Activity timeline
T1222 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 20 reports, and 33 of the 33 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1222 File and Directory Permissions Modification is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix. Threadlinqs maps 33 of 2623 tracked threats (1.3%) to it; by severity that is 8 critical, 24 high, 1 medium.
Threats that use T1222 most often also use T1082 System Information Discovery (23 threats), T1059 Command and Scripting Interpreter (21 threats), T1005 Data from Local System (20 threats), T1068 Exploitation for Privilege Escalation (17 threats), T1036 Masquerading (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
17 tracked threat actors appear in the threats that use T1222; the most frequent are Chaotic Eclipse (2), Nightmare Eclipse (2), ALPHV (1), BlackCat (1), Earth Lamia (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1222.
Data sources
Telemetry that can reveal T1222, per MITRE ATT&CK.
- Active Directory — Active Directory Object Modification
- Command — Command Execution
- File — File Metadata
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 33 tracked threats that use T1222.
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege…high
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass…high
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Processhigh
- LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installedhigh
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)high
- SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE…critical
- "LegacyHive" Windows User Profile Service Zero-Day Allows Non-Admin Registry Hive Hijackinghigh
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…high
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo…high
- CrashStealer: Native C++ macOS Infostealer Masquerading as Apple's CrashReporter via Notarized 'Werkbit'…high
- Cisco Unified CM / Unified CM SME SSRF Vulnerability (CVE-2026-20230) — WebDialer File-Write to Root…critical
- The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)high
- GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing…high
- Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider Recruitmenthigh
- RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patchedhigh
- GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware…high
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Critical Cursor AI Code Editor Flaws (CVE-2026-50548, CVE-2026-50549) — "DuneSlide" Zero-Click Prompt…critical
- Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A)high
- Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret…high
- Schneider Electric Floating License Manager - CVE-2024-2658 Local Privilege Escalation via Uncontrolled…high
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity…high
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection…high
- CVE-2026-20262: Cisco Catalyst SD-WAN Manager (vManage) Arbitrary File Upload Flaw Exploited as Zero-Day for…medium
- Linux Kernel cgroups v1 release_agent Container Escape & Privilege Escalation (CVE-2022-0492) — Added to…critical
- Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…high
- KnowledgeDeliver LMS ViewState Deserialization Zero-Day CVE-2026-5426 — Unauthenticated RCE via Shared…critical
- CVE-2025-29635 — Mirai Variant Campaign Recruiting D-Link DIR-823X Routers via /goform/set_prohibiting…high
Detection coverage
Threadlinqs maintains 30 detection rules mapped to T1222 (SPL 14, KQL 6, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1222.001 Windows Permissions — 7 tracked threats
- T1222.002 Linux and Mac Permissions — 17 tracked threats