Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-08

Sable Squirrel

As of 2026-08-16, Sable Squirrel is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. ATT&CK coverage spans 18 techniques across 8 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036.005 (Match Legitimate Resource Name or Location), T1204.002 (User Execution: Malicious File).

Tracked threats
21 high · 1 medium
First seen
2026-08-15
Last seen
2026-08-16
ATT&CK techniques
18across 2 of 2 threats
Related CVEs
0None referenced
2 tracked threat(s) · Categories: MALWARE

Activity timeline

Sable Squirrel appears in 2 tracked threats between and .

ATT&CK techniques observed

18 techniques observed across 2 of 2 tracked threats · Resource Development (7), Command and Control (3), Stealth (formerly Defense Evasion) (3), Discovery (1), Execution (1), Initial Access (1)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 2 of 2 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 2 of 2 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 2 of 2 tracked threats
  • T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 2 of 2 tracked threats
  • T1608.001 Upload Malware — Resource Developmentobserved in 2 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 1 of 2 tracked threats
  • T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 1 of 2 tracked threats
  • T1583.008 Acquire Infrastructure: Malvertising — Resource Developmentobserved in 1 of 2 tracked threats
  • T1584.001 Compromise Infrastructure: Domains — Resource Developmentobserved in 1 of 2 tracked threats
  • T1587.001 Malware — Resource Developmentobserved in 1 of 2 tracked threats
  • T1596.001 Search Open Technical Databases: DNS/Passive DNS — Reconnaissanceobserved in 1 of 2 tracked threats

Tracked threats