# T1014 Rootkit

> As of 2026-10-05, T1014 (Rootkit) appears in 81 tracked threats, first reported 2026-02-04 and most recently 2026-09-27, with linked actors including GhostEmperor, Sapphire Sleet, APT38; it most often appears alongside T1685 (Disable or Modify Tools).

- **Tracked threats:** 81 (27 critical, 48 high, 5 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-09-27
- **Threat actors:** 51
- **Detection rules:** 144 (counts only; Blue tier and above)

## Key facts

- **ID:** T1014
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1014/

## Activity timeline

T1014 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 23 reports, and 81 of the 81 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1014 Rootkit is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 81 of 2623 tracked threats (3.1%) to it; by severity that is 27 critical, 48 high, 5 medium.

Threats that use T1014 most often also use [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (51 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (50 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (46 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (42 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (40 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

51 tracked threat actors appear in the threats that use T1014; the most frequent are [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (4), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (4), [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (3), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (3).

## Data sources

Telemetry that can reveal T1014, per MITRE ATT&CK.

- Drive — Drive Modification
- File — File Modification
- Firmware — Firmware Modification

## Threat actors using it

- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 3
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 3
- [UAT-9244](https://intel.threadlinqs.com/actor/UAT-9244) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 2
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 2

## Tracked threats

The 30 most recent of 81 tracked threats that use T1014.

- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…](https://intel.threadlinqs.com/threat/TL-2026-2619) — critical — 2026-09-22
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…](https://intel.threadlinqs.com/threat/TL-2026-2561) — critical — 2026-09-18
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…](https://intel.threadlinqs.com/threat/TL-2026-2303) — medium — 2026-09-02
- [Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing](https://intel.threadlinqs.com/threat/TL-2026-2284) — high — 2026-09-01
- [Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2](https://intel.threadlinqs.com/threat/TL-2026-2264) — high — 2026-08-30
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — critical — 2026-08-23
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…](https://intel.threadlinqs.com/threat/TL-2026-2096) — high — 2026-08-21
- [Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel Access](https://intel.threadlinqs.com/threat/TL-2026-2049) — high — 2026-08-17
- [Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Access](https://intel.threadlinqs.com/threat/TL-2026-2041) — critical — 2026-08-17
- ["Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)](https://intel.threadlinqs.com/threat/TL-2026-2039) — medium — 2026-08-17
- [MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generation](https://intel.threadlinqs.com/threat/TL-2026-2036) — high — 2026-08-16
- [HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)](https://intel.threadlinqs.com/threat/TL-2026-2013) — high — 2026-08-14
- [Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side](https://intel.threadlinqs.com/threat/TL-2026-2002) — high — 2026-08-13
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone…](https://intel.threadlinqs.com/threat/TL-2026-1912) — critical — 2026-08-06
- [1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)](https://intel.threadlinqs.com/threat/TL-2026-1837) — high — 2026-08-03
- [CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1812) — critical — 2026-08-01
- [1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)](https://intel.threadlinqs.com/threat/TL-2026-1791) — medium — 2026-07-31
- [PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague /…](https://intel.threadlinqs.com/threat/TL-2026-1772) — high — 2026-07-30
- [Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC](https://intel.threadlinqs.com/threat/TL-2026-1730) — 2026-07-27
- [CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-1725) — critical — 2026-07-27
- [Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkit](https://intel.threadlinqs.com/threat/TL-2026-1498) — high — 2026-07-18
- [Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig'…](https://intel.threadlinqs.com/threat/TL-2026-1489) — high — 2026-07-18
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…](https://intel.threadlinqs.com/threat/TL-2026-1477) — high — 2026-07-18
- [Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…](https://intel.threadlinqs.com/threat/TL-2026-1453) — high — 2026-07-17
- [Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1404) — critical — 2026-07-16
- [Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed…](https://intel.threadlinqs.com/threat/TL-2026-1400) — high — 2026-07-16

## Related CVEs

CVEs referenced by the tracked threats that use T1014, most frequent first.

- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-10189](https://intel.threadlinqs.com/cve/CVE-2020-10189)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)

## Detection coverage

Threadlinqs maintains 144 detection rules mapped to T1014 (SPL 51, KQL 48, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.

144 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1014
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
