# T1200 Hardware Additions

> As of 2026-10-05, T1200 (Hardware Additions) appears in 16 tracked threats, first reported 2026-04-23 and most recently 2026-09-01, with linked actors including Luna Moth, Silent Ransom Group, UNC3753; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 16 (6 critical, 8 high, 1 medium)
- **First seen:** 2026-04-23
- **Last seen:** 2026-09-01
- **Threat actors:** 7
- **Detection rules:** 30 (counts only; Blue tier and above)

## Key facts

- **ID:** T1200
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1200/

## Activity timeline

T1200 first appeared in tracked threats on 2026-04-23 and was most recently reported on 2026-09-01. The busiest month was 2026-07 with 6 reports, and 16 of the 16 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1200 Hardware Additions is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 16 of 2623 tracked threats (0.6%) to it; by severity that is 6 critical, 8 high, 1 medium.

Threats that use T1200 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (12 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (10 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (9 threats), [T1211 Exploitation for Stealth](https://intel.threadlinqs.com/technique/T1211) (7 threats), [T1091 Replication Through Removable Media](https://intel.threadlinqs.com/technique/T1091) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1200; the most frequent are [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) (2), [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) (2), [UNC3753](https://intel.threadlinqs.com/actor/UNC3753) (2), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1200.

- [M1034 Limit Hardware Installation](https://attack.mitre.org/mitigations/M1034/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)

## Data sources

Telemetry that can reveal T1200, per MITRE ATT&CK.

- Application Log — Application Log Content
- Drive — Drive Creation
- Network Traffic — Network Traffic Flow

## Threat actors using it

- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 2
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 2
- [UNC3753](https://intel.threadlinqs.com/actor/UNC3753) — 2
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 1

## Tracked threats

16 tracked threats use T1200.

- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1437) — critical — 2026-07-17
- [CISA Adds CVE-2026-46817 (Oracle E-Business Suite Payments Unauthenticated Takeover) and CVE-2023-4346 (KNX…](https://intel.threadlinqs.com/threat/TL-2026-1395) — critical — 2026-07-16
- [CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day](https://intel.threadlinqs.com/threat/TL-2026-1346) — medium — 2026-07-15
- [Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS…](https://intel.threadlinqs.com/threat/TL-2026-1326) — high — 2026-07-14
- [Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)](https://intel.threadlinqs.com/threat/TL-2026-1250) — 2026-07-13
- [Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash](https://intel.threadlinqs.com/threat/TL-2026-1200) — high — 2026-07-11
- [usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB…](https://intel.threadlinqs.com/threat/TL-2026-0876) — high — 2026-06-19
- [usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) devices](https://intel.threadlinqs.com/threat/TL-2026-0871) — high — 2026-06-19
- [usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…](https://intel.threadlinqs.com/threat/TL-2026-0860) — critical — 2026-06-18
- [Microsoft June 2026 Patch Tuesday — 198+ CVEs Including CVE-2026-49160 (HTTP.sys 'HTTP/2 Bomb' DoS)…](https://intel.threadlinqs.com/threat/TL-2026-0732) — high — 2026-06-09
- [UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration…](https://intel.threadlinqs.com/threat/TL-2026-0707) — high — 2026-06-07
- [Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US…](https://intel.threadlinqs.com/threat/TL-2026-0612) — high — 2026-05-28
- [UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching…](https://intel.threadlinqs.com/threat/TL-2026-0564) — critical — 2026-05-22
- [YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC…](https://intel.threadlinqs.com/threat/TL-2026-0512) — critical — 2026-05-13
- [Apple iOS/iPadOS Notification Services Data Retention Zero-Day (CVE-2026-28950) — Exploited In-The-Wild for…](https://intel.threadlinqs.com/threat/TL-2026-0413) — high — 2026-04-23

## Related CVEs

CVEs referenced by the tracked threats that use T1200, most frequent first.

- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-50507](https://intel.threadlinqs.com/cve/CVE-2026-50507)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2023-4346](https://intel.threadlinqs.com/cve/CVE-2023-4346)
- [CVE-2026-28950](https://intel.threadlinqs.com/cve/CVE-2026-28950)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-42909](https://intel.threadlinqs.com/cve/CVE-2026-42909)
- [CVE-2026-42913](https://intel.threadlinqs.com/cve/CVE-2026-42913)
- [CVE-2026-42985](https://intel.threadlinqs.com/cve/CVE-2026-42985)
- [CVE-2026-42992](https://intel.threadlinqs.com/cve/CVE-2026-42992)
- [CVE-2026-42993](https://intel.threadlinqs.com/cve/CVE-2026-42993)
- [CVE-2026-44799](https://intel.threadlinqs.com/cve/CVE-2026-44799)
- [CVE-2026-44801](https://intel.threadlinqs.com/cve/CVE-2026-44801)
- [CVE-2026-45586](https://intel.threadlinqs.com/cve/CVE-2026-45586)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-49160](https://intel.threadlinqs.com/cve/CVE-2026-49160)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)

## Detection coverage

Threadlinqs maintains 30 detection rules mapped to T1200 (SPL 8, KQL 11, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

30 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1200
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
