Activity timeline
T1125 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 35 reports, and 85 of the 85 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1125 Video Capture is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 85 of 2623 tracked threats (3.2%) to it; by severity that is 11 critical, 64 high, 9 medium.
Threats that use T1125 most often also use T1113 Screen Capture (64 threats), T1082 System Information Discovery (61 threats), T1027 Obfuscated Files or Information (51 threats), T1041 Exfiltration Over C2 Channel (49 threats), T1123 Audio Capture (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
30 tracked threat actors appear in the threats that use T1125; the most frequent are APT36 (3), Transparent Tribe (3), UAT-11795 (3), APT37 (2), APT38 (2).
Data sources
Telemetry that can reveal T1125, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution
Threat actors using it
Tracked threats
The 30 most recent of 85 tracked threats that use T1125.
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…high
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accountshigh
- FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATshigh
- New E4del and PINHOLE RATs Abuse FTP Server Banners as Dead-Drop Resolvershigh
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…high
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…high
- "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack…critical
- Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings)high
- Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscationhigh
- Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre…
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…high
- Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)high
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoorhigh
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaignhigh
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…high
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Callshigh
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…high
- Russian Intelligence Services Hijack Unsecured IP Cameras Across NATO, EU and Ukraine to Surveil Weapons…high
- Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure…high
- Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS…medium
- Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)medium
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaignsmedium
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef…medium
Detection coverage
Threadlinqs maintains 55 detection rules mapped to T1125 (SPL 11, KQL 24, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.