Activity timeline
T1127 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 6 reports, and 18 of the 18 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1127 Trusted Developer Utilities Proxy Execution is catalogued by MITRE ATT&CK under the Execution and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 2 critical, 14 high, 2 medium.
Threats that use T1127 most often also use T1105 Ingress Tool Transfer (12 threats), T1005 Data from Local System (10 threats), T1027 Obfuscated Files or Information (10 threats), T1059 Command and Scripting Interpreter (10 threats), T1082 System Information Discovery (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1127; the most frequent are APT36 (1), Mini Shai-Hulud (1), MuddyWater (1), SHADOW-WATER-063 (1), SideCopy (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1127.
Data sources
Telemetry that can reveal T1127, per MITRE ATT&CK.
- Command — Command Execution
- Module — Module Load
- Process — Process Creation, Process Metadata
Threat actors using it
Tracked threats
18 tracked threats use T1127.
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- Abuse of AWS Systems Manager (SSM) Agent as a Remote Access Trojanmedium
- ViteVenom Campaign: Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAThigh
- Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositorieshigh
- Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to…high
- ClickFix / KongTuke Clipboard-Hijacking Social-Engineering Technique (MITRE T1204.004) — Fake-CAPTCHA Lures…high
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchershigh
- Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…high
- TonRAT Node.js Implant Campaign — Photo-Themed ZIP/.LNK Lures Target Hospitality Sector for Persistent…high
- Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines…critical
- Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installershigh
- GPU-Targeted Cryptojacking Campaign — SEO + AI Chatbot Poisoning Delivers ScreenConnect & SimpleRunPE…high
- SHADOW-WATER-063 Banana RAT — Brazilian Banking Trojan with FastAPI Polymorphism Panel, AES-256-CBC…high
- AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian Governments, Hospitals, and Defense Personnelhigh
- CPUID Supply Chain Attack Delivers STX RAT via Trojanized CPU-Z, HWMonitor, and PerfMonitor Downloadscritical
- .arpa TLD Abuse — IPv6 Reverse DNS Phishing, Dangling CNAME Hijacking via Hurricane Electric and Cloudflaremedium
- CVE-2026-20841: Command Injection in Windows Notepad Markdown Link Handling Enables Arbitrary Code Executionhigh
- Rogue AgreeTo Outlook Add-In: Abandoned Extension Hijacked Into Supply Chain Phishing Kit — 4,000+…high
Detection coverage
Threadlinqs maintains 13 detection rules mapped to T1127 (SPL 4, KQL 4, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1127.001 MSBuild — 5 tracked threats
- T1127.002 ClickOnce — 0 tracked threats
- T1127.003 JamPlus — 0 tracked threats