# T1123 Audio Capture

> As of 2026-10-05, T1123 (Audio Capture) appears in 80 tracked threats, first reported 2026-02-12 and most recently 2026-09-29, with linked actors including APT37, Void Arachne, APT36; it most often appears alongside T1113 (Screen Capture).

- **Tracked threats:** 80 (8 critical, 62 high, 10 medium)
- **First seen:** 2026-02-12
- **Last seen:** 2026-09-29
- **Threat actors:** 28
- **Detection rules:** 50 (counts only; Blue tier and above)

## Key facts

- **ID:** T1123
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1123/

## Activity timeline

T1123 first appeared in tracked threats on 2026-02-12 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 33 reports, and 80 of the 80 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1123 Audio Capture is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 80 of 2623 tracked threats (3%) to it; by severity that is 8 critical, 62 high, 10 medium.

Threats that use T1123 most often also use [T1113 Screen Capture](https://intel.threadlinqs.com/technique/T1113) (67 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (60 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (52 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (52 threats), [T1125 Video Capture](https://intel.threadlinqs.com/technique/T1125) (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

28 tracked threat actors appear in the threats that use T1123; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (5), [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) (4), [APT36](https://intel.threadlinqs.com/actor/APT36) (3), [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) (3), [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) (3).

## Data sources

Telemetry that can reveal T1123, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 5
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 3
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [UNC2452](https://intel.threadlinqs.com/actor/UNC2452) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 2
- [Iran Ministry of Intelligence](https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Security](https://intel.threadlinqs.com/actor/Security) — 2

## Tracked threats

The 30 most recent of 80 tracked threats that use T1123.

- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…](https://intel.threadlinqs.com/threat/TL-2026-2519) — high — 2026-09-15
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — high — 2026-08-31
- [Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts](https://intel.threadlinqs.com/threat/TL-2026-2167) — high — 2026-08-27
- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…](https://intel.threadlinqs.com/threat/TL-2026-2170) — high — 2026-08-26
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [Apple Patches ImageIO Integer Overflow (CVE-2026-65346) Exploitable via Malicious Images](https://intel.threadlinqs.com/threat/TL-2026-2060) — high — 2026-08-18
- ["Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack…](https://intel.threadlinqs.com/threat/TL-2026-2001) — critical — 2026-08-12
- [Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings)](https://intel.threadlinqs.com/threat/TL-2026-1950) — high — 2026-08-08
- [CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…](https://intel.threadlinqs.com/threat/TL-2026-1857) — high — 2026-08-04
- [CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT…](https://intel.threadlinqs.com/threat/TL-2026-1853) — critical — 2026-08-04
- [CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign](https://intel.threadlinqs.com/threat/TL-2026-2765) — high — 2026-07-31
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD](https://intel.threadlinqs.com/threat/TL-2026-1787) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…](https://intel.threadlinqs.com/threat/TL-2026-1777) — high — 2026-07-30
- [UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…](https://intel.threadlinqs.com/threat/TL-2026-1726) — medium — 2026-07-27
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…](https://intel.threadlinqs.com/threat/TL-2026-1664) — high — 2026-07-24
- [HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API](https://intel.threadlinqs.com/threat/TL-2026-1555) — high — 2026-07-20
- [Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS…](https://intel.threadlinqs.com/threat/TL-2026-1500) — medium — 2026-07-18
- [Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)](https://intel.threadlinqs.com/threat/TL-2026-1487) — medium — 2026-07-18
- [DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1485) — medium — 2026-07-18
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18

## Related CVEs

CVEs referenced by the tracked threats that use T1123, most frequent first.

- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174)
- [CVE-2025-43529](https://intel.threadlinqs.com/cve/CVE-2025-43529)
- [CVE-2026-20700](https://intel.threadlinqs.com/cve/CVE-2026-20700)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2021-1048](https://intel.threadlinqs.com/cve/CVE-2021-1048)
- [CVE-2021-37973](https://intel.threadlinqs.com/cve/CVE-2021-37973)
- [CVE-2021-37976](https://intel.threadlinqs.com/cve/CVE-2021-37976)
- [CVE-2021-38000](https://intel.threadlinqs.com/cve/CVE-2021-38000)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)
- [CVE-2023-2033](https://intel.threadlinqs.com/cve/CVE-2023-2033)
- [CVE-2023-2136](https://intel.threadlinqs.com/cve/CVE-2023-2136)
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079)
- [CVE-2023-41991](https://intel.threadlinqs.com/cve/CVE-2023-41991)
- [CVE-2023-41992](https://intel.threadlinqs.com/cve/CVE-2023-41992)
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993)
- [CVE-2023-4762](https://intel.threadlinqs.com/cve/CVE-2023-4762)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2023-6895](https://intel.threadlinqs.com/cve/CVE-2023-6895)
- [CVE-2024-4610](https://intel.threadlinqs.com/cve/CVE-2024-4610)
- [CVE-2025-20700](https://intel.threadlinqs.com/cve/CVE-2025-20700)
- [CVE-2025-20701](https://intel.threadlinqs.com/cve/CVE-2025-20701)
- [CVE-2025-20702](https://intel.threadlinqs.com/cve/CVE-2025-20702)
- [CVE-2025-31277](https://intel.threadlinqs.com/cve/CVE-2025-31277)
- [CVE-2025-43510](https://intel.threadlinqs.com/cve/CVE-2025-43510)
- [CVE-2025-43520](https://intel.threadlinqs.com/cve/CVE-2025-43520)
- [CVE-2025-48543](https://intel.threadlinqs.com/cve/CVE-2025-48543)
- [CVE-2025-6554](https://intel.threadlinqs.com/cve/CVE-2025-6554)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-20146](https://intel.threadlinqs.com/cve/CVE-2026-20146)

## Detection coverage

Threadlinqs maintains 50 detection rules mapped to T1123 (SPL 10, KQL 21, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.

50 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1123
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
