# T1129 Shared Modules

> As of 2026-10-05, T1129 (Shared Modules) appears in 68 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including Void Arachne, APT36, Cavern Manticore; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 68 (13 critical, 53 high, 2 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 32
- **Detection rules:** 60 (counts only; Blue tier and above)

## Key facts

- **ID:** T1129
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1129/

## Activity timeline

T1129 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 28 reports, and 67 of the 68 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1129 Shared Modules is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 68 of 2623 tracked threats (2.6%) to it; by severity that is 13 critical, 53 high, 2 medium.

Threats that use T1129 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (56 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (56 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (46 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (46 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (45 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1129; the most frequent are [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) (3), [APT36](https://intel.threadlinqs.com/actor/APT36) (2), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (2), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1129.

- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)

## Data sources

Telemetry that can reveal T1129, per MITRE ATT&CK.

- Module — Module Load
- Process — OS API Execution

## Threat actors using it

- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 3
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 2
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 2
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1

## Tracked threats

The 30 most recent of 68 tracked threats that use T1129.

- [BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…](https://intel.threadlinqs.com/threat/TL-2026-2875) — high — 2026-10-03
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2](https://intel.threadlinqs.com/threat/TL-2026-2520) — high — 2026-09-15
- [JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloads](https://intel.threadlinqs.com/threat/TL-2026-2259) — high — 2026-08-31
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — high — 2026-08-31
- [ShieldBreak: Windows Defender Cloud-Hydration Zero-Day Bypasses RoguePlanet Patch (CVE-2026-50656) for…](https://intel.threadlinqs.com/threat/TL-2026-2020) — critical — 2026-08-14
- [SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD](https://intel.threadlinqs.com/threat/TL-2026-1787) — high — 2026-07-31
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [Joyfill npm Packages Compromised with Blockchain C2 Loader](https://intel.threadlinqs.com/threat/TL-2026-1771) — medium — 2026-07-30
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Fastjson 1.x RCE (CVE-2026-16723) — Gadget-Free Deserialization Bypass Actively Exploited in Spring Boot…](https://intel.threadlinqs.com/threat/TL-2026-1682) — critical — 2026-07-25
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power Grids](https://intel.threadlinqs.com/threat/TL-2026-1598) — high — 2026-07-21
- [ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage](https://intel.threadlinqs.com/threat/TL-2026-1558) — high — 2026-07-20
- [TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain](https://intel.threadlinqs.com/threat/TL-2026-1557) — high — 2026-07-20
- [HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API](https://intel.threadlinqs.com/threat/TL-2026-1555) — high — 2026-07-20
- [Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT](https://intel.threadlinqs.com/threat/TL-2026-1552) — high — 2026-07-19
- [Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1454) — high — 2026-07-17
- [ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest…](https://intel.threadlinqs.com/threat/TL-2026-1444) — high — 2026-07-17
- [GST Refund Phishing Delivers Remcos RAT via Multi-Stage .NET Bitmap-Steganography Infection Chain](https://intel.threadlinqs.com/threat/TL-2026-1443) — high — 2026-07-17
- [TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chain](https://intel.threadlinqs.com/threat/TL-2026-1420) — high — 2026-07-16
- [UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign](https://intel.threadlinqs.com/threat/TL-2026-1413) — high — 2026-07-16
- [QuimaRAT v2.0: Cross-Platform Java-Based RAT Sold via Malware-as-a-Service Model](https://intel.threadlinqs.com/threat/TL-2026-1389) — high — 2026-07-15
- [AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader](https://intel.threadlinqs.com/threat/TL-2026-1387) — critical — 2026-07-15
- [AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver…](https://intel.threadlinqs.com/threat/TL-2026-1344) — high — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use T1129, most frequent first.

- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-36899](https://intel.threadlinqs.com/cve/CVE-2023-36899)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-16723](https://intel.threadlinqs.com/cve/CVE-2026-16723)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-50656](https://intel.threadlinqs.com/cve/CVE-2026-50656)
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102)

## Detection coverage

Threadlinqs maintains 60 detection rules mapped to T1129 (SPL 22, KQL 17, Sigma 21). Rule content is available to Blue tier accounts and above; this page shows counts only.

60 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1129
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
