Activity timeline
T1553.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 23 reports, and 82 of the 82 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1553.002 Code Signing is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of T1553 Subvert Trust Controls. Threadlinqs maps 82 of 2623 tracked threats (3.1%) to it; by severity that is 19 critical, 58 high, 5 medium.
Threats that use T1553.002 most often also use T1036.005 Match Legitimate Resource Name or Location (55 threats), T1071.001 Web Protocols (55 threats), T1027 Obfuscated Files or Information (49 threats), T1082 System Information Discovery (49 threats), T1204.002 Malicious File (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
36 tracked threat actors appear in the threats that use T1553.002; the most frequent are APT38 (4), Sapphire Sleet (4), Stardust Chollima (4), UNC1549 (3), Andariel (2).
Data sources
Telemetry that can reveal T1553.002, per MITRE ATT&CK.
- File — File Metadata
Threat actors using it
Tracked threats
The 30 most recent of 82 tracked threats that use T1553.002.
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)high
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…high
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholinghigh
- Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usagemedium
- Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloadinghigh
- Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…critical
- D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…high
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…high
- FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATshigh
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…high
- Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card Purchaseshigh
- Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAThigh
- HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)high
- Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAThigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedureshigh
- Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser…high
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…high
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoorhigh
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…high
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…critical
Detection coverage
Threadlinqs maintains 145 detection rules mapped to T1553.002 (SPL 44, KQL 51, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1553 Subvert Trust Controls — 160 tracked threats at the technique level.