# T1001 Data Obfuscation

> As of 2026-10-05, T1001 (Data Obfuscation) appears in 30 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including APT28, APT38, Andariel; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 30 (7 critical, 22 high, 1 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 25
- **Detection rules:** 17 (counts only; Blue tier and above)

## Key facts

- **ID:** T1001
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1001/

## Activity timeline

T1001 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 13 reports, and 29 of the 30 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1001 Data Obfuscation is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 7 critical, 22 high, 1 medium.

Threats that use T1001 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (27 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (24 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (23 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (22 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

25 tracked threat actors appear in the threats that use T1001; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (2), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1001.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1001, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 2
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 2
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 2
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 1
- [Calypso](https://intel.threadlinqs.com/actor/Calypso) — 1
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 1

## Tracked threats

30 tracked threats use T1001.

- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — high — 2026-10-03
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates…](https://intel.threadlinqs.com/threat/TL-2026-1606) — high — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East…](https://intel.threadlinqs.com/threat/TL-2026-1582) — high — 2026-07-21
- [ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider…](https://intel.threadlinqs.com/threat/TL-2026-1572) — high — 2026-07-20
- [HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)](https://intel.threadlinqs.com/threat/TL-2026-1567) — high — 2026-07-20
- [HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API](https://intel.threadlinqs.com/threat/TL-2026-1555) — high — 2026-07-20
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Compromised @injectivelabs/sdk-ts npm Package (v1.20.21) Exfiltrates Cryptocurrency Wallet Mnemonics and…](https://intel.threadlinqs.com/threat/TL-2026-1381) — high — 2026-07-15
- [SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1227) — high — 2026-07-11
- [PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret)](https://intel.threadlinqs.com/threat/TL-2026-1215) — high — 2026-07-11
- [NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for…](https://intel.threadlinqs.com/threat/TL-2026-1112) — high — 2026-07-03
- [Mistic Windows Backdoor - In-Memory Code Execution via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-1017) — critical — 2026-06-30
- [TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector](https://intel.threadlinqs.com/threat/TL-2026-1010) — high — 2026-06-30
- [SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1005) — critical — 2026-06-30
- [Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026](https://intel.threadlinqs.com/threat/TL-2026-0993) — critical — 2026-06-28
- [JadeSnow: Hijacked npm/Go Supply Chain Attack with VSCode Exploitation and Blockchain Dead Drops](https://intel.threadlinqs.com/threat/TL-2026-0987) — critical — 2026-06-28
- [Indirect Setup-Error Prompt Abuse: Clean GitHub Repo + Failing Python Package + DNS TXT Payload Tricks AI…](https://intel.threadlinqs.com/threat/TL-2026-0955) — high — 2026-06-27
- [Showboat (EvaRAT): PRC-Backed Modular Linux Post-Exploitation Framework Targeting Middle East Telecom Firms…](https://intel.threadlinqs.com/threat/TL-2026-0839) — high — 2026-06-17
- [BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by…](https://intel.threadlinqs.com/threat/TL-2026-0532) — high — 2026-05-19
- [TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload](https://intel.threadlinqs.com/threat/TL-2026-0304) — critical — 2026-03-31
- [VoidLink Linux Rootkit Framework — eBPF + LKM Hybrid Persistence with ICMP C2](https://intel.threadlinqs.com/threat/TL-2026-0284) — high — 2026-03-25
- [Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation…](https://intel.threadlinqs.com/threat/TL-2026-0266) — critical — 2026-03-21
- [APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage…](https://intel.threadlinqs.com/threat/TL-2026-0204) — high — 2026-03-10
- [LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries](https://intel.threadlinqs.com/threat/TL-2026-0063) — critical — 2026-02-12
- [NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date…](https://intel.threadlinqs.com/threat/TL-2026-0095) — high — 2021-11-25

## Related CVEs

CVEs referenced by the tracked threats that use T1001, most frequent first.

- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2021-35394](https://intel.threadlinqs.com/cve/CVE-2021-35394)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2024-21338](https://intel.threadlinqs.com/cve/CVE-2024-21338)
- [CVE-2024-7971](https://intel.threadlinqs.com/cve/CVE-2024-7971)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 17 detection rules mapped to T1001 (SPL 9, KQL 4, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

17 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1001.001 Junk Data — 2 tracked threats
- T1001.002 Steganography — 7 tracked threats
- T1001.003 Protocol or Service Impersonation — 3 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
