# T1525 Implant Internal Image

> As of 2026-10-05, T1525 (Implant Internal Image) appears in 15 tracked threats, first reported 2026-02-03 and most recently 2026-07-20, with linked actors including APT38, Lazarus Group, Mini Shai-Hulud; it most often appears alongside T1036 (Masquerading).

- **Tracked threats:** 15 (4 critical, 8 high, 2 medium, 1 low)
- **First seen:** 2026-02-03
- **Last seen:** 2026-07-20
- **Threat actors:** 6
- **Detection rules:** 7 (counts only; Blue tier and above)

## Key facts

- **ID:** T1525
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1525/

## Activity timeline

T1525 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-07-20. The busiest month was 2026-07 with 5 reports, and 15 of the 15 threats were reported in the twelve months to 2026-07.

## How adversaries use it

T1525 Implant Internal Image is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 4 critical, 8 high, 2 medium, 1 low.

Threats that use T1525 most often also use [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (11 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (10 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (10 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (9 threats), [T1070 Indicator Removal](https://intel.threadlinqs.com/technique/T1070) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1525; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (1), [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) (1), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (1), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1525.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1525, per MITRE ATT&CK.

- Image — Image Creation, Image Metadata, Image Modification

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1
- [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) — 1

## Tracked threats

15 tracked threats use T1525.

- [CodeTracer: Forensic Attribution Tool for Backdoored AI Code-Completion Models](https://intel.threadlinqs.com/threat/TL-2026-1577) — low — 2026-07-20
- [Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositories](https://intel.threadlinqs.com/threat/TL-2026-1307) — high — 2026-07-14
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — high — 2026-07-14
- [Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data…](https://intel.threadlinqs.com/threat/TL-2026-1165) — high — 2026-07-10
- [Unpatched Unauthenticated RCE in Argo CD Repo-Server via Kustomize GenerateManifest gRPC Endpoint](https://intel.threadlinqs.com/threat/TL-2026-2423) — high — 2026-07-01
- [Miasma Malware Supply Chain Attack Targets npm Packages, Go Module, and GitHub Actions CI/CD Pipelines](https://intel.threadlinqs.com/threat/TL-2026-0963) — critical — 2026-06-27
- [Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1242) — high — 2026-06-26
- [Mastra NPM Packages Trojanized with Malicious Dependency Injection - 116 Packages Compromised](https://intel.threadlinqs.com/threat/TL-2026-0977) — critical — 2026-06-17
- [Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…](https://intel.threadlinqs.com/threat/TL-2026-1234) — high — 2026-06-04
- [NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests Cloud Credentials and AI API Keys via Langflow RCE…](https://intel.threadlinqs.com/threat/TL-2026-0514) — high — 2026-05-14
- [Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defenses](https://intel.threadlinqs.com/threat/TL-2026-1467) — medium — 2026-04-02
- [Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch…](https://intel.threadlinqs.com/threat/TL-2026-0121) — critical — 2026-02-16
- [DockerDash: Critical Ask Gordon AI Vulnerability - Code Execution via Image Metadata](https://intel.threadlinqs.com/threat/TL-2026-0059) — critical — 2026-02-03
- [White House Revokes Biden-Era Software Security Memorandums](https://intel.threadlinqs.com/threat/TL-2026-0048) — medium — 2026-02-03
- [175,000 Exposed Ollama LLM Hosts Enable AI Model Abuse](https://intel.threadlinqs.com/threat/TL-2026-0047) — high — 2026-02-03

## Related CVEs

CVEs referenced by the tracked threats that use T1525, most frequent first.

- [CVE-2026-1281](https://intel.threadlinqs.com/cve/CVE-2026-1281)
- [CVE-2026-1340](https://intel.threadlinqs.com/cve/CVE-2026-1340)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 7 detection rules mapped to T1525 (SPL 2, KQL 2, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

7 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1525
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
