T1554: T1554
Essential information
- MITRE technique ID
T1554- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/04/2026 16:32
- Author / Source
- The MITRE Corporation
Aliases
Compromise Host Software Binary
Platforms
windows macos linux ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | persistence |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (9)
-
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Curly COMrades usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 16:03 · Modified 21/12/2025 16:03
-
TeamPCP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/03/2026 22:18 · Modified 20/03/2026 22:18
-
GlassWorm usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 18:54 · Modified 21/12/2025 18:54
-
UNC6508 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 16/06/2026 13:48 · Modified 16/06/2026 13:48
-
Sukob usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/05/2026 18:46 · Modified 21/05/2026 18:46
-
Matrix usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:35 · Modified 21/12/2025 08:35
-
The MITRE Corporation Confidence 100
[APT5](https://attack.mitre.org/groups/G1023) is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
UNC3886 usesThe MITRE Corporation Confidence 100
[UNC3886](https://attack.mitre.org/groups/G1048) is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13
Malware (39)
-
Mirai usesFamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
- MacRansom
-
crypto-javascri usesFamilyPublished 20/05/2026 11:12 · Modified 20/05/2026 11:12
-
Shai-Hulud usesFamilyPublished 01/06/2026 19:31 · Modified 01/06/2026 19:31
- WARPWIRE
-
XCSSET usesFamilyPublished 11/03/2025 17:34 · Modified 11/03/2025 17:34
-
INFINITERED usesFamilyPublished 15/06/2026 19:33 · Modified 15/06/2026 19:33
- Kessel
- SLOWPULSE
-
Xorddos usesFamilyPublished 14/04/2026 08:54 · Modified 14/04/2026 08:54
- Bonadan
- BOLDMOVE
-
MucorAgent usesFamilyPublished 12/08/2025 14:57 · Modified 12/08/2025 14:57
-
Resocks usesFamilyPublished 12/08/2025 14:57 · Modified 12/08/2025 14:57
- WIREFIRE
-
POISONPLUG.SHADOW usesFamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
PHASEJAM usesFamilyPublished 09/01/2025 08:56 · Modified 09/01/2025 08:56
- Kobalos
-
DanaBot usesFamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
-
ScatterBrain usesFamilyPublished 29/01/2025 01:42 · Modified 29/01/2025 01:42
-
Ailurophile Stealer usesFamilyPublished 09/09/2024 09:26 · Modified 09/09/2024 09:26
-
mcpAddon.js usesFamilyPublished 22/04/2026 22:57 · Modified 22/04/2026 22:57
- ThiefQuest
-
PYbot usesFamilyPublished 27/11/2024 18:19 · Modified 27/11/2024 18:19
-
DiscordGo usesFamilyPublished 27/11/2024 18:19 · Modified 27/11/2024 18:19
-
GlassWorm usesFamilyPublished 26/03/2026 20:45 · Modified 26/03/2026 20:45
-
Arti usesFamilyPublished 20/05/2026 11:12 · Modified 20/05/2026 11:12
- BFG Agonizer
- Industroyer
- LITTLELAMB.WOOLTEA
- BUSHWALK
- KeRanger
-
Ebury usesFamilyPublished 15/05/2024 16:00 · Modified 15/05/2024 16:00
- SbaProxy
- LIGHTWIRE
- FileCoder
-
Canister Worm usesFamilyPublished 22/04/2026 22:57 · Modified 22/04/2026 22:57
-
StealC usesFamilyPublished 27/03/2026 08:46 · Modified 27/03/2026 08:46
- FRAMESTING
Reports (13)
-
12 MITREs 1 Malware 8 Observables 1 APTPublished 15/06/2026 19:33 · Modified 16/06/2026 11:48
-
AlienVault Confidence 100 19 MITREs 2 Malwares 1 IOC 1 Observable 1 APTPublished 20/05/2026 13:12 · Modified 21/05/2026 16:46 · threat-report
-
20 MITREs 8 ObservablesPublished 11/05/2026 11:49 · Modified 11/05/2026 19:27
-
AlienVault Confidence 100 18 MITREs 3 IOCs 3 Observables 1 APTPublished 27/04/2026 18:18 · Modified 27/04/2026 16:31 · threat-report
-
20 MITREs 1 Malware 4 Observables 1 APTPublished 25/04/2026 00:01 · Modified 27/04/2026 14:58
-
AlienVault Confidence 100 19 MITREs 2 Malwares 14 IOCs 14 Observables 1 APTPublished 23/04/2026 00:57 · Modified 27/04/2026 14:33 · threat-report
-
1 CVE 14 MITREs 7 ObservablesPublished 26/11/2025 09:27 · Modified 21/12/2025 18:02
-
8 MITREs 1 MalwarePublished 17/04/2025 13:06 · Modified 17/04/2025 16:38
-
11 MITREs 1 ObservablePublished 26/03/2025 16:55 · Modified 26/03/2025 17:20
-
20 MITREs 2 Malwares 2 Observables 1 APTPublished 29/01/2025 01:42 · Modified 29/01/2025 12:02
-
11 CVEs 17 MITREs 3 Malwares 12 Observables 1 APTPublished 27/11/2024 18:19 · Modified 27/11/2024 18:32
-
10 MITREs 1 Malware 2 ObservablesPublished 19/08/2024 13:39 · Modified 19/08/2024 13:59
-
16 MITREs 2 Malwares 68 ObservablesPublished 16/08/2024 08:21 · Modified 16/08/2024 08:53
Vulnerabilities (CVE) (12)
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This …
- Published
- 03/11/2021
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 20/12/2025
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the …
- Published
- 12/03/2025
- Modified
- 12/03/2025
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code …
- Attack vector
- NETWORK
- Published
- 09/06/2022
- Modified
- 21/12/2025
A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and …
- Published
- 16/05/2022
- Modified
- 20/12/2025
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended …
- Attack vector
- Network
- Published
- 18/09/2024
- Modified
- 21/12/2025
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This …
- Published
- 19/12/2017
- Modified
- 13/05/2026
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user …
- Published
- 07/08/2023
- Modified
- 20/12/2025
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 01/05/2015
- Modified
- 22/04/2026
Campaign (3)
- Cutting Edge uses
- RedPenguin uses
- 2016 Ukraine Electric Power Attack uses
Course Of Action (1)
- Code Signing mitigates