# T1529 System Shutdown/Reboot

> As of 2026-10-05, T1529 (System Shutdown/Reboot) appears in 80 tracked threats, first reported 2026-02-02 and most recently 2026-09-27, with linked actors including Static Tundra, APT44, Black Basta; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 80 (38 critical, 37 high, 4 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-27
- **Threat actors:** 26
- **Detection rules:** 70 (counts only; Blue tier and above)

## Key facts

- **ID:** T1529
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1529/

## Activity timeline

T1529 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 33 reports, and 80 of the 80 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1529 System Shutdown/Reboot is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 80 of 2623 tracked threats (3%) to it; by severity that is 38 critical, 37 high, 4 medium.

Threats that use T1529 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (53 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (52 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (47 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (46 threats), [T1070 Indicator Removal](https://intel.threadlinqs.com/technique/T1070) (37 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

26 tracked threat actors appear in the threats that use T1529; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (4), [APT44](https://intel.threadlinqs.com/actor/APT44) (2), [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) (2), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (2), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (2).

## Data sources

Telemetry that can reveal T1529, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation
- Sensor Health — Host Status

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 4
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 2
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 2
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 2
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 2
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [UTA0533](https://intel.threadlinqs.com/actor/UTA0533) — 2
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 2
- [Y2K Operators](https://intel.threadlinqs.com/actor/Y2K%20Operators) — 2
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 1

## Tracked threats

The 30 most recent of 80 tracked threats that use T1529.

- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — critical — 2026-09-03
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…](https://intel.threadlinqs.com/threat/TL-2026-2317) — high — 2026-09-03
- [UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…](https://intel.threadlinqs.com/threat/TL-2026-2196) — critical — 2026-08-28
- [NASA JPL AIT-GUI Missing Authentication and CSRF Flaw Allows Unauthenticated Spacecraft Command Injection…](https://intel.threadlinqs.com/threat/TL-2026-2081) — critical — 2026-08-20
- [CVE-2026-64849 — MLflow Server-Side Request Forgery (SSRF) Vulnerability in Model Registry Webhooks](https://intel.threadlinqs.com/threat/TL-2026-2077) — critical — 2026-08-19
- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — critical — 2026-08-19
- [Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone…](https://intel.threadlinqs.com/threat/TL-2026-1912) — critical — 2026-08-06
- [Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1901) — critical — 2026-08-05
- [ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…](https://intel.threadlinqs.com/threat/TL-2026-1883) — critical — 2026-08-05
- [GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-1773) — high — 2026-07-30
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28
- [Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC](https://intel.threadlinqs.com/threat/TL-2026-1730) — 2026-07-27
- [KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars](https://intel.threadlinqs.com/threat/TL-2026-1699) — high — 2026-07-25
- [DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops…](https://intel.threadlinqs.com/threat/TL-2026-1680) — critical — 2026-07-25
- [Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power Grids](https://intel.threadlinqs.com/threat/TL-2026-1598) — high — 2026-07-21
- [Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing…](https://intel.threadlinqs.com/threat/TL-2026-1564) — critical — 2026-07-20
- [CVE-2026-47291: Remote Code Execution in Windows HTTP.sys (Kernel-Mode Integer Overflow)](https://intel.threadlinqs.com/threat/TL-2026-1545) — critical — 2026-07-19
- [Pre-Auth Remote Code Execution in Enterprise Network Printer Firmware via Fuzzed Management Protocol (STAR…](https://intel.threadlinqs.com/threat/TL-2026-1542) — high — 2026-07-19
- [Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)](https://intel.threadlinqs.com/threat/TL-2026-1487) — medium — 2026-07-18
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo\[.\]org…](https://intel.threadlinqs.com/threat/TL-2026-1483) — high — 2026-07-18
- [HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte Payload](https://intel.threadlinqs.com/threat/TL-2026-1457) — medium — 2026-07-17
- [The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWorm](https://intel.threadlinqs.com/threat/TL-2026-1418) — high — 2026-07-16
- [Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed…](https://intel.threadlinqs.com/threat/TL-2026-1400) — high — 2026-07-16
- [SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…](https://intel.threadlinqs.com/threat/TL-2026-1390) — critical — 2026-07-15
- [SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth…](https://intel.threadlinqs.com/threat/TL-2026-1382) — critical — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use T1529, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2020-15791](https://intel.threadlinqs.com/cve/CVE-2020-15791)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1781](https://intel.threadlinqs.com/cve/CVE-2024-1781)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)

## Detection coverage

Threadlinqs maintains 70 detection rules mapped to T1529 (SPL 20, KQL 17, Sigma 33). Rule content is available to Blue tier accounts and above; this page shows counts only.

70 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1529
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
