# T1106 Native API

> As of 2026-10-05, T1106 (Native API) appears in 308 tracked threats, first reported 2026-01-14 and most recently 2026-10-02, with linked actors including Mustang Panda, APT38, APT28; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 308 (71 critical, 214 high, 21 medium, 1 low)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-02
- **Threat actors:** 88
- **Detection rules:** 295 (counts only; Blue tier and above)

## Key facts

- **ID:** T1106
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1106/

## Activity timeline

T1106 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 102 reports, and 308 of the 308 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1106 Native API is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 308 of 2623 tracked threats (11.7%) to it; by severity that is 71 critical, 214 high, 21 medium, 1 low.

Threats that use T1106 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (228 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (195 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (172 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (169 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (157 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

88 tracked threat actors appear in the threats that use T1106; the most frequent are [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (8), [APT38](https://intel.threadlinqs.com/actor/APT38) (5), [APT28](https://intel.threadlinqs.com/actor/APT28) (4), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (4), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (4).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1106.

- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)

## Data sources

Telemetry that can reveal T1106, per MITRE ATT&CK.

- Module — Module Load
- Process — OS API Execution

## Threat actors using it

- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 8
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 4
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 4
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 4
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 4
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 3
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 3
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3

## Tracked threats

The 30 most recent of 308 tracked threats that use T1106.

- [Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on…](https://intel.threadlinqs.com/threat/TL-2026-2841) — medium — 2026-10-02
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)](https://intel.threadlinqs.com/threat/TL-2026-2613) — medium — 2026-09-22
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — high — 2026-09-19
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass](https://intel.threadlinqs.com/threat/TL-2026-2481) — high — 2026-09-13
- [CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry…](https://intel.threadlinqs.com/threat/TL-2026-2480) — high — 2026-09-13
- [CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…](https://intel.threadlinqs.com/threat/TL-2026-2479) — high — 2026-09-13
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2477) — high — 2026-09-13
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain](https://intel.threadlinqs.com/threat/TL-2026-2457) — high — 2026-09-12
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2426) — high — 2026-09-10
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — high — 2026-09-08
- [Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak](https://intel.threadlinqs.com/threat/TL-2026-2383) — high — 2026-09-07
- [FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…](https://intel.threadlinqs.com/threat/TL-2026-2362) — high — 2026-09-06
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02
- [Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plot](https://intel.threadlinqs.com/threat/TL-2026-2275) — low — 2026-08-31
- [HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege…](https://intel.threadlinqs.com/threat/TL-2026-2258) — medium — 2026-08-31
- [SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2166) — medium — 2026-08-27
- [Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)](https://intel.threadlinqs.com/threat/TL-2026-2156) — critical — 2026-08-26
- [Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon](https://intel.threadlinqs.com/threat/TL-2026-2148) — high — 2026-08-26

## Related CVEs

CVEs referenced by the tracked threats that use T1106, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-32435](https://intel.threadlinqs.com/cve/CVE-2023-32435)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-41990](https://intel.threadlinqs.com/cve/CVE-2023-41990)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)

## Detection coverage

Threadlinqs maintains 295 detection rules mapped to T1106 (SPL 99, KQL 95, Sigma 101). Rule content is available to Blue tier accounts and above; this page shows counts only.

295 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1106
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
