Activity timeline
T1553.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-02 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1553.005 Mark-of-the-Web Bypass is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of T1553 Subvert Trust Controls. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 1 critical, 11 high, 1 medium.
Threats that use T1553.005 most often also use T1027 Obfuscated Files or Information (10 threats), T1059.001 PowerShell (10 threats), T1204.002 Malicious File (10 threats), T1036.005 Match Legitimate Resource Name or Location (9 threats), T1071.001 Web Protocols (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
16 tracked threat actors appear in the threats that use T1553.005; the most frequent are APT28 (1), APT29 (1), APT38 (1), APT43 (1), BlueDelta (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1553.005.
Data sources
Telemetry that can reveal T1553.005, per MITRE ATT&CK.
- File — File Creation, File Metadata
Threat actors using it
Tracked threats
13 tracked threats use T1553.005.
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Accesshigh
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Daymedium
- Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM…high
- 109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) and StealC Infostealer via Cloned Open-Source…high
- Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaScritical
- APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via…high
- ClickFix Browser Cache Smuggling — Social Engineering MaaS Toolkit Storing Malware Payloads in Browser Cache…high
- Screensaver (.SCR) Files Used as Initial Access Vectorhigh
- DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web…high
- UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Siteshigh
Detection coverage
Threadlinqs maintains 52 detection rules mapped to T1553.005 (SPL 19, KQL 16, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1553 Subvert Trust Controls — 160 tracked threats at the technique level.