Activity timeline
T1222.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 4 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1222.002 Linux and Mac Permissions is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of T1222 File and Directory Permissions Modification. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 7 critical, 10 high.
Threats that use T1222.002 most often also use T1059.004 Unix Shell (15 threats), T1005 Data from Local System (10 threats), T1068 Exploitation for Privilege Escalation (8 threats), T1083 File and Directory Discovery (8 threats), T1190 Exploit Public-Facing Application (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
1 tracked threat actor appear in the threats that use T1222.002; the most frequent are Markas Escobar (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1222.002.
Data sources
Telemetry that can reveal T1222.002, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata
- Process — Process Creation
Threat actors using it
Tracked threats
17 tracked threats use T1222.002.
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)high
- Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…high
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…critical
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2critical
- CVE-2026-43760: macOS Screen Sharing Logic Flaw Allows VNC-Authenticated Root Command Executioncritical
- CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Accesscritical
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)high
- CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Roothigh
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…high
- Cursor IDE "DuneSlide" Sandbox Escape RCE via Zero-Click Prompt Injection (CVE-2026-50548, CVE-2026-50549)critical
- macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…high
- CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on…high
- Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…high
- Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…critical
- CVE-2026-31979: Himmelblau Root Privilege Escalation via Symlink Attack on Kerberos Cachehigh
- CVE-2026-33017: Langflow Unauthenticated RCE via Public Flow Build Endpoint — Active Exploitation Within 20…critical
Detection coverage
Threadlinqs maintains 33 detection rules mapped to T1222.002 (SPL 11, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1222 File and Directory Permissions Modification — 33 tracked threats at the technique level.