# T1222.002 Linux and Mac Permissions

> As of 2026-10-05, T1222.002 (Linux and Mac Permissions) appears in 17 tracked threats, first reported 2026-03-19 and most recently 2026-09-27, with linked actors including Markas Escobar; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 17 (7 critical, 10 high)
- **First seen:** 2026-03-19
- **Last seen:** 2026-09-27
- **Threat actors:** 1
- **Detection rules:** 33 (counts only; Blue tier and above)

## Key facts

- **ID:** T1222.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1222
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1222/002/

## Activity timeline

T1222.002 first appeared in tracked threats on 2026-03-19 and was most recently reported on 2026-09-27. The busiest month was 2026-08 with 4 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1222.002 Linux and Mac Permissions is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1222 File and Directory Permissions Modification](https://intel.threadlinqs.com/technique/T1222). Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 7 critical, 10 high.

Threats that use T1222.002 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (15 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (10 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (8 threats), [T1083 File and Directory Discovery](https://intel.threadlinqs.com/technique/T1083) (8 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1222.002; the most frequent are [Markas Escobar](https://intel.threadlinqs.com/actor/Markas%20Escobar) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1222.002.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)

## Data sources

Telemetry that can reveal T1222.002, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata
- Process — Process Creation

## Threat actors using it

- [Markas Escobar](https://intel.threadlinqs.com/actor/Markas%20Escobar) — 1

## Tracked threats

17 tracked threats use T1222.002.

- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)](https://intel.threadlinqs.com/threat/TL-2026-2682) — high — 2026-09-27
- [Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…](https://intel.threadlinqs.com/threat/TL-2026-2639) — high — 2026-09-24
- [CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…](https://intel.threadlinqs.com/threat/TL-2026-2542) — critical — 2026-09-16
- [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://intel.threadlinqs.com/threat/TL-2026-2099) — critical — 2026-08-21
- [CVE-2026-43760: macOS Screen Sharing Logic Flaw Allows VNC-Authenticated Root Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2038) — critical — 2026-08-16
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- [1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)](https://intel.threadlinqs.com/threat/TL-2026-1837) — high — 2026-08-03
- [CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root](https://intel.threadlinqs.com/threat/TL-2026-1633) — high — 2026-07-22
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…](https://intel.threadlinqs.com/threat/TL-2026-1477) — high — 2026-07-18
- [Cursor IDE "DuneSlide" Sandbox Escape RCE via Zero-Click Prompt Injection (CVE-2026-50548, CVE-2026-50549)](https://intel.threadlinqs.com/threat/TL-2026-1047) — critical — 2026-07-01
- [macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…](https://intel.threadlinqs.com/threat/TL-2026-0923) — high — 2026-06-23
- [CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on…](https://intel.threadlinqs.com/threat/TL-2026-0872) — high — 2026-06-19
- [Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…](https://intel.threadlinqs.com/threat/TL-2026-0596) — high — 2026-05-26
- [Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…](https://intel.threadlinqs.com/threat/TL-2026-0483) — critical — 2026-05-08
- [CVE-2026-31979: Himmelblau Root Privilege Escalation via Symlink Attack on Kerberos Cache](https://intel.threadlinqs.com/threat/TL-2026-0258) — high — 2026-03-20
- [CVE-2026-33017: Langflow Unauthenticated RCE via Public Flow Build Endpoint — Active Exploitation Within 20…](https://intel.threadlinqs.com/threat/TL-2026-0250) — critical — 2026-03-19

## Related CVEs

CVEs referenced by the tracked threats that use T1222.002, most frequent first.

- [CVE-2026-43760](https://intel.threadlinqs.com/cve/CVE-2026-43760)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-31979](https://intel.threadlinqs.com/cve/CVE-2026-31979)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-65400](https://intel.threadlinqs.com/cve/CVE-2026-65400)
- [CVE-2026-76460](https://intel.threadlinqs.com/cve/CVE-2026-76460)
- [CVE-2026-87886](https://intel.threadlinqs.com/cve/CVE-2026-87886)
- [CVE-2026-8933](https://intel.threadlinqs.com/cve/CVE-2026-8933)

## Detection coverage

Threadlinqs maintains 33 detection rules mapped to T1222.002 (SPL 11, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

33 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1222 File and Directory Permissions Modification](https://intel.threadlinqs.com/technique/T1222) — 33 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1222.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
