Activity timeline
T1001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 13 reports, and 29 of the 30 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1001 Data Obfuscation is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 7 critical, 22 high, 1 medium.
Threats that use T1001 most often also use T1027 Obfuscated Files or Information (27 threats), T1071 Application Layer Protocol (24 threats), T1082 System Information Discovery (23 threats), T1059 Command and Scripting Interpreter (22 threats), T1140 Deobfuscate/Decode Files or Information (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
25 tracked threat actors appear in the threats that use T1001; the most frequent are APT28 (2), APT38 (2), Andariel (2), BlueDelta (2), Cavern Manticore (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1001.
Data sources
Telemetry that can reveal T1001, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
30 tracked threats use T1001.
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394high
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates…high
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East…high
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider…high
- HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)high
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- Compromised @injectivelabs/sdk-ts npm Package (v1.20.21) Exfiltrates Cryptocurrency Wallet Mnemonics and…high
- SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operationshigh
- PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret)high
- NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for…high
- Mistic Windows Backdoor - In-Memory Code Execution via DLL Sideloadingcritical
- TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sectorhigh
- SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscationcritical
- Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026critical
- JadeSnow: Hijacked npm/Go Supply Chain Attack with VSCode Exploitation and Blockchain Dead Dropscritical
- Indirect Setup-Error Prompt Abuse: Clean GitHub Repo + Failing Python Package + DNS TXT Payload Tricks AI…high
- Showboat (EvaRAT): PRC-Backed Modular Linux Post-Exploitation Framework Targeting Middle East Telecom Firms…high
- BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by…high
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payloadcritical
- VoidLink Linux Rootkit Framework — eBPF + LKM Hybrid Persistence with ICMP C2high
- Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation…critical
- APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage…high
- LABYRINTH CHOLLIMA Evolves into Three DPRK Adversariescritical
- NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date…high
Detection coverage
Threadlinqs maintains 17 detection rules mapped to T1001 (SPL 9, KQL 4, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1001.001 Junk Data — 2 tracked threats
- T1001.002 Steganography — 7 tracked threats
- T1001.003 Protocol or Service Impersonation — 3 tracked threats