T1112 - Modify Registry - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
33
occurrences
First Seen
November 17, 2025
Last Seen
July 23, 2026

T1112 - Modify Registry is a mitre_attack tracked across 28 threat clusters and 33 intelligence report mentions on ThreatCluster. First observed November 17, 2025; most recent activity July 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • T1485 — attack.mitre.org · July 23, 2026
  • 001 — attack.mitre.org · July 23, 2026
  • New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry — Cybersecuritynews · July 15, 2026
  • How to get free Windows 10 security patches until October 2027 - and avoid the $30 fee — Zdnet · June 26, 2026
  • G0034 — attack.mitre.org · June 24, 2026
  • A VBScript campaign distributed through WhatsApp deploying RMM software — Securelist · June 22, 2026
  • GhostTree Attack Abused Recursive Windows Junctions to Hide Malware — Bleepingcomputer · June 16, 2026
  • Microsoft May security patch fails for some due to boot partition size glitch — Csoonline · May 18, 2026

CVSS v3.1 Breakdown