# T1125 Video Capture

> As of 2026-10-05, T1125 (Video Capture) appears in 85 tracked threats, first reported 2026-01-14 and most recently 2026-09-29, with linked actors including APT36, Transparent Tribe, UAT-11795; it most often appears alongside T1113 (Screen Capture).

- **Tracked threats:** 85 (11 critical, 64 high, 9 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-09-29
- **Threat actors:** 30
- **Detection rules:** 55 (counts only; Blue tier and above)

## Key facts

- **ID:** T1125
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1125/

## Activity timeline

T1125 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 35 reports, and 85 of the 85 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1125 Video Capture is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 85 of 2623 tracked threats (3.2%) to it; by severity that is 11 critical, 64 high, 9 medium.

Threats that use T1125 most often also use [T1113 Screen Capture](https://intel.threadlinqs.com/technique/T1113) (64 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (61 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (51 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (49 threats), [T1123 Audio Capture](https://intel.threadlinqs.com/technique/T1123) (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

30 tracked threat actors appear in the threats that use T1125; the most frequent are [APT36](https://intel.threadlinqs.com/actor/APT36) (3), [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) (3), [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) (3), [APT37](https://intel.threadlinqs.com/actor/APT37) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (2).

## Data sources

Telemetry that can reveal T1125, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution

## Threat actors using it

- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 2
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945) — 2
- [TA4922](https://intel.threadlinqs.com/actor/TA4922) — 2
- [UNC2452](https://intel.threadlinqs.com/actor/UNC2452) — 2

## Tracked threats

The 30 most recent of 85 tracked threats that use T1125.

- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…](https://intel.threadlinqs.com/threat/TL-2026-2519) — high — 2026-09-15
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — high — 2026-09-11
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts](https://intel.threadlinqs.com/threat/TL-2026-2167) — high — 2026-08-27
- [FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATs](https://intel.threadlinqs.com/threat/TL-2026-2119) — high — 2026-08-23
- [New E4del and PINHOLE RATs Abuse FTP Server Banners as Dead-Drop Resolvers](https://intel.threadlinqs.com/threat/TL-2026-2117) — high — 2026-08-22
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…](https://intel.threadlinqs.com/threat/TL-2026-2031) — high — 2026-08-16
- ["Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack…](https://intel.threadlinqs.com/threat/TL-2026-2001) — critical — 2026-08-12
- [Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings)](https://intel.threadlinqs.com/threat/TL-2026-1950) — high — 2026-08-08
- [Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1914) — high — 2026-08-06
- [Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre…](https://intel.threadlinqs.com/threat/TL-2026-1889) — 2026-08-05
- [CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…](https://intel.threadlinqs.com/threat/TL-2026-1857) — high — 2026-08-04
- [Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)](https://intel.threadlinqs.com/threat/TL-2026-1846) — high — 2026-08-03
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign](https://intel.threadlinqs.com/threat/TL-2026-2765) — high — 2026-07-31
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…](https://intel.threadlinqs.com/threat/TL-2026-1751) — high — 2026-07-29
- [BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls](https://intel.threadlinqs.com/threat/TL-2026-1720) — high — 2026-07-27
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [Russian Intelligence Services Hijack Unsecured IP Cameras Across NATO, EU and Ukraine to Surveil Weapons…](https://intel.threadlinqs.com/threat/TL-2026-1624) — high — 2026-07-22
- [Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-1501) — high — 2026-07-18
- [Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS…](https://intel.threadlinqs.com/threat/TL-2026-1500) — medium — 2026-07-18
- [Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)](https://intel.threadlinqs.com/threat/TL-2026-1487) — medium — 2026-07-18
- [DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1485) — medium — 2026-07-18
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef…](https://intel.threadlinqs.com/threat/TL-2026-1480) — medium — 2026-07-18

## Related CVEs

CVEs referenced by the tracked threats that use T1125, most frequent first.

- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2016-7407](https://intel.threadlinqs.com/cve/CVE-2016-7407)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882)
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570)
- [CVE-2021-1048](https://intel.threadlinqs.com/cve/CVE-2021-1048)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-37973](https://intel.threadlinqs.com/cve/CVE-2021-37973)
- [CVE-2021-37976](https://intel.threadlinqs.com/cve/CVE-2021-37976)
- [CVE-2021-38000](https://intel.threadlinqs.com/cve/CVE-2021-38000)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)
- [CVE-2021-39275](https://intel.threadlinqs.com/cve/CVE-2021-39275)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-2033](https://intel.threadlinqs.com/cve/CVE-2023-2033)
- [CVE-2023-2136](https://intel.threadlinqs.com/cve/CVE-2023-2136)
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079)
- [CVE-2023-41991](https://intel.threadlinqs.com/cve/CVE-2023-41991)
- [CVE-2023-41992](https://intel.threadlinqs.com/cve/CVE-2023-41992)
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-4762](https://intel.threadlinqs.com/cve/CVE-2023-4762)
- [CVE-2023-6895](https://intel.threadlinqs.com/cve/CVE-2023-6895)
- [CVE-2024-11182](https://intel.threadlinqs.com/cve/CVE-2024-11182)
- [CVE-2024-27443](https://intel.threadlinqs.com/cve/CVE-2024-27443)
- [CVE-2024-4610](https://intel.threadlinqs.com/cve/CVE-2024-4610)

## Detection coverage

Threadlinqs maintains 55 detection rules mapped to T1125 (SPL 11, KQL 24, Sigma 20). Rule content is available to Blue tier accounts and above; this page shows counts only.

55 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1125
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
