Activity timeline
T1601.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 7 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1601.001 Patch System Image is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of T1601 Modify System Image. Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 5 critical, 5 high.
Threats that use T1601.001 most often also use T1190 Exploit Public-Facing Application (6 threats), T1016 System Network Configuration Discovery (4 threats), T1082 System Information Discovery (4 threats), T1203 Exploitation for Client Execution (4 threats), T1211 Exploitation for Stealth (4 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
2 tracked threat actors appear in the threats that use T1601.001; the most frequent are Static Tundra (2), INC Ransomware (1).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1601.001.
Data sources
Telemetry that can reveal T1601.001, per MITRE ATT&CK.
- File — File Modification
Threat actors using it
Tracked threats
11 tracked threats use T1601.001.
- CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)critical
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…high
- Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel Accesshigh
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…critical
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)critical
- 11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)high
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…high
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…critical
- UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653…high
- Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)
- Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…critical
Detection coverage
Threadlinqs maintains 33 detection rules mapped to T1601.001 (SPL 11, KQL 11, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1601 Modify System Image — 32 tracked threats at the technique level.