Activity timeline
T1123 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 33 reports, and 80 of the 80 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1123 Audio Capture is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 80 of 2623 tracked threats (3%) to it; by severity that is 8 critical, 62 high, 10 medium.
Threats that use T1123 most often also use T1113 Screen Capture (67 threats), T1082 System Information Discovery (60 threats), T1027 Obfuscated Files or Information (52 threats), T1041 Exfiltration Over C2 Channel (52 threats), T1125 Video Capture (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
28 tracked threat actors appear in the threats that use T1123; the most frequent are APT37 (5), Void Arachne (4), APT36 (3), Midnight Blizzard (3), Transparent Tribe (3).
Data sources
Telemetry that can reveal T1123, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution
Threat actors using it
Tracked threats
The 30 most recent of 80 tracked threats that use T1123.
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…high
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accountshigh
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…high
- Apple Patches ImageIO Integer Overflow (CVE-2026-65346) Exploitable via Malicious Imageshigh
- "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack…critical
- Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings)high
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…high
- CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT…critical
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaignhigh
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVDhigh
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…high
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…medium
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…high
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…high
- ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…high
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS…medium
- Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)medium
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaignsmedium
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
Detection coverage
Threadlinqs maintains 50 detection rules mapped to T1123 (SPL 10, KQL 21, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.