Activity timeline
T1525 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 15 of the 15 threats were reported in the twelve months to 2026-07.
How adversaries use it
T1525 Implant Internal Image is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 4 critical, 8 high, 2 medium, 1 low.
Threats that use T1525 most often also use T1036 Masquerading (11 threats), T1005 Data from Local System (10 threats), T1059 Command and Scripting Interpreter (10 threats), T1027 Obfuscated Files or Information (9 threats), T1070 Indicator Removal (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1525; the most frequent are APT38 (1), Lazarus Group (1), Mini Shai-Hulud (1), Stardust Chollima (1), TeamPCP (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1525.
Data sources
Telemetry that can reveal T1525, per MITRE ATT&CK.
- Image — Image Creation, Image Metadata, Image Modification
Threat actors using it
Tracked threats
15 tracked threats use T1525.
- CodeTracer: Forensic Attribution Tool for Backdoored AI Code-Completion Modelslow
- Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositorieshigh
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)high
- Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data…high
- Unpatched Unauthenticated RCE in Argo CD Repo-Server via Kustomize GenerateManifest gRPC Endpointhigh
- Miasma Malware Supply Chain Attack Targets npm Packages, Go Module, and GitHub Actions CI/CD Pipelinescritical
- Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…high
- Mastra NPM Packages Trojanized with Malicious Dependency Injection - 116 Packages Compromisedcritical
- Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…high
- NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests Cloud Credentials and AI API Keys via Langflow RCE…high
- Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defensesmedium
- Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch…critical
- DockerDash: Critical Ask Gordon AI Vulnerability - Code Execution via Image Metadatacritical
- White House Revokes Biden-Era Software Security Memorandumsmedium
- 175,000 Exposed Ollama LLM Hosts Enable AI Model Abusehigh
Detection coverage
Threadlinqs maintains 7 detection rules mapped to T1525 (SPL 2, KQL 2, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.