Activity timeline
T1547.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 7 reports, and 15 of the 15 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1547.006 Kernel Modules and Extensions is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of T1547 Boot or Logon Autostart Execution. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 9 high, 1 medium.
Threats that use T1547.006 most often also use T1685 Disable or Modify Tools (11 threats), T1005 Data from Local System (9 threats), T1014 Rootkit (9 threats), T1071.001 Web Protocols (8 threats), T1068 Exploitation for Privilege Escalation (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1547.006; the most frequent are CUBA (1), GhostEmperor (1), Hyadina (1), LockBit (1), Markas Escobar (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1547.006.
Data sources
Telemetry that can reveal T1547.006, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Modification
- Kernel — Kernel Module Load
- Process — Process Creation
Threat actors using it
Tracked threats
15 tracked threats use T1547.006.
- "Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)medium
- Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…high
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)high
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoorcritical
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loadercritical
- Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…high
- 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…high
- Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…high
- Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flashhigh
- GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driverhigh
- FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT…critical
- UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching…critical
- Windows False File Immutability Kernel Exploit — Cloud File Sync Driver (cldflt.sys) Bypass, PoC Available…high
- Ransomware Threat Landscape 2025-2027 — RaaS Destabilization, Conti Leak Cascade, ESXi Hypervisor Targeting…critical
- BYOVD EDR Killer Tooling — Ransomware Groups Weaponizing Signed Kernel Drivers to Blind Endpoint Detectionhigh
Detection coverage
Threadlinqs maintains 33 detection rules mapped to T1547.006 (SPL 12, KQL 7, Sigma 13, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1547 Boot or Logon Autostart Execution — 349 tracked threats at the technique level.