REVIEW 4 major objections 5 minor 1 cited by
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
T0 review · 4 major / 5 minor · reviewed 2026-08-07 · deepseek-v4-flash
Pith's one-line read APTs cannot operate without C&C servers, and HTTP(S) is the evasion channel in 81% of campaigns.
desk verdict A useful, messy consolidation of APT C&C TTPs whose headline percentages rest on a convenience sample; worth refereeing, but the numbers need re-framing. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrying object is a network-level TTP (tactics, techniques, and procedures) taxonomy with three branches: DNS-based techniques (DGA, dynamic DNS, FQDN hijacking, DNS tunneling), traffic-based techniques (web-protocol misuse, data obfuscation through protocol impersonation, non-application protocols such as raw TCP or ICMP, stealthy bursts, low profile), and channel-based techniques (multi-layer encrypted channels and fallback channels). The taxonomy is filled in by reading the vendor reports into per-campaign feature tables and then validating selected techniques against collected traffic and domain datasets, so the percentage claims come from campaign-level binary features rather than from individual packet labels.
What would settle it
Compile a fresh sample of every APT campaign disclosed by several major vendors between 2023 and 2025, code the same TTP features without excluding any campaign, and compare the HTTPS share (81%), DNS share (45%), fallback-channel share (60.6%), and multi-hop proxy share (51.5%); a substantial shortfall would show that the paper's percentages are artifacts of its campaign-selection rule.
Extended reading notes
Core claim
The paper claims that no APT can function without C&C infrastructure, and that infrastructure is reachable mostly through DNS-addressed servers. Across 33 campaigns drawn from 118 industry technical reports spanning 22 years, HTTP(S) is the workhorse evasion protocol: 81% of campaigns use HTTPS, essentially all use HTTP at some point, and 45% use DNS for resolution or tunneling. The defensive consequence is that fallback channels are not an edge case: 60.6% of campaigns split traffic across multiple C&C servers to defeat volume-based detection, 54.5% layer encryption so that decrypting one layer still leaves another, and 51.5% use domain fronting or multi-hop proxies. The paper also reports that 84.8% of campaigns use backdoors and 78.7% use remote-access trojans, with botnets rare, and it frames these findings as requirements for the next generation of network-based APT detection.
Load-bearing premise
The headline percentages rest on the assumption that the 33 selected campaigns and the 118 vendor reports used to code them are representative of all APTs, and that techniques missing from a report were not actually used.
Editorial extensions
If this is right
- A network intrusion detection system that does not treat HTTP(S) payloads and DNS queries as primary detection surfaces will miss the two channels that carry most APT C&C traffic.
- Any volume-based detector can be evaded by the 60.6% of campaigns that divide traffic across multiple C&C servers, so detector features should be per-flow or per-context rather than aggregate-volume.
- Decrypting TLS at the perimeter is insufficient when 54.5% of campaigns wrap command traffic in additional encoding or cipher layers underneath the session.
- Detection of malicious domains has to cover dynamic DNS, typosquatting, TLD squatting, FQDN hijacking, and DGA, because 45% of campaigns use DNS beyond simple resolution.
- Because 24.2% of campaigns deliver malware through spearphishing links, domain and URL reputation belongs inside the network-detection loop, not only at the mail gateway.
Reading between the lines
- The 81% and 60.6% figures are best read as lower bounds: a campaign counted as not using a technique may simply be one whose vendor report omitted it, so true prevalence could be higher.
- The selection rule of choosing one high-damage campaign per timeframe skews the sample toward well-resourced, well-documented actors, so the trend that fallback channels are increasing may be stronger for prominent campaigns than for the general APT population.
- A direct test of the paper's generalization would be to repeat the same campaign-level feature extraction on a sample built from all reports released in a fixed later window, without impact-based preselection, and check whether the HTTPS and fallback-channel shares are reproduced.
- The taxonomy could be extended to protocols the paper flags but does not fully count, such as DNS over HTTPS, cloud APIs, and P2P SMB, where the same evasion logic is likely migrating.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper surveys 33 APT campaigns documented in 118 industry reports, supplemented by the authors' own traffic datasets, with the goal of characterizing network-based tactics, techniques, and procedures (TTPs) for command-and-control (C&C) communication. It presents quantitative claims about protocol usage (81% HTTPS, 45% DNS), channel-based evasion (60.6% fallback channels, 54.5% multi-level encryption), and DNS-based TTPs (27.2% dynamic DNS, 24.2% DGA/DNS tunneling), and it develops a taxonomy of 13 network-based TTPs. The paper concludes with recommendations for next-generation NIDS, emphasizing HTTP(S) and DNS inspection and the need to treat fallback channels and multi-hop proxies as first-class detection signals.
Significance. The qualitative contribution is valuable: the TTP taxonomy (Figure 5), the per-campaign tables, and the real-traffic examples of domain fronting, protocol impersonation, fallback channels, and raw-TCP/ICMP channels give concrete, actionable evidence for detection research. The paper also draws on a large corpus of industry reports and the authors' own datasets, and several figures (Figures 8–13) provide traffic-level grounding that is often missing in survey papers. If the quantitative claims were properly scoped, they would provide useful evidence for prioritizing HTTP(S) and DNS inspection. However, the headline percentages are load-bearing and currently rest on an unstated representativeness assumption, and at least one internal inconsistency affects the paper's central protocol claim.
major comments (4)
- [Section III] The selection of the 33 campaigns is non-random: the methodology states that campaigns are chosen for 'fair distribution' over 22 years, 'availability of data from industry vendors,' and 'the one that causes major damage' (Section III). This is a damage-maximizing, availability-biased sample, yet the abstract and Section X present the resulting percentages (81% HTTPS, 45% DNS, 60.6% fallback channels, 54.5% multi-level encryption) as facts about APTs generally. The authors should either reframe these numbers as descriptive statistics of the selected sample with an explicit limitations paragraph, or justify representativeness and provide uncertainty estimates. As written, the central quantitative claims overgeneralize.
- [Abstract vs. Section X] The abstract states that 'the most popular protocol to deploy evasion techniques is using HTTP(S) with 81% of APT campaigns,' but Section X and Figure 14.b state that all campaigns use HTTP and that 81% rely on HTTPS to bypass NIDS. These statements conflict: if HTTP is used by all campaigns, then the 81% figure cannot refer to HTTP(S) as a combined category. This internal inconsistency affects the paper's most prominent protocol claim and must be corrected.
- [Sections V and X] The analysis treats a TTP as absent when no vendor report mentions it, effectively assuming that the 118 reports are complete descriptions of each campaign. This assumption is never stated or defended; the paper acknowledges only that industry is the primary information source. Because the abstract frames the numbers as facts about APT campaigns, the authors should explicitly state that the percentages describe what is documented in the selected reports, not necessarily what occurred, and discuss the implications of report incompleteness.
- [Figure 14 and Table III] The percentages in Figure 14 are said to be based on the 33 campaigns in Table III, but the paper does not provide the per-campaign counts that map Table III's checkmarks to the reported figures. A reader cannot verify 60.6%, 54.5%, 51.5%, 27.2%, or 24.2% from the material as presented. Please include the underlying counts (e.g., a supplementary table listing, for each campaign, which TTPs were counted) or a machine-readable version of Table III.
minor comments (5)
- [Section III] In the HEALP dataset description, the text reads 'we collect xxx domains'; the placeholder 'xxx' should be replaced with the actual number of domains collected, as this is part of the dataset description needed for reproducibility.
- [Figure 11] The caption describes 'Stealthy malicious APT StringPity' while the surrounding text refers to njRAT; the mismatch should be resolved.
- [Figure 13] The caption uses 'GRIFFON' while the text and Section II use 'Griffon'; please standardize the spelling.
- [Section X] The sentence 'Figure 14.b shows that all APT campaigns have continued using HTTP since 2001' should be checked against Table III, since some rows appear to have no HTTP checkmark; if those rows do use HTTP, the claim should be clarified to avoid overstatement.
- [References] The dataset references [4], [25], and [127] point to prior work and a GitHub repository, but the paper does not clearly state how the reader can access the APTracePlus and MCFP datasets used for the traffic figures; consider adding a data-availability note.
Circularity Check
No circularity: the paper's headline percentages are transcriptions of external industry reports, and its self-cited datasets are illustrative, not the fitted source of the claims.
full rationale
The paper is an empirical survey, not a derivation. Section III defines the dataset: 33 APT campaigns are selected from 118 industry reports based on 'fair distribution' and 'availability of data from industry vendors'. Section V tabulates protocol and TTP presence per campaign in Tables I-III, and Section X computes percentages such as 81% HTTPS and 60.6% fallback channels by simple arithmetic over those tables. No equation maps a fitted parameter to a predicted quantity, and no claim is defined in terms of the quantity it purports to explain. The authors' self-citations [4], [25], [127] supply traffic datasets and domain artifacts used to illustrate TTPs (e.g., Zebrocy, Mivast/Sakula, GRIFFON), but those artifacts are not the source of the headline percentages and are not fitted to the survey conclusions. The acknowledged reliance on industry reporting is a data-validity limitation, not a circularity: the percentages describe what vendor reports document, but the paper does not disguise that as a model output. No load-bearing step reduces to its own input, so no circularity is present.
Assumptions & free parameters
assumptions (3)
- domain assumption Industry vendor reports accurately and completely describe each APT campaign's C&C behavior.
- ad hoc to paper The 33 selected campaigns are representative of the population of APTs.
- domain assumption A TTP not mentioned in a campaign's industry reports was not used by that campaign.
Cite this review
Pith. "Pith review of Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures." pith.science (2026). https://pith.science/paper/ILVUB3JT
@misc{pith2026250208830,
author = {Pith},
title = {Pith review of: Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures},
year = {2026},
howpublished = {\url{https://pith.science/paper/ILVUB3JT}},
note = {Machine review of arXiv:2502.08830}
}
read the original abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques. To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to take into account the specific context of the attack explained in this paper. In this study, we select 33 APT campaigns based on the fair distribution over the past 22 years to observe the evolution of APTs over time. We focus on their evasion techniques and how they stay undetected for months or years. We found that APTs cannot continue their operations without C&C servers, which are mostly addressed by Domain Name System (DNS). We identify several TTPs used for DNS, such as Dynamic DNS, typosquatting, and TLD squatting. The next step for APT operators is to start communicating with a victim. We found that the most popular protocol to deploy evasion techniques is using HTTP(S) with 81% of APT campaigns. HTTP(S) can evade firewall filtering and pose as legitimate web-based traffic. DNS protocol is also widely used by 45% of APTs for DNS resolution and tunneling. We identify and analyze the TTPs associated with using HTTP(S) based on real artifacts.
Figures
Figures from the paper (11 more)
Forward citations
Cited by 1 Pith paper
-
Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations
An intermittent observer can recover DSSE search queries with up to about 90% accuracy by linking query groups across observation rounds via co-occurrence graph matching.
Reference graph
Works this paper leans on
-
[1]
Computer security incident handling guide,
P. Cichonski, T. Millar, T. Grance, and K. Scarfone, “Computer security incident handling guide,” NIST Special Publication , vol. 800, no. 61, pp. 1–147, 2012
2012
-
[2]
Advanced persistent threats and how to monitor and deter them,
C. Tankard, “Advanced persistent threats and how to monitor and deter them,” Network security, vol. 2011, no. 8, pp. 16–19, 2011
2011
-
[3]
APT 1: Exposing one of china’s cyber espionage units,
D. McWhorter, “APT 1: Exposing one of china’s cyber espionage units,” Feb 2013. FireEye Mandiant Lab
2013
-
[4]
E ARLYCROW: Detecting APT malware command and control over HTTP(S) using contextual summaries,
A. Alageel and S. Maffeis, “E ARLYCROW: Detecting APT malware command and control over HTTP(S) using contextual summaries,” in 25th International Information Security Conference (ISC 22) , pp. 290– 316, Springer, 2022
2022
-
[5]
Apt beaconing detection: A systematic review,
M. A. Talib, Q. Nasir, A. B. Nassif, T. Mokhamed, N. Ahmed, and B. Mahfood, “Apt beaconing detection: A systematic review,” Computers & Security , p. 102875, 2022
2022
-
[6]
Survey of publicly available reports on advanced persistent threat actors,
A. Lemay, J. Calvet, F. Menet, and J. M. Fernandez, “Survey of publicly available reports on advanced persistent threat actors,” Computers & Security, vol. 72, pp. 26–59, 2018
2018
-
[7]
Apt datasets and attack modeling for automated detection methods: A review,
B. Stojanovi ´c, K. Hofer-Schmitz, and U. Kleb, “Apt datasets and attack modeling for automated detection methods: A review,” Computers & Security, vol. 92, p. 101734, 2020
2020
-
[8]
A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,
A. Alshamrani, S. Myneni, A. Chowdhary, and D. Huang, “A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,” IEEE Communications Surveys & Tutorials , 2019
2019
Show all 129 references
-
[9]
Finding cyber threats with att&ck™-based analytics,
B. E. Strom, J. A. Battaglia, M. S. Kemmerer, W. Kupersanin, D. P. Miller, C. Wampler, S. M. Whitley, and R. D. Wolf, “Finding cyber threats with att&ck™-based analytics,” tech. rep., The MITRE Corporation, 2017
2017
-
[10]
APT 28 under the scope a journey into exfiltrating intelligence and government information,
R. Benchea, C. Vatamanu, A. Maximciuc, and V . Lunca¸ su, “APT 28 under the scope a journey into exfiltrating intelligence and government information,” 2015
2015
-
[11]
Sednit update: How fancy bear spent the year
E. Research, “Sednit update: How fancy bear spent the year.” https://www.welivesecurity.com/2017/12/21/sednit-update-fancy-bear- spent-year/, December 2017. Accessed: 2019-04-10
2017
-
[12]
Operation cobalt kitty: A large-scale APT in asia carried out by the oceanlotus group
A. Dahan, “Operation cobalt kitty: A large-scale APT in asia carried out by the oceanlotus group.” https://www.cybereason.com/blog/operation- cobalt-kitty-apt. Accessed: 2019-04-14
2019
-
[13]
Operation cobalt kitty cybereason labs analysis,
C. Labs and A. Dahan, “Operation cobalt kitty cybereason labs analysis,” 2017
2017
-
[14]
The dukes 7 years of russian cyberespionage,
F.-S. L. T. Intelligence, “The dukes 7 years of russian cyberespionage,” 2016
2016
-
[15]
Bears in the midst: Intrusion into the democratic national committee
D. Alperovitch, “Bears in the midst: Intrusion into the democratic national committee.” https://www .crowdstrike.com/blog/bears-midst- intrusion-democratic-national-committee/. Accessed: 2019-04-14
2019
-
[16]
Buckeye cyberespionage group shifts gaze from us to hong kong
S. S. Response, “Buckeye cyberespionage group shifts gaze from us to hong kong.” https://www .symantec.com/connect/blogs/ buckeye-cyberespionage-group-shifts-gaze-us-hong-kong, September
-
[17]
Where you at?: Indicators of lateral movement using at.exe on windows 7 systems
H. Carvey, “Where you at?: Indicators of lateral movement using at.exe on windows 7 systems.” https://www .secureworks.com/blog/ where-you-at-indicators-of-lateral-movement-using-at-exe- on-windows-7-systems, September 2014. Accessed: 2019-04-14
2014
-
[18]
Evasive maneuvers by the wekby group with custom rop-packing and dns covert channels
A. Shelmire, “Evasive maneuvers by the wekby group with custom rop-packing and dns covert channels.” https://www .anomali.com/blog/ evasive-maneuvers-the-wekby-group-attempts-to-evade- analysis-via-custom-rop, July 2015. Accessed: 2019-04-14
2015
-
[19]
APT 37 (reaper) the overlooked north korean actor, special report,
F. Lab, “APT 37 (reaper) the overlooked north korean actor, special report,” 2018
2018
-
[20]
A taxonomy of botnet behavior, detection, and defense,
S. Khattak, N. R. Ramay, K. R. Khan, A. A. Syed, and S. A. Khayam, “A taxonomy of botnet behavior, detection, and defense,” IEEE communications surveys & tutorials , vol. 16, no. 2, pp. 898– 924, 2013
2013
-
[21]
Detecting APT malware infections based on malicious dns and traffic analysis,
G. Zhao, K. Xu, L. Xu, and B. Wu, “Detecting APT malware infections based on malicious dns and traffic analysis,” IEEE access , vol. 3, pp. 1132–1142, 2015
2015
-
[22]
Botnet communication patterns,
G. V ormayr, T. Zseby, and J. Fabini, “Botnet communication patterns,” IEEE Communications Surveys & Tutorials , vol. 19, no. 4, pp. 2768– 2796, 2017
2017
-
[23]
Advanced persistent threats: Behind the scenes,
M. Ussath, D. Jaeger, F. Cheng, and C. Meinel, “Advanced persistent threats: Behind the scenes,” in Annual Conference on Information Science and Systems (CISS 16) , pp. 181–186, IEEE, 2016
2016
-
[24]
A study on advanced persistent threats,
P. Chen, L. Desmet, and C. Huygens, “A study on advanced persistent threats,” in IFIP International Conference on Communications and Multimedia Security, pp. 63–72, Springer, 2014
2014
-
[25]
H AWK-E YE: Holistic detection of APT command and control domains,
A. Alageel and S. Maffeis, “H AWK-E YE: Holistic detection of APT command and control domains,” in In The 36th ACM/SIGAPP Sympo- sium on Applied Computing (SAC 21) , pp. 1664–1673, ACM, 2021
2021
-
[26]
Intelligence- driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,
E. M. Hutchins, M. J. Cloppert, and R. M. Amin, “Intelligence- driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,” Leading Issues in Information Warfare & Security Research, vol. 1, no. 1, p. 80, 2011
2011
-
[27]
Sys- tems for detecting advanced persistent threats: A development roadmap using intelligent data analysis,
J. de Vries, H. Hoogstraaten, J. van den Berg, and S. Daskapan, “Sys- tems for detecting advanced persistent threats: A development roadmap using intelligent data analysis,” in 2012 International Conference on Cyber Security, pp. 54–61, IEEE, 2012
2012
-
[28]
A context-based detection framework for advanced persistent threats,
P. Giura and W. Wang, “A context-based detection framework for advanced persistent threats,” in International Conference on Cyber Security, pp. 69–74, IEEE, 2012
2012
-
[29]
Technical aspects of cyber kill chain,
T. Yadav and A. M. Rao, “Technical aspects of cyber kill chain,” in In- ternational Symposium on Security in Computing and Communication , pp. 438–452, Springer, 2015
2015
-
[30]
A cyber kill chain based taxonomy of banking trojans for evolutionary computational intelligence,
D. Kiwia, A. Dehghantanha, K.-K. R. Choo, and J. Slaughter, “A cyber kill chain based taxonomy of banking trojans for evolutionary computational intelligence,” Journal of computational science , vol. 27, pp. 394–409, 2018
2018
-
[31]
A markov multi- phase transferable belief model: An application for predicting data exfiltration apts,
G. Ioannou, P. Louvieris, N. Clewley, and G. Powell, “A markov multi- phase transferable belief model: An application for predicting data exfiltration apts,” in Proceedings of the 16th International Conference on Information Fusion , pp. 842–849, IEEE, 2013
2013
-
[32]
Holmes: real-time APT detection through correlation of sus- picious information flows,
S. M. Milajerdi, R. Gjomemo, B. Eshete, R. Sekar, and V . Venkatakr- ishnan, “Holmes: real-time APT detection through correlation of sus- picious information flows,” arXiv preprint arXiv:1810.01594 , 2018
2018 arXiv
-
[33]
Situation awareness of multistage cyber attacks by semantic event fusion,
S. Mathew, S. Upadhyaya, M. Sudit, and A. Stotz, “Situation awareness of multistage cyber attacks by semantic event fusion,” in Military Communications Conference (MILCOM 10) , pp. 1286–1291, IEEE, 2010
2010
-
[34]
Dark matter: Uncovering the darkcomet rat ecosystem,
B. Farinholt, M. Rezaeirad, D. McCoy, and K. Levchenko, “Dark matter: Uncovering the darkcomet rat ecosystem,” in Proceedings of The Web Conference (WWW 20) , pp. 2109–2120, 2020
2020
-
[35]
Schrödinger’s RAT: Profiling the stakeholders in the remote access trojan ecosystem,
M. Rezaeirad, B. Farinholt, H. Dharmdasani, P. Pearce, K. Levchenko, and D. McCoy, “Schrödinger’s RAT: Profiling the stakeholders in the remote access trojan ecosystem,” in 27th USENIX Security Symposium (USENIX Security 18) , pp. 1043–1060, 2018
2018
-
[36]
To catch a ratter: Monitoring the behavior of amateur darkcomet rat operators in the wild,
B. Farinholt, M. Rezaeirad, P. Pearce, H. Dharmdasani, H. Yin, S. Le Blond, D. McCoy, and K. Levchenko, “To catch a ratter: Monitoring the behavior of amateur darkcomet rat operators in the wild,” in IEEE Symposium on Security and Privacy (S&P 17), pp. 770– 787, IEEE, 2017. 25
2017
-
[37]
Fin7.5: the infamous cybercrime rig “fin7
M. Heinemeyer, “Fin7.5: the infamous cybercrime rig “fin7” continues its activities.” https://securelist .com/fin7-5-the-infamous-cybercrime- rig-fin7-continues-its-activities/90703//. Accessed: 2021-07-18
2021
-
[38]
The elderwood project,
G. O’Gorman and G. McDonald, “The elderwood project,” September 2012
2012
-
[39]
C. G. I. Team, CrowdStrike Intelligence Report: Putter Panda. Crowd- Strike, June 2014
2014
-
[40]
APT 3 adversary emulation plan,
C. A. Korban, D. P. Miller, A. Pennington, C. B. Thomas, and T. M. Corporation, “APT 3 adversary emulation plan,” September 2017
2017
-
[41]
Opera- tion double tap
N. Moran, M. Scott, M. Oppenheim, and J. Homan, “Opera- tion double tap.” https://www .fireeye.com/blog/threat-research/2014/ 11/operation_doubletap.html, November 2014. Accessed: 2019-04-23
2014
-
[42]
Yates, APT 3 Uncovered: The code evolution of Pirpi
M. Yates, APT 3 Uncovered: The code evolution of Pirpi . Palo Alto Networks, June 2017
2017
-
[43]
Operation cloud hopper,
PwC and B. Systems, “Operation cloud hopper,” April 2017
2017
-
[44]
Operation cloud hopper technical annex,
PwC and B. Systems, “Operation cloud hopper technical annex,” April 2017
2017
-
[45]
Darwin’s favorite APT group
N. Moran and M. Oppenheim, “Darwin’s favorite APT group.” https://www.fireeye.com/blog/threat-research/2014/09/darwins- favorite-apt-group-2 .html. Accessed: 2019-04-18
2014
-
[46]
Operation “ke3chang
N. Villeneuve, J. T. Bennett, N. Moran, T. Haq, M. Scott, and K. Geers, “Operation “ke3chang”: Targeted attacks against ministries of foreign affairs,” 2014
2014
-
[47]
Apt15 is alive and strong: An analysis of royalcli and royaldns
N. Group, “Apt15 is alive and strong: An analysis of royalcli and royaldns.” https://www .nccgroup.trust/uk/about-us/newsroom-and- events/blogs/2018/march/apt15-is-alive-and-strong-an-analysis-of- royalcli-and- royaldns/. Accessed: 2019-04-18
2018
-
[48]
The eps awakens - part 2
R. Winters, “The eps awakens - part 2.” https://www .fireeye.com/ blog/threat-research/2015/12/the-eps-awakens-part-two .html, Decem- ber 2015. Accessed: 2019-04-18
2015
-
[49]
The eps awakens
G. Jiang, D. Caselden, and R. Winters, “The eps awakens.” https:// www.fireeye.com/blog/threat-research/2015/12/the_eps_awakens.html, December 2015. Accessed: 2019-04-18
2015
-
[50]
Hiding in plain sight: Fireeye and microsoft expose,
F. L. . F. T. Intelligence, “Hiding in plain sight: Fireeye and microsoft expose,” May 2015
2015
-
[51]
New attacks linked to c0d0so0 group
J. Grunzweig and B. Lee, “New attacks linked to c0d0so0 group.” https: //unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group/. Accessed: 2019-04-10
2019
-
[52]
Privileges and credentials: Phished at the request of counsel
I. Ahl, “Privileges and credentials: Phished at the request of counsel.” https://www.fireeye.com/blog/threat-research/2017/06/phished-at-the- request-of-counsel .html. Accessed: 2019-04-10
2017
-
[53]
Threat group 3390 cyberespionage
D. S. C. T. U. T. Intelligence, “Threat group 3390 cyberespionage.” https://www.secureworks.com/research/threat-group-3390-targets- organizations-for-cyberespionage, August 2015. Accessed: 2019-04- 23
2015
-
[54]
Bronze union cyberespionage persists despite dis- closures
C. T. U. R. Team, “Bronze union cyberespionage persists despite dis- closures.” https://www .secureworks.com/research/bronze-union, June
-
[55]
Luckymouse hits national data center to organize country- level waterholing campaign
D. Legezo, “Luckymouse hits national data center to organize country- level waterholing campaign.” https://securelist .com/luckymouse-hits- national-data-center/86083/, June 2018. Accessed: 2019-04-23
2018
-
[56]
APT 28: A window into russia’s cyber espionage operations and a special report,
F. Lab, “APT 28: A window into russia’s cyber espionage operations and a special report,” 2014
2014
-
[57]
Anthe, P
C. Anthe, P. Chrzan, E. Florio, C. Foster, P. Henry, J. Jones, N. Ng, N. O’Sullivan, D. Pecelj, A. Penta, I. Ragragio, T. Rains, and P. Rebriy, Microsoft Security Intelligence Report , vol. 19. Microsoft, June 2015
2015
-
[58]
APT 28: New espionage operations target mili- tary and government organizations
S. R. A. I. Team, “APT 28: New espionage operations target mili- tary and government organizations.” https://www.symantec.com/blogs/ election-security/apt28-espionage-military-government, October 2018. Accessed: 2019-04-10
2018
-
[59]
Lab, En Route with Sednit Part 2: Observing the Comings and Goings, vol
E. Lab, En Route with Sednit Part 2: Observing the Comings and Goings, vol. 1. ESET, October 2016
2016
-
[60]
Grizzly steppe – russian malicious cyber activity,
D. of Homeland Security and F. B. of Investigation, “Grizzly steppe – russian malicious cyber activity,” December 2016
2016
-
[61]
Not so cozy: An uncomfortable examination of a suspected apt29 phishing campaign
M. Dunwoody, A. Thompson, B. Withnell, J. Leathery, M. Matonis, and N. Carr, “Not so cozy: An uncomfortable examination of a suspected apt29 phishing campaign.” https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy- an-uncomfortable-examination-of-a-suspected- apt29...
2018
-
[62]
Labs, APT 30 and the mechanics of a long-running cyber espionage operation
F. Labs, APT 30 and the mechanics of a long-running cyber espionage operation. FireEye, April 2015
2015
-
[63]
Fake or fake: Keeping up with oceanlotus decoys
R. Dumont, “Fake or fake: Keeping up with oceanlotus decoys.” https://www.welivesecurity.com/2019/03/20/fake-or-fake-keeping-up- with-oceanlotus-decoys/. Accessed: 2019-04-14
2019
-
[64]
Cyber espionage is alive and well: APT 32 and the threat to global corporations
N. Carr, “Cyber espionage is alive and well: APT 32 and the threat to global corporations.” https://www .fireeye.com/blog/threat-research/ 2017/05/cyber-espionage-apt32.html, May 2017. Accessed: 2019-06- 10
2017
-
[65]
Insights into iranian cyber espionage: APT 33 targets aerospace and energy sectors and has ties to destructive malware
J. O’Leary, J. Kimble, K. Vanderlee, and N. Fraser, “Insights into iranian cyber espionage: APT 33 targets aerospace and energy sectors and has ties to destructive malware.” https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights- into-iranian-cyber-espionage .html...
2017
-
[66]
Elfin: Relentless espionage group targets multiple organizations in saudi arabia and u.s
S. R. A. I. T. at Symantec, “Elfin: Relentless espionage group targets multiple organizations in saudi arabia and u.s..” https: //www.symantec.com/blogs/threat-intelligence/elfin-apt33-espionage. Accessed: 2019-04-20
2019
-
[67]
Overruled: Containing a potentially destructive adversary
G. Ackerman, R. Cole, A. Thompson, A. Orleans, and N. Carr, “Overruled: Containing a potentially destructive adversary.” https://www.fireeye.com/blog/threat-research/2018/12/overruled- containing-a-potentially-destructive-adversary .html. Accessed: 2019-04-20
2018
-
[68]
New targeted attack in the middle east by apt34, a suspected iranian threat group, using cve-2017-11882 ex- ploit
M. Sardiwal, V . Cannon, N. Fraser, Y . Londhe, N. Richard, and J. O’Leary, “New targeted attack in the middle east by apt34, a suspected iranian threat group, using cve-2017-11882 ex- ploit.” https://www .fireeye.com/blog/threat-research/2017/12/targeted- attack-in-middle-eas...
2017
-
[69]
Oilrig uses ismdoor variant; possibly linked to greenbug threat group
R. Falcone and B. Lee, “Oilrig uses ismdoor variant; possibly linked to greenbug threat group.” https://unit42 .paloaltonetworks.com/unit42- oilrig-uses-ismdoor-variant-possibly-linked- greenbug-threat-group/. Accessed: 2019-04-21
2019
-
[70]
Rocket kitten: A campaign with 9 lives,
T. Intelligence and C. P. Research, “Rocket kitten: A campaign with 9 lives,” 2015
2015
-
[71]
China-based cyber threat group uses drop- box for malware communications and targets hong kong media outlets
F. T. Intelligence, “China-based cyber threat group uses drop- box for malware communications and targets hong kong media outlets.” https://www .fireeye.com/blog/threat-research/2015/11/china- based-threat.html. Accessed: 2019-04-20
2015
-
[72]
Operation blockbuster: Unraveling the long thread of the sony attack,
Novetta, “Operation blockbuster: Unraveling the long thread of the sony attack,” August 2017
2017
-
[73]
Operation blockbuster: Remote administration tools and content staging malware report,
Novetta, “Operation blockbuster: Remote administration tools and content staging malware report,” August 2017
2017
-
[74]
Colbat snatch,
P. Technologies, “Colbat snatch,” December 2016
2016
-
[75]
Multiple cobalt personality disorder
V . Svajcer, “Multiple cobalt personality disorder.” https: //blog.talosintelligence.com/2018/07/multiple-cobalt-personality- disorder.html, July 2018. Accessed: 2019-04-05
2018
-
[76]
S. S. Response, Dragonfly: Cyberespionage AttacksAgainst Energy Suppliers. Symantec, July 2014
2014
-
[77]
Lab, The Duqu 2.0 technical details
K. Lab, The Duqu 2.0 technical details . Kaspersky, June 2015
2015
-
[78]
On the hunt for fin7: Pursuing an enigmatic and evasive global crimi- nal operation
N. Carr, K. Goody, S. Miller, and B. Vengerik, “On the hunt for fin7: Pursuing an enigmatic and evasive global crimi- nal operation.” https://www .fireeye.com/blog/threat-research/2018/08/ fin7-pursuing-an-enigmatic-and-evasive-global-criminal- operation.html, August 2018. Acc...
2018
-
[79]
Apt40: Examining a china-nexus espionage actor
F. Plan, N. Fraser, J. O’Leary, V . Cannon, and B. Read, “Apt40: Examining a china-nexus espionage actor.” https: //www.fireeye.com/blog/threat-research/2019/03/apt40-examining- a-china-nexus-espionage-actor .html, March 2019. Accessed: 2019- 05-04
2019
-
[80]
Suspected chinese cyber espionage group (temp.periscope) targeting u.s. engineering and maritime industries
F. Lab, “Suspected chinese cyber espionage group (temp.periscope) targeting u.s. engineering and maritime industries.” https: //www.fireeye.com/blog/threat-research/2018/03/suspected-chinese- espionage-group-targeting-maritime-and- engineering-industries.html, March 2018. Acce...
2018
-
[81]
The msnmm campaigns the earliest naikon APT campaigns,
K. Baumgartner and M. Golovkin, “The msnmm campaigns the earliest naikon APT campaigns,” May 2015
2015
-
[82]
Camerashy closing the aperture on china’s unit 78020,
T. Inc. and D. G. Inc, “Camerashy closing the aperture on china’s unit 78020,” 2015. Accessed: 2019-01-25
2015
-
[83]
Untangling the patchwork cyberespionage group,
D. Lunghi, J. Horejsi, and C. Pernet, “Untangling the patchwork cyberespionage group,” October 2018
2018
-
[84]
Patchwork APT group targets us think tanks
M. Meltzer, S. Koessel, and S. Adair, “Patchwork APT group targets us think tanks.” https://www.volexity.com/blog/2018/06/07/patchwork- apt-group-targets-us-think-tanks/, June 2018. Accessed: 2019-04-02
2018
-
[85]
N. G. Andy Settle and A. Toro, Monsoon – analysis of an APT campaign espionage and data loss under the cover of current affairs , vol. 1. Raytheon - Forcepoint Security Labs, September 2016
2016
-
[86]
F.-S. L. S. Response, Blackenergy and Quedagh. F-Secure, 2014
2014
-
[87]
Research and A
G. Research and A. Team, The ProjectSauron APT. Technical analysis. Kaspersky, August 2016
2016
-
[88]
Backdoor.remsec indicators of compromise,
S. S. Response, “Backdoor.remsec indicators of compromise,” August 2016. 26
2016
-
[89]
S. S. Response, Regin: Top-tier espionage tool enables stealthy surveil- lance. Symantec, Auguest 2014
2014
-
[90]
Research and A
G. Research and A. Team, Cloud Atlas: RedOctober APT is back in style. Kaspersky, December 2014. Accessed: 2019-05-04
2014
-
[91]
Research and A
G. Research and A. Team, Red October” Diplomatic Cyber Attacks Investigation. Kaspersky, January 2013. Accessed: 2019-05-04
2013
-
[92]
Research and A
G. Research and A. Team, Red October” – Part Two, the Modules . Kaspersky, January 2013. Accessed: 2019-05-04
2013
-
[93]
Puttering into the future
J. Gross and J. Walter, “Puttering into the future. . . .” https: //threatvector.cylance.com/en_us/home/puttering-into-the-future .html, January 2016. Accessed: 2019-04-23
2016
-
[94]
Decoding network data from a gh0st rat variant
N. Pantazopoulos, “Decoding network data from a gh0st rat variant.” https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/ 2018/april/decoding-network-data-from-a-gh0st-rat-variant/, April
2018
-
[95]
New wekby attacks use dns requests as command and control mechanism
J. Grunzweig, M. Scott, and B. Lee, “New wekby attacks use dns requests as command and control mechanism.” https://unit42.paloaltonetworks.com/unit42-new-wekby-attacks- use-dns-requests-as-command- and-control-mechanism/, September 2014. Accessed: 2019-04-14
2014
-
[96]
Emissary panda – a potential new malicious tool
N. Group, “Emissary panda – a potential new malicious tool.” https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/ 2018/may/emissary-panda-a-potential-new-malicious-tool/, May
2018
-
[97]
Apt29 domain fronting with tor
M. Dunwoody, “Apt29 domain fronting with tor.” https://www.fireeye.com/blog/threat-research/2017/03/ apt29_domain_frontin.html. Accessed: 2019-04-14
2017
-
[98]
Oceanlotus blossoms: Mass digital surveillance and attacks targeting asean, asian nations, the me- dia, human rights groups, and civil society
D. Lassalle, S. Koessel, and S. Adair, “Oceanlotus blossoms: Mass digital surveillance and attacks targeting asean, asian nations, the me- dia, human rights groups, and civil society.” https://www.volexity.com/ blog/2017/11/06/oceanlotus-blossoms-mass-digital-surveillance-and-...
2017
-
[99]
Oceanlotus old techniques, new backdoor,
ESET, “Oceanlotus old techniques, new backdoor,” March 2018
2018
-
[100]
Accessed: 2019-04-23
2019
-
[101]
Oilrig malware campaign up- dates toolset and expands targets
J. Grunzweig and R. Falcone, “Oilrig malware campaign up- dates toolset and expands targets.” https://unit42.paloaltonetworks.com/ unit42-oilrig-malware-campaign-updates-toolset-and- expands-targets/. Accessed: 2019-04-21
2019
-
[102]
Magic hound campaign attacks saudi targets
B. Lee and R. Falcone, “Magic hound campaign attacks saudi targets.” https://unit42.paloaltonetworks.com/unit42-magic-hound-campaign- attacks-saudi-targets/, February 2017. Accessed: 2019-04-23
2017
-
[103]
Loaders and installers and uninstallers report,
Novetta, “Loaders and installers and uninstallers report,” August 2017
2017
-
[104]
Palo Alto - Unit 42. OilReg
“Palo Alto - Unit 42. OilReg.” https://pan-unit42 .github.io/ playbook_viewer/. Accessed: April 2019
2019
-
[105]
Secrets of cobalt: How cobalt hackers bypass your defenses
V . Matveena, “Secrets of cobalt: How cobalt hackers bypass your defenses.” https://www .group-ib.com/blog/cobalt, August 2017. Ac- cessed: 2019-04-05
2017
-
[106]
S. R. A. I. Team, Dragonfly: Western energy sector targeted by sophisticated attack group. Symantec, October 2017. Accessed: 2019- 04-09
2017
-
[107]
US-CERT at Department of Homeland Security. Russian govern- ment cyber activity targeting energy and other critical infrastructure sectors
“US-CERT at Department of Homeland Security. Russian govern- ment cyber activity targeting energy and other critical infrastructure sectors.” https://www.us-cert.gov/ncas/alerts/TA18-074A, March 2018. Accessed: 2019-04-09
2018
-
[108]
Lazarus resurfaces, targets global banks and bitcoin users
R. Sherstobitoff, “Lazarus resurfaces, targets global banks and bitcoin users.” https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/ lazarus-resurfaces-targets-global-banks-bitcoin-users/, Feb 2018. Ac- cessed: 2019-04-08
2018
-
[109]
Nanhaishu rating the south china sea,
F.-S. L. Threat Intelligence, “Nanhaishu rating the south china sea,” July 2016
2016
-
[110]
Unveiling patchwork – the copy-paste apt: A targeted at- tack caught with cyber deception
C. Inc., “Unveiling patchwork – the copy-paste apt: A targeted at- tack caught with cyber deception.” https://cymmetria .com/research/ patchwork-targeted-attack/, 2016. Accessed: 2019-04-02
2016
-
[111]
Lab, The regin platform nation-state ownage of gsm networks
K. Lab, The regin platform nation-state ownage of gsm networks . Kaspersky, November 2014
2014
-
[112]
Behind the carbanak backdoor
J. T. Bennett and B. Vengerik, “Behind the carbanak backdoor.” https://www.fireeye.com/blog/threat-research/2017/06/behind-the- carbanak-backdoor.html, June 2017. Accessed: 2019-05-01
2017
-
[113]
A bigram based real time dns tunnel detection approach,
C. Qi, X. Chen, C. Xu, J. Shi, and P. Liu, “A bigram based real time dns tunnel detection approach,” Procedia Computer Science , vol. 17, pp. 852–860, 2013
2013
-
[114]
A comprehensive measurement study of domain generating malware,
D. Plohmann, K. Yakdan, M. Klatt, J. Bader, and E. Gerhards-Padilla, “A comprehensive measurement study of domain generating malware,” in 25th USENIX Security Symposium (USENIX Security 16) , pp. 263– 278, 2016
2016
-
[115]
A taxonomy of domain-generation algorithms,
A. K. Sood and S. Zeadally, “A taxonomy of domain-generation algorithms,” IEEE Security & Privacy , vol. 14, no. 4, pp. 46–53, 2016
2016
-
[116]
Detecting DNS tunnels using character frequency analysis,
K. Born and D. Gustafson, “Detecting DNS tunnels using character frequency analysis,” arXiv preprint arXiv:1004.4358 , 2010
2010 arXiv
-
[117]
Blocking- resistant communication through domain fronting.,
D. Fifield, C. Lan, R. Hynes, P. Wegmann, and V . Paxson, “Blocking- resistant communication through domain fronting.,” Proceedings on Privacy Enhancing Technologies, vol. 2015, no. 2, pp. 46–64, 2015
2015
-
[118]
Brazking android malware upgraded and targeting brazil- ian banks
S. Tavor, “Brazking android malware upgraded and targeting brazil- ian banks.” https://securityintelligence .com/posts/brazking-android- malware-upgraded-targeting-brazilian-banks/. 2021-07-17
2021
-
[119]
Weekly threat briefs
F. T. Intelligence, “Weekly threat briefs.” https://www .fortiguard.com/ resources/threat-brief/2018/06/08/fortiguard-threat-intelligence-brief- june-08-2018. 2018-06-08
2018
-
[120]
Stealthy domain generation algorithms,
Y . Fu, L. Yu, O. Hambolu, I. Ozcelik, B. Husain, J. Sun, K. Sapra, D. Du, C. T. Beasley, and R. R. Brooks, “Stealthy domain generation algorithms,” IEEE Transactions on Information Forensics and Security, vol. 12, no. 6, pp. 1430–1443, 2017
2017
-
[121]
Okrum and ketrican: an overview of recent ke3chang group activity,
E. Research, “Okrum and ketrican: an overview of recent ke3chang group activity,” December 2017. Accessed: 2019-07-01
2017
-
[122]
Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor
Mandiant, “Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor.” https://support .solarwinds.com/SuccessCenter/s/article/ Orion-Improvement-Program?language=en_US. 2022-07-01
2022
-
[123]
Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor
Mandiant, “Highly evasive attacker leverages solarwinds supply chain to compromise multiple global victims with sunburst backdoor.” https://www.mandiant.com/resources/blog/evasive-attacker-leverages- solarwinds-supply-chain-compromises-with-sunburst-backdoor/. 2022-05-10
2022
-
[124]
Malware analysis report- 10135536-b
US-CERT, “Malware analysis report- 10135536-b.” https: //www.cisa.gov/sites/default/files/publications/MAR-10135536- B_WHITE.PDF. 2017-11-13
2017
-
[125]
Evolution of attacks on cisco ios devices
G. Holmes, “Evolution of attacks on cisco ios devices.” https: //blogs.cisco.com/security/evolution-of-attacks-on-cisco-ios-devices. 2015-10-08
2015
-
[126]
Remcos malware information
TrendMicro, “Remcos malware information.” https: //success.trendmicro.com/dcx/s/solution/1123281-remcos-malware- information?language=en_US&sfdcIFrameOrigin=null. 2019-12-30
2019
-
[127]
E ARLYCROW github repository
“E ARLYCROW github repository.” https://github .com/ICL-ml4csec/ EarlyCrowAPT. 27
-
[128]
Does this look infected? a summary of APT41 targeting U.S. state governments
Rufus Brown, Van Ta, and J. Wolfram, “Does this look infected? a summary of APT41 targeting U.S. state governments.” https:// www.mandiant.com/resources/blog/apt41-us-state-governments. Ac- cessed: 2023-06-29
2023
-
[2018]
Accessed: 2019-04-18
2019
Reviewed August 7, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.