C0001A defensive guide to the Enterprise ATT&CK campaign record C0001, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a highly targeted 2019 campaign whose operators assembled multiple unrelated open-source components.
Open profile →C0002A defensive guide to the Enterprise ATT&CK campaign record C0002, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an espionage campaign reported against oil, energy, and petrochemical companies and related individuals.
Open profile →C0004A defensive guide to the Enterprise ATT&CK campaign record C0004, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a suspected hacker-for-hire espionage campaign reported across multiple industries and regions.
Open profile →C0005A defensive guide to the Enterprise ATT&CK campaign record C0005, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a campaign reported against Colombian government and private-sector organizations, especially energy and metallurgical entities.
Open profile →C0006A defensive guide to the Enterprise ATT&CK campaign record C0006, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2017–2018 campaign against humanitarian-aid and inter-Korean affairs organizations across several countries.
Open profile →C0007A defensive guide to the Enterprise ATT&CK campaign record C0007, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a suspected Chinese espionage campaign reported against government and foreign organizations in Southeast Asia.
Open profile →C0010A defensive guide to the Enterprise ATT&CK campaign record C0010, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed cyber-espionage campaign reported against Israeli shipping, government, aviation, energy, and healthcare organizations.
Open profile →C0011A defensive guide to the Enterprise ATT&CK campaign record C0011, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed suspected espionage campaign reported against university and college students in India.
Open profile →C0012A defensive guide to the Enterprise ATT&CK campaign record C0012, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a cyber-espionage campaign against technology and manufacturing companies reported since at least 2019.
Open profile →C0013A defensive guide to the Enterprise ATT&CK campaign record C0013, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a global espionage campaign reported against nuclear, defense, government, energy, and financial organizations.
Open profile →C0014A defensive guide to the Enterprise ATT&CK campaign record C0014, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a global cyber-espionage campaign reported against governments, managed-service providers, and many industries.
Open profile →C0015A defensive guide to the Enterprise ATT&CK campaign record C0015, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed five-day ransomware intrusion involving Bazar, Cobalt Strike, Conti, and other tools.
Open profile →C0016A defensive guide to the Enterprise ATT&CK campaign record C0016, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a long-running espionage campaign reported across industries in East Asia, Southeast Asia, Europe, and the United States.
Open profile →C0017A defensive guide to the Enterprise ATT&CK campaign record C0017, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed APT41 campaign that compromised multiple United States state-government networks in 2021–2022.
Open profile →C0018A defensive guide to the Enterprise ATT&CK campaign record C0018, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed month-long intrusion that culminated in AvosLocker ransomware deployment.
Open profile →C0020A defensive guide to the Enterprise ATT&CK campaign record C0020, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2000 incident in which a wastewater control system was abused to disrupt operations and release sewage.
Open profile →C0021A defensive guide to the Enterprise ATT&CK campaign record C0021, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed November 2018 spearphishing campaign against public, nonprofit, educational, and private-sector organizations.
Open profile →C0022A defensive guide to the Enterprise ATT&CK campaign record C0022, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an espionage operation using employment-themed lures against defense, aerospace, government, and other sectors.
Open profile →C0023A defensive guide to the Enterprise ATT&CK campaign record C0023, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an APT29 campaign beginning in 2013 against foreign ministries and a European embassy in Washington, D.C..
Open profile →C0024A defensive guide to the Enterprise ATT&CK campaign record C0024, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing the 2020 APT29 supply-chain operation involving the SolarWinds Orion software build process and follow-on access.
Open profile →C0025A defensive guide to the Enterprise ATT&CK campaign record C0025, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2016 campaign that disrupted Ukrainian electric-power distribution using Industroyer.
Open profile →C0026A defensive guide to the Enterprise ATT&CK campaign record C0026, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed 2022 campaign that selectively delivered malware to prior ANDROMEDA victims in Ukraine.
Open profile →C0027A defensive guide to the Enterprise ATT&CK campaign record C0027, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed financially motivated 2022 campaign linked to Scattered Spider and focused on telecommunications and business-process outsourcing companies.
Open profile →C0028A defensive guide to the Enterprise ATT&CK campaign record C0028, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2015 campaign that disrupted Ukrainian electric-power substations using BlackEnergy and KillDisk.
Open profile →C0029A defensive guide to the Enterprise ATT&CK campaign record C0029, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a China-nexus espionage campaign that exploited Ivanti Connect Secure zero-day vulnerabilities beginning in late 2023.
Open profile →C0030A defensive guide to the Enterprise ATT&CK campaign record C0030, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a campaign against a petrochemical organization that targeted Triconex safety controllers with the Triton framework.
Open profile →C0031A defensive guide to the Enterprise ATT&CK campaign record C0031, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing global intrusions that defaced Unitronics Vision Series PLC human-machine interfaces across multiple sectors.
Open profile →C0032A defensive guide to the Enterprise ATT&CK campaign record C0032, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed 2019 campaign associated in public reporting with the Triton adversaries and focused on footholds in IT environments.
Open profile →C0033A defensive guide to the Enterprise ATT&CK campaign record C0033, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing an unnamed PROMETHIUM campaign that used StrongPity against Android users.
Open profile →C0034A defensive guide to the Enterprise ATT&CK campaign record C0034, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2022 campaign against a Ukrainian electric utility that combined malware and living-off-the-land behavior to issue unauthorized SCADA commands.
Open profile →C0035A defensive guide to the Enterprise ATT&CK campaign record C0035, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing activity involving compromised end-of-life SOHO equipment used to obscure access to critical-infrastructure victims.
Open profile →C0036A defensive guide to the Enterprise ATT&CK campaign record C0036, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a February 2024 malicious-email campaign distributing a substantially revised Pikabot variant.
Open profile →C0037A defensive guide to the Enterprise ATT&CK campaign record C0037, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing 2023 Pikabot distribution activity linked to Black Basta ransomware deployment through malicious email attachments.
Open profile →C0038A defensive guide to the Enterprise ATT&CK campaign record C0038, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a disruptive 2022 campaign by Iranian state-affiliated actors against Albanian government networks.
Open profile →C0039A defensive guide to the Enterprise ATT&CK campaign record C0039, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing 2024 zero-day exploitation of Versa Director servers at service providers for credential capture and follow-on access.
Open profile →C0040A defensive guide to the Enterprise ATT&CK campaign record C0040, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing APT41 information-gathering activity from 2023 through July 2024 against organizations in Europe, Asia, and the Middle East.
Open profile →C0041A defensive guide to the Enterprise ATT&CK campaign record C0041, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a January 2024 incident against a Ukrainian municipal heating provider involving FrostyGoop and legitimate Modbus commands.
Open profile →C0042A defensive guide to the Enterprise ATT&CK campaign record C0042, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2021 OilRig campaign that targeted Israeli organizations using the SampleCheck5000 downloader and Solar backdoor.
Open profile →C0043A defensive guide to the Enterprise ATT&CK campaign record C0043, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing PRC-linked intrusions during 2021–2022 against Indian electric-utility, logistics, and related IT environments.
Open profile →C0044A defensive guide to the Enterprise ATT&CK campaign record C0044, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2022 OilRig campaign that targeted Israeli organizations with the Mango backdoor.
Open profile →C0045A defensive guide to the Enterprise ATT&CK campaign record C0045, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a campaign beginning in late 2023 that exploited exposed Ray AI framework instances across several sectors.
Open profile →C0046A defensive guide to the Enterprise ATT&CK campaign record C0046, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2023–2024 campaign against networking devices in government and critical-infrastructure environments.
Open profile →C0047A defensive guide to the Enterprise ATT&CK campaign record C0047, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing Mustang Panda phishing and PlugX activity against East and Southeast Asian entities from 2023 through 2024.
Open profile →C0048A defensive guide to the Enterprise ATT&CK campaign record C0048, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a March–April 2024 campaign that exploited a PAN-OS GlobalProtect zero-day vulnerability.
Open profile →C0049A defensive guide to the Enterprise ATT&CK campaign record C0049, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing long-term intrusions in Australia involving external-service exploitation, credential capture, lateral movement, and data theft.
Open profile →C0050A defensive guide to the Enterprise ATT&CK campaign record C0050, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2023–2024 campaign that used a tailored J-magic backdoor against Juniper routers serving as VPN gateways.
Open profile →C0051A defensive guide to the Enterprise ATT&CK campaign record C0051, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing APT28 activity from 2022 through 2024 that used nearby compromised networks and Wi-Fi paths to reach intended targets.
Open profile →C0052A defensive guide to the Enterprise ATT&CK campaign record C0052, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing activity conducted through commercially leased virtual-private-server operational-relay-box networks.
Open profile →C0053A defensive guide to the Enterprise ATT&CK campaign record C0053, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing activity conducted through a hybrid operational-relay-box network combining compromised devices and leased virtual private servers.
Open profile →C0054A defensive guide to the Enterprise ATT&CK campaign record C0054, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a mobile campaign that used zero-click iMessage exploit chains and the TriangleDB implant against iOS devices.
Open profile →C0055A defensive guide to the Enterprise ATT&CK campaign record C0055, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a botnet of compromised SOHO routers used as egress infrastructure by multiple China-affiliated threat actors.
Open profile →C0056A defensive guide to the Enterprise ATT&CK campaign record C0056, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing investigative tracking of custom TINYSHELL variants deployed on Juniper MX routers.
Open profile →C0057A defensive guide to the Enterprise ATT&CK campaign record C0057, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a cascading supply-chain compromise that moved from a trojanized trading application into 3CX build environments.
Open profile →C0058A defensive guide to the Enterprise ATT&CK campaign record C0058, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing July 2025 exploitation waves against incompletely patched on-premises Microsoft SharePoint servers.
Open profile →C0059A defensive guide to the Enterprise ATT&CK campaign record C0059, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a campaign beginning in 2024 that used voice phishing to compromise Salesforce instances for data theft and extortion.
Open profile →C0060A defensive guide to the Enterprise ATT&CK campaign record C0060, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2024 MirrorFace spearphishing campaign against organizations in Japan and Central Europe.
Open profile →C0061A defensive guide to the Enterprise ATT&CK campaign record C0061, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2024 suspected PRC-nexus campaign against business-to-business IT service providers in Southern Europe.
Open profile →C0062A defensive guide to the Enterprise ATT&CK campaign record C0062, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a September 2025 campaign in which a likely China-nexus actor manipulated Claude Code agents and MCP tools to automate portions of intrusions.
Open profile →C0063A defensive guide to the Enterprise ATT&CK campaign record C0063, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing destructive December 2025 attacks against Polish energy infrastructure involving Windows and PowerShell wipers.
Open profile →