Activity timeline
T1014 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 23 reports, and 81 of the 81 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1014 Rootkit is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 81 of 2623 tracked threats (3.1%) to it; by severity that is 27 critical, 48 high, 5 medium.
Threats that use T1014 most often also use T1685 Disable or Modify Tools (51 threats), T1082 System Information Discovery (50 threats), T1027 Obfuscated Files or Information (46 threats), T1005 Data from Local System (42 threats), T1190 Exploit Public-Facing Application (40 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
51 tracked threat actors appear in the threats that use T1014; the most frequent are GhostEmperor (4), Sapphire Sleet (4), APT38 (3), Lazarus Group (3), Mustang Panda (3).
Data sources
Telemetry that can reveal T1014, per MITRE ATT&CK.
- Drive — Drive Modification
- File — File Modification
- Firmware — Firmware Modification
Threat actors using it
Tracked threats
The 30 most recent of 81 tracked threats that use T1014.
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…critical
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…critical
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…medium
- Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholinghigh
- Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2high
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitationcritical
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…high
- Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel Accesshigh
- Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Accesscritical
- "Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)medium
- MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generationhigh
- HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)high
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone…critical
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)high
- CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Executioncritical
- 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)medium
- PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague /…high
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…critical
- Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkithigh
- Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig'…high
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…high
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…high
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoorcritical
- Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed…high
Detection coverage
Threadlinqs maintains 144 detection rules mapped to T1014 (SPL 51, KQL 48, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.