T1129: T1129
Essential information
- MITRE technique ID
T1129- Confidence
- 100/100
- Revoked
- No
- Published
- 31/05/2017 23:31
- Modified
- 27/03/2026 01:08
- Author / Source
- The MITRE Corporation
Aliases
Shared Modules
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | execution |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (29)
-
The Gentlemen usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
CL0P relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Mirai relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Nexus Team relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
NyashTeam and Kapchenka relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[POLONIUM](https://attack.mitre.org/groups/G1005) is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Proton66 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SideCopy relatedThe MITRE Corporation Confidence 100
[SideCopy](https://attack.mitre.org/groups/G1008) is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. [SideCopy](https://attack.mitre.org/groups/G1008)'s name comes from its…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Silver Fox relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Swan Vector relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TA2726, TA2727 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (87)
-
Strrat usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Attor usesFamily The MITRE Corporation Confidence 100
[Attor](https://attack.mitre.org/software/S0438) is a Windows-based espionage platform that has been seen in use since 2013. [Attor](https://attack.mitre.org/software/S0438) has a loadable plugin architecture to customize functionality for specific targets.(Citation: ESET Attor…
First seen 01/01/1970 · Last seen 16/11/5138 · -
OSX_OCEANLOTUS.D usesFamily The MITRE Corporation Confidence 100
[OSX_OCEANLOTUS.D](https://attack.mitre.org/software/S0352) is a macOS backdoor used by [APT32](https://attack.mitre.org/groups/G0050). First discovered in 2015, [APT32](https://attack.mitre.org/groups/G0050) has continued to make improvements using a plugin architecture to extend capabilities, specifically using `.dylib`…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Bumblebee usesFamily The MITRE Corporation Confidence 100
[Bumblebee](https://attack.mitre.org/software/S1039) is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to download and execute additional payloads since…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Akira usesThe MITRE Corporation Confidence 100
[Akira](https://attack.mitre.org/software/S1129) ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity [Akira](https://attack.mitre.org/groups/G1024). [Akira](https://attack.mitre.org/software/S1129) ransomware has been used in attacks across North America, Europe,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
BCDropper usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TechnoCreep usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TX Stealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Umbral-Stealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Putin Team usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Roarur usesThe MITRE Corporation Confidence 100
[Hydraq](https://attack.mitre.org/software/S0203) is a data-theft trojan first used by [Elderwood](https://attack.mitre.org/groups/G0066) in the 2009 Google intrusion known as Operation Aurora, though variations of this trojan have been used in more…
First seen 01/01/1970 · Last seen 16/11/5138 · -
DISGOMOJI usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (37)
-
17 MITREs 3 Malwares 1 Observable
-
TINKYWINKEY KEYLOGGER related12 MITREs 1 Malware 3 Observables
-
1 CVE 15 MITREs 2 Malwares 121 Observables 1 APT
-
8 MITREs 3 Malwares 20 Observables
-
7 MITREs 3 Malwares 16 Observables 1 APT
-
10 MITREs 3 Malwares
-
15 MITREs 4 Malwares 48 Observables 1 APT
-
9 MITREs 3 Malwares 28 Observables 1 APT
-
5 MITREs 1 Malware 11 Observables
-
12 MITREs 4 Malwares 96 Observables 1 APT
-
The Shelby Strategy related13 MITREs 2 Malwares 1 APT
-
20 MITREs 3 Malwares 48 Observables 1 APT
Vulnerabilities (CVE) (34)
Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web …
- Attack vector
- LOCAL
- Published
- 24/08/2021
- Modified
- 10/03/2026
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute …
- Attack vector
- Local
- Published
- 02/07/2024
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
- Published
- 03/11/2021
- Modified
- 03/03/2026
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. …
- Attack vector
- Network
- Published
- 25/07/2023
- Modified
- 21/12/2025
Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a …
- Attack vector
- NETWORK
- Published
- 02/08/2023
- Modified
- 21/12/2025
Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary …
- Attack vector
- Network
- Published
- 20/10/2025
- Modified
- 03/03/2026
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.
- Attack vector
- LOCAL
- Published
- 24/07/2023
- Modified
- 21/12/2025
Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.
- Attack vector
- Local
- Published
- 23/06/2023
- Modified
- 03/03/2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an …
- Attack vector
- NETWORK
- Published
- 20/07/2023
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel …
- Published
- 03/11/2021
- Modified
- 03/03/2026
Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a …
- Attack vector
- NETWORK
- Published
- 02/08/2023
- Modified
- 21/12/2025
Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage …
- Attack vector
- NETWORK
- Published
- 02/08/2023
- Modified
- 21/12/2025