T1547.001 - Startup Folder - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
January 5, 2026
Last Seen
January 15, 2026

Related Threat Clusters

  • Gootloader Malware Evades Detection with Malformed ZIP Archives

    Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and…

    5 articles · Updated January 16, 2026
  • VVS Stealer Malware Targets Discord Accounts with Python Code

    VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…

    7 articles · Updated January 5, 2026
  • AsyncRAT Deployment via Phishing and Cloudflare Exploitation

    Threat actors have leveraged phishing emails to initiate a multi-stage intrusion chain that deploys the AsyncRAT remote access trojan. This operation utilizes Cloudflare's free-tier infrastructure and legitimate Python…

    3 articles · Updated January 14, 2026

Recent Intelligence Reports

  • Gootloader now uses 1,000 — Bleepingcomputer · January 15, 2026
  • AsyncRAT Phishing Chain Abuses WebDAV and Cloudflare — Socprime · January 14, 2026
  • Analyzing a Multi — Feeds.Trendmicro · January 12, 2026
  • VVS Stealer: PyInstaller Malware Steals Discord Tokens — Socprime · January 5, 2026

CVSS v3.1 Breakdown