with tor

    M. Dunwoody, “Apt29 domain fronting with tor.” https://www.fireeye.com/blog/threat-research/2017/03/ apt29_domain_frontin.html. Accessed: 2019-04-14

  90. [98]

    Oceanlotus blossoms: Mass digital surveillance and attacks targeting asean, asian nations, the me- dia, human rights groups, and civil society

    D. Lassalle, S. Koessel, and S. Adair, “Oceanlotus blossoms: Mass digital surveillance and attacks targeting asean, asian nations, the me- dia, human rights groups, and civil society.” https://www.volexity.com/ blog/2017/11/06/oceanlotus-blossoms-mass-digital-surveillance-and-...

  91. [99]

    Oceanlotus old techniques, new backdoor,

    ESET, “Oceanlotus old techniques, new backdoor,” March 2018

  92. [100]

    Accessed: 2019-04-23

  93. [101]

    Oilrig malware campaign up- dates toolset and expands targets

    J. Grunzweig and R. Falcone, “Oilrig malware campaign up- dates toolset and expands targets.” https://unit42.paloaltonetworks.com/ unit42-oilrig-malware-campaign-updates-toolset-and- expands-targets/. Accessed: 2019-04-21

  94. [102]

    Magic hound campaign attacks saudi targets

    B. Lee and R. Falcone, “Magic hound campaign attacks saudi targets.” https://unit42.paloaltonetworks.com/unit42-magic-hound-campaign- attacks-saudi-targets/, February 2017. Accessed: 2019-04-23

  95. [103]

    Loaders and installers and uninstallers report,

    Novetta, “Loaders and installers and uninstallers report,” August 2017

  96. [104]

    Palo Alto - Unit 42. OilReg

    “Palo Alto - Unit 42. OilReg.” https://pan-unit42 .github.io/ playbook_viewer/. Accessed: April 2019

  97. [105]

    Secrets of cobalt: How cobalt hackers bypass your defenses

    V . Matveena, “Secrets of cobalt: How cobalt hackers bypass your defenses.” https://www .group-ib.com/blog/cobalt, August 2017. Ac- cessed: 2019-04-05

  98. [106]

    S. R. A. I. Team, Dragonfly: Western energy sector targeted by sophisticated attack group. Symantec, October 2017. Accessed: 2019- 04-09

  99. [107]

    US-CERT at Department of Homeland Security. Russian govern- ment cyber activity targeting energy and other critical infrastructure sectors

    “US-CERT at Department of Homeland Security. Russian govern- ment cyber activity targeting energy and other critical infrastructure sectors.” https://www.us-cert.gov/ncas/alerts/TA18-074A, March 2018. Accessed: 2019-04-09

  100. [108]

    Lazarus resurfaces, targets global banks and bitcoin users

    R. Sherstobitoff, “Lazarus resurfaces, targets global banks and bitcoin users.” https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/ lazarus-resurfaces-targets-global-banks-bitcoin-users/, Feb 2018. Ac- cessed: 2019-04-08

  101. [109]

    Nanhaishu rating the south china sea,

    F.-S. L. Threat Intelligence, “Nanhaishu rating the south china sea,” July 2016

  102. [110]

    Unveiling patchwork – the copy-paste apt: A targeted at- tack caught with cyber deception

    C. Inc., “Unveiling patchwork – the copy-paste apt: A targeted at- tack caught with cyber deception.” https://cymmetria .com/research/ patchwork-targeted-attack/, 2016. Accessed: 2019-04-02

  103. [111]

    Lab, The regin platform nation-state ownage of gsm networks

    K. Lab, The regin platform nation-state ownage of gsm networks . Kaspersky, November 2014

  104. [112]

    Behind the carbanak backdoor

    J. T. Bennett and B. Vengerik, “Behind the carbanak backdoor.” https://www.fireeye.com/blog/threat-research/2017/06/behind-the- carbanak-backdoor.html, June 2017. Accessed: 2019-05-01

  105. [113]

    A bigram based real time dns tunnel detection approach,

    C. Qi, X. Chen, C. Xu, J. Shi, and P. Liu, “A bigram based real time dns tunnel detection approach,” Procedia Computer Science , vol. 17, pp. 852–860, 2013

  106. [114]

    A comprehensive measurement study of domain generating malware,

    D. Plohmann, K. Yakdan, M. Klatt, J. Bader, and E. Gerhards-Padilla, “A comprehensive measurement study of domain generating malware,” in 25th USENIX Security Symposium (USENIX Security 16) , pp. 263– 278, 2016

  107. [115]

    A taxonomy of domain-generation algorithms,

    A. K. Sood and S. Zeadally, “A taxonomy of domain-generation algorithms,” IEEE Security & Privacy , vol. 14, no. 4, pp. 46–53, 2016

  108. [116]

    Detecting DNS tunnels using character frequency analysis,

    K. Born and D. Gustafson, “Detecting DNS tunnels using character frequency analysis,” arXiv preprint arXiv:1004.4358 , 2010

  109. [117]

    Blocking- resistant communication through domain fronting.,

    D. Fifield, C. Lan, R. Hynes, P. Wegmann, and V . Paxson, “Blocking- resistant communication through domain fronting.,” Proceedings on Privacy Enhancing Technologies, vol. 2015, no. 2, pp. 46–64, 2015

  110. [118]

    Brazking android malware upgraded and targeting brazil- ian banks

    S. Tavor, “Brazking android malware upgraded and targeting brazil- ian banks.” https://securityintelligence .com/posts/brazking-android- malware-upgraded-targeting-brazilian-banks/. 2021-07-17

  111. [119]

    Weekly threat briefs

    F. T. Intelligence, “Weekly threat briefs.” https://www .fortiguard.com/ resources/threat-brief/2018/06/08/fortiguard-threat-intelligence-brief- june-08-2018. 2018-06-08

  112. [120]

    Stealthy domain generation algorithms,

    Y . Fu, L. Yu, O. Hambolu, I. Ozcelik, B. Husain, J. Sun, K. Sapra, D. Du, C. T. Beasley, and R. R. Brooks, “Stealthy domain generation algorithms,” IEEE Transactions on Information Forensics and Security, vol. 12, no. 6, pp. 1430–1443, 2017

  113. [121]

    Okrum and ketrican: an overview of recent ke3chang group activity,

    E. Research, “Okrum and ketrican: an overview of recent ke3chang group activity,” December 2017. Accessed: 2019-07-01

  114. [122]

    Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor

    Mandiant, “Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor.” https://support .solarwinds.com/SuccessCenter/s/article/ Orion-Improvement-Program?language=en_US. 2022-07-01

  115. [123]

    Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor

    Mandiant, “Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor.” https://www.mandiant.com/resources/blog/evasive-attacker-leverages- solarwinds-supply-chain-compromises-with-sunburst-backdoor/. 2022-05-10

  116. [124]

    Malware analysis report- 10135536-b

    US-CERT, “Malware analysis report- 10135536-b.” https: //www.cisa.gov/sites/default/files/publications/MAR-10135536- B_WHITE.PDF. 2017-11-13

  117. [125]

    Evolution of attacks on cisco ios devices

    G. Holmes, “Evolution of attacks on cisco ios devices.” https: //blogs.cisco.com/security/evolution-of-attacks-on-cisco-ios-devices. 2015-10-08

  118. [126]

    Remcos malware information

    TrendMicro, “Remcos malware information.” https: //success.trendmicro.com/dcx/s/solution/1123281-remcos-malware- information?language=en_US&sfdcIFrameOrigin=null. 2019-12-30

  119. [127]

    E ARLYCROW github repository

    “E ARLYCROW github repository.” https://github .com/ICL-ml4csec/ EarlyCrowAPT. 27

  120. [128]

    Does this look infected? a summary of APT41 targeting U.S. state governments

    Rufus Brown, Van Ta, and J. Wolfram, “Does this look infected? a summary of APT41 targeting U.S. state governments.” https:// www.mandiant.com/resources/blog/apt41-us-state-governments. Ac- cessed: 2023-06-29

  121. [2018]

    Accessed: 2019-04-18

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.