Activity timeline
T1129 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 28 reports, and 67 of the 68 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1129 Shared Modules is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 68 of 2623 tracked threats (2.6%) to it; by severity that is 13 critical, 53 high, 2 medium.
Threats that use T1129 most often also use T1027 Obfuscated Files or Information (56 threats), T1082 System Information Discovery (56 threats), T1005 Data from Local System (46 threats), T1041 Exfiltration Over C2 Channel (46 threats), T1140 Deobfuscate/Decode Files or Information (45 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
32 tracked threat actors appear in the threats that use T1129; the most frequent are Void Arachne (3), APT36 (2), Cavern Manticore (2), Mustang Panda (2), TeamPCP (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1129.
Data sources
Telemetry that can reveal T1129, per MITRE ATT&CK.
- Module — Module Load
- Process — OS API Execution
Threat actors using it
Tracked threats
The 30 most recent of 68 tracked threats that use T1129.
- BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…high
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…critical
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2high
- JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloadshigh
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloadinghigh
- ShieldBreak: Windows Defender Cloud-Hydration Zero-Day Bypasses RoguePlanet Patch (CVE-2026-50656) for…critical
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVDhigh
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- Joyfill npm Packages Compromised with Blockchain C2 Loadermedium
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…critical
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojancritical
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resiliencehigh
- Fastjson 1.x RCE (CVE-2026-16723) — Gadget-Free Deserialization Bypass Actively Exploited in Spring Boot…critical
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power Gridshigh
- ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stagehigh
- TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chainhigh
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAThigh
- Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…high
- ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest…high
- GST Refund Phishing Delivers Remcos RAT via Multi-Stage .NET Bitmap-Steganography Infection Chainhigh
- TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chainhigh
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaignhigh
- QuimaRAT v2.0: Cross-Platform Java-Based RAT Sold via Malware-as-a-Service Modelhigh
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loadercritical
- AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver…high
Detection coverage
Threadlinqs maintains 60 detection rules mapped to T1129 (SPL 22, KQL 17, Sigma 21). Rule content is available to Blue tier accounts and above; this page shows counts only.