# T1127 Trusted Developer Utilities Proxy Execution

> As of 2026-10-05, T1127 (Trusted Developer Utilities Proxy Execution) appears in 18 tracked threats, first reported 2026-02-12 and most recently 2026-09-03, with linked actors including APT36, Mini Shai-Hulud, MuddyWater; it most often appears alongside T1105 (Ingress Tool Transfer).

- **Tracked threats:** 18 (2 critical, 14 high, 2 medium)
- **First seen:** 2026-02-12
- **Last seen:** 2026-09-03
- **Threat actors:** 9
- **Detection rules:** 13 (counts only; Blue tier and above)

## Key facts

- **ID:** T1127
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1127/

## Activity timeline

T1127 first appeared in tracked threats on 2026-02-12 and was most recently reported on 2026-09-03. The busiest month was 2026-07 with 6 reports, and 18 of the 18 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1127 Trusted Developer Utilities Proxy Execution is catalogued by MITRE ATT&CK under the Execution and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 2 critical, 14 high, 2 medium.

Threats that use T1127 most often also use [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (12 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (10 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (10 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1127; the most frequent are [APT36](https://intel.threadlinqs.com/actor/APT36) (1), [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) (1), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (1), [SHADOW-WATER-063](https://intel.threadlinqs.com/actor/SHADOW-WATER-063) (1), [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1127.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1127, per MITRE ATT&CK.

- Command — Command Execution
- Module — Module Load
- Process — Process Creation, Process Metadata

## Threat actors using it

- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [SHADOW-WATER-063](https://intel.threadlinqs.com/actor/SHADOW-WATER-063) — 1
- [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) — 1
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 1
- [UAC-0247](https://intel.threadlinqs.com/actor/UAC-0247) — 1
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 1
- [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat) — 1

## Tracked threats

18 tracked threats use T1127.

- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…](https://intel.threadlinqs.com/threat/TL-2026-2304) — high — 2026-09-03
- [Abuse of AWS Systems Manager (SSM) Agent as a Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1644) — medium — 2026-07-22
- [ViteVenom Campaign: Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT](https://intel.threadlinqs.com/threat/TL-2026-1461) — high — 2026-07-17
- [Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositories](https://intel.threadlinqs.com/threat/TL-2026-1307) — high — 2026-07-14
- [Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to…](https://intel.threadlinqs.com/threat/TL-2026-1297) — high — 2026-07-14
- [ClickFix / KongTuke Clipboard-Hijacking Social-Engineering Technique (MITRE T1204.004) — Fake-CAPTCHA Lures…](https://intel.threadlinqs.com/threat/TL-2026-1130) — high — 2026-07-05
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — high — 2026-07-02
- [Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1242) — high — 2026-06-26
- [TonRAT Node.js Implant Campaign — Photo-Themed ZIP/.LNK Lures Target Hospitality Sector for Persistent…](https://intel.threadlinqs.com/threat/TL-2026-0946) — high — 2026-06-25
- [Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines…](https://intel.threadlinqs.com/threat/TL-2026-0928) — critical — 2026-06-23
- [Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers](https://intel.threadlinqs.com/threat/TL-2026-0822) — high — 2026-06-16
- [GPU-Targeted Cryptojacking Campaign — SEO + AI Chatbot Poisoning Delivers ScreenConnect & SimpleRunPE…](https://intel.threadlinqs.com/threat/TL-2026-0597) — high — 2026-05-26
- [SHADOW-WATER-063 Banana RAT — Brazilian Banking Trojan with FastAPI Polymorphism Panel, AES-256-CBC…](https://intel.threadlinqs.com/threat/TL-2026-0534) — high — 2026-05-19
- [AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian Governments, Hospitals, and Defense Personnel](https://intel.threadlinqs.com/threat/TL-2026-0389) — high — 2026-04-17
- [CPUID Supply Chain Attack Delivers STX RAT via Trojanized CPU-Z, HWMonitor, and PerfMonitor Downloads](https://intel.threadlinqs.com/threat/TL-2026-0364) — critical — 2026-04-14
- [.arpa TLD Abuse — IPv6 Reverse DNS Phishing, Dangling CNAME Hijacking via Hurricane Electric and Cloudflare](https://intel.threadlinqs.com/threat/TL-2026-0154) — medium — 2026-02-28
- [CVE-2026-20841: Command Injection in Windows Notepad Markdown Link Handling Enables Arbitrary Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1549) — high — 2026-02-19
- [Rogue AgreeTo Outlook Add-In: Abandoned Extension Hijacked Into Supply Chain Phishing Kit — 4,000+…](https://intel.threadlinqs.com/threat/TL-2026-0077) — high — 2026-02-12

## Related CVEs

CVEs referenced by the tracked threats that use T1127, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)

## Detection coverage

Threadlinqs maintains 13 detection rules mapped to T1127 (SPL 4, KQL 4, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

13 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1127.001 MSBuild — 5 tracked threats
- T1127.002 ClickOnce — 0 tracked threats
- T1127.003 JamPlus — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1127
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
