Activity timeline
T1554 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 31 reports, and 82 of the 82 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1554 Compromise Host Software Binary is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 82 of 2623 tracked threats (3.1%) to it; by severity that is 32 critical, 43 high, 7 medium.
Threats that use T1554 most often also use T1027 Obfuscated Files or Information (56 threats), T1005 Data from Local System (53 threats), T1041 Exfiltration Over C2 Channel (50 threats), T1082 System Information Discovery (46 threats), T1059 Command and Scripting Interpreter (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
30 tracked threat actors appear in the threats that use T1554; the most frequent are TeamPCP (8), APT38 (2), Andariel (2), Contagious Interview (2), Contagious Interview cluster (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1554.
Data sources
Telemetry that can reveal T1554, per MITRE ATT&CK.
- File — File Creation, File Deletion, File Metadata, File Modification
Threat actors using it
Tracked threats
The 30 most recent of 82 tracked threats that use T1554.
- Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attackscritical
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host fileshigh
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Softwarehigh
- CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…high
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affectedcritical
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…medium
- CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…high
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnethigh
- GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruexmedium
- MacSync Stealer: Malvertising Campaign Impersonates Claude/Apple Support to Deploy macOS Infostealerhigh
- Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser…high
- XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projectshigh
- npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for…critical
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)critical
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- Joyfill npm Packages Compromised with Blockchain C2 Loadermedium
- CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memorycritical
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…critical
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojancritical
- Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags…medium
- Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow…high
- Prompt Injection in AWS Kiro Leads to Remote Code Execution via Unprotected MCP Config (mcp.json)high
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)high
- CVE-2026-53910: Heap-Based Buffer Overflow in GNU diffutils diff3 (Signed Integer Overflow)medium
- Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Executioncritical
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accountshigh
Detection coverage
Threadlinqs maintains 134 detection rules mapped to T1554 (SPL 50, KQL 40, Sigma 44). Rule content is available to Blue tier accounts and above; this page shows counts only.