# T1007 System Service Discovery

> As of 2026-10-05, T1007 (System Service Discovery) appears in 37 tracked threats, first reported 2026-02-12 and most recently 2026-09-13, with linked actors including APT38, APT43, Contagious Interview cluster; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 37 (9 critical, 27 high, 1 medium)
- **First seen:** 2026-02-12
- **Last seen:** 2026-09-13
- **Threat actors:** 15
- **Detection rules:** 25 (counts only; Blue tier and above)

## Key facts

- **ID:** T1007
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1007/

## Activity timeline

T1007 first appeared in tracked threats on 2026-02-12 and was most recently reported on 2026-09-13. The busiest month was 2026-07 with 14 reports, and 37 of the 37 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1007 System Service Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 37 of 2623 tracked threats (1.4%) to it; by severity that is 9 critical, 27 high, 1 medium.

Threats that use T1007 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (27 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (21 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (21 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (20 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

15 tracked threat actors appear in the threats that use T1007; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) (1), [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) (1), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (1).

## Data sources

Telemetry that can reveal T1007, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [REvil](https://intel.threadlinqs.com/actor/REvil) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [StrikeShark](https://intel.threadlinqs.com/actor/StrikeShark) — 1
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1

## Tracked threats

The 30 most recent of 37 tracked threats that use T1007.

- [CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…](https://intel.threadlinqs.com/threat/TL-2026-2479) — high — 2026-09-13
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2380) — high — 2026-09-07
- [SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2098) — high — 2026-08-21
- [khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2067) — high — 2026-08-18
- [Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2005) — high — 2026-08-13
- [Attackers Compile khunt Toolkit Inside Oracle Database to Escalate SQL Injection to Windows SYSTEM Access](https://intel.threadlinqs.com/threat/TL-2026-1910) — critical — 2026-08-06
- [OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege…](https://intel.threadlinqs.com/threat/TL-2026-1887) — high — 2026-08-05
- [DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography](https://intel.threadlinqs.com/threat/TL-2026-1847) — high — 2026-08-03
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…](https://intel.threadlinqs.com/threat/TL-2026-1579) — critical — 2026-07-20
- [HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset…](https://intel.threadlinqs.com/threat/TL-2026-1528) — high — 2026-07-19
- [Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…](https://intel.threadlinqs.com/threat/TL-2026-1448) — high — 2026-07-17
- [Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil…](https://intel.threadlinqs.com/threat/TL-2026-1446) — medium — 2026-07-17
- [SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor, and XMRig Deployment](https://intel.threadlinqs.com/threat/TL-2026-1269) — high — 2026-07-13
- [The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and…](https://intel.threadlinqs.com/threat/TL-2026-1220) — high — 2026-07-11
- [EtherRAT: DPRK-Linked Vishing Campaign Abuses Microsoft Teams and Ethereum Smart Contracts to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1191) — high — 2026-07-10
- [GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot…](https://intel.threadlinqs.com/threat/TL-2026-1167) — high — 2026-07-10
- [GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1147) — high — 2026-07-09
- [SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1101) — high — 2026-07-03
- [Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading…](https://intel.threadlinqs.com/threat/TL-2026-1038) — high — 2026-07-01
- [FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) &…](https://intel.threadlinqs.com/threat/TL-2026-0884) — high — 2026-06-20
- [FortiSandbox Unauthenticated RCE Chain: JRPC API Path-Traversal Auth Bypass and OS Command Injection…](https://intel.threadlinqs.com/threat/TL-2026-0823) — critical — 2026-06-16
- [EndPoint (formerly Midnight) Babuk-Derived Ransomware — Windows/ESXi/NAS Double Extortion with ChaCha20+RSA…](https://intel.threadlinqs.com/threat/TL-2026-0652) — high — 2026-06-01
- [ABB Ability zenon Remote Transport Service CVE-2025-8754 — Missing Authentication Allows Unauthorized Remote…](https://intel.threadlinqs.com/threat/TL-2026-0594) — high — 2026-05-26
- [BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by…](https://intel.threadlinqs.com/threat/TL-2026-0532) — high — 2026-05-19
- [Tiflux RMM Triple-Threat Campaign — Service-Agreement Malspam Chains UltraVNC + Splashtop + ScreenConnect…](https://intel.threadlinqs.com/threat/TL-2026-0520) — high — 2026-05-17
- [Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and…](https://intel.threadlinqs.com/threat/TL-2026-0500) — high — 2026-05-12

## Related CVEs

CVEs referenced by the tracked threats that use T1007, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-8754](https://intel.threadlinqs.com/cve/CVE-2025-8754)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-20817](https://intel.threadlinqs.com/cve/CVE-2026-20817)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514)
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519)
- [CVE-2026-21522](https://intel.threadlinqs.com/cve/CVE-2026-21522)
- [CVE-2026-21525](https://intel.threadlinqs.com/cve/CVE-2026-21525)
- [CVE-2026-21532](https://intel.threadlinqs.com/cve/CVE-2026-21532)
- [CVE-2026-21533](https://intel.threadlinqs.com/cve/CVE-2026-21533)

## Detection coverage

Threadlinqs maintains 25 detection rules mapped to T1007 (SPL 8, KQL 10, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

25 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1007
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
