# T1112 Modify Registry

> As of 2026-10-05, T1112 (Modify Registry) appears in 183 tracked threats, first reported 2022-04-07 and most recently 2026-10-01, with linked actors including Void Arachne, Nightmare Eclipse, ALPHV; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 183 (31 critical, 130 high, 20 medium, 1 low)
- **First seen:** 2022-04-07
- **Last seen:** 2026-10-01
- **Threat actors:** 70
- **Detection rules:** 283 (counts only; Blue tier and above)

## Key facts

- **ID:** T1112
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Defense Impairment
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1112/

## Activity timeline

T1112 first appeared in tracked threats on 2022-04-07 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 76 reports, and 182 of the 183 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1112 Modify Registry is catalogued by MITRE ATT&CK under the Persistence and Defense Impairment tactics in the Enterprise matrix. Threadlinqs maps 183 of 2623 tracked threats (7%) to it; by severity that is 31 critical, 130 high, 20 medium, 1 low.

Threats that use T1112 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (110 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (110 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (104 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (91 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (89 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

70 tracked threat actors appear in the threats that use T1112; the most frequent are [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) (7), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (5), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (4), [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [APT43](https://intel.threadlinqs.com/actor/APT43) (4).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1112.

- [M1024 Restrict Registry Permissions](https://attack.mitre.org/mitigations/M1024/)

## Data sources

Telemetry that can reveal T1112, per MITRE ATT&CK.

- Command — Command Execution
- Network Traffic — Network Traffic Flow
- Process — OS API Execution, Process Creation
- Windows Registry — Windows Registry Key Creation, Windows Registry Key Deletion, Windows Registry Key Modification

## Threat actors using it

- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 7
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 5
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 4
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 4
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 3
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 3
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 3
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 3

## Tracked threats

The 30 most recent of 183 tracked threats that use T1112.

- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…](https://intel.threadlinqs.com/threat/TL-2026-2828) — medium — 2026-10-01
- [Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans](https://intel.threadlinqs.com/threat/TL-2026-2824) — high — 2026-10-01
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user…](https://intel.threadlinqs.com/threat/TL-2026-2786) — high — 2026-09-29
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…](https://intel.threadlinqs.com/threat/TL-2026-2773) — high — 2026-09-29
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…](https://intel.threadlinqs.com/threat/TL-2026-2645) — high — 2026-09-25
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)](https://intel.threadlinqs.com/threat/TL-2026-2628) — high — 2026-09-23
- [PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…](https://intel.threadlinqs.com/threat/TL-2026-2593) — medium — 2026-09-20
- [CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-2533) — critical — 2026-09-16
- [Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass](https://intel.threadlinqs.com/threat/TL-2026-2481) — high — 2026-09-13
- [CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry…](https://intel.threadlinqs.com/threat/TL-2026-2480) — high — 2026-09-13
- [BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2426) — high — 2026-09-10
- [PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2380) — high — 2026-09-07
- [FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…](https://intel.threadlinqs.com/threat/TL-2026-2362) — high — 2026-09-06
- [Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…](https://intel.threadlinqs.com/threat/TL-2026-2323) — high — 2026-09-03
- [Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…](https://intel.threadlinqs.com/threat/TL-2026-2283) — high — 2026-09-01
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — high — 2026-08-31
- [Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach](https://intel.threadlinqs.com/threat/TL-2026-2219) — high — 2026-08-29
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — high — 2026-08-29
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)](https://intel.threadlinqs.com/threat/TL-2026-2182) — high — 2026-08-28
- [SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2166) — medium — 2026-08-27
- [TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate Transparency](https://intel.threadlinqs.com/threat/TL-2026-2133) — high — 2026-08-24
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — critical — 2026-08-23

## Related CVEs

CVEs referenced by the tracked threats that use T1112, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514)
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519)
- [CVE-2026-21522](https://intel.threadlinqs.com/cve/CVE-2026-21522)

## Detection coverage

Threadlinqs maintains 283 detection rules mapped to T1112 (SPL 101, KQL 101, Sigma 81). Rule content is available to Blue tier accounts and above; this page shows counts only.

283 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1112
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
