Threadlinqs IntelligenceStart free

ATT&CK techniquePersistence

T1176 Software Extensions

PersistenceEnterprise

As of 2026-10-05, T1176 (Software Extensions) appears in 75 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including GlassWorm, DarkSpectre, Forg365 operators; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
7514 critical, 58 high, 2 medium
First seen
2026-02-02
Last seen
2026-10-03
Threat actors
26In the threats using it
Detection rules
122Blue tier and above

Data as of:

Activity timeline

T1176 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 24 reports, and 75 of the 75 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1176 Software Extensions is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 75 of 2623 tracked threats (2.9%) to it; by severity that is 14 critical, 58 high, 2 medium.

Threats that use T1176 most often also use T1027 Obfuscated Files or Information (46 threats), T1005 Data from Local System (42 threats), T1539 Steal Web Session Cookie (42 threats), T1041 Exfiltration Over C2 Channel (38 threats), T1071 Application Layer Protocol (35 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

26 tracked threat actors appear in the threats that use T1176; the most frequent are GlassWorm (3), DarkSpectre (2), Forg365 operators (2), GlassWorm Operator (2), GlassWorm Operators (2).

Mitigations

MITRE ATT&CK lists 5 mitigations for T1176.

Data sources

Telemetry that can reveal T1176, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Creation
  • Network Traffic — Network Connection Creation, Network Traffic Flow
  • Process — Process Creation
  • Windows Registry — Windows Registry Key Creation

Threat actors using it

Tracked threats

The 30 most recent of 75 tracked threats that use T1176.

Detection coverage

Threadlinqs maintains 122 detection rules mapped to T1176 (SPL 39, KQL 38, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.

122 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1176.001 Browser Extensions — 4 tracked threats
  • T1176.002 IDE Extensions — 0 tracked threats