# T1176 Software Extensions

> As of 2026-10-05, T1176 (Software Extensions) appears in 75 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including GlassWorm, DarkSpectre, Forg365 operators; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 75 (14 critical, 58 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 26
- **Detection rules:** 122 (counts only; Blue tier and above)

## Key facts

- **ID:** T1176
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1176/

## Activity timeline

T1176 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 24 reports, and 75 of the 75 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1176 Software Extensions is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 75 of 2623 tracked threats (2.9%) to it; by severity that is 14 critical, 58 high, 2 medium.

Threats that use T1176 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (46 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (42 threats), [T1539 Steal Web Session Cookie](https://intel.threadlinqs.com/technique/T1539) (42 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (38 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (35 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

26 tracked threat actors appear in the threats that use T1176; the most frequent are [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) (3), [DarkSpectre](https://intel.threadlinqs.com/actor/DarkSpectre) (2), [Forg365 operators](https://intel.threadlinqs.com/actor/Forg365%20operators) (2), [GlassWorm Operator](https://intel.threadlinqs.com/actor/GlassWorm%20Operator) (2), [GlassWorm Operators](https://intel.threadlinqs.com/actor/GlassWorm%20Operators) (2).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1176.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1176, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Flow
- Process — Process Creation
- Windows Registry — Windows Registry Key Creation

## Threat actors using it

- [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) — 3
- [DarkSpectre](https://intel.threadlinqs.com/actor/DarkSpectre) — 2
- [Forg365 operators](https://intel.threadlinqs.com/actor/Forg365%20operators) — 2
- [GlassWorm Operator](https://intel.threadlinqs.com/actor/GlassWorm%20Operator) — 2
- [GlassWorm Operators](https://intel.threadlinqs.com/actor/GlassWorm%20Operators) — 2
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 2
- [REF9334](https://intel.threadlinqs.com/actor/REF9334) — 2
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [CL-CRI-1089](https://intel.threadlinqs.com/actor/CL-CRI-1089) — 1

## Tracked threats

The 30 most recent of 75 tracked threats that use T1176.

- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer](https://intel.threadlinqs.com/threat/TL-2026-2699) — high — 2026-09-27
- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…](https://intel.threadlinqs.com/threat/TL-2026-2544) — high — 2026-09-16
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2380) — high — 2026-09-07
- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2273) — high — 2026-09-01
- [Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2235) — high — 2026-08-30
- [Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detection](https://intel.threadlinqs.com/threat/TL-2026-2145) — high — 2026-08-25
- [Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access](https://intel.threadlinqs.com/threat/TL-2026-2129) — medium — 2026-08-24
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…](https://intel.threadlinqs.com/threat/TL-2026-2120) — high — 2026-08-23
- [OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio…](https://intel.threadlinqs.com/threat/TL-2026-2018) — high — 2026-08-14
- [Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side](https://intel.threadlinqs.com/threat/TL-2026-2002) — high — 2026-08-13
- [Fake CCleaner Installer Delivers GhostDesk Chrome Spyware with Keylogging, Credential Theft, and Crypto…](https://intel.threadlinqs.com/threat/TL-2026-1990) — high — 2026-08-11
- [Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader…](https://intel.threadlinqs.com/threat/TL-2026-1976) — high — 2026-08-10
- [GepyS Banking Malware and Rust Clipboard Hijacker: Two H1 2026 Attack Chains (Gen Digital)](https://intel.threadlinqs.com/threat/TL-2026-1934) — high — 2026-08-07
- [Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws](https://intel.threadlinqs.com/threat/TL-2026-1931) — critical — 2026-08-07
- [ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…](https://intel.threadlinqs.com/threat/TL-2026-1800) — high — 2026-07-31
- [Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150…](https://intel.threadlinqs.com/threat/TL-2026-1795) — 2026-07-31
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29
- [Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…](https://intel.threadlinqs.com/threat/TL-2026-1693) — high — 2026-07-25
- [CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web…](https://intel.threadlinqs.com/threat/TL-2026-1637) — high — 2026-07-22
- [Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through…](https://intel.threadlinqs.com/threat/TL-2026-1605) — high — 2026-07-22
- [Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-1501) — high — 2026-07-18
- [PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…](https://intel.threadlinqs.com/threat/TL-2026-1416) — high — 2026-07-16
- [OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Apps](https://intel.threadlinqs.com/threat/TL-2026-1383) — high — 2026-07-15
- [OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)](https://intel.threadlinqs.com/threat/TL-2026-1363) — critical — 2026-07-15
- [Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and…](https://intel.threadlinqs.com/threat/TL-2026-1318) — critical — 2026-07-14

## Related CVEs

CVEs referenced by the tracked threats that use T1176, most frequent first.

- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-2586](https://intel.threadlinqs.com/cve/CVE-2022-2586)
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386)
- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487)
- [CVE-2023-4911](https://intel.threadlinqs.com/cve/CVE-2023-4911)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-10881](https://intel.threadlinqs.com/cve/CVE-2026-10881)
- [CVE-2026-10882](https://intel.threadlinqs.com/cve/CVE-2026-10882)
- [CVE-2026-12437](https://intel.threadlinqs.com/cve/CVE-2026-12437)
- [CVE-2026-12438](https://intel.threadlinqs.com/cve/CVE-2026-12438)
- [CVE-2026-12439](https://intel.threadlinqs.com/cve/CVE-2026-12439)
- [CVE-2026-12440](https://intel.threadlinqs.com/cve/CVE-2026-12440)
- [CVE-2026-12441](https://intel.threadlinqs.com/cve/CVE-2026-12441)
- [CVE-2026-12442](https://intel.threadlinqs.com/cve/CVE-2026-12442)
- [CVE-2026-15107](https://intel.threadlinqs.com/cve/CVE-2026-15107)
- [CVE-2026-15129](https://intel.threadlinqs.com/cve/CVE-2026-15129)
- [CVE-2026-15130](https://intel.threadlinqs.com/cve/CVE-2026-15130)
- [CVE-2026-15131](https://intel.threadlinqs.com/cve/CVE-2026-15131)
- [CVE-2026-15132](https://intel.threadlinqs.com/cve/CVE-2026-15132)
- [CVE-2026-15899](https://intel.threadlinqs.com/cve/CVE-2026-15899)
- [CVE-2026-15900](https://intel.threadlinqs.com/cve/CVE-2026-15900)
- [CVE-2026-15901](https://intel.threadlinqs.com/cve/CVE-2026-15901)
- [CVE-2026-15902](https://intel.threadlinqs.com/cve/CVE-2026-15902)
- [CVE-2026-15903](https://intel.threadlinqs.com/cve/CVE-2026-15903)
- [CVE-2026-15904](https://intel.threadlinqs.com/cve/CVE-2026-15904)
- [CVE-2026-15905](https://intel.threadlinqs.com/cve/CVE-2026-15905)
- [CVE-2026-16413](https://intel.threadlinqs.com/cve/CVE-2026-16413)

## Detection coverage

Threadlinqs maintains 122 detection rules mapped to T1176 (SPL 39, KQL 38, Sigma 45). Rule content is available to Blue tier accounts and above; this page shows counts only.

122 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1176.001 Browser Extensions — 4 tracked threats
- T1176.002 IDE Extensions — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1176
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
