Threadlinqs IntelligenceStart free

ATT&CK techniquePersistenceDefense Impairment

T1112 Modify Registry

PersistenceDefense ImpairmentEnterprise

As of 2026-10-05, T1112 (Modify Registry) appears in 183 tracked threats, first reported 2022-04-07 and most recently 2026-10-01, with linked actors including Void Arachne, Nightmare Eclipse, ALPHV; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
18331 critical, 130 high, 20 medium, 1 low
First seen
2022-04-07
Last seen
2026-10-01
Threat actors
70In the threats using it
Detection rules
283Blue tier and above

Data as of:

Activity timeline

T1112 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 76 reports, and 182 of the 183 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1112 Modify Registry is catalogued by MITRE ATT&CK under the Persistence and Defense Impairment tactics in the Enterprise matrix. Threadlinqs maps 183 of 2623 tracked threats (7%) to it; by severity that is 31 critical, 130 high, 20 medium, 1 low.

Threats that use T1112 most often also use T1027 Obfuscated Files or Information (110 threats), T1082 System Information Discovery (110 threats), T1685 Disable or Modify Tools (104 threats), T1140 Deobfuscate/Decode Files or Information (91 threats), T1005 Data from Local System (89 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

70 tracked threat actors appear in the threats that use T1112; the most frequent are Void Arachne (7), Nightmare Eclipse (5), ALPHV (4), APT38 (4), APT43 (4).

Mitigations

MITRE ATT&CK lists 1 mitigation for T1112.

Data sources

Telemetry that can reveal T1112, per MITRE ATT&CK.

  • Command — Command Execution
  • Network Traffic — Network Traffic Flow
  • Process — OS API Execution, Process Creation
  • Windows Registry — Windows Registry Key Creation, Windows Registry Key Deletion, Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 183 tracked threats that use T1112.

Detection coverage

Threadlinqs maintains 283 detection rules mapped to T1112 (SPL 101, KQL 101, Sigma 81). Rule content is available to Blue tier accounts and above; this page shows counts only.

283 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans