T1129: T1129
Essential information
- MITRE technique ID
T1129- Confidence
- 100/100
- Revoked
- No
- Published
- 31/05/2017 23:31
- Modified
- 27/03/2026 01:08
- Author / Source
- The MITRE Corporation
Aliases
Shared Modules
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | execution |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (29)
-
UNC6691 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Wagmi relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Water Curse relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ZeroTrace Team relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
interlock relatedRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (87)
-
Matanbuchus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lumma Stealer usesThe MITRE Corporation Confidence 100
[Lumma Stealer](https://attack.mitre.org/software/S1213) is an information stealer malware family in use since at least 2022. [Lumma Stealer](https://attack.mitre.org/software/S1213) is a Malware as a Service (MaaS) where captured data has been…
First seen 01/01/1970 · Last seen 16/11/5138 · -
VersaMem usesFamily The MITRE Corporation Confidence 100
[VersaMem](https://attack.mitre.org/software/S1154) is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, [VersaMem](https://attack.mitre.org/software/S1154) was used during [Versa Director Zero Day Exploitation](https://attack.mitre.org/campaigns/C0039) by…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Pickai usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
FoggyWeb usesFamily The MITRE Corporation Confidence 100
[FoggyWeb](https://attack.mitre.org/software/S0661) is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active Directory Federated Services (AD FS) server. It has been used by…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Yurei Ransomware usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Spark RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TencShell usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Ebury usesFamily The MITRE Corporation Confidence 100
[Ebury](https://attack.mitre.org/software/S0377) is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by [Windigo](https://attack.mitre.org/groups/G0124). [Ebury](https://attack.mitre.org/software/S0377) is primarily installed through modifying shared libraries (`.so` files) executed…
First seen 01/01/1970 · Last seen 16/11/5138 · -
CreepyDrive usesFamily The MITRE Corporation Confidence 100
[CreepyDrive](https://attack.mitre.org/software/S1023) is a custom implant has been used by [POLONIUM](https://attack.mitre.org/groups/G1005) since at least early 2022 for C2 with and exfiltration to actor-controlled OneDrive accounts.(Citation: Microsoft POLONIUM June 2022)…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Reverse RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LightSpy usesFamily The MITRE Corporation Confidence 100
First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (37)
-
17 MITREs 3 Malwares 1 Observable
-
TINKYWINKEY KEYLOGGER related12 MITREs 1 Malware 3 Observables
-
1 CVE 15 MITREs 2 Malwares 121 Observables 1 APT
-
8 MITREs 3 Malwares 20 Observables
-
7 MITREs 3 Malwares 16 Observables 1 APT
-
10 MITREs 3 Malwares
-
15 MITREs 4 Malwares 48 Observables 1 APT
-
9 MITREs 3 Malwares 28 Observables 1 APT
-
5 MITREs 1 Malware 11 Observables
-
12 MITREs 4 Malwares 96 Observables 1 APT
-
The Shelby Strategy related13 MITREs 2 Malwares 1 APT
-
20 MITREs 3 Malwares 48 Observables 1 APT
Vulnerabilities (CVE) (34)
Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs.
- Attack vector
- LOCAL
- Published
- 24/07/2023
- Modified
- 21/12/2025
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, …
- Attack vector
- NETWORK
- Published
- 05/11/2025
- Modified
- 15/03/2026
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing …
- Attack vector
- NETWORK
- Published
- 13/04/2024
- Modified
- 21/12/2025
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
- Attack vector
- Network
- Published
- 19/07/2023
- Modified
- 27/05/2026
Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and …
- Attack vector
- Local
- Complexity
- LOW
- Published
- 05/03/2024
- Modified
- 04/04/2026
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.46 and …
- Attack vector
- NETWORK
- Published
- 18/07/2023
- Modified
- 21/12/2025
Reflected Cross-Site Scripting (XSS)
- Attack vector
- NETWORK
- Published
- 19/07/2023
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
- Attack vector
- Local
- Published
- 26/07/2023
- Modified
- 21/12/2025
Privilege Escalation to root administrator (nsroot)
- Attack vector
- ADJACENT_NETWORK
- Published
- 19/07/2023
- Modified
- 21/12/2025
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the …
- Attack vector
- NETWORK
- Published
- 03/04/2023
- Modified
- 21/12/2025
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss …
- Attack vector
- NETWORK
- Published
- 30/01/2023
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 20/12/2025