T1176Software Extensions
T1176 — Software Extensions is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 10 detection use cases covering it and 56 threat-intel articles citing it.
Persistence
10Use cases
56Articles
2Sub-techniques
1Tactic
Sub-techniques (2)
Use cases covering this technique (10)
Suspicious browser extension installation [LLM] OkoBot browser-extension loader extl.exe deployed via HDUtil [LLM] External browser process connects to SiYuan kernel loopback admin port 127.0.0.1:6806 [LLM] Browser extension manifest rewritten adding networking/host permissions (supply-chain) [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro [LLM] VS Code child process fetching payload from nrwl/nx orphan commit (Nx Console v18.95.0 dropper) [LLM] Context.ai compromised Chrome extension (ID omddlmnhcofjbnbflmjginpjjblphbgk) present on endpoint [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro [LLM] Solidity Language malicious Cursor/VS Code extension folder created on disk (solidityai.solidity-* and related) [LLM] Browser extension folder write at vulnerable React DevTools 4.27.8 / Vue.js devtools 6.5.0Articles citing this technique (56)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit ESET Threat Report H1 2026 art-221
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-454
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556