# T1554 Compromise Host Software Binary

> As of 2026-10-05, T1554 (Compromise Host Software Binary) appears in 82 tracked threats, first reported 2026-01-01 and most recently 2026-10-01, with linked actors including TeamPCP, APT38, Andariel; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 82 (32 critical, 43 high, 7 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-10-01
- **Threat actors:** 30
- **Detection rules:** 134 (counts only; Blue tier and above)

## Key facts

- **ID:** T1554
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1554/

## Activity timeline

T1554 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 31 reports, and 82 of the 82 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1554 Compromise Host Software Binary is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 82 of 2623 tracked threats (3.1%) to it; by severity that is 32 critical, 43 high, 7 medium.

Threats that use T1554 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (56 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (53 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (50 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (46 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

30 tracked threat actors appear in the threats that use T1554; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (8), [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (2), [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1554.

- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)

## Data sources

Telemetry that can reveal T1554, per MITRE ATT&CK.

- File — File Creation, File Deletion, File Metadata, File Modification

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 8
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 2
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 2
- [GlassWorm Operators](https://intel.threadlinqs.com/actor/GlassWorm%20Operators) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 2
- [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) — 2
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1

## Tracked threats

The 30 most recent of 82 tracked threats that use T1554.

- [Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks](https://intel.threadlinqs.com/threat/TL-2026-2830) — critical — 2026-10-01
- [Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files](https://intel.threadlinqs.com/threat/TL-2026-2812) — high — 2026-09-30
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software](https://intel.threadlinqs.com/threat/TL-2026-2555) — high — 2026-09-17
- [CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…](https://intel.threadlinqs.com/threat/TL-2026-2536) — high — 2026-09-16
- [Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected](https://intel.threadlinqs.com/threat/TL-2026-2524) — critical — 2026-09-15
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…](https://intel.threadlinqs.com/threat/TL-2026-2303) — medium — 2026-09-02
- [CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-2151) — high — 2026-08-26
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21
- [GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex](https://intel.threadlinqs.com/threat/TL-2026-2059) — medium — 2026-08-18
- [MacSync Stealer: Malvertising Campaign Impersonates Claude/Apple Support to Deploy macOS Infostealer](https://intel.threadlinqs.com/threat/TL-2026-2061) — high — 2026-08-17
- [Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser…](https://intel.threadlinqs.com/threat/TL-2026-1907) — high — 2026-08-06
- [XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projects](https://intel.threadlinqs.com/threat/TL-2026-1870) — high — 2026-08-04
- [npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for…](https://intel.threadlinqs.com/threat/TL-2026-1866) — critical — 2026-08-04
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Joyfill npm Packages Compromised with Blockchain C2 Loader](https://intel.threadlinqs.com/threat/TL-2026-1771) — medium — 2026-07-30
- [CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memory](https://intel.threadlinqs.com/threat/TL-2026-1762) — critical — 2026-07-29
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags…](https://intel.threadlinqs.com/threat/TL-2026-1735) — medium — 2026-07-28
- [Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow…](https://intel.threadlinqs.com/threat/TL-2026-1690) — high — 2026-07-23
- [Prompt Injection in AWS Kiro Leads to Remote Code Execution via Unprotected MCP Config (mcp.json)](https://intel.threadlinqs.com/threat/TL-2026-1631) — high — 2026-07-22
- [RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)](https://intel.threadlinqs.com/threat/TL-2026-1629) — high — 2026-07-22
- [CVE-2026-53910: Heap-Based Buffer Overflow in GNU diffutils diff3 (Signed Integer Overflow)](https://intel.threadlinqs.com/threat/TL-2026-1623) — medium — 2026-07-22
- [Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Execution](https://intel.threadlinqs.com/threat/TL-2026-1617) — critical — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accounts](https://intel.threadlinqs.com/threat/TL-2026-1514) — high — 2026-07-19

## Related CVEs

CVEs referenced by the tracked threats that use T1554, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2021-30952](https://intel.threadlinqs.com/cve/CVE-2021-30952)
- [CVE-2022-22948](https://intel.threadlinqs.com/cve/CVE-2022-22948)
- [CVE-2022-32917](https://intel.threadlinqs.com/cve/CVE-2022-32917)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2022-42856](https://intel.threadlinqs.com/cve/CVE-2022-42856)
- [CVE-2022-46689](https://intel.threadlinqs.com/cve/CVE-2022-46689)
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867)
- [CVE-2023-23514](https://intel.threadlinqs.com/cve/CVE-2023-23514)
- [CVE-2023-23529](https://intel.threadlinqs.com/cve/CVE-2023-23529)
- [CVE-2023-28204](https://intel.threadlinqs.com/cve/CVE-2023-28204)
- [CVE-2023-28206](https://intel.threadlinqs.com/cve/CVE-2023-28206)
- [CVE-2023-32373](https://intel.threadlinqs.com/cve/CVE-2023-32373)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-32435](https://intel.threadlinqs.com/cve/CVE-2023-32435)
- [CVE-2023-34048](https://intel.threadlinqs.com/cve/CVE-2023-34048)
- [CVE-2023-37450](https://intel.threadlinqs.com/cve/CVE-2023-37450)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2023-41974](https://intel.threadlinqs.com/cve/CVE-2023-41974)
- [CVE-2023-41990](https://intel.threadlinqs.com/cve/CVE-2023-41990)
- [CVE-2023-41991](https://intel.threadlinqs.com/cve/CVE-2023-41991)
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993)
- [CVE-2023-42916](https://intel.threadlinqs.com/cve/CVE-2023-42916)
- [CVE-2023-42917](https://intel.threadlinqs.com/cve/CVE-2023-42917)
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000)

## Detection coverage

Threadlinqs maintains 134 detection rules mapped to T1554 (SPL 50, KQL 40, Sigma 44). Rule content is available to Blue tier accounts and above; this page shows counts only.

134 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1554
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
