# T1553.005 Mark-of-the-Web Bypass

> As of 2026-10-05, T1553.005 (Mark-of-the-Web Bypass) appears in 13 tracked threats, first reported 2026-01-01 and most recently 2026-09-29, with linked actors including APT28, APT29, APT38; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 13 (1 critical, 11 high, 1 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-09-29
- **Threat actors:** 16
- **Detection rules:** 52 (counts only; Blue tier and above)

## Key facts

- **ID:** T1553.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1553
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1553/005/

## Activity timeline

T1553.005 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-09-29. The busiest month was 2026-02 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1553.005 Mark-of-the-Web Bypass is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553). Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 1 critical, 11 high, 1 medium.

Threats that use T1553.005 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (10 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (10 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (9 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

16 tracked threat actors appear in the threats that use T1553.005; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT29](https://intel.threadlinqs.com/actor/APT29) (1), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1553.005.

- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1553.005, per MITRE ATT&CK.

- File — File Creation, File Metadata

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) — 1
- [Star Blizzard](https://intel.threadlinqs.com/actor/Star%20Blizzard) — 1

## Tracked threats

13 tracked threats use T1553.005.

- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1880) — high — 2026-08-04
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day](https://intel.threadlinqs.com/threat/TL-2026-1346) — medium — 2026-07-15
- [Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM…](https://intel.threadlinqs.com/threat/TL-2026-0715) — high — 2026-06-08
- [109 Fake GitHub Repositories Deliver SmartLoader (LuaJIT) and StealC Infostealer via Cloned Open-Source…](https://intel.threadlinqs.com/threat/TL-2026-0457) — high — 2026-05-05
- [Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaS](https://intel.threadlinqs.com/threat/TL-2026-0151) — critical — 2026-02-27
- [APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via…](https://intel.threadlinqs.com/threat/TL-2026-0133) — high — 2026-02-23
- [ClickFix Browser Cache Smuggling — Social Engineering MaaS Toolkit Storing Malware Payloads in Browser Cache…](https://intel.threadlinqs.com/threat/TL-2026-0127) — high — 2026-02-21
- [Screensaver (.SCR) Files Used as Initial Access Vector](https://intel.threadlinqs.com/threat/TL-2026-0104) — high — 2026-02-16
- [DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web…](https://intel.threadlinqs.com/threat/TL-2026-0092) — high — 2026-01-14
- [UNC5142 EtherHiding: BNB Smart Chain-Based Malware Distribution via Compromised WordPress Sites](https://intel.threadlinqs.com/threat/TL-2026-1512) — high — 2026-01-01

## Related CVEs

CVEs referenced by the tracked threats that use T1553.005, most frequent first.

- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-50507](https://intel.threadlinqs.com/cve/CVE-2026-50507)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)

## Detection coverage

Threadlinqs maintains 52 detection rules mapped to T1553.005 (SPL 19, KQL 16, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

52 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553) — 160 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1553.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
