Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| Qilin (fka Agenda) · Qilincampaign | Uses | RustHoundmalware | — | Correlated cluster | 2026-09-25 |
| SPECTREcampaign | Uses | SPECTREmalware | — | Correlated cluster | 2026-08-20 |
| payload · XMRigcampaign | Uses | Troymalware | — | Correlated cluster | 2026-09-03 |
| Cavern Manticore · Caverncampaign | Uses | Cavern Agentmalware | — | Correlated cluster | 2026-07-08 |
| BADBOXcampaign | Uses | NovaCookiesmalware | — | Correlated cluster | 2026-08-27 |
| Qilin ransomwarecampaign | Uses | QTRoutermalware | — | Correlated cluster | 2026-09-11 |
| BadIIScampaign | Uses | DeepAuditmalware | — | Correlated cluster | 2026-08-26 |
| XZ Utils backdoorcampaign | Uses | Axios supply chain attackmalware | — | Correlated cluster | 2026-08-21 |
| JWRcampaign | Uses | JSFuckmalware | — | Correlated cluster | 2026-09-14 |
| Information stealerscampaign | Uses | infostealermalware | — | Correlated cluster | 2026-09-03 |
| AnyDeskcampaign | Uses | Neo-reGeorgmalware | — | Correlated cluster | 2026-09-17 |
| PhantomCorecampaign | Uses | Oyster (CleanBoost)malware | — | Correlated cluster | 2026-08-25 |
| Qilin (fka Agenda) · Qilincampaign | Uses | AiLockmalware | — | Correlated cluster | 2026-09-25 |
| PromptSpycampaign | Uses | PromptSpymalware | — | Correlated cluster | 2026-09-03 |
| Qilin (fka Agenda) · Qilincampaign | Uses | INCmalware | — | Correlated cluster | 2026-09-25 |
| Trojanized PDF softwarecampaign | Uses | XG-Webmalware | — | Correlated cluster | 2026-08-17 |
| Qilin (fka Agenda) · Qilincampaign | Uses | Vidarmalware | — | Correlated cluster | 2026-09-25 |
| PowerShell-based RATcampaign | Uses | AnonyMousKITmalware | — | Correlated cluster | 2026-08-31 |
| AnyDeskcampaign | Uses | Toy Ghouls backdoormalware | — | Correlated cluster | 2026-09-17 |
| AnyDeskcampaign | Uses | SysReadSvc.dllmalware | — | Correlated cluster | 2026-09-17 |
| Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaign | Uses | DeepSeekmalware | — | Correlated cluster | 2026-09-16 |
| TeamPCP Cloud Stealercampaign | Uses | SHADOWLADDERmalware | — | Correlated cluster | 2026-09-02 |
| Qilin (fka Agenda) · Qilincampaign | Uses | ngrokmalware | — | Correlated cluster | 2026-09-25 |
| AnyDeskcampaign | Uses | RedExtmalware | — | Correlated cluster | 2026-09-17 |
| Ransomwarecampaign | Uses | Wormsmalware | — | Correlated cluster | 2026-09-02 |
| PowerShell-based RATcampaign | Uses | Qilin ransomwaremalware | — | Correlated cluster | 2026-08-31 |
| SPECTREcampaign | Uses | badsecretsmalware | — | Correlated cluster | 2026-08-20 |
| payload · XMRigcampaign | Uses | DotNetZip.dllmalware | — | Correlated cluster | 2026-09-03 |
| HomeLand Justiceattack-campaign | Uses | Data Encrypted for Impacttechnique | — | ATT&CK Campaign | 2021-05-01 |
| Triton Safety Instrumented System Attackattack-campaign | Uses | Scheduled Tasktechnique | — | ATT&CK Campaign | 2017-06-01 |
| Anthropic AI-orchestrated Campaignattack-campaign | Uses | System Information Discoverytechnique | — | ATT&CK Campaign | 2025-09-01 |
| Operation Wocaoattack-campaign | Uses | Software Discoverytechnique | — | ATT&CK Campaign | 2017-12-01 |
| Frankensteinattack-campaign | Uses | Automated Exfiltrationtechnique | — | ATT&CK Campaign | 2019-01-01 |
| Cutting Edgeattack-campaign | Uses | Indicator Removaltechnique | — | ATT&CK Campaign | 2023-12-01 |
| SolarWinds Compromiseattack-campaign | Uses | Web Session Cookietechnique | — | ATT&CK Campaign | 2019-08-01 |
| SharePoint ToolShell Exploitationattack-campaign | Uses | Web Protocolstechnique | — | ATT&CK Campaign | 2025-07-01 |
| Leviathan Australian Intrusionsattack-campaign | Uses | Input Capturetechnique | — | ATT&CK Campaign | 2022-04-01 |
| 3CX Supply Chain Attackattack-campaign | Uses | Drive-by Compromisetechnique | — | ATT&CK Campaign | 2022-11-01 |
| ArcaneDoorattack-campaign | Uses | External Remote Servicestechnique | — | ATT&CK Campaign | 2023-07-01 |
| Operation CuckooBeesattack-campaign | Uses | System Owner/User Discoverytechnique | — | ATT&CK Campaign | 2019-12-01 |
| Operation Wocaoattack-campaign | Uses | Local Groupstechnique | — | ATT&CK Campaign | 2017-12-01 |
| C0027attack-campaign | Uses | Cloud Servicestechnique | — | ATT&CK Campaign | 2022-06-01 |
| Operation CuckooBeesattack-campaign | Uses | Domain Accounttechnique | — | ATT&CK Campaign | 2019-12-01 |
| RedDelta Modified PlugX Infection Chain Operationsattack-campaign | Uses | System Information Discoverytechnique | — | ATT&CK Campaign | 2023-07-01 |
| 3CX Supply Chain Attackattack-campaign | Uses | Compromise Software Supply Chaintechnique | — | ATT&CK Campaign | 2022-11-01 |
| Salesforce Data Exfiltrationattack-campaign | Uses | Spearphishing Voicetechnique | — | ATT&CK Campaign | 2004-10-01 |
| APT41 DUSTattack-campaign | Uses | Code Signingtechnique | — | ATT&CK Campaign | 2023-01-31 |
| 2015 Ukraine Electric Power Attackattack-campaign | Uses | Disable or Modify Toolstechnique | — | ATT&CK Campaign | 2015-12-01 |
| Operation Honeybeeattack-campaign | Uses | Ingress Tool Transfertechnique | — | ATT&CK Campaign | 2017-08-01 |
| Operation Honeybeeattack-campaign | Uses | Servertechnique | — | ATT&CK Campaign | 2017-08-01 |