Activity timeline
T1010 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 16 reports, and 40 of the 40 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1010 Application Window Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 40 of 2623 tracked threats (1.5%) to it; by severity that is 4 critical, 34 high, 2 medium.
Threats that use T1010 most often also use T1027 Obfuscated Files or Information (34 threats), T1082 System Information Discovery (31 threats), T1113 Screen Capture (31 threats), T1140 Deobfuscate/Decode Files or Information (30 threats), T1005 Data from Local System (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
15 tracked threat actors appear in the threats that use T1010; the most frequent are APT37 (4), APT36 (1), APT43 (1), BlackSuit affiliate (1), Cavern Manticore (1).
Data sources
Telemetry that can reveal T1010, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 40 tracked threats that use T1010.
- JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloadshigh
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…high
- Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaignhigh
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoorhigh
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session Hijackinghigh
- MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal…high
- Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panelhigh
- SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)high
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWormhigh
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaignhigh
- Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process…high
- Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used to Map Active Directory Post-RDP Compromisemedium
- Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmationshigh
- SCMBANKER PowerShell Banking Trojan Targets Mexican Financial Sector via ClickFix Fake CAPTCHA Lures (REF6045)high
- CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deploymentcritical
- Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and…high
- CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…critical
- SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaignhigh
- Operation DragonReturn — China-Nexus DcRAT Multi-Stage Espionage Campaign Targeting Govt. of India Ministry…critical
- Multi-Stage Steganographic Loader Delivers Remcos RAT and Rotating Infostealers via .NET Bitmap Resource…high
- Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing…high
- ScarCruft (APT37) Deploys Python-Based NarwhalRAT via Fake Microsoft Account Security Alerts and LNK-in-ZIP…high
- FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) &…high
- AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…high
- NarwhalRAT: APT37-Linked Python RAT Deployed via Fake Microsoft OTP-Abuse Alerts Against South Korean Targetshigh
Detection coverage
Threadlinqs maintains 19 detection rules mapped to T1010 (SPL 4, KQL 10, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.