Activity timeline
T1112 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 76 reports, and 182 of the 183 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1112 Modify Registry is catalogued by MITRE ATT&CK under the Persistence and Defense Impairment tactics in the Enterprise matrix. Threadlinqs maps 183 of 2623 tracked threats (7%) to it; by severity that is 31 critical, 130 high, 20 medium, 1 low.
Threats that use T1112 most often also use T1027 Obfuscated Files or Information (110 threats), T1082 System Information Discovery (110 threats), T1685 Disable or Modify Tools (104 threats), T1140 Deobfuscate/Decode Files or Information (91 threats), T1005 Data from Local System (89 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
70 tracked threat actors appear in the threats that use T1112; the most frequent are Void Arachne (7), Nightmare Eclipse (5), ALPHV (4), APT38 (4), APT43 (4).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1112.
Data sources
Telemetry that can reveal T1112, per MITRE ATT&CK.
- Command — Command Execution
- Network Traffic — Network Traffic Flow
- Process — OS API Execution, Process Creation
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Deletion, Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 183 tracked threats that use T1112.
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…medium
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scanshigh
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user…high
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)high
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…medium
- CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)critical
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypasshigh
- CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry…high
- BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loadinghigh
- PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionhigh
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…high
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…high
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breachhigh
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Electionhigh
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)high
- SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loadingmedium
- TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate Transparencyhigh
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitationcritical
Detection coverage
Threadlinqs maintains 283 detection rules mapped to T1112 (SPL 101, KQL 101, Sigma 81). Rule content is available to Blue tier accounts and above; this page shows counts only.