# T1601 Modify System Image

> As of 2026-10-05, T1601 (Modify System Image) appears in 32 tracked threats, first reported 2026-02-25 and most recently 2026-09-24, with linked actors including Static Tundra, FSB Center 16, UAT-8616; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 32 (14 critical, 16 high, 1 medium)
- **First seen:** 2026-02-25
- **Last seen:** 2026-09-24
- **Threat actors:** 7
- **Detection rules:** 30 (counts only; Blue tier and above)

## Key facts

- **ID:** T1601
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1601/

## Activity timeline

T1601 first appeared in tracked threats on 2026-02-25 and was most recently reported on 2026-09-24. The busiest month was 2026-07 with 11 reports, and 32 of the 32 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1601 Modify System Image is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix. Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 14 critical, 16 high, 1 medium.

Threats that use T1601 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (21 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (20 threats), [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) (17 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (16 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1601; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (4), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (2), [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1601.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1043 Credential Access Protection](https://attack.mitre.org/mitigations/M1043/)
- [M1045 Code Signing](https://attack.mitre.org/mitigations/M1045/)
- [M1046 Boot Integrity](https://attack.mitre.org/mitigations/M1046/)

## Data sources

Telemetry that can reveal T1601, per MITRE ATT&CK.

- File — File Modification

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 4
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1

## Tracked threats

The 30 most recent of 32 tracked threats that use T1601.

- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — medium — 2026-09-24
- [Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Access](https://intel.threadlinqs.com/threat/TL-2026-2041) — critical — 2026-08-17
- [ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…](https://intel.threadlinqs.com/threat/TL-2026-1872) — critical — 2026-08-04
- [US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…](https://intel.threadlinqs.com/threat/TL-2026-1751) — high — 2026-07-29
- [CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-1725) — critical — 2026-07-27
- [Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft…](https://intel.threadlinqs.com/threat/TL-2026-1497) — high — 2026-07-18
- [CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for…](https://intel.threadlinqs.com/threat/TL-2026-1385) — critical — 2026-07-15
- [FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171)…](https://intel.threadlinqs.com/threat/TL-2026-1312) — critical — 2026-07-14
- [Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1282) — critical — 2026-07-13
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…](https://intel.threadlinqs.com/threat/TL-2026-1277) — high — 2026-07-13
- [FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…](https://intel.threadlinqs.com/threat/TL-2026-1276) — high — 2026-07-13
- [CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static…](https://intel.threadlinqs.com/threat/TL-2026-1272) — high — 2026-07-13
- [Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related…](https://intel.threadlinqs.com/threat/TL-2026-1251) — high — 2026-07-13
- [Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)](https://intel.threadlinqs.com/threat/TL-2026-1250) — 2026-07-13
- [RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1006) — critical — 2026-06-30
- [XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact](https://intel.threadlinqs.com/threat/TL-2026-1001) — high — 2026-06-30
- [Linux Kernel act_pedit COW Out-of-Bounds Write Enables Local Privilege Escalation to Root (CVE-2026-46331)](https://intel.threadlinqs.com/threat/TL-2026-0964) — high — 2026-06-27
- [DirtyClone Linux Kernel Local Privilege Escalation via __pskb_copy_fclone() (CVE-2026-43503)](https://intel.threadlinqs.com/threat/TL-2026-0962) — high — 2026-06-27
- [Cisco Catalyst SD-WAN Manager CVE-2026-20245 — Actively Exploited 0-Day: Authenticated File-Upload Command…](https://intel.threadlinqs.com/threat/TL-2026-0696) — high — 2026-06-06
- [Acer Wave 7 Mesh Routers — Max-Severity Unauthenticated Zero-Days CVE-2026-49200 (Cleartext Credential…](https://intel.threadlinqs.com/threat/TL-2026-0674) — critical — 2026-06-03
- [Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security…](https://intel.threadlinqs.com/threat/TL-2026-0563) — critical — 2026-05-22
- [PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For…](https://intel.threadlinqs.com/threat/TL-2026-0543) — high — 2026-05-21
- [DirtyDecrypt / DirtyCBC — Linux Kernel rxgk Root LPE with Public PoC (CVE-2026-31635)](https://intel.threadlinqs.com/threat/TL-2026-0524) — high — 2026-05-18
- [Cisco Catalyst SD-WAN CVE-2026-20182 — Critical Authentication Bypass Zero-Day Actively Exploited by…](https://intel.threadlinqs.com/threat/TL-2026-0516) — critical — 2026-05-14
- [YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC…](https://intel.threadlinqs.com/threat/TL-2026-0512) — critical — 2026-05-13
- [CVE-2026-31431 "Copy Fail" — Linux Kernel algif_aead Deterministic Local Privilege Escalation Affecting All…](https://intel.threadlinqs.com/threat/TL-2026-0486) — high — 2026-05-08
- [Malicious NuGet Packages Impersonate Chinese UI Libraries — IR.* Infostealer With clrjit.dll JIT Hook…](https://intel.threadlinqs.com/threat/TL-2026-0473) — critical — 2026-05-07
- [Linux Kernel 'Copy Fail' Local Privilege Escalation (CVE-2026-31431) — algif_aead 4-Byte Page Cache Write to…](https://intel.threadlinqs.com/threat/TL-2026-0445) — high — 2026-04-30
- [Firestarter Malware Persists on Cisco ASA/Firepower Through Firmware Updates (CVE-2025-20333…](https://intel.threadlinqs.com/threat/TL-2026-0422) — critical — 2026-04-24
- [Keenadu: Firmware-Level Android Supply Chain Backdoor via Zygote Process Injection](https://intel.threadlinqs.com/threat/TL-2026-0251) — high — 2026-03-19

## Related CVEs

CVEs referenced by the tracked threats that use T1601, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2024-1781](https://intel.threadlinqs.com/cve/CVE-2024-1781)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-2894](https://intel.threadlinqs.com/cve/CVE-2025-2894)
- [CVE-2025-29635](https://intel.threadlinqs.com/cve/CVE-2025-29635)
- [CVE-2025-35027](https://intel.threadlinqs.com/cve/CVE-2025-35027)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-60017](https://intel.threadlinqs.com/cve/CVE-2025-60017)
- [CVE-2025-60250](https://intel.threadlinqs.com/cve/CVE-2025-60250)
- [CVE-2025-60251](https://intel.threadlinqs.com/cve/CVE-2025-60251)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-16812](https://intel.threadlinqs.com/cve/CVE-2026-16812)
- [CVE-2026-20182](https://intel.threadlinqs.com/cve/CVE-2026-20182)
- [CVE-2026-20245](https://intel.threadlinqs.com/cve/CVE-2026-20245)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-27509](https://intel.threadlinqs.com/cve/CVE-2026-27509)
- [CVE-2026-27510](https://intel.threadlinqs.com/cve/CVE-2026-27510)
- [CVE-2026-31635](https://intel.threadlinqs.com/cve/CVE-2026-31635)
- [CVE-2026-33000](https://intel.threadlinqs.com/cve/CVE-2026-33000)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)

## Detection coverage

Threadlinqs maintains 30 detection rules mapped to T1601 (SPL 10, KQL 9, Sigma 9, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

30 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1601.001 Patch System Image](https://intel.threadlinqs.com/technique/T1601.001) — 11 tracked threats
- T1601.002 Downgrade System Image — 7 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1601
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
