Pith. sign in

Paper Citation Record · LEDGER

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures

As of 13 August 2026, this Paper Citation Record lists 100 of 129 outbound references and 1 inbound Pith citation observation for arXiv:2502.08830.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2502.08830 v1

Coverage vector

measured 100 of 129 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-07T23:35:22.985699Z

measured 101 of 101 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-13T06:32:02.005865+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-05T10:43:07.700563Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-10T05:30:23.456663Z

Reference resolution

100 of 129 outbound references displayed

  • verified exact1
  • verified fuzzy46
  • unresolved52
  • parse uncertain1
  • malformed identifier0
  • metadata mismatch0

External citation measurements

0
pith, observed 2026-08-10T05:30:23.456663Z

Outbound references

Observation 9c57aa00-ad48-4f80-856f-116966edf673 · outbound

This paper cites Computer security incident handling guide,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Computer security incident handling guide,

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.646244Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.646244Z digest=sha256:ea2a622979a6c4768c0b1aa1c4a55ab1a25547676fe4e5d2726a52ef4fcaf185

Observation f6fbc5fa-2ece-44eb-8ba9-55bd2605fe50 · outbound

This paper cites Advanced persistent threats and how to monitor and deter them,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Advanced persistent threats and how to monitor and deter them,

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.649796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.649796Z digest=sha256:4c59fe89b95333a5884eff19711bf1c38dbd8c1d6ebb961faf8e2afbc4677a8b

Observation 8b8f1ff0-7567-4676-917d-7989628b78f0 · outbound

This paper cites APT 1: Exposing one of china’s cyber espionage units,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures APT 1: Exposing one of china’s cyber espionage units,

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.652801Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.652801Z digest=sha256:975ae554d0e7038e36842eb5c2c34eb0707bb4ed801750962750abc5f9b9f349

Observation dbf8544b-0f63-440d-98c1-6d0eaa8adb9f · outbound

This paper cites E ARLYCROW: Detecting APT malware command and control over HTTP(S) using contextual summaries,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures E ARLYCROW: Detecting APT malware command and control over HTTP(S) using contextual summaries,

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.656937Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.656937Z digest=sha256:4159023560eb49c8b2621509347626f7271b574b423a343fea90cb02e9c3dd37

Observation 44dd7f4e-07d4-4903-810e-bc2432c9d18a · outbound

This paper cites Apt beaconing detection: A systematic review,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Apt beaconing detection: A systematic review,

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.660856Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.660856Z digest=sha256:88abcc3b96e3e5016e6cf086882993280443a2171833bddc21fadfefca2c510d

Observation 26d74dcc-d828-4301-bb7a-cc34d61077ca · outbound

This paper cites Survey of publicly available reports on advanced persistent threat actors,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Survey of publicly available reports on advanced persistent threat actors,

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.664769Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.664769Z digest=sha256:86ae0ab3724949bee1b7c853de94fc2e35a75c302feccc2cb4911883e0bd31cb

Observation 2e4651e9-8634-4e92-9a51-69ec776d23c6 · outbound

This paper cites Apt datasets and attack modeling for automated detection methods: A review,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Apt datasets and attack modeling for automated detection methods: A review,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.669497Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.669497Z digest=sha256:c5a1e6ccd5eea43d18e464400534ea71d426a6f850410b7ffb6c9828901d256f

Observation ca5b8936-1f69-475a-a019-3688c8e476bf · outbound

This paper cites A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.673739Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.673739Z digest=sha256:302764a170faa07a6500a54cb6d6e7fe0d60b263c15375af580d7b9c5f50ed06

Observation d4d77364-3308-4f12-a098-17f25154762a · outbound

This paper cites Finding cyber threats with att&ck™-based analytics,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Finding cyber threats with att&ck™-based analytics,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.677087Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.677087Z digest=sha256:19674f64c8a667bc325a1e2c4bf3d33b6bca4fcb6531ebc87576771082722777

Observation 733c086f-0cae-4243-9f21-f4f815628219 · outbound

This paper cites APT 28 under the scope a journey into exfiltrating intelligence and government information,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures APT 28 under the scope a journey into exfiltrating intelligence and government information,

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.680544Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.680544Z digest=sha256:ac7e1df30232da5de39e91974919a1636a2163249c0165e99456ba942826ab88

Observation 1b7632a8-d432-4094-b1bd-b123a2512059 · outbound

This paper cites Sednit update: How fancy bear spent the year.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Sednit update: How fancy bear spent the year

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.684073Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.684073Z digest=sha256:f05a2aff7de4ead53103a718a95c6e9eb26f588923bfc240ab55d710c7111771

Observation 457c0c5b-0ff9-4da0-9399-49f4aa47b490 · outbound

This paper cites Operation cobalt kitty: A large-scale APT in asia carried out by the oceanlotus group.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Operation cobalt kitty: A large-scale APT in asia carried out by the oceanlotus group

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.687388Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.687388Z digest=sha256:25e907d950d4721f186cca8dbcc684429b76306c5882a2ecbdcd44ab954a7836

Observation 559bef54-cdee-4aca-b157-c6b0d68bbb82 · outbound

This paper cites Operation cobalt kitty cybereason labs analysis,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Operation cobalt kitty cybereason labs analysis,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.690823Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.690823Z digest=sha256:c1a206d58e918b95ee07458f1d3e79875889eaa13276ebec9187afda609ed85f

Observation 59a11d99-26d9-47e5-bfd7-58f266b8aa06 · outbound

This paper cites The dukes 7 years of russian cyberespionage,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures The dukes 7 years of russian cyberespionage,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.694189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.694189Z digest=sha256:eb50595feab080c52c0105c46666487b243a2d9df7d928c886a4b61c083401f6

Observation 7cccd95a-36bc-4c61-b953-b48d8ecafb74 · outbound

This paper cites Bears in the midst: Intrusion into the democratic national committee.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Bears in the midst: Intrusion into the democratic national committee

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.697559Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.697559Z digest=sha256:e361a4b0e8d26c89c937c1e61bb9943bf579743364cedc6cd7f60c5935bb6b4b

Observation b665c94f-c363-42e4-b70e-10d3f00cb9bb · outbound

This paper cites Buckeye cyberespionage group shifts gaze from us to hong kong.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Buckeye cyberespionage group shifts gaze from us to hong kong

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.700856Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.700856Z digest=sha256:dc70c6d68dc8160bfe1b030e5bb328d277989a1b60641def78dcc2d7b3f8383f

Observation 550d7160-e059-4e31-b673-3d37c21a8412 · outbound

This paper cites Where you at?: Indicators of lateral movement using at.exe on windows 7 systems.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Where you at?: Indicators of lateral movement using at.exe on windows 7 systems

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.707896Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.707896Z digest=sha256:6adf5c258d7c01e9c05bb64016a769f59ae496f3cfbb5f5159188c77212bfd6e

Observation 9dc5709d-3ca2-4ddd-b9ee-0f010b085555 · outbound

This paper cites Evasive maneuvers by the wekby group with custom rop-packing and dns covert channels.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Evasive maneuvers by the wekby group with custom rop-packing and dns covert channels

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.711390Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.711390Z digest=sha256:7b4334aac4fe900320437d3518f5bf7ecffcd452be52ed19c9b751ed3b0eadc9

Observation 5f65e229-6482-45dc-be57-e81d8151b3a0 · outbound

This paper cites APT 37 (reaper) the overlooked north korean actor, special report,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures APT 37 (reaper) the overlooked north korean actor, special report,

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.714825Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.714825Z digest=sha256:ee607ca5bbb8f9b13f3cfb4fc5e0525c4b756a5c89ee99b172be57b2dad6aa9c

Observation 0f873496-590a-49e6-b8b6-64fe98841de2 · outbound

This paper cites A taxonomy of botnet behavior, detection, and defense,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures A taxonomy of botnet behavior, detection, and defense,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.718563Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.718563Z digest=sha256:5cc970bced924c6dd8ce947f4d0677ba92d1c2ae0b8934204b77dc8d1fa30178

Observation 3735ab84-30c3-4d12-8b9c-46940332a6fd · outbound

This paper cites Detecting APT malware infections based on malicious dns and traffic analysis,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Detecting APT malware infections based on malicious dns and traffic analysis,

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.722240Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.722240Z digest=sha256:4abbcbeb764596e75207b0d6b7546eb772b3cecb59ec3774049e7a79bdeb2a5e

Observation bd0f8f98-191a-4233-8946-79a680f90ec6 · outbound

This paper cites Botnet communication patterns,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Botnet communication patterns,

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.725929Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.725929Z digest=sha256:d9227b8040bbd4fc02b1066b1d66abae3021451ec403221abec90d359edb9205

Observation 1670e588-ecb1-4bcd-b389-21870d3c01a7 · outbound

This paper cites Advanced persistent threats: Behind the scenes,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Advanced persistent threats: Behind the scenes,

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.729365Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.729365Z digest=sha256:c67bec091c423f39b1635390b87f718de88c5518a3e3566266f28624d1150daa

Observation 93133b80-0bbc-4c5a-a16f-0e0f70e84081 · outbound

This paper cites A study on advanced persistent threats,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures A study on advanced persistent threats,

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.733120Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.733120Z digest=sha256:42281771119834eecbd6310c38155988b1ba619c473411ce8a1a4050af54a326

Observation 9a5e5e43-6110-41df-8798-b63fc1c41146 · outbound

This paper cites H AWK-E YE: Holistic detection of APT command and control domains,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures H AWK-E YE: Holistic detection of APT command and control domains,

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.736564Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.736564Z digest=sha256:e5cb8b1126778d4c0cc41d13067390cdce74dfe182d522e8f1806bee162f7cc6

Observation 47d5f66f-b919-42db-b644-5d43cb3395ed · outbound

This paper cites Intelligence- driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Intelligence- driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.740118Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.740118Z digest=sha256:50d8503c110e8d35f6bab575cf61465ba7dd10493a761376d86749674f7d9aa8

Observation b4a13848-5953-464f-b785-54af61e73208 · outbound

This paper cites Sys- tems for detecting advanced persistent threats: A development roadmap using intelligent data analysis,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Sys- tems for detecting advanced persistent threats: A development roadmap using intelligent data analysis,

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.743064Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.743064Z digest=sha256:0e0476694a8b52a598a4351111f89e136ca76bfffe73bae66d6cff93b8e766d6

Observation 2090bc96-4e18-4d54-a396-a3d4ff6a8375 · outbound

This paper cites A context-based detection framework for advanced persistent threats,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures A context-based detection framework for advanced persistent threats,

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.745923Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.745923Z digest=sha256:eda47428f7d4ae57d062cad00f3962d10313609d5ba1ae61ea7b7ba5302f6e2b

Observation e46e959e-cd60-447f-a63f-e819d33cfbea · outbound

This paper cites Technical aspects of cyber kill chain,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Technical aspects of cyber kill chain,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.748658Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.748658Z digest=sha256:2e9f5a0f0fee8b344a33eeb188545032effec0dff357aa9ed634cc9c93efb688

Observation ada5b21f-f2eb-4e27-92d5-f80e058aa7f1 · outbound

This paper cites A cyber kill chain based taxonomy of banking trojans for evolutionary computational intelligence,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures A cyber kill chain based taxonomy of banking trojans for evolutionary computational intelligence,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.751572Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.751572Z digest=sha256:521329e77737f5c5c502280b24c4088adf10ad37ef2f4d0bbaaf4b036f06017d

Observation 00d5f55d-5360-484d-843c-85637fa2f2d9 · outbound

This paper cites A markov multi- phase transferable belief model: An application for predicting data exfiltration apts,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures A markov multi- phase transferable belief model: An application for predicting data exfiltration apts,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.754608Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.754608Z digest=sha256:95182120ac733fedf05aed66f05caf2bc24a38c5a07d3514cf24e3e5eed99fb1

Observation c4862444-ee8f-4b4e-be5a-73f610d7e804 · outbound

This paper cites HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows

Reference 32

Resolution
verified exact
local_arxiv, observed 2026-08-07T23:35:23.262031Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.757252Z digest=sha256:f2f5faebb52f36bc1f5c165cb5fe4b152a7d8782d0edcb05007a7658c6ae0980

Observation a2cc9170-4c33-457d-b7d6-746e6008df24 · outbound

This paper cites Situation awareness of multistage cyber attacks by semantic event fusion,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Situation awareness of multistage cyber attacks by semantic event fusion,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.760498Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.760498Z digest=sha256:ce253c4d07f50eca5f42d84d4ce4d896334cb8465e97b5bf1035d651f300bbef

Observation 5c7227f8-b9f5-4956-b997-4d339ced4343 · outbound

This paper cites Dark matter: Uncovering the darkcomet rat ecosystem,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Dark matter: Uncovering the darkcomet rat ecosystem,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.763445Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.763445Z digest=sha256:2b3911fe5c338a5432c76c1f0d9d4c658ab042500fe7cee4745b0b965d14c9c1

Observation 088b0357-b5fb-463c-bcc9-8e04a8609b34 · outbound

This paper cites Schrödinger’s RAT: Profiling the stakeholders in the remote access trojan ecosystem,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Schrödinger’s RAT: Profiling the stakeholders in the remote access trojan ecosystem,

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.766228Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.766228Z digest=sha256:f244deb013b8a050d286cda3a28d064a5af94b1319909ff82bfe7df1329d09fd

Observation e9283908-d2d6-4fea-9648-5569fbdb7deb · outbound

This paper cites To catch a ratter: Monitoring the behavior of amateur darkcomet rat operators in the wild,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures To catch a ratter: Monitoring the behavior of amateur darkcomet rat operators in the wild,

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.769772Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.769772Z digest=sha256:f4aec38176df78bab85a55fbef2ba862946e0e83ce06c62d67729d6e07bb5031

Observation b9c6c9eb-cd12-4c52-9248-fc2d6f6b9012 · outbound

This paper cites Fin7.5: the infamous cybercrime rig “fin7.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Fin7.5: the infamous cybercrime rig “fin7

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.773305Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.773305Z digest=sha256:327299155f379b8cddded944e95daaf4a744fd3c9539b21b4bbf5a5c9627dc79

Observation 6bef525e-c2bb-42aa-8b77-d86bda599683 · outbound

This paper cites The elderwood project,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures The elderwood project,

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.776681Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.776681Z digest=sha256:fdf1b202e932499bac101c8002dd47554c50aa8734308130fe10e521a52aa702

Observation 3d8e3262-c220-487b-a188-6db6bcbc8532 · outbound

This paper cites an unresolved cited work.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Unresolved cited work

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.779947Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.779947Z digest=sha256:233a84677cc63d5d7c05e49b9f6bbf0affcb20937a1e7b12b4c0f3954c3d4f08

Observation 77f6cbda-f8c6-46e9-aa74-de57a6edfc9d · outbound

This paper cites APT 3 adversary emulation plan,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures APT 3 adversary emulation plan,

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.783373Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.783373Z digest=sha256:14d1f2885a1ac30b427b6ded5f9921a0a0f94533e07088d49ac2d95524b44164

Observation 49ed2836-8205-4338-95db-2011fb6f1163 · outbound

This paper cites Opera- tion double tap.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Opera- tion double tap

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.786811Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.786811Z digest=sha256:7f71ef614c109c0ba28422dd71f5f04ed58bde0e5d6a78edfad6e9a6cf0fdf39

Observation 96bfe9b6-781c-4f5a-bd9c-8c735eac2470 · outbound

This paper cites Yates, APT 3 Uncovered: The code evolution of Pirpi.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Yates, APT 3 Uncovered: The code evolution of Pirpi

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.790463Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.790463Z digest=sha256:adc3e3ed90e25041db505bf62cbb1e9bdd49ecc54425d6df8a7bbd2c6a764c0e

Observation c7963bd8-b53d-4a05-93a8-4311f68bc303 · outbound

This paper cites Operation cloud hopper,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Operation cloud hopper,

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.793979Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.793979Z digest=sha256:7a2b46599a409e0bcb31adc047459e24a6a088c04fabcd096fa21869c61493a1

Observation 88499f63-3d13-4034-8301-66d667d8d828 · outbound

This paper cites Operation cloud hopper technical annex,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Operation cloud hopper technical annex,

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.797392Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.797392Z digest=sha256:d52e6809538a54287520fe048e9bcb1c8775953c180f6b43454dc031e6e407da

Observation f7791d48-2da0-4b79-aec7-3e8ee3cd59f7 · outbound

This paper cites Darwin’s favorite APT group.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Darwin’s favorite APT group

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.800795Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.800795Z digest=sha256:9cd43b08c0dcea757dcb5286971804395e2a532b3976a07177458056fd51d6dc

Observation 889bef84-fd73-444b-90c6-b848f82f9e60 · outbound

This paper cites Operation “ke3chang.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Operation “ke3chang

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.804162Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.804162Z digest=sha256:5dfa513cd408bf57bc2db57282ed2c68da93433f67a9d9ecd2c78b389e9e5233

Observation 96eac31c-9585-4fca-b411-6de730f30820 · outbound

This paper cites Apt15 is alive and strong: An analysis of royalcli and royaldns.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Apt15 is alive and strong: An analysis of royalcli and royaldns

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.807430Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.807430Z digest=sha256:46254300af1657a8b600647dc9f5355f1e54f8b611d62fcd70e57f32ba4ba2cb

Observation edda471e-64f2-44ff-a4d0-04db47b7f20d · outbound

This paper cites The eps awakens - part 2.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures The eps awakens - part 2

Reference 48

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.810781Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.810781Z digest=sha256:3f81badbc4fa5a37c3c6c838e6d18de72f66a708b4d84778c54d4b4e600357a3

Observation 089facba-2eed-4b2e-95b3-c7e5ab59c5da · outbound

This paper cites The eps awakens.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures The eps awakens

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T23:35:22.813955Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.813955Z digest=sha256:1c7f2374922848ec3fa1031fd083020a769bbf4421d3572100c47f556cc9612f

Observation 0162fc42-0a6d-4dd1-b79e-2f505ae2ecda · outbound

This paper cites Hiding in plain sight: Fireeye and microsoft expose,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Hiding in plain sight: Fireeye and microsoft expose,

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:24.061542Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.817580Z digest=sha256:cbdafadbbf37653835d6875d8c0284048c83af6a2e23426c592933cb550aeb42

Observation 500366d1-ec44-4bc3-8ebc-21f2342a6558 · outbound

This paper cites New attacks linked to c0d0so0 group.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures New attacks linked to c0d0so0 group

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:24.051434Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.820883Z digest=sha256:49e848c392bf8ac640a0bd98e6aeb6f4a56c17aac9ddd8c95750fa95a909d613

Observation 46aa87c4-92af-4889-860c-c66bf966c382 · outbound

This paper cites Privileges and credentials: Phished at the request of counsel.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Privileges and credentials: Phished at the request of counsel

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:24.041928Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.823961Z digest=sha256:bc29e286945dc984ffeb10c176187c7f46235d9bc24ca08c58fa2c5da4637c3e

Observation aea56fbd-b22c-4460-a3b5-e49925e0af0f · outbound

This paper cites Threat group 3390 cyberespionage.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Threat group 3390 cyberespionage

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:24.032374Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.827255Z digest=sha256:b4a1a574a59f3f103a9016cca1f0da7c0411ae6bc6b2aef4d0e82b89cd0584d1

Observation fd7412c8-96c1-41cd-ad2d-12edaedd2876 · outbound

This paper cites Bronze union cyberespionage persists despite dis- closures.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Bronze union cyberespionage persists despite dis- closures

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:24.022572Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.830548Z digest=sha256:29052798720a600cc4f888dbf57dfb94e55798da324d9a5762f5867ec6b31858

Observation 14f3f2e3-b2de-4a70-8385-fef0e3fcf423 · outbound

This paper cites Luckymouse hits national data center to organize country- level waterholing campaign.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Luckymouse hits national data center to organize country- level waterholing campaign

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:24.012610Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.837202Z digest=sha256:1fe0f60a7f39438b0dc56a4e0d39528e1c86faa1bf41ffa5acf375d4e0cb9c4c

Observation b80f38af-a5c5-4f02-8a71-2d6c0d91256e · outbound

This paper cites APT 28: A window into russia’s cyber espionage operations and a special report,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures APT 28: A window into russia’s cyber espionage operations and a special report,

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:24.002647Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.840452Z digest=sha256:80375d488b560487af61903b21f3b1fddddfabbb38352e7f7d850f1d92711d04

Observation bb1b8239-767e-4843-8643-4592ce52f6b1 · outbound

This paper cites Anthe, P.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Anthe, P

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.992106Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.843999Z digest=sha256:83d6acac339a780728f06b37bb253062239c02e68dc7501ccb9cd910542bae7b

Observation 8b194009-b595-480b-97d3-77819e8de76d · outbound

This paper cites APT 28: New espionage operations target mili- tary and government organizations.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures APT 28: New espionage operations target mili- tary and government organizations

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.982385Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.847334Z digest=sha256:532d4b3df9d5b9d857cf8980e4ab45455477ad451d5053558d905c4bff772b74

Observation 1eed2df5-ef85-45b2-aef1-5299c4cf42a6 · outbound

This paper cites Lab, En Route with Sednit Part 2: Observing the Comings and Goings, vol.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Lab, En Route with Sednit Part 2: Observing the Comings and Goings, vol

Reference 59

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.972106Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.850748Z digest=sha256:7db27af7ab607d97b6c902ee979cc5577a15bbf49045b56047cd4c60b8d025df

Observation e72371ff-25c7-471d-91bd-08deacfa8704 · outbound

This paper cites Grizzly steppe – russian malicious cyber activity,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Grizzly steppe – russian malicious cyber activity,

Reference 60

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.962776Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.854093Z digest=sha256:63f827695e7a588c2fd0180119b29cc1ecc57f136c0c34c7238b37a459025720

Observation 11758e14-513e-4f5e-915f-e4de340eb31a · outbound

This paper cites Not so cozy: An uncomfortable examination of a suspected apt29 phishing campaign.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Not so cozy: An uncomfortable examination of a suspected apt29 phishing campaign

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.953303Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.857376Z digest=sha256:a314a9bab353c2546586c7585d61e0a789f431cc438667da466140671ce48182

Observation 2fa29983-8a0a-41e3-967a-676bdc3d8609 · outbound

This paper cites Labs, APT 30 and the mechanics of a long-running cyber espionage operation.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Labs, APT 30 and the mechanics of a long-running cyber espionage operation

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.943399Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.860736Z digest=sha256:e8a4f7ea18aeba37723f64c44bec8f82049cbe218cedf0f0a455b8a82dca98d7

Observation e6a66b9e-d591-4415-8621-6d2c6b4b5cfe · outbound

This paper cites Fake or fake: Keeping up with oceanlotus decoys.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Fake or fake: Keeping up with oceanlotus decoys

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.933158Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.864169Z digest=sha256:088108d9e296cbfc4c628d3d321c1881625a6920428938a6a89228cc8265486c

Observation b7f330ac-5d55-4299-a455-80e37500703c · outbound

This paper cites Cyber espionage is alive and well: APT 32 and the threat to global corporations.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Cyber espionage is alive and well: APT 32 and the threat to global corporations

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.922770Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.867017Z digest=sha256:44ef30ef98254e6945a8c07d478067136454a98bc5aedfbef9d4af34f14ad907

Observation a0ae1323-cb1c-4dbc-b5fe-425fd6ef6b24 · outbound

This paper cites Insights into iranian cyber espionage: APT 33 targets aerospace and energy sectors and has ties to destructive malware.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Insights into iranian cyber espionage: APT 33 targets aerospace and energy sectors and has ties to destructive malware

Reference 65

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.912076Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.870160Z digest=sha256:2576433f87f81602e73096aae9363ccf2eb27c6f310d08a68a9decaef3cbe9fc

Observation 61e45b20-2335-43a6-8af8-3bba8a6314d9 · outbound

This paper cites Elfin: Relentless espionage group targets multiple organizations in saudi arabia and u.s.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Elfin: Relentless espionage group targets multiple organizations in saudi arabia and u.s

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.901734Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.872986Z digest=sha256:3f7c7a2e3703f0f9bfefeb0ff9127c164f0649a34f2b27eacba627d8d9fc24dc

Observation 0a8f6610-9129-441f-9996-f2c81d277cbc · outbound

This paper cites Overruled: Containing a potentially destructive adversary.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Overruled: Containing a potentially destructive adversary

Reference 67

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.891613Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.875829Z digest=sha256:625faacca78d707bfec03f24dda378f32a5493297993d303cf086fa8b0e78187

Observation b4bb269f-b664-4df3-a1fd-2d6697f220c8 · outbound

This paper cites New targeted attack in the middle east by apt34, a suspected iranian threat group, using cve-2017-11882 ex- ploit.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures New targeted attack in the middle east by apt34, a suspected iranian threat group, using cve-2017-11882 ex- ploit

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.881723Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.878540Z digest=sha256:f15f7d73e1d56d7beffb359093ec0b440235d2baa67df9f3539bbd48f3985ad7

Observation 8e3fe395-ecda-46bc-8daa-2b70cc747902 · outbound

This paper cites Oilrig uses ismdoor variant; possibly linked to greenbug threat group.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Oilrig uses ismdoor variant; possibly linked to greenbug threat group

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.871471Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.881175Z digest=sha256:1b8c08b65e9778a17606ff559f35172138477c96edada0da96cc6a5a458a02e4

Observation 9b6c96bb-146b-4133-ae9d-b5fdaa4c0409 · outbound

This paper cites Rocket kitten: A campaign with 9 lives,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Rocket kitten: A campaign with 9 lives,

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.861016Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.883773Z digest=sha256:e1509d1d5bc938bb8b404b959ac1ac35de012a08d5f9db2cedfa241f566df309

Observation 5772b97e-7a4f-4946-94b5-84d52341687a · outbound

This paper cites China-based cyber threat group uses drop- box for malware communications and targets hong kong media outlets.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures China-based cyber threat group uses drop- box for malware communications and targets hong kong media outlets

Reference 71

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.850743Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.886414Z digest=sha256:564c6c1f111c564ae7007d63f3ba5867adf6c32e970a566b4924ee39e488b34b

Observation 87db63c7-14e6-495d-baa7-f2634fef91f1 · outbound

This paper cites Operation blockbuster: Unraveling the long thread of the sony attack,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Operation blockbuster: Unraveling the long thread of the sony attack,

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.840073Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.889071Z digest=sha256:d16a9c6dc0fb87bba3b7c0657f4d8ffe641cf5e9a3cd80556890a33ab8c1beb4

Observation 6da56f66-73b6-431e-acbe-0412ec9bb551 · outbound

This paper cites Operation blockbuster: Remote administration tools and content staging malware report,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Operation blockbuster: Remote administration tools and content staging malware report,

Reference 73

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.828861Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.891980Z digest=sha256:a6493e694e98e19a29021f43b7ccbacc351115f9acb9e3cab71deb92641c7c4e

Observation c8b69a9a-06f0-4ab4-818e-953b481e1133 · outbound

This paper cites Colbat snatch,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Colbat snatch,

Reference 74

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.818659Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.895278Z digest=sha256:c819b21917ca9a12250694398b9d0ccdd80d59935c0ffb61062120ad49ff1a2a

Observation 2489ca3f-ae9b-453c-a730-ff681d7a3a09 · outbound

This paper cites Multiple cobalt personality disorder.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Multiple cobalt personality disorder

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.808745Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.898577Z digest=sha256:6fcacd3fd2d4162e6ec5bd99d5bbebe9d6446565f1e0b49930045b18f00f3265

Observation 26d72547-846e-4908-af9b-09d501c1d25a · outbound

This paper cites an unresolved cited work.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Unresolved cited work

Reference 76

Resolution
unresolved
raw_fallback, observed 2026-08-07T23:35:23.798555Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.901815Z digest=sha256:2ed645b90743f9d218005e821c3a8a33adc7b97d21dbd5165abbdbe4ec98c3b2

Observation 5d7598b6-5354-4284-aa3e-1e0391a0efc2 · outbound

This paper cites Lab, The Duqu 2.0 technical details.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Lab, The Duqu 2.0 technical details

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.788767Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.905135Z digest=sha256:eafead83703591454cbb66c270d2a8d00b5ec05c9584f3c70bd986c375304440

Observation 7435171a-e55f-4d9a-b87b-54c77b0cf040 · outbound

This paper cites On the hunt for fin7: Pursuing an enigmatic and evasive global crimi- nal operation.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures On the hunt for fin7: Pursuing an enigmatic and evasive global crimi- nal operation

Reference 78

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.778828Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.908308Z digest=sha256:53310b510e334a98885b8b80bc6e71b656e19815354c77a423f20bfd31d324af

Observation 57b1a906-7079-4bbb-baa5-2667201d5cf3 · outbound

This paper cites Apt40: Examining a china-nexus espionage actor.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Apt40: Examining a china-nexus espionage actor

Reference 79

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.768727Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.911607Z digest=sha256:8a62c54452dbcc718407b76a3165cbc6e92fb407d11dd8faac2ee35fddd54c01

Observation f5f5250c-67e9-49f2-a93d-184cb4bab181 · outbound

This paper cites Suspected chinese cyber espionage group (temp.periscope) targeting u.s. engineering and maritime industries.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Suspected chinese cyber espionage group (temp.periscope) targeting u.s. engineering and maritime industries

Reference 80

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.758543Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.914940Z digest=sha256:e3e207c08921d1ea0e6b393836bf144b4a34aca506ad83f63d3c6778f26d0b4d

Observation edea8532-ed1a-468b-a6ac-cd8beaef5996 · outbound

This paper cites The msnmm campaigns the earliest naikon APT campaigns,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures The msnmm campaigns the earliest naikon APT campaigns,

Reference 81

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.747946Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.918583Z digest=sha256:5ef6b421baef4749bc4484d90fb10cae7bf985b14c1b293f8b5e3ea04dd072ff

Observation 0204b5d1-df61-4757-89b0-f545db9a2f10 · outbound

This paper cites Camerashy closing the aperture on china’s unit 78020,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Camerashy closing the aperture on china’s unit 78020,

Reference 82

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.736936Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.921971Z digest=sha256:0cc4f8977ef16c5ba4797cecd3b2b6efc2c9aa837fbd32af9f908331a65d6fa2

Observation 39772987-f61e-46dc-8670-e4f75e83ab75 · outbound

This paper cites Untangling the patchwork cyberespionage group,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Untangling the patchwork cyberespionage group,

Reference 83

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.726252Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.925373Z digest=sha256:a16ee245cbf63958838f381cad407e2f742ff10d1e6c6bbbdadd45f9f32c244a

Observation 34281caf-502a-4748-948e-060c7698e179 · outbound

This paper cites Patchwork APT group targets us think tanks.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Patchwork APT group targets us think tanks

Reference 84

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.715621Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.928745Z digest=sha256:ebe46e0a45ea065ec677827ba5be746c3c7205e2394b85e03af38188e20c3d8a

Observation 107b30b3-282e-4ea5-a2b7-a504a43abaec · outbound

This paper cites an unresolved cited work.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Unresolved cited work

Reference 85

Resolution
unresolved
raw_fallback, observed 2026-08-07T23:35:23.705455Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.931939Z digest=sha256:5c1ab6764aa23ef85c33385d2a733179aca4e9b46f32268e43c3c2b1f265e299

Observation 9fc688c2-64c1-4cd2-9f81-8d02d02b44de · outbound

This paper cites an unresolved cited work.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Unresolved cited work

Reference 86

Resolution
unresolved
raw_fallback, observed 2026-08-07T23:35:23.695515Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.935267Z digest=sha256:6cdc7f8343d3776a5d97e7e11a70923423e1aef6ec86e4d7d9ca414411caa5eb

Observation f74b8225-dd93-4d68-b3e7-deaa48ffe059 · outbound

This paper cites Research and A.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Research and A

Reference 87

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.685534Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.938573Z digest=sha256:dd2804a01c4c7ea70beff0ecae520778d2d402f99cd1151a2357126288b04487

Observation ab481c5b-e7b6-434a-adfd-ff3b7d4b4a94 · outbound

This paper cites Backdoor.remsec indicators of compromise,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Backdoor.remsec indicators of compromise,

Reference 88

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.675798Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.942010Z digest=sha256:90ef18c327ae4e7ef4908052add7c625291935c9e37a54b002788479e35fe3be

Observation 2700a7fd-5650-404a-a591-dddfc8a18edc · outbound

This paper cites an unresolved cited work.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Unresolved cited work

Reference 89

Resolution
unresolved
raw_fallback, observed 2026-08-07T23:35:23.665293Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.945800Z digest=sha256:10b19d7cd3cc46be3de58246c7ff61c531d4dcc8a73c369c4c20cc3290d98810

Observation 727c4c86-f6fd-4c8b-8623-b9f66d615f91 · outbound

This paper cites Research and A.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Research and A

Reference 90

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.655165Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.949152Z digest=sha256:13a4b9ec25a1844354383946afeee756b9f317b556f199f45f9ab246c25b1ef3

Observation 59e892a6-cb81-4d24-802e-6542aaad63dc · outbound

This paper cites Research and A.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Research and A

Reference 91

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.645208Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.952630Z digest=sha256:beb5191f9a4aa1f086240ad46a6cd128899b3e30e53f909d0bad95fa2688e8c4

Observation c198da4d-9740-4cb4-b4ff-3aa91ff8b993 · outbound

This paper cites Research and A.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Research and A

Reference 92

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.635008Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.956120Z digest=sha256:f95642d5dc409d8c89c0e2ac63fbcd8f0520c19ac25fb15c0ec61327bdf70b39

Observation cdc5bc10-b304-4028-9bfc-2fba28dc5687 · outbound

This paper cites Puttering into the future.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Puttering into the future

Reference 93

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.625336Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.959287Z digest=sha256:b2002522049911b5d61de9748553aa339a41217e896b916f45dea34a7db1e989

Observation 168c5707-e4a1-4271-b00a-13b51e48ac63 · outbound

This paper cites Decoding network data from a gh0st rat variant.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Decoding network data from a gh0st rat variant

Reference 94

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.615417Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.962440Z digest=sha256:9defe3744bb975077318287f0d4fcf17a5d05ab7697c968621b629981dfdb58c

Observation f8a14192-bc5e-4ae9-8746-77381b450aec · outbound

This paper cites New wekby attacks use dns requests as command and control mechanism.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures New wekby attacks use dns requests as command and control mechanism

Reference 95

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.596492Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.968827Z digest=sha256:aafec5abb42ffc7a766e9bb1c2a13d1eb340c5b0d9c076ca15dd5a1bf704b51e

Observation 62d26c5a-632e-4f66-b3d4-b0027902170a · outbound

This paper cites Emissary panda – a potential new malicious tool.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Emissary panda – a potential new malicious tool

Reference 96

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.586135Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.972334Z digest=sha256:96e191bbc077a5ed70d59c26e87ee9296dc587ef82f5f8c7275f08a49f2c73a7

Observation 628574dd-e1e9-4da6-8ed7-23e747313a5a · outbound

This paper cites Apt29 domain fronting with tor.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Apt29 domain fronting with tor

Reference 97

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.575360Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.978895Z digest=sha256:0b8d8e5d6d2284ed5b7c1ebaca6789136df658c005213524f66bcf163e6ef258

Observation 84fa5327-eb9c-439d-a787-7fa95ea8672a · outbound

This paper cites Oceanlotus blossoms: Mass digital surveillance and attacks targeting asean, asian nations, the me- dia, human rights groups, and civil society.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Oceanlotus blossoms: Mass digital surveillance and attacks targeting asean, asian nations, the me- dia, human rights groups, and civil society

Reference 98

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.563790Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.982363Z digest=sha256:39a794f632c2df2b6bc4ec233916aa60e435004f99d1bbaaf0d7af7a3250dde1

Observation 6e7442a8-efa1-495b-975c-ee41c91c7012 · outbound

This paper cites Oceanlotus old techniques, new backdoor,.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Oceanlotus old techniques, new backdoor,

Reference 99

Resolution
verified fuzzy
raw_fallback, observed 2026-08-07T23:35:23.552338Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-07T23:35:22.985699Z digest=sha256:50f04840c6bde76e6611ce8adb737df20c7d781b779374e953d9fc5a51000579

Observation cb642fd1-b3dc-49e6-a666-061a9c921127 · outbound

This paper cites an unresolved cited work.

Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures Unresolved cited work

Reference 100

Resolution
parse uncertain
no resolver link, observed 2026-08-07T23:35:22.975872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T23:35:22.975872Z digest=sha256:efbfef146ee0a82a577a1284541364e644fb8159620b10d73ebd411164967752

Pith citing papers

Observation f0e1ee45-9e25-4aa5-a5d3-00e07699e6ed · inbound

Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations cites this paper.

Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures

Reference 6

Resolution
verified exact
local_arxiv, observed 2026-08-05T10:43:13.031329Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.

source=pdf_text observed=2026-08-05T10:43:07.700563Z digest=sha256:9823efbff80da8d2fb1c36152045a9f9d4846003e8d0f79e12bda28e51a2dae1