Activity timeline
T1005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 424 reports, and 1172 of the 1173 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1005 Data from Local System is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 1173 of 2623 tracked threats (44.7%) to it; by severity that is 397 critical, 672 high, 89 medium, 2 low.
Threats that use T1005 most often also use T1082 System Information Discovery (728 threats), T1027 Obfuscated Files or Information (654 threats), T1041 Exfiltration Over C2 Channel (639 threats), T1059 Command and Scripting Interpreter (595 threats), T1071 Application Layer Protocol (498 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
190 tracked threat actors appear in the threats that use T1005; the most frequent are TeamPCP (41), APT38 (29), Lazarus Group (21), Sapphire Sleet (19), Stardust Chollima (19).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1005.
Data sources
Telemetry that can reveal T1005, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Process — OS API Execution, Process Creation
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 1173 tracked threats that use T1005.
- Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board…high
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…critical
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty…high
- Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft…critical
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- Frontline Education data breach via exploited third-party software vulnerability exposes school district…high
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)critical
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses…high
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Datahigh
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplacemedium
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)high
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible…critical
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Sitecritical
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromisedmedium
Detection coverage
Threadlinqs maintains 1195 detection rules mapped to T1005 (SPL 363, KQL 441, Sigma 389, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.