# T0831 Manipulation of Control

> As of 2026-10-05, T0831 (Manipulation of Control) appears in 10 tracked threats, first reported 2026-02-02 and most recently 2026-08-19, with linked actors including Sandworm, Static Tundra, APT44; it most often appears alongside T1046 (Network Service Discovery).

- **Tracked threats:** 10 (10 critical)
- **First seen:** 2026-02-02
- **Last seen:** 2026-08-19
- **Threat actors:** 7
- **Detection rules:** 7 (counts only; Blue tier and above)

## Key facts

- **ID:** T0831
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact (ICS)
- **Matrix:** ICS
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T0831/

## Activity timeline

T0831 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-08-19. The busiest month was 2026-02 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T0831 Manipulation of Control is catalogued by MITRE ATT&CK under the Impact (ICS) tactic in the ICS matrix. Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 10 critical.

Threats that use T0831 most often also use [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (8 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (8 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (6 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (6 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T0831; the most frequent are [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (4), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (3), [APT44](https://intel.threadlinqs.com/actor/APT44) (2), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (2), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) (1).

## Threat actors using it

- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 4
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 3
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 1
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 1

## Tracked threats

10 tracked threats use T0831.

- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — critical — 2026-08-19
- [CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1159) — critical — 2026-07-10
- [ZionSiphon — Ideologically Motivated .NET OT Malware Targeting Israeli Water & Desalination Infrastructure…](https://intel.threadlinqs.com/threat/TL-2026-0458) — critical — 2026-05-05
- [Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)](https://intel.threadlinqs.com/threat/TL-2026-0335) — critical — 2026-04-08
- [CISA KEV: Hikvision Camera Auth Bypass (CVE-2017-7921) & Rockwell Logix Credential Exposure (CVE-2021-22681)…](https://intel.threadlinqs.com/threat/TL-2026-0181) — critical — 2026-03-06
- [CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0166) — critical — 2026-03-02
- [Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and…](https://intel.threadlinqs.com/threat/TL-2026-0125) — critical — 2026-02-21
- [Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities](https://intel.threadlinqs.com/threat/TL-2026-0053) — critical — 2026-02-03
- [Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar Farms](https://intel.threadlinqs.com/threat/TL-2026-0037) — critical — 2026-02-03
- [Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0004) — critical — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T0831, most frequent first.

- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2020-15791](https://intel.threadlinqs.com/cve/CVE-2020-15791)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-51218](https://intel.threadlinqs.com/cve/CVE-2026-51218)

## Detection coverage

Threadlinqs maintains 7 detection rules mapped to T0831 (SPL 3, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

7 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T0831
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
