CTIPilot

Microsoft Windows

product · product:microsoft-windows single-source

Coverage timeline
16
first 2026-06-10 → last 2026-09-03
Peak priority
high
8 high · 8 notable
Sources cited
44
29 hosts
Sections touched
4
active-threats, deep-dive, research
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
80
pinned v19.2 · see below

ATT&CK techniques

80 techniques observed across 16 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595Active Scanning×1

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

Resource Development TA0042

T1588.005Obtain Capabilities: Exploits×1

Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1608.006Stage Capabilities: SEO Poisoning×1

Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims. Search engines typically display results to users based on purchased ads as well as the site’s ranking/score/reputation calculated by their web crawlers and algorithms.

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

T1190Exploit Public-Facing Application×4

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-06-10/cve-2026-47291-microsoft-june-patch-tuesday-http-sys-pre-aut · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×2

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×3

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1059.001Command and Scripting Interpreter: PowerShell×2

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×1

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×2

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1106Native API×1

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1204.002User Execution: Malicious File×5

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · 2026-07-26/rapid7-exposed-webdav-delivery-lab-cve-2025-33053-clickfix · ATT&CK page ↗

T1204.004User Execution: Malicious Copy and Paste×1

An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.

Evidence: 2026-07-26/rapid7-exposed-webdav-delivery-lab-cve-2025-33053-clickfix · ATT&CK page ↗

T1574Hijack Execution Flow×1

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×6

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×3

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1112Modify Registry×4
T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

T1543.001Create or Modify System Process: Launch Agent×1

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×2

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×2

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×3

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1055Process Injection×4

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1055.004Process Injection: Asynchronous Procedure Call×1

Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗

T1055.012Process Injection: Process Hollowing×2

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗

T1068Exploitation for Privilege Escalation×5

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1134.001Access Token Manipulation: Token Impersonation/Theft×1

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗

T1543.001Create or Modify System Process: Launch Agent×1

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>. Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×2

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1547Boot or Logon Autostart Execution×1

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

Evidence: 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×2

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1548Abuse Elevation Control Mechanism×2

Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control×2

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

Stealth TA0005

T1014Rootkit×3

Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

T1027Obfuscated Files or Information×7

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit +1 more · ATT&CK page ↗

T1027.007Obfuscated Files or Information: Dynamic API Resolution×1

Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native API functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1027.009Obfuscated Files or Information: Embedded Payloads×1

Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets.

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

T1027.013Obfuscated Files or Information: Encrypted/Encoded File×1

Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., Deobfuscate/Decode Files or Information) at the time of execution/use.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×3

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1055Process Injection×4

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1055.004Process Injection: Asynchronous Procedure Call×1

Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗

T1055.012Process Injection: Process Hollowing×2

Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of a separate live process.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗

T1070.004Indicator Removal: File Deletion×2

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1134.001Access Token Manipulation: Token Impersonation/Theft×1

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×2

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1218System Binary Proxy Execution×1

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.

Evidence: 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · ATT&CK page ↗

T1218.011System Binary Proxy Execution: Rundll32×1

Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: <code>rundll32.exe {DLLname, DLLfunction}</code>).

Evidence: 2026-07-26/rapid7-exposed-webdav-delivery-lab-cve-2025-33053-clickfix · ATT&CK page ↗

T1564.003Hide Artifacts: Hidden Window×1

Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks.

Evidence: 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1564.004Hide Artifacts: NTFS File Attributes×1

Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition contains a Master File Table (MFT) that maintains a record for every file/directory on the partition. Within MFT entries are file attributes, such as Extended Attributes (EA) and Data [known as Alternate Data Streams (ADSs) when more than one Data attribute is present], that can be used to store arbitrary data (and even complete files).

Evidence: 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · ATT&CK page ↗

T1574Hijack Execution Flow×1

Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of persistence, since this hijacked execution may reoccur over time. Adversaries may also use these mechanisms to elevate privileges or evade defenses, such as application control or other restrictions on execution.

Evidence: 2026-07-29/legacyhive-offline-registry-hive-profile-hijack-no-fix · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×6

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-08-28/cncmachinerms-babadeda-loader-enumtimeformats-shellcode · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

T1620Reflective Code Loading×1

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

Defense Impairment TA0112

T1112Modify Registry×4
T1553.002Subvert Trust Controls: Code Signing×1

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1685Disable or Modify Tools×7

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-08-23/btr-sys-defender-remediation-driver-kernel-primitive · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/shieldbreak-defender-rogueplanet-patch-bypass-no-fix · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule +1 more · ATT&CK page ↗

T1688Safe Mode Boot×1

Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services. Third-party security software such as endpoint detection and response (EDR) tools may not start after booting Windows in safe mode. There are two versions of safe mode: Safe Mode and Safe Mode with Networking. It is possible to start additional services after a safe mode boot.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

Credential Access TA0006

T1003.002OS Credential Dumping: Security Account Manager×1

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.

Evidence: 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · ATT&CK page ↗

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1110.003Brute Force: Password Spraying×1

Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

T1539Steal Web Session Cookie×2

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1555.003Credentials from Password Stores: Credentials from Web Browsers×3

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

Evidence: 2026-09-03/moiclient-byovd-rpc-uac-bypass-invoice-backdoor · 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

Discovery TA0007

T1016.001System Network Configuration Discovery: Internet Connection Discovery×1

Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using Ping, <code>tracert</code>, and GET requests to websites, or performing initial speed testing to confirm bandwidth.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · ATT&CK page ↗

T1018Remote System Discovery×1

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

T1033System Owner/User Discovery×1

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1049System Network Connections Discovery×1

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1057Process Discovery×2

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

T1082System Information Discovery×3

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

T1087.002Account Discovery: Domain Account×1

Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

Collection TA0009

T1056.001Input Capture: Keylogging×1

Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1113Screen Capture×2

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1115Clipboard Data×1

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

Evidence: 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1123Audio Capture×1

An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1125Video Capture×1

An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1185Browser Session Hijacking×1

Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.

Evidence: 2026-07-28/medusahvnc-hidden-desktop-browser-session-hijacking · ATT&CK page ↗

T1560.001Archive Collected Data: Archive via Utility×1

Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×4

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1090Proxy×2

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1090.003Proxy: Multi-hop Proxy×1

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1102Web Service×2

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Evidence: 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1102.002Web Service: Bidirectional Communication×1

Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.

Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗

T1105Ingress Tool Transfer×4

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · 2026-07-26/rapid7-exposed-webdav-delivery-lab-cve-2025-33053-clickfix · ATT&CK page ↗

T1219Remote Access Tools×2

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1571Non-Standard Port×1

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · ATT&CK page ↗

T1573Encrypted Channel×1

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

Evidence: 2026-08-07/fake-zoom-dotnet-downloader-overlord-rat-macos · ATT&CK page ↗

Exfiltration TA0010

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-17/akira-safe-mode-boot-edr-blinding-sonicwall-vpn · ATT&CK page ↗

T1499Endpoint Denial of Service×1

Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-06-10/cve-2026-47291-microsoft-june-patch-tuesday-http-sys-pre-aut · ATT&CK page ↗

Story timeline

  1. 2026-09-03MoiClient: an invoice-themed backdoor chains an RPC-based UAC bypass with a vulnerable Lenovo PC Manager driver to kill security products and steal browser credentials
    active-threatsA debug-object handle borrowed from winver.exe is enough to hijack a self-elevating system binary with no prompt
  2. 2026-09-03Kimsuky's seafood-invoice LNK campaign abuses Backblaze B2 cloud storage as C2 and exfiltration infrastructure, keyed by victim BIOS serial number
    active-threatsThe command-and-control channel is a legitimate cloud storage API, not a registered domain
  3. 2026-08-28Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh (a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler) with confirmed expansion into the UK, France, Albania and Belarus
    active-threatsAn Iranian espionage actor already tracked for aerospace and telecom targeting adds a new backdoor and materially widens its named European footprint
  4. 2026-08-28CNCMachineRMS, an undocumented remote-access trojan delivered through a four-stage BabaDeda loader chain that smuggles shellcode via a benign Windows date-formatting API
    active-threatsA ClickFix lure abuses a signed IBM SPSS binary's own scripting engine, then hides its final shellcode injection inside a Windows time-formatting call
  5. 2026-08-23SPECTRE unlinks EDR's kernel callbacks one at a time using a two-driver BYOVD toolkit and an offset table for thirteen Windows builds, and its Linux half hides through ftrace rather than the syscall table
    active-threatsA cross-platform implant that blinds named endpoint products to process, thread and image-load events for the rest of the session
  6. 2026-08-23Windows Defender ships its own kernel write primitive: BTR.sys, the signed boot-time remediation driver, takes an encrypted job list from an alternate data stream and will delete or create any file or registry value asked of it
    deep-diveNo exploit, no vulnerability, nothing to blocklist; the driver is a required Defender component, and its instructions live in a hidden stream on its own file
  7. 2026-08-17Akira blinds EDR by rebooting a victim host into Safe Mode with Networking, the operator's first observed use of the technique, and the stripped-down boot starved its own encryptor
    active-threatsAkira reboots a SonicWall-VPN victim into Safe Mode to strip EDR, and starves its own encryptor
  8. 2026-08-15Mustang Panda's CoolClient backdoor gains a kernel driver signed with a 2013 certificate that expired in 2014, and it hides the malware's own C2 traffic by hooking the driver Windows uses to report network state
    active-threatsKaspersky documents a previously undocumented CoolClient rootkit driver, deployed only once the implant already holds SCM access and SeTcbPrivilege
  9. 2026-08-12ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025
    trending-vulnerabilitiesNightmare Eclipse drops a Defender privilege-escalation patch bypass on Patch Tuesday itself, with no fix available
  10. 2026-08-12Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers
    deep-diveCheck Point ties Operation Dream Job's 2026 wave to an exploited kernel zero-day patched on 11 August, with confirmed compromises in France and Germany
  11. 2026-08-07A fake Zoom installer stages Overlord RAT through the first .NET macOS downloader Jamf has observed, PE-format DLLs bundled inside a Mach-O binary
    active-threatsmacOS malware picks up .NET: one downloader codebase now targets Mac and Windows, and the Go payload is Garble-obfuscated to break static analysis
  12. 2026-07-31Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent
    active-threatsThe autonomous agent attacked at scale and landed nothing; the same operator's hand-driven NetScaler exploitation took data from three organisations
  13. 2026-07-29LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems
    researchLevelBlue reproduces Nightmare Eclipse's latest Windows PoC on a July-2026-patched build, no CVE, no fix, and the abuse uses only legitimate APIs
  14. 2026-07-28MedusaHVNC: a malware-as-a-service RAT that drives the victim's own logged-in browser on an invisible second Windows desktop
    active-threatsMedusaHVNC rides real logged-in browser sessions on a hidden Windows desktop, defeating device-based fraud checks
  15. 2026-07-26An exposed WebDAV delivery lab shows industrialised .url/.lnk lure testing against CVE-2025-33053, with LLM-written tooling and ClickFix pages
    research1,048 artifacts on an exposed staging server show how a delivery operator now QA-tests lures like a product team
  16. 2026-06-10CVE-2026-47291, Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)
    trending-vulnerabilities

Where this entity is cited

  • active-threats10
  • trending-vulnerabilities2
  • research2
  • deep-dive2

Source distribution

  • msrc.microsoft.com6 (14%)
  • levelblue.com3 (7%)
  • rapid7.com3 (7%)
  • thehackernews.com3 (7%)
  • 0patch.com2 (5%)
  • asec.ahnlab.com2 (5%)
  • cisa.gov2 (5%)
  • research.checkpoint.com2 (5%)
  • other21 (48%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (44)

Entries about Microsoft Windows (16)

2026-09-03 · view entry permalink →

NOTABLENATOB2

Kimsuky's seafood-invoice LNK campaign abuses Backblaze B2 cloud storage as C2 and exfiltration infrastructure, keyed by victim BIOS serial number

AhnLab ASEC attributes a new malicious-LNK campaign to Kimsuky based on code and behavioural overlap with prior Kimsuky LNK operations: matching PowerShell extraction syntax, the same fixed-offset method of extracting data embedded in the LNK, and the same Task Scheduler registration pattern (AhnLab ASEC, 2026-09-01). The lure is a spearphishing attachment named "[Royal Hotel Seoul] Request for Review of Seafood Ingredient Purchases.LNK." Running it uses PowerShell to extract embedded data: it drops a legitimate-looking decoy .hwp document at the same path, displayed to the victim, while simultaneously writing an XOR-encrypted ZIP to C:\ProgramData\systmp\sunshine containing a PowerShell script (termsvc.ps1) and a JScript file, saved separately as C:\ProgramData\systmp\ping_<first-4-UUID-digits>.js (AhnLab ASEC, 2026-09-01). Persistence is a Scheduled Task named MicrosoftOffice2016_<first-4-UUID-digits> that runs the JS file via wscript.exe roughly every 14 minutes; the obfuscated script checks for the presence of termsvc.ps1 and bypasses the PowerShell execution policy to run it hidden (AhnLab ASEC, 2026-09-01). termsvc.ps1 collects OS name and architecture, system timezone, public IP (queried via api.ipify.org), username, domain, the running-process list, and computer name, then authenticates to the Backblaze B2 API and uploads the collected data to a per-victim path keyed on the BIOS serial number, a legitimate cloud-storage service used as command-and-control infrastructure rather than attacker-registered domains (AhnLab ASEC, 2026-09-01). It then polls the same B2 path for a follow-up command file, saves it under an arbitrary name as a .cmd in %TEMP%, executes it hidden via cmd.exe /c, and deletes the local copy roughly 120 seconds later. The actor deletes the original LNK and the intermediate ZIP during execution, leaving only the components needed for the persistence loop.

Triage: authenticated outbound HTTPS traffic to Backblaze B2 API endpoints from a workstation with no legitimate backup or storage use case, alongside a Scheduled Task invoking wscript.exe against a script under C:\ProgramData on a short (~14-minute) interval, is the reusable detection hook, it generalises beyond this campaign to "legitimate cloud storage abused as C2," a pattern increasingly common across unrelated actors, not only Kimsuky.

In this attack, Backblaze B2 was used not merely as a file storage space but as a C2 infrastructure to exfiltrate information from infected PCs and relay follow-up commands.

Based on such similarities in code and behavior, AhnLab determined that this malicious LNK is also linked to the Kim Sukki group.

it is configured to execute ping_<FIRST 4 digits of UUID>.Js approximately every 14 minutes via wscript.Exe

AhnLab ASEC 2026-09-01
threat03 Sep 05:18Zsingle-sourceOpen finding ↗
Sources: AhnLab ASEC

2026-09-03 · view entry permalink →

NOTABLENATOB2

MoiClient: an invoice-themed backdoor chains an RPC-based UAC bypass with a vulnerable Lenovo PC Manager driver to kill security products and steal browser credentials

AhnLab's ASEC documents MoiClient (named for the "moimoi" string in its BYOVD component) distributed as a .vhdx file disguised as an invoice email attachment. The archive contains Invoice.Pdf.Exe, actually the legitimate SumatraPDF viewer, used to DLL-sideload a same-directory malicious uxtheme.dll, plus hidden support files (AhnLab ASEC, 2026-09-01). Execution moves into a legitimate process via classic process hollowing: MoiClient spawns explorer.exe suspended and overwrites its entry point with shellcode from a co-located data.dat. For privilege escalation, MoiClient connects over ncalrpc to the RPC interface of the AppInfo Service, launches winver.exe as a debug target to acquire a debug-object handle, then drives ComputerDefaults.exe (a system binary that auto-elevates) through the same RPC path, clones its process handle, and sets that cloned handle as the parent of subsequent sc.exe and PowerShell processes so they inherit elevated privileges with no UAC prompt shown (AhnLab ASEC, 2026-09-01). With elevated rights, MoiClient drops a vulnerable Lenovo PC Manager kernel driver, version 2.5.30.11281 of BootRepair.sys, under the name moimoi.sys in the %Public% path, registers it as a kernel service, and uses its device interface to pass process IDs of running security products for forced termination, targeting Windows Defender, Malwarebytes, Bitdefender, Kaspersky, Avast, AVG and McAfee by process name (AhnLab ASEC, 2026-09-01). A separate technique specifically neutralises Windows Defender: MoiClient downloads defendnot.dll and defendnot-loader.exe from its command-and-control server and runs them through the elevated PowerShell session. Persistence is a Task Scheduler job named MicrosoftWindowsUpdateTask<4-digit-number> (or the existing name with a trailing period appended on a collision) that fires every 30 minutes, re-launching the renamed SumatraPDF binary to re-trigger the DLL-sideload chain (AhnLab ASEC, 2026-09-01). The final payload, "MoiXD Stealer," runs in memory and uses a ChromeElevator-style technique to steal browser-stored passwords.

Triage: the RPC-based UAC bypass, cloning a process handle obtained through winver.exe as a debug target and attaching it as the parent of sc.exe or PowerShell, resembles a technique class Google Project Zero documented in 2019 against the AppInfo Service; a sc.exe or PowerShell process whose parent-process chain traces back through winver.exe or ComputerDefaults.exe rather than a normal interactive shell is not typical UAC-elevation behaviour and is the observable signature the mechanism supports.

MoiClient uses the ncalrpc protocol sequence to connect to the RPC interface of the AppInfo Service, then executes winver.Exe as a debug target and acquires the debug object handle.

version 2.5.30.11281 Of BootRepair.Sys (a vulnerable driver in Lenovo PC Manager) was exploited. MoiClient creates this driver in the %Public% Path under the name moimoi.Sys

The registered task runs every 30 minutes. At that time, SumatraPDF (named "demo.Exe") is launched, and "uxtheme.Dll," which is located in the same Path and is actually MoiClient, is reloaded.

AhnLab ASEC 2026-09-01
threat03 Sep 05:17Zsingle-sourceOpen finding ↗
Sources: AhnLab ASEC

2026-08-28 · view entry permalink →

NOTABLEupdatedNATOB2

CNCMachineRMS, an undocumented remote-access trojan delivered through a four-stage BabaDeda loader chain that smuggles shellcode via a benign Windows date-formatting API

LevelBlue SpiderLabs documents CNCMachineRMS, a previously undocumented 1.14 MB x64 remote-access trojan delivered through a four-stage BabaDeda loader chain. A ClickFix-style lure launches a legitimately signed IBM SPSS IDE executable (WinWrapIDE.exe), abusing its scripting engine to load a malicious DLL: "infection starts with a ClickFix lure that launches a legitimately signed IBM SPSS IDE executable, WinWrapIDE.exe, whose scripting engine is abused to load a malicious DLL" (LevelBlue SpiderLabs, 2026-08-10). Four decoy DLLs then load in sequence through standard Windows DLL import resolution before the final stage smuggles its shellcode into execution via EnumTimeFormatsEx, a benign date-formatting Windows API: "the final stage smuggles shellcode into execution via EnumTimeFormatsEx, a benign date-formatting API" (LevelBlue SpiderLabs, 2026-08-10), a technique that hides the injection point from analysts looking for conventional process-injection APIs.

The final implant has no import table and resolves its APIs by hash at runtime, builds its strings on the stack rather than storing them statically, uses a custom C2 protocol, takes a screenshot on first contact, beacons roughly every 600 seconds, and installs seven distinct persistence mechanisms: "it takes a screenshot on first contact, then beacons every 600 seconds", while the decoded strings describe "a local account backdoor, seven persistence mechanisms, and twenty typed commands for staging and running whatever the operator sends next" (LevelBlue SpiderLabs, 2026-08-10). Capabilities include interactive shell access, file management, screen capture and local account backdoors. BabaDeda-chain ClickFix lures are a recurring initial-access vector across the covered sectors, making the delivery mechanism as relevant as the payload itself.

Triage: the API-hashing and stack-built-strings design defeats static string-based detection, so behavioural signals carry the weight here, a legitimately signed application (IBM SPSS or any similarly abused signed binary) spawning a scripting-engine child process that loads an unsigned DLL is the first anomaly, and a process invoking EnumTimeFormatsEx immediately followed by execution flow transferring into memory it just wrote (rather than into a legitimate formatting routine) is the discriminator against the API's ordinary, benign use, no legitimate application calls this function as a prelude to code execution elsewhere in its own address space.

Infection starts with a ClickFix lure that launches a legitimately signed IBM SPSS IDE executable, WinWrapIDE.exe, whose scripting engine is abused to load a malicious DLL.

The final stage smuggles shellcode into execution via EnumTimeFormatsEx, a benign date-formatting API.

It takes a screenshot on first contact, then beacons every 600 seconds.

LevelBlue SpiderLabs 2026-08-10
Correctionrun 2026-08-30T1312Z-auditevidencesourcing_notebody

Two quotations here were not verbatim. The delivery quote is: "Infection starts with a ClickFix lure that launches a legitimately signed IBM SPSS IDE executable, WinWrapIDE.exe, whose scripting engine is abused to load a malicious DLL" (LevelBlue SpiderLabs, 2026-08-10); the executable is named in the source and was dropped here. The second was a composite that does not exist as a sentence anywhere in the article: LevelBlue writes "It takes a screenshot on first contact, then beacons every 600 seconds" as its own bullet, and separately that the decoded strings describe "a local account backdoor, seven persistence mechanisms, and twenty typed commands for staging and running whatever the operator sends next" (same article). Every behaviour this entry describes is still what LevelBlue reports; what was wrong was presenting two passages as one quotation.

threat28 Aug 06:30Zsingle-sourceOpen finding ↗

Earlier coverage (13)

2026-08-28HIGHNATOB2Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh (a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler) with confirmed expansion into the UK, France, Albania and BelarusGroup-IB documents new infrastructure and a new toolset for Nimbus Manticore, the Iranian IRGC-affiliated actor tracked under multiple aliases. A reverse SSH tunneler establishes outbound connections over port 443 to give operators interactive access into compromised networks; a TWOSTROKE-family C++ backdoor masquerades as the Windows Terminal Server SDK DLL for search-order hijacking. Infrastructure analysis indicates targeting expanded specifically into the UK, France, Albania and Belarus, alongside continued Middle Eastern activity, the actor's third distinct toolset refresh reported in roughly seven months.2026-08-12HIGHupdatedNATOB2ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025Researcher Nightmare Eclipse published ShieldBreak on 2026-08-11/12, a proof-of-concept the researcher describes as a full bypass of the patch Microsoft shipped in July for RoguePlanet (CVE-2026-50656), the Microsoft Malware Protection Engine privilege-escalation flaw that yields a SYSTEM shell on fully updated Windows. Two properties make it worse than what it replaces: it is listed with a 100 percent success rate where RoguePlanet was an unreliable race, and it is listed as tested on Windows Server 2025 alongside Windows 11 25H2, where the June exploit did not run. No patch exists, no vendor has publicly reproduced it, and Microsoft had not commented at publication.2026-08-23HIGHNATOB2SPECTRE unlinks EDR's kernel callbacks one at a time using a two-driver BYOVD toolkit and an offset table for thirteen Windows builds, and its Linux half hides through ftrace rather than the syscall tableCisco Talos published an analysis on 2026-08-20 of SPECTRE, a cross-platform C backdoor deployed by a Chinese-speaking intrusion actor it tracks as UAT-10147 against compromised IIS and Linux web servers. The Windows variant loads one of two long-known vulnerable drivers as a transient kernel service, locates the kernel image through a documented information call, and uses a hardcoded per-build offset table covering thirteen Windows versions to unlink registered process-creation, thread-creation and image-load notification callbacks from their linked lists, blinding callback-dependent endpoint products, which Talos names as CrowdStrike Falcon, SentinelOne and Microsoft Defender, for the remainder of the session. Credential access deliberately avoids LSASS entirely, and the C2 configuration is held in an alternate data stream on the hosts file so it can be rotated without recompiling. The Linux variant persists as a systemd unit ordered ahead of security tooling and hides through the kernel's ftrace debugging interface rather than by patching the syscall table.2026-08-23HIGHNATOB2Windows Defender ships its own kernel write primitive: BTR.sys, the signed boot-time remediation driver, takes an encrypted job list from an alternate data stream and will delete or create any file or registry value asked of itCheck Point Research published an analysis on 2026-08-20 showing that BTR.sys, the Microsoft-signed "Boot Time Removal Tool" driver Windows Defender extracts from MpEngine.dll to finish remediation actions that need a reboot, exposes a general-purpose kernel-mode file and registry primitive once its transaction format is understood. There is no memory corruption and no vulnerability: the driver reads an RC4-encrypted job list from an NTFS alternate data stream on its own file and executes six action types, two of which amount to arbitrary file write and arbitrary registry write. Because the driver is a functionally required Defender component carrying a genuine signature, it cannot be added to the vulnerable-driver blocklist or blocked by WDAC without breaking Defender's own remediation, and because the tool extracts it from the local MpEngine.dll there is no third-party binary for a blocklist to key on. The precondition is pre-existing administrative privilege, which is why MSRC declined to service it; Check Point reports no evidence of real-world abuse.2026-08-15NOTABLEupdatedNATOB2Mustang Panda's CoolClient backdoor gains a kernel driver signed with a 2013 certificate that expired in 2014, and it hides the malware's own C2 traffic by hooking the driver Windows uses to report network stateKaspersky's GReAT team published on 2026-08-14 a new CoolClient backdoor variant, attributed to the actor it tracks as HoneyMyte and also known as Mustang Panda, that installs a signed kernel-mode driver as a Windows service. The driver hides processes, files, registry keys and (distinctively) strips the implant's own C2 addresses from the network information Windows returns to user-mode tools. It is deployed only where the implant already holds Service Control Manager access and SeTcbPrivilege, and follows a PlugX foothold.2026-07-31HIGHexploitedupdatedNATOB2Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agentPalo Alto Unit 42 obtained full visibility into a Chinese-speaking operator's offensive tooling after the operator's own agent framework started an HTTP file server from its home directory, exposing tool configurations, API keys, exploit scripts, target lists and session logs. The operator ran DeepSeek behind the open-source Hermes Agent for fully autonomous target enumeration and exploitation against seven CVEs and more than 460 targets, and every autonomous exploitation attempt failed, defeated only by target-side configuration. The three confirmed compromises came from the operator's own manual work against Citrix NetScaler ADC/Gateway (CVE-2026-3055), exfiltrating appliance memory and searching it for session cookies, including multi-day targeting of a Malaysian government entity. That CVE is KEV-listed and was already being exploited by an unrelated cluster months earlier.2026-08-17HIGHNATOB2Akira blinds EDR by rebooting a victim host into Safe Mode with Networking, the operator's first observed use of the technique, and the stripped-down boot starved its own encryptorHuntress documents the first Akira intrusion it has observed using a Safe Mode with Networking reboot to take endpoint defences offline. After a credential spray resolved into a successful login on a SonicWall SSL VPN with no multi-factor authentication, the operator wrote its own AnyDesk service into the Safe Mode service allow-list, forced a reboot through msconfig, and worked from 06:29 UTC until 08:10 UTC on a host where neither the EDR agent nor Microsoft Defender real-time protection could start. The encryptor then failed (Safe Mode's constrained virtual memory starved the process tree) but Active Directory dumps and archived file shares had already left, so the intrusion stayed extortion-viable, and Huntress is explicit that the failure was the attacker's own memory-budget mistake rather than a defence to rely on.2026-07-29NOTABLEupdatedNATOB2LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systemsLevelBlue SpiderLabs published a full analysis on 2026-07-27 of LegacyHive, the latest public Windows proof-of-concept from the Nightmare Eclipse disclosure persona. It is not a software vulnerability: the chain edits a helper account's ntuser.dat offline through Microsoft's own Registry Offline API, repoints the User Shell Folders Local AppData value into an attacker-created NT Object Manager namespace, uses a batch opportunistic lock on UsrClass.dat to pause until profile initialisation reaches the right moment, then forces a profile load via CreateProcessWithLogonW with LOGON_WITH_PROFILE, aliasing into a third account's profile data without ever holding that account's credentials. LevelBlue reproduced the whole chain on fully patched Windows with July 2026 updates installed and reports no Microsoft mitigation for this class of abuse. It is strictly post-compromise: the attacker needs a low-privileged session plus a separate helper account's credentials.2026-08-12HIGHexploitedNATOB1Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress serversCheck Point Research published the analysis behind CVE-2026-68820 on 2026-08-11, the sole exploitation-detected flaw in Microsoft's August Patch Tuesday: a use-after-free race in the Windows Ancillary Function Driver for WinSock that a DPRK-linked Lazarus intrusion used to reach SYSTEM and load the FudModule v3.1 kernel rootkit. The delivery is a fake defence-sector job offer leading to a trojanised PDF viewer or a DLL-sideloading bundle; the command-and-control runs on compromised Roundcube and WordPress servers, one of them a French victim organisation later reused to phish others. Check Point records successful targeting in France and Germany, and CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day.2026-08-07NOTABLENATOB2A fake Zoom installer stages Overlord RAT through the first .NET macOS downloader Jamf has observed, PE-format DLLs bundled inside a Mach-O binaryJamf Threat Labs analysed a counterfeit Zoom installer, a macOS ARM64 Mach-O binary named ZoomMeetings built as a self-contained .NET 10 single-file application, the first case Jamf has observed of .NET rather than Go or Rust used as a macOS downloader. Because .NET assemblies keep the Windows PE container for their bytecode even inside a Mach-O wrapper, one codebase targets both platforms; static analysis pulled 34 embedded PE/DLL files, one carrying Zoom product metadata copied from the legitimate installer. The stage-two payload is a Garble-obfuscated Go build of the open-source Overlord framework, reached over an encrypted WebSocket.2026-07-28NOTABLENATOB2MedusaHVNC: a malware-as-a-service RAT that drives the victim's own logged-in browser on an invisible second Windows desktopBlackFog analysed MedusaHVNC (2026-07-27), a Windows remote-access trojan sold as malware-as-a-service whose hidden-VNC module opens Chrome, Edge or Firefox on a separate, invisible Windows desktop using the victim's existing browser profile, so the operator drives live, already-authenticated sessions from the victim's own machine while the user sees nothing. The five-stage chain runs from an obfuscated JScript launcher through an AutoIt interpreter that XOR-decrypts a loader and injects it into charmap.exe, then unpacks the final payload behind repeating-XOR and ChaCha20 layers. Because the session originates from the real device with the real profile, controls that key on device fingerprint and session continuity see nothing unusual.2026-07-26NOTABLEexploitedNATOB1An exposed WebDAV delivery lab shows industrialised .url/.lnk lure testing against CVE-2025-33053, with LLM-written tooling and ClickFix pagesRapid7 pivoted from a single WebDAV rundll32 alert to an exposed, fully operational malware delivery lab holding 1,048 artifacts organised like a development workspace: 453 shortcut-based launchers, 236 filename-spoofing tests, 146 trusted-Windows-tool execution tests, encrypted droppers, ClickFix pages impersonating Cloudflare, Adobe and Discord, and LLM-generated operator documentation. The operator was systematically testing CVE-2025-33053 (a Windows shortcut working-directory resolution flaw that makes a legitimate binary load an attacker-supplied file from a remote WebDAV share) and its own notes claim the technique raises no SmartScreen or Mark-of-the-Web prompt.2026-06-10HIGHupdatedCVE-2026-47291, Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)June Patch Tuesday is the largest ever (198 CVEs); headline is an HTTP.sys pre-auth RCE (CVE-2026-47291, CVSS 9.8); separately Chrome patched an in-the-wild V8 zero-day (CVE-2026-11645, now CISA KEV). (Rapid7, 2026-06-09; Chrome, 2026-06-08).