Activity timeline
T1008 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 39 reports, and 81 of the 81 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1008 Fallback Channels is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 81 of 2623 tracked threats (3.1%) to it; by severity that is 17 critical, 62 high, 1 medium.
Threats that use T1008 most often also use T1027 Obfuscated Files or Information (79 threats), T1082 System Information Discovery (65 threats), T1041 Exfiltration Over C2 Channel (62 threats), T1005 Data from Local System (57 threats), T1140 Deobfuscate/Decode Files or Information (57 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
48 tracked threat actors appear in the threats that use T1008; the most frequent are Cavern Manticore (4), TeamPCP (3), UAT-11795 (3), APT38 (2), APT43 (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1008.
Data sources
Telemetry that can reveal T1008, per MITRE ATT&CK.
- Network Traffic — Network Connection Creation, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 81 tracked threats that use T1008.
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentialscritical
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…high
- SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attackshigh
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Servicehigh
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…high
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRighigh
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)critical
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail…high
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojancritical
- EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contracthigh
- FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.aihigh
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channelhigh
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…high
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…high
- TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East…high
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider…high
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAThigh
Detection coverage
Threadlinqs maintains 109 detection rules mapped to T1008 (SPL 33, KQL 33, Sigma 43). Rule content is available to Blue tier accounts and above; this page shows counts only.