# T1601.001 Patch System Image

> As of 2026-10-05, T1601.001 (Patch System Image) appears in 11 tracked threats, first reported 2026-05-08 and most recently 2026-09-03, with linked actors including Static Tundra, INC Ransomware; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 11 (5 critical, 5 high)
- **First seen:** 2026-05-08
- **Last seen:** 2026-09-03
- **Threat actors:** 2
- **Detection rules:** 33 (counts only; Blue tier and above)

## Key facts

- **ID:** T1601.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1601
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1601/001/

## Activity timeline

T1601.001 first appeared in tracked threats on 2026-05-08 and was most recently reported on 2026-09-03. The busiest month was 2026-07 with 7 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1601.001 Patch System Image is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1601 Modify System Image](https://intel.threadlinqs.com/technique/T1601). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 5 critical, 5 high.

Threats that use T1601.001 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (6 threats), [T1016 System Network Configuration Discovery](https://intel.threadlinqs.com/technique/T1016) (4 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (4 threats), [T1203 Exploitation for Client Execution](https://intel.threadlinqs.com/technique/T1203) (4 threats), [T1211 Exploitation for Stealth](https://intel.threadlinqs.com/technique/T1211) (4 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1601.001; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (2), [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) (1).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1601.001.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1043 Credential Access Protection](https://attack.mitre.org/mitigations/M1043/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)
- [M1046 Boot Integrity](https://attack.mitre.org/mitigations/M1046/)

## Data sources

Telemetry that can reveal T1601.001, per MITRE ATT&CK.

- File — File Modification

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 2
- [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) — 1

## Tracked threats

11 tracked threats use T1601.001.

- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — critical — 2026-09-03
- [Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…](https://intel.threadlinqs.com/threat/TL-2026-2223) — high — 2026-08-29
- [Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel Access](https://intel.threadlinqs.com/threat/TL-2026-2049) — high — 2026-08-17
- [SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1462) — critical — 2026-07-17
- [OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)](https://intel.threadlinqs.com/threat/TL-2026-1363) — critical — 2026-07-15
- [11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1340) — high — 2026-07-14
- [FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…](https://intel.threadlinqs.com/threat/TL-2026-1283) — high — 2026-07-13
- [NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…](https://intel.threadlinqs.com/threat/TL-2026-1279) — critical — 2026-07-13
- [UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653…](https://intel.threadlinqs.com/threat/TL-2026-1257) — high — 2026-07-13
- [Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)](https://intel.threadlinqs.com/threat/TL-2026-1250) — 2026-07-13
- [Linux Kernel 'Dirty Frag' Universal Local Privilege Escalation — xfrm-ESP & RxRPC Page-Cache Write (No CVE…](https://intel.threadlinqs.com/threat/TL-2026-0483) — critical — 2026-05-08

## Related CVEs

CVEs referenced by the tracked threats that use T1601.001, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2025-31718](https://intel.threadlinqs.com/cve/CVE-2025-31718)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)

## Detection coverage

Threadlinqs maintains 33 detection rules mapped to T1601.001 (SPL 11, KQL 11, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

33 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1601 Modify System Image](https://intel.threadlinqs.com/technique/T1601) — 32 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1601.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
