Activity timeline
T1106 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 102 reports, and 308 of the 308 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1106 Native API is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 308 of 2623 tracked threats (11.7%) to it; by severity that is 71 critical, 214 high, 21 medium, 1 low.
Threats that use T1106 most often also use T1082 System Information Discovery (228 threats), T1027 Obfuscated Files or Information (195 threats), T1005 Data from Local System (172 threats), T1140 Deobfuscate/Decode Files or Information (169 threats), T1041 Exfiltration Over C2 Channel (157 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
88 tracked threat actors appear in the threats that use T1106; the most frequent are Mustang Panda (8), APT38 (5), APT28 (4), Andariel (4), BlueDelta (4).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1106.
Data sources
Telemetry that can reveal T1106, per MITRE ATT&CK.
- Module — Module Load
- Process — OS API Execution
Threat actors using it
Tracked threats
The 30 most recent of 308 tracked threats that use T1106.
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on…medium
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)medium
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…critical
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)high
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypasshigh
- CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry…high
- CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…high
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injectionmedium
- CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalationhigh
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attackshigh
- BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loadinghigh
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Servicehigh
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leakhigh
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
- Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plotlow
- HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege…medium
- SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loadingmedium
- Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)critical
- Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demonhigh
Detection coverage
Threadlinqs maintains 295 detection rules mapped to T1106 (SPL 99, KQL 95, Sigma 101). Rule content is available to Blue tier accounts and above; this page shows counts only.