Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

Miasma operator

As of 2026-06-08, Miasma operator is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning supply chain. ATT&CK coverage spans 34 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1102 (Web Service), T1140 (Deobfuscate/Decode Files or Information).

Tracked threats
22 critical
First seen
2026-06-01
Last seen
2026-06-08
ATT&CK techniques
34across 2 of 2 threats
Related CVEs
0None referenced
2 tracked threat(s) · Categories: SUPPLY_CHAIN

Activity timeline

Miasma operator appears in 2 tracked threats between and .

ATT&CK techniques observed

34 techniques observed across 2 of 2 tracked threats · Credential Access (5), Initial Access (5), Stealth (formerly Defense Evasion) (5), Discovery (4), Execution (4), Command and Control (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 2 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 2 of 2 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 2 of 2 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 2 of 2 tracked threats
  • T1546 Event Triggered Execution — Persistenceobserved in 2 of 2 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 2 tracked threats
  • T1003 OS Credential Dumping — Credential Accessobserved in 1 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 1 of 2 tracked threats
  • T1059.004 Unix Shell — Executionobserved in 1 of 2 tracked threats
  • T1059.007 JavaScript — Executionobserved in 1 of 2 tracked threats

Tracked threats