T1125 - Video Capture - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
February 12, 2026
Last Seen
July 27, 2026

T1125 - Video Capture is a mitre_attack tracked by ThreatCluster, appearing in 12 threat clusters built from 13 intelligence report mentions.

T1125 - Video Capture is a mitre_attack tracked across 12 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed February 12, 2026; most recent activity July 27, 2026.

Related Threat Clusters

  • Russian UAT-11795 Targets Users with Trojans in Legitimate Software

    A Russian threat actor known as UAT-11795 has been deploying the Starland RAT and WLDR agent since June 2025, primarily targeting users in the U.S., Germany, Romania, and Venezuela. The group uses trojanized installers…

    6 articles · Updated July 17, 2026
  • CrystalX RAT: New Malware Combines Data Theft and Prankware Features

    In March 2026, cybersecurity researchers discovered CrystalX RAT, a new malware-as-a-service (MaaS) being promoted in private Telegram channels. This malware offers a wide range of capabilities, including remote access,…

    10 articles · Updated April 1, 2026
  • Ontario Police Use Secretive Spyware, Risk Dropping Major Cases

    Ontario Provincial Police are employing advanced phone-hacking spyware known as on-device investigative tools (ODITs) to access suspects' smartphones. This technology allows police to download data, read encrypted…

    5 articles · Updated May 19, 2026
  • OkoBot Malware Targets Cryptocurrency Users to Steal Seed Phrases

    The OkoBot malware framework has been identified as a significant threat to cryptocurrency users, specifically targeting Ledger and Trezor wallets. This multi-stage malware captures sensitive information, including…

    20 articles · Updated July 15, 2026
  • AI-Generated Browser Ransomware Emerges Using File System Access API

    Check Point Research has identified a new form of ransomware generated by the AI model DeepSeek, which operates entirely within web browsers by exploiting the File System Access API. This attack method requires no…

    11 articles · Updated July 1, 2026
  • UK Supreme Court Rules Against Bahrain's State Immunity in Spyware Case

    The UK Supreme Court has ruled that Bahrain cannot claim state immunity in a lawsuit filed by two dissidents, Saeed Shehabi and Moosa Mohammed, alleging that their computers were infected with FinSpy spyware in 2011.…

    14 articles · Updated July 27, 2026
  • QuimaRAT Malware Emerges as Cross-Platform Threat via MaaS Model

    QuimaRAT, a new Java-based remote access trojan (RAT), has been identified as a significant threat targeting Windows, macOS, and Linux systems. Offered as malware-as-a-service (MaaS), it has subscription costs ranging…

    2 articles · Updated July 7, 2026
  • Rise of AI-Driven Scams Targeting UK SMEs

    UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…

    748 articles · Updated March 12, 2026
  • BeatBanker Android Malware Targets Brazilian Users via Fake Starlink App

    The BeatBanker malware, posing as a Starlink app, is targeting Android users in Brazil through phishing sites mimicking the Google Play Store. This dual-mode malware combines banking trojan capabilities with…

    20 articles · Updated March 10, 2026
  • Azerbaijani Man Sentenced for Espionage at Greek Naval Base

    A Greek court sentenced a 27-year-old Azerbaijani man to seven years and one month in prison for espionage related to the Souda naval base on Crete. The man was arrested in June 2025 after being accused of monitoring…

    4 articles · Updated May 21, 2026

Recent Intelligence Reports

  • Dissidents win in Supreme Court against Bahrain appeal — Leighday · July 27, 2026
  • Bahrain cannot claim sovereign immunity for spyware attack against UK dissidents, top UK court rules — Computerweekly · July 27, 2026
  • Russian hackers trojanize WebEx, Zoom apps to push Starland malware — Bleepingcomputer · July 16, 2026
  • Kaspersky reveals a new malicious framework targeting cryptocurrency users with the use of ... — Kaspersky · July 15, 2026
  • New QuimaRAT malware targets Windows, Linux, and macOS via MaaS model — Scworld · July 7, 2026
  • When AI Invents the Attack: Browser-Native Ransomware — Organisator.Ch · July 1, 2026
  • Greek Court Sentences Azerbaijani Man for Espionage at Crete Base — Globalbankingandfinance · May 21, 2026
  • Ontario Police Would Rather Drop Cases Than Reveal Their Phone — Iphoneincanada.Ca · May 19, 2026

Frequently asked questions

What is T1125 - Video Capture?

T1125 - Video Capture is a mitre_attack tracked by ThreatCluster, appearing in 12 threat clusters built from 13 intelligence report mentions.

Is T1125 - Video Capture still active?

The most recent intelligence report mentioning T1125 - Video Capture on ThreatCluster is dated July 27, 2026. Activity was first observed February 12, 2026, giving a tracked span from then to July 27, 2026.

What is T1125 - Video Capture associated with?

Across ThreatCluster reporting, T1125 - Video Capture most frequently co-occurs with Malware, Phishing, Ransomware, Trojan, OkoBot Campaign, among 12 tracked related entities.

What are the latest developments involving T1125 - Video Capture?

The most significant recent cluster is “Russian UAT-11795 Targets Users with Trojans in Legitimate Software” (6 articles · Updated July 17, 2026). T1125 - Video Capture appears across 12 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1125 - Video Capture?

T1125 - Video Capture appears in 13 intelligence report mentions across 12 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown