T1127: T1127
Essential information
- MITRE technique ID
T1127- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 05/05/2026 12:36
- Author / Source
- The MITRE Corporation
Aliases
Trusted Developer Utilities Proxy Execution
Platforms
windows
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (26)
-
The MITRE Corporation Confidence 100
[Transparent Tribe](https://attack.mitre.org/groups/G0134) is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[POLONIUM](https://attack.mitre.org/groups/G1005) is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
SideCopy usesThe MITRE Corporation Confidence 100
[SideCopy](https://attack.mitre.org/groups/G1008) is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. [SideCopy](https://attack.mitre.org/groups/G1008)'s name comes from its …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
LilacSquid usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:07 · Modified 21/12/2025 05:07
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 08/04/2026 13:02 -
Amatera Stealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:18 · Modified 21/12/2025 14:18
-
The MITRE Corporation Confidence 100
[HEXANE](https://attack.mitre.org/groups/G1001) is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Andariel](https://attack.mitre.org/groups/G0138) is a North Korean state-sponsored threat group that has been active since at least 2009. [Andariel](https://attack.mitre.org/groups/G0138) has primarily focused its operations--which have included destructive attacks--against South Korean …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 22/05/2026 04:12 -
The MITRE Corporation Confidence 100
[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
UNC2565 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:28 · Modified 20/12/2025 23:28
-
bluebottle usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:16 · Modified 20/12/2025 23:16
-
Crimson usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:01 · Modified 21/12/2025 00:01
-
Mallox usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:47 · Modified 21/12/2025 04:47
-
Makop usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:47 · Modified 20/12/2025 23:47
-
The MITRE Corporation Confidence 100
[menuPass](https://attack.mitre.org/groups/G0045) is a threat group that has been active since at least 2006. Individual members of [menuPass](https://attack.mitre.org/groups/G0045) are known to have acted in association with the Chinese Ministry …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:34 · Modified 20/12/2025 19:34
-
Dark Pink usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:05 · Modified 20/12/2025 23:05
-
Grandoreiro usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:03 · Modified 21/12/2025 03:03
-
Cluster B usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:05 · Modified 20/12/2025 23:05
-
CloudWizard usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:45 · Modified 21/12/2025 00:45
-
The MITRE Corporation Confidence 100
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
GoldenJackal usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:36 · Modified 21/12/2025 00:36
-
IMPERIAL KITTEN usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 01:51 · Modified 21/12/2025 01:51
Malware (123)
- HyperBro
-
Redline usesFamilyPublished 08/05/2026 11:31 · Modified 08/05/2026 11:31
- CryptoClippy
-
AllaKore RAT usesFamilyPublished 21/08/2025 16:16 · Modified 21/08/2025 16:16
-
AsyncRAT usesFamilyPublished 11/06/2026 16:31 · Modified 11/06/2026 16:31
- Margulas
-
NetSupport usesFamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
- Cucky
- Dridex
-
GuLoader usesFamilyPublished 19/09/2024 19:34 · Modified 19/09/2024 19:34
-
Trigona usesFamilyPublished 01/05/2026 17:53 · Modified 01/05/2026 17:53
- Mimilite
- Scarab
- CommonMagic
-
Metasploit usesFamilyPublished 03/02/2026 08:21 · Modified 03/02/2026 08:21
- PapaCreep
-
Akira usesFamilyPublished 12/06/2026 16:57 · Modified 12/06/2026 16:57
-
zgRAT usesFamilyPublished 21/08/2025 00:37 · Modified 21/08/2025 00:37
- CreepySnail
- Drokbk
- Hannabi Grabber
-
PyInstaller usesFamilyPublished 31/01/2025 10:09 · Modified 31/01/2025 10:09
- PrCtrl
- Chaos
- Turla
-
ElizaRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 01:11 · Modified 21/12/2025 01:11
- Engima Stealer
-
LegionLoader usesFamilyPublished 05/04/2025 07:55 · Modified 05/04/2025 07:55
- El Machete
-
Stealerium usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:38 · Modified 20/12/2025 23:34
- DeepCreep
-
Satacom usesFamilyPublished 10/02/2025 13:54 · Modified 10/02/2025 13:54
- HotRat
- MASEPIE
- FONELAUNCH
- Lyceum
- Ministealer
-
Phobos usesFamilyPublished 30/09/2024 10:39 · Modified 30/09/2024 10:39
-
Quasar usesFamilyPublished 24/02/2025 14:22 · Modified 24/02/2025 14:22
- HYPERSCRAPE
- SpaceColon
-
Hijackloader usesFamilyPublished 10/06/2026 11:58 · Modified 10/06/2026 11:58
-
SquidLoader usesFamilyPublished 21/07/2025 12:03 · Modified 21/07/2025 12:03
-
NOOPDOOR usesFamilyPublished 27/11/2024 18:31 · Modified 27/11/2024 18:31
- UPPERCUT
-
PureRAT usesFamilyPublished 28/01/2026 17:20 · Modified 28/01/2026 17:20
-
Rhadamanthys usesFamilyPublished 29/04/2026 02:24 · Modified 29/04/2026 02:24
- Jupyter Stealer
- NETWIRE
- Nokoyawa
- Ares
-
Havoc usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
PXA usesFamilyPublished 10/10/2025 20:35 · Modified 10/10/2025 20:35
-
Lorem Ipsum usesFamilyPublished 04/05/2026 23:46 · Modified 04/05/2026 23:46
-
DUCKTAIL usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:35 · Modified 21/12/2025 01:43
- Kinsing
-
Babyk usesFamilyPublished 09/10/2025 20:09 · Modified 09/10/2025 20:09
-
CoinMiner usesFamilyPublished 14/04/2026 08:54 · Modified 14/04/2026 08:54
-
Sliver usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
- DroxiDat
-
XWorm usesFamilyPublished 27/03/2026 08:45 · Modified 27/03/2026 08:45
- dotRunpeX
-
AllaKore usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 21/12/2025 00:13
-
PureLogs usesFamilyPublished 26/05/2026 15:20 · Modified 26/05/2026 15:20
- DWservice
-
LockBit usesFamilyPublished 06/05/2026 10:26 · Modified 06/05/2026 10:26
- Mythic Poseidon
-
SORVEPOTEL usesFamilyPublished 06/05/2026 19:35 · Modified 06/05/2026 19:35
-
Grandoreiro - S0531 usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
- MegaCreep
- SysUpdate
- Dark Pink
- OCEANMAP
- FlipCreep
-
Remcos - S0332 usesFamilyPublished 31/01/2025 10:09 · Modified 31/01/2025 10:09
-
Agent Tesla usesFamilyPublished 28/05/2024 13:32 · Modified 28/05/2024 13:32
-
Yashma usesFamilyPublished 09/08/2024 11:19 · Modified 09/08/2024 11:19
- CreepyDrive
-
Cobalt Strike usesFamilyPublished 16/12/2024 14:25 · Modified 16/12/2024 14:25
- Gopuram
-
SolarMarker usesFamilyPublished 14/05/2024 13:06 · Modified 14/05/2024 13:06
- CosmicBeetle
-
Gootloader usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
PoshC2 usesFamilyPublished 26/06/2025 17:27 · Modified 26/06/2025 17:27
- Agent Racoon
-
Mallox usesFamilyPublished 25/10/2024 20:49 · Modified 25/10/2024 20:49
- Ntospy
- DuckLogs
-
LimeRAT usesFamilyPublished 26/08/2025 15:21 · Modified 26/08/2025 15:21
- Polar
- Crimson
-
SharpHound usesFamilyPublished 16/01/2026 13:31 · Modified 16/01/2026 13:31
- WarzoneRAT
-
Poseidon usesFamilyPublished 01/08/2025 12:31 · Modified 01/08/2025 12:31
-
FinalDraft usesFamilyPublished 05/05/2026 14:07 · Modified 05/05/2026 14:07
-
ROADSWEEP usesFamilyPublished 20/09/2024 11:10 · Modified 20/09/2024 11:10
- IMAPLoader
- BlackBit
- StandardKeyboard
- ServHelper
-
AgentTesla usesFamilyPublished 22/04/2026 07:06 · Modified 22/04/2026 07:06
- Sidewinder
- PowerMagic
- Transparent Tribe
-
FormBook usesFamilyPublished 22/04/2026 12:43 · Modified 22/04/2026 12:43
- Minas
- TechnoCreep
-
Xollam usesFamilyPublished 14/05/2024 18:03 · Modified 14/05/2024 18:03
- CAPI
- CHIMNEYSWEEP
-
MeshAgent usesFamilyPublished 02/09/2025 08:34 · Modified 02/09/2025 08:34
-
ParrotStealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:48 · Modified 20/12/2025 21:48
- SYK
-
QuasarRAT usesFamilyPublished 25/02/2026 11:35 · Modified 25/02/2026 11:35
- STEELHOOK
-
NOOPLDR usesFamilyPublished 07/10/2024 19:59 · Modified 07/10/2024 19:59
- Capra
- Golang
-
Amatera Stealer usesFamilyPublished 09/03/2026 09:42 · Modified 09/03/2026 09:42
- DarkTortilla
- AstraLocker
- FIN7
- Army Knife
Reports (10)
-
AlienVault Confidence 100 20 MITREs 3 IOCs 3 Observables 1 APTPublished 18/05/2026 21:29 · Modified 18/05/2026 19:56 · threat-report
-
AlienVault Confidence 100 20 MITREs 1 Malware 13 IOCs 13 ObservablesPublished 05/05/2026 01:46 · Modified 05/05/2026 10:36 · threat-report
-
20 MITREs 2 Malwares 7 ObservablesPublished 10/10/2025 20:35 · Modified 10/10/2025 21:09
-
7 MITREs 1 MalwarePublished 06/10/2025 18:55 · Modified 08/10/2025 16:09
-
7 MITREs 1 Malware 23 ObservablesPublished 06/10/2025 18:55 · Modified 06/10/2025 19:09
-
12 MITREs 1 Malware 9 ObservablesPublished 14/02/2025 15:42 · Modified 14/02/2025 15:46
-
Cuckoo Threat Actor Arsenal related14 MITREs 2 Malwares 9 Observables 1 APTPublished 07/10/2024 19:59 · Modified 07/10/2024 20:36
-
20 MITREs 1 Malware 9 Observables 1 APTPublished 05/08/2024 08:43 · Modified 05/08/2024 09:05
-
18 MITREs 1 Malware 18 Observables 1 APTPublished 20/05/2024 09:40 · Modified 20/05/2024 10:05
-
15 MITREs 3 Malwares 10 Observables 1 APTPublished 14/05/2024 18:03 · Modified 14/05/2024 18:30
Vulnerabilities (CVE) (7)
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern …
- Published
- 01/05/2023
- Modified
- 20/12/2025
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 09/08/2017
- Modified
- 22/04/2026
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
- Attack vector
- Network
- Published
- 10/12/2021
- Modified
- 27/05/2026
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
- Attack vector
- Local
- Complexity
- Low
- Published
- 15/11/2017
- Modified
- 29/05/2026
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file …
- Attack vector
- Local
- Published
- 24/08/2023
- Modified
- 27/05/2026
Attack patterns (MITRE) (3)
Course Of Action (3)
- Execution Prevention mitigates
- Disable or Remove Feature or Program mitigates
- Restrict Web-Based Content mitigates