Activity timeline
T1601 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 11 reports, and 32 of the 32 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1601 Modify System Image is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix. Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 14 critical, 16 high, 1 medium.
Threats that use T1601 most often also use T1059 Command and Scripting Interpreter (21 threats), T1190 Exploit Public-Facing Application (20 threats), T1552 Unsecured Credentials (17 threats), T1068 Exploitation for Privilege Escalation (16 threats), T1041 Exfiltration Over C2 Channel (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1601; the most frequent are Static Tundra (4), FSB Center 16 (2), UAT-8616 (2), APT28 (1), Chaotic Eclipse (1).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1601.
Data sources
Telemetry that can reveal T1601, per MITRE ATT&CK.
- File — File Modification
Threat actors using it
Tracked threats
The 30 most recent of 32 tracked threats that use T1601.
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Accesscritical
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…critical
- US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…high
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…critical
- Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft…high
- CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for…critical
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171)…critical
- Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructurecritical
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…high
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…high
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static…high
- Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related…high
- Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)
- RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitationcritical
- XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impacthigh
- Linux Kernel act_pedit COW Out-of-Bounds Write Enables Local Privilege Escalation to Root (CVE-2026-46331)high
- DirtyClone Linux Kernel Local Privilege Escalation via __pskb_copy_fclone() (CVE-2026-43503)high
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 — Actively Exploited 0-Day: Authenticated File-Upload Command…high
- Acer Wave 7 Mesh Routers — Max-Severity Unauthenticated Zero-Days CVE-2026-49200 (Cleartext Credential…critical
- Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security…critical
- PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For…high
- DirtyDecrypt / DirtyCBC — Linux Kernel rxgk Root LPE with Public PoC (CVE-2026-31635)high
- Cisco Catalyst SD-WAN CVE-2026-20182 — Critical Authentication Bypass Zero-Day Actively Exploited by…critical
- YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC…critical
- CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All…high
- Malicious NuGet Packages Impersonate Chinese UI Libraries — IR.* Infostealer With clrjit.dll JIT Hook…critical
- Linux Kernel 'Copy Fail' Local Privilege Escalation (CVE-2026-31431) — algif_aead 4-Byte Page Cache Write to…high
- Firestarter Malware Persists on Cisco ASA/Firepower Through Firmware Updates (CVE-2025-20333…critical
- Keenadu: Firmware-Level Android Supply Chain Backdoor via Zygote Process Injectionhigh
Detection coverage
Threadlinqs maintains 30 detection rules mapped to T1601 (SPL 10, KQL 9, Sigma 9, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1601.001 Patch System Image — 11 tracked threats
- T1601.002 Downgrade System Image — 7 tracked threats