Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)

T1014 Rootkit

Stealth (formerly Defense Evasion)Enterprise

As of 2026-10-05, T1014 (Rootkit) appears in 81 tracked threats, first reported 2026-02-04 and most recently 2026-09-27, with linked actors including GhostEmperor, Sapphire Sleet, APT38; it most often appears alongside T1685 (Disable or Modify Tools).

Tracked threats
8127 critical, 48 high, 5 medium
First seen
2026-02-04
Last seen
2026-09-27
Threat actors
51In the threats using it
Detection rules
144Blue tier and above

Data as of:

Activity timeline

T1014 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 23 reports, and 81 of the 81 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1014 Rootkit is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 81 of 2623 tracked threats (3.1%) to it; by severity that is 27 critical, 48 high, 5 medium.

Threats that use T1014 most often also use T1685 Disable or Modify Tools (51 threats), T1082 System Information Discovery (50 threats), T1027 Obfuscated Files or Information (46 threats), T1005 Data from Local System (42 threats), T1190 Exploit Public-Facing Application (40 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

51 tracked threat actors appear in the threats that use T1014; the most frequent are GhostEmperor (4), Sapphire Sleet (4), APT38 (3), Lazarus Group (3), Mustang Panda (3).

Data sources

Telemetry that can reveal T1014, per MITRE ATT&CK.

  • Drive — Drive Modification
  • File — File Modification
  • Firmware — Firmware Modification

Threat actors using it

Tracked threats

The 30 most recent of 81 tracked threats that use T1014.

Detection coverage

Threadlinqs maintains 144 detection rules mapped to T1014 (SPL 51, KQL 48, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.

144 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans