# T1547.006 Kernel Modules and Extensions

> As of 2026-10-05, T1547.006 (Kernel Modules and Extensions) appears in 15 tracked threats, first reported 2026-02-04 and most recently 2026-08-17, with linked actors including CUBA, GhostEmperor, Hyadina; it most often appears alongside T1685 (Disable or Modify Tools).

- **Tracked threats:** 15 (5 critical, 9 high, 1 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-08-17
- **Threat actors:** 7
- **Detection rules:** 33 (counts only; Blue tier and above)

## Key facts

- **ID:** T1547.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Privilege Escalation
- **Matrix:** Enterprise
- **Parent:** T1547
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1547/006/

## Activity timeline

T1547.006 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-08-17. The busiest month was 2026-07 with 7 reports, and 15 of the 15 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1547.006 Kernel Modules and Extensions is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix, as a sub-technique of [T1547 Boot or Logon Autostart Execution](https://intel.threadlinqs.com/technique/T1547). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 9 high, 1 medium.

Threats that use T1547.006 most often also use [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (11 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (9 threats), [T1014 Rootkit](https://intel.threadlinqs.com/technique/T1014) (9 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (8 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1547.006; the most frequent are [CUBA](https://intel.threadlinqs.com/actor/CUBA) (1), [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (1), [Hyadina](https://intel.threadlinqs.com/actor/Hyadina) (1), [LockBit](https://intel.threadlinqs.com/actor/LockBit) (1), [Markas Escobar](https://intel.threadlinqs.com/actor/Markas%20Escobar) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1547.006.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)

## Data sources

Telemetry that can reveal T1547.006, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation, File Modification
- Kernel — Kernel Module Load
- Process — Process Creation

## Threat actors using it

- [CUBA](https://intel.threadlinqs.com/actor/CUBA) — 1
- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 1
- [Hyadina](https://intel.threadlinqs.com/actor/Hyadina) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [Markas Escobar](https://intel.threadlinqs.com/actor/Markas%20Escobar) — 1
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 1
- [UAT-9244](https://intel.threadlinqs.com/actor/UAT-9244) — 1

## Tracked threats

15 tracked threats use T1547.006.

- ["Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)](https://intel.threadlinqs.com/threat/TL-2026-2039) — medium — 2026-08-17
- [Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…](https://intel.threadlinqs.com/threat/TL-2026-1918) — high — 2026-08-06
- [1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)](https://intel.threadlinqs.com/threat/TL-2026-1837) — high — 2026-08-03
- [Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1404) — critical — 2026-07-16
- [AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader](https://intel.threadlinqs.com/threat/TL-2026-1387) — critical — 2026-07-15
- [Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…](https://intel.threadlinqs.com/threat/TL-2026-1379) — high — 2026-07-15
- [313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…](https://intel.threadlinqs.com/threat/TL-2026-1374) — high — 2026-07-15
- [Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…](https://intel.threadlinqs.com/threat/TL-2026-1286) — high — 2026-07-13
- [Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash](https://intel.threadlinqs.com/threat/TL-2026-1200) — high — 2026-07-11
- [GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver](https://intel.threadlinqs.com/threat/TL-2026-1148) — high — 2026-07-09
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT…](https://intel.threadlinqs.com/threat/TL-2026-0749) — critical — 2026-06-10
- [UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching…](https://intel.threadlinqs.com/threat/TL-2026-0564) — critical — 2026-05-22
- [Windows False File Immutability Kernel Exploit — Cloud File Sync Driver (cldflt.sys) Bypass, PoC Available…](https://intel.threadlinqs.com/threat/TL-2026-0134) — high — 2026-02-23
- [Ransomware Threat Landscape 2025-2027 — RaaS Destabilization, Conti Leak Cascade, ESXi Hypervisor Targeting…](https://intel.threadlinqs.com/threat/TL-2026-0115) — critical — 2026-02-06
- [BYOVD EDR Killer Tooling — Ransomware Groups Weaponizing Signed Kernel Drivers to Blind Endpoint Detection](https://intel.threadlinqs.com/threat/TL-2026-0091) — high — 2026-02-04

## Related CVEs

CVEs referenced by the tracked threats that use T1547.006, most frequent first.

- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2026-23670](https://intel.threadlinqs.com/cve/CVE-2026-23670)

## Detection coverage

Threadlinqs maintains 33 detection rules mapped to T1547.006 (SPL 12, KQL 7, Sigma 13, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

33 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1547 Boot or Logon Autostart Execution](https://intel.threadlinqs.com/technique/T1547) — 349 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1547.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
