# T1553.002 Code Signing

> As of 2026-10-05, T1553.002 (Code Signing) appears in 82 tracked threats, first reported 2026-02-02 and most recently 2026-09-30, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1036.005 (Match Legitimate Resource Name or Location).

- **Tracked threats:** 82 (19 critical, 58 high, 5 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-30
- **Threat actors:** 36
- **Detection rules:** 145 (counts only; Blue tier and above)

## Key facts

- **ID:** T1553.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1553
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1553/002/

## Activity timeline

T1553.002 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 23 reports, and 82 of the 82 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1553.002 Code Signing is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553). Threadlinqs maps 82 of 2623 tracked threats (3.1%) to it; by severity that is 19 critical, 58 high, 5 medium.

Threats that use T1553.002 most often also use [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (55 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (55 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (49 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (49 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

36 tracked threat actors appear in the threats that use T1553.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (4), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (4), [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) (3), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2).

## Data sources

Telemetry that can reveal T1553.002, per MITRE ATT&CK.

- File — File Metadata

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 4
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 3
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 2
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 2
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 2
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 2

## Tracked threats

The 30 most recent of 82 tracked threats that use T1553.002.

- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — high — 2026-09-29
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — high — 2026-09-26
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systems](https://intel.threadlinqs.com/threat/TL-2026-2612) — medium — 2026-09-22
- [Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…](https://intel.threadlinqs.com/threat/TL-2026-2602) — high — 2026-09-21
- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…](https://intel.threadlinqs.com/threat/TL-2026-2527) — high — 2026-09-15
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing](https://intel.threadlinqs.com/threat/TL-2026-2284) — high — 2026-09-01
- [Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage](https://intel.threadlinqs.com/threat/TL-2026-2234) — medium — 2026-08-30
- [Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2203) — high — 2026-08-29
- [Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-2162) — critical — 2026-08-27
- [D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…](https://intel.threadlinqs.com/threat/TL-2026-2147) — high — 2026-08-25
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…](https://intel.threadlinqs.com/threat/TL-2026-2120) — high — 2026-08-23
- [FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATs](https://intel.threadlinqs.com/threat/TL-2026-2119) — high — 2026-08-23
- [Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…](https://intel.threadlinqs.com/threat/TL-2026-2103) — high — 2026-08-21
- [Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card Purchases](https://intel.threadlinqs.com/threat/TL-2026-2102) — high — 2026-08-21
- [Post-DEF CON Phishing Campaign Abuses Google Apps Script Sidebar to Deliver AMOS Stealer and NetSupport RAT](https://intel.threadlinqs.com/threat/TL-2026-2449) — high — 2026-08-19
- [HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)](https://intel.threadlinqs.com/threat/TL-2026-2013) — high — 2026-08-14
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedures](https://intel.threadlinqs.com/threat/TL-2026-1966) — high — 2026-08-10
- [Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser…](https://intel.threadlinqs.com/threat/TL-2026-1907) — high — 2026-08-06
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…](https://intel.threadlinqs.com/threat/TL-2026-1894) — high — 2026-08-05
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…](https://intel.threadlinqs.com/threat/TL-2026-1693) — high — 2026-07-25
- [Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…](https://intel.threadlinqs.com/threat/TL-2026-1649) — critical — 2026-07-23

## Related CVEs

CVEs referenced by the tracked threats that use T1553.002, most frequent first.

- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2025-0282](https://intel.threadlinqs.com/cve/CVE-2025-0282)
- [CVE-2025-24054](https://intel.threadlinqs.com/cve/CVE-2025-24054)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-33053](https://intel.threadlinqs.com/cve/CVE-2025-33053)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)
- [CVE-2026-26030](https://intel.threadlinqs.com/cve/CVE-2026-26030)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-57909](https://intel.threadlinqs.com/cve/CVE-2026-57909)
- [CVE-2026-57910](https://intel.threadlinqs.com/cve/CVE-2026-57910)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2026-9089](https://intel.threadlinqs.com/cve/CVE-2026-9089)

## Detection coverage

Threadlinqs maintains 145 detection rules mapped to T1553.002 (SPL 44, KQL 51, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.

145 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553) — 160 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1553.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
