Activity timeline
T1012 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 29 reports, and 63 of the 63 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1012 Query Registry is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 63 of 2623 tracked threats (2.4%) to it; by severity that is 7 critical, 51 high, 5 medium.
Threats that use T1012 most often also use T1082 System Information Discovery (50 threats), T1027 Obfuscated Files or Information (42 threats), T1140 Deobfuscate/Decode Files or Information (41 threats), T1057 Process Discovery (38 threats), T1105 Ingress Tool Transfer (38 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
28 tracked threat actors appear in the threats that use T1012; the most frequent are Nightmare Eclipse (3), APT38 (2), Chaos (2), Gamaredon Group (2), Nightmare-Eclipse (2).
Data sources
Telemetry that can reveal T1012, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
- Windows Registry — Windows Registry Key Access
Threat actors using it
Tracked threats
The 30 most recent of 63 tracked threats that use T1012.
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scanshigh
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…high
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoorhigh
- Fake CCleaner Installer Delivers GhostDesk Chrome Spyware with Keylogging, Credential Theft, and Crypto…high
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- Tax Season Phishing and Malware Campaign Targets Indian Taxpayers via Fake Income Tax Department Noticeshigh
- LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installedhigh
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…medium
- msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaShigh
- Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network Detectionhigh
- TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities…high
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- LegacyHive: Public PoC for Unpatched Windows User Profile Service (ProfSvc) Arbitrary Hive Load Elevation of…high
- W32/SkyAI (Skynet/Topozuy) — Windows Malware with Embedded LLM Prompt-Injection AV-Evasion Attempt…medium
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil…medium
- The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWormhigh
- LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)high
- LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Servicehigh
- BoryptGrab Infostealer Campaign Abuses ~292 Fake GitHub Repos Impersonating Legitimate Softwarehigh
- Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process…high
Detection coverage
Threadlinqs maintains 37 detection rules mapped to T1012 (SPL 10, KQL 14, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.