# T1553.006 Code Signing Policy Modification

> As of 2026-10-05, T1553.006 (Code Signing Policy Modification) appears in 14 tracked threats, first reported 2026-02-22 and most recently 2026-09-23, with linked actors including APT38, Andariel, Lazarus Group; it most often appears alongside T1685 (Disable or Modify Tools).

- **Tracked threats:** 14 (5 critical, 8 high, 1 medium)
- **First seen:** 2026-02-22
- **Last seen:** 2026-09-23
- **Threat actors:** 9
- **Detection rules:** 30 (counts only; Blue tier and above)

## Key facts

- **ID:** T1553.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1553
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1553/006/

## Activity timeline

T1553.006 first appeared in tracked threats on 2026-02-22 and was most recently reported on 2026-09-23. The busiest month was 2026-08 with 4 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1553.006 Code Signing Policy Modification is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553). Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 8 high, 1 medium.

Threats that use T1553.006 most often also use [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (11 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (8 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (7 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (7 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1553.006; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (2), [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) (1), [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1553.006.

- [M1024 Restrict Registry Permissions](https://attack.mitre.org/mitigations/M1024/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1046 Boot Integrity](https://attack.mitre.org/mitigations/M1046/)

## Data sources

Telemetry that can reveal T1553.006, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 1
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 1
- [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 1

## Tracked threats

14 tracked threats use T1553.006.

- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- ["Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)](https://intel.threadlinqs.com/threat/TL-2026-2039) — medium — 2026-08-17
- [Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware](https://intel.threadlinqs.com/threat/TL-2026-2017) — high — 2026-08-14
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver…](https://intel.threadlinqs.com/threat/TL-2026-1344) — high — 2026-07-15
- [11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1340) — high — 2026-07-14
- [usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…](https://intel.threadlinqs.com/threat/TL-2026-0860) — critical — 2026-06-18
- [Lazarus RemotePE Memory-Only RAT — DPAPILoader + RemotePELoader Chain Targeting Financial & Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-0579) — high — 2026-05-25
- [ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with…](https://intel.threadlinqs.com/threat/TL-2026-0471) — high — 2026-05-06
- [FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 Apple App Store Apps (SparkKitty-linked…](https://intel.threadlinqs.com/threat/TL-2026-0395) — critical — 2026-04-20
- [GIBCRYPTO Destructive Ransomware with Snake Keylogger Shared Telegram C2 Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0210) — critical — 2026-03-11
- [Windows False File Immutability Kernel Exploit — Cloud File Sync Driver (cldflt.sys) Bypass, PoC Available…](https://intel.threadlinqs.com/threat/TL-2026-0134) — high — 2026-02-23
- [Predator Spyware iOS SpringBoard Hook — Intellexa Recording Indicator Bypass via Kernel-Level Sensor…](https://intel.threadlinqs.com/threat/TL-2026-0132) — high — 2026-02-22

## Related CVEs

CVEs referenced by the tracked threats that use T1553.006, most frequent first.

- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-23670](https://intel.threadlinqs.com/cve/CVE-2026-23670)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2026-76460](https://intel.threadlinqs.com/cve/CVE-2026-76460)
- [CVE-2026-83548](https://intel.threadlinqs.com/cve/CVE-2026-83548)
- [CVE-2026-83549](https://intel.threadlinqs.com/cve/CVE-2026-83549)
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102)
- [CVE-2026-85103](https://intel.threadlinqs.com/cve/CVE-2026-85103)
- [CVE-2026-91843](https://intel.threadlinqs.com/cve/CVE-2026-91843)

## Detection coverage

Threadlinqs maintains 30 detection rules mapped to T1553.006 (SPL 11, KQL 7, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

30 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553) — 160 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1553.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
