# T1010 Application Window Discovery

> As of 2026-10-05, T1010 (Application Window Discovery) appears in 40 tracked threats, first reported 2026-03-18 and most recently 2026-08-31, with linked actors including APT37, APT36, APT43; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 40 (4 critical, 34 high, 2 medium)
- **First seen:** 2026-03-18
- **Last seen:** 2026-08-31
- **Threat actors:** 15
- **Detection rules:** 19 (counts only; Blue tier and above)

## Key facts

- **ID:** T1010
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1010/

## Activity timeline

T1010 first appeared in tracked threats on 2026-03-18 and was most recently reported on 2026-08-31. The busiest month was 2026-07 with 16 reports, and 40 of the 40 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1010 Application Window Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 40 of 2623 tracked threats (1.5%) to it; by severity that is 4 critical, 34 high, 2 medium.

Threats that use T1010 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (34 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (31 threats), [T1113 Screen Capture](https://intel.threadlinqs.com/technique/T1113) (31 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (30 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

15 tracked threat actors appear in the threats that use T1010; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (4), [APT36](https://intel.threadlinqs.com/actor/APT36) (1), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) (1), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1).

## Data sources

Telemetry that can reveal T1010, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 4
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 1
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 1
- [SHADOW-WATER-063](https://intel.threadlinqs.com/actor/SHADOW-WATER-063) — 1
- [Storm-1811](https://intel.threadlinqs.com/actor/Storm-1811) — 1

## Tracked threats

The 30 most recent of 40 tracked threats that use T1010.

- [JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloads](https://intel.threadlinqs.com/threat/TL-2026-2259) — high — 2026-08-31
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…](https://intel.threadlinqs.com/threat/TL-2026-2163) — high — 2026-08-27
- [Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2005) — high — 2026-08-13
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1733) — high — 2026-07-27
- [MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal…](https://intel.threadlinqs.com/threat/TL-2026-1723) — high — 2026-07-27
- [Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel](https://intel.threadlinqs.com/threat/TL-2026-1695) — high — 2026-07-22
- [SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)](https://intel.threadlinqs.com/threat/TL-2026-1589) — high — 2026-07-21
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWorm](https://intel.threadlinqs.com/threat/TL-2026-1418) — high — 2026-07-16
- [UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign](https://intel.threadlinqs.com/threat/TL-2026-1413) — high — 2026-07-16
- [Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process…](https://intel.threadlinqs.com/threat/TL-2026-1285) — high — 2026-07-13
- [Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used to Map Active Directory Post-RDP Compromise](https://intel.threadlinqs.com/threat/TL-2026-1281) — medium — 2026-07-13
- [Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmations](https://intel.threadlinqs.com/threat/TL-2026-1252) — high — 2026-07-13
- [SCMBANKER PowerShell Banking Trojan Targets Mexican Financial Sector via ClickFix Fake CAPTCHA Lures (REF6045)](https://intel.threadlinqs.com/threat/TL-2026-1175) — high — 2026-07-10
- [CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1150) — critical — 2026-07-09
- [Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and…](https://intel.threadlinqs.com/threat/TL-2026-1079) — high — 2026-07-02
- [CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…](https://intel.threadlinqs.com/threat/TL-2026-1000) — critical — 2026-06-30
- [SharkLoader Malware Deploys Cobalt Strike Beacon via DLL Side-Loading in StrikeShark Campaign](https://intel.threadlinqs.com/threat/TL-2026-0961) — high — 2026-06-27
- [Operation DragonReturn — China-Nexus DcRAT Multi-Stage Espionage Campaign Targeting Govt. of India Ministry…](https://intel.threadlinqs.com/threat/TL-2026-0956) — critical — 2026-06-27
- [Multi-Stage Steganographic Loader Delivers Remcos RAT and Rotating Infostealers via .NET Bitmap Resource…](https://intel.threadlinqs.com/threat/TL-2026-0939) — high — 2026-06-25
- [Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing…](https://intel.threadlinqs.com/threat/TL-2026-0911) — high — 2026-06-23
- [ScarCruft (APT37) Deploys Python-Based NarwhalRAT via Fake Microsoft Account Security Alerts and LNK-in-ZIP…](https://intel.threadlinqs.com/threat/TL-2026-0890) — high — 2026-06-20
- [FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) &…](https://intel.threadlinqs.com/threat/TL-2026-0884) — high — 2026-06-20
- [AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian…](https://intel.threadlinqs.com/threat/TL-2026-0841) — high — 2026-06-17
- [NarwhalRAT: APT37-Linked Python RAT Deployed via Fake Microsoft OTP-Abuse Alerts Against South Korean Targets](https://intel.threadlinqs.com/threat/TL-2026-1525) — high — 2026-06-15

## Related CVEs

CVEs referenced by the tracked threats that use T1010, most frequent first.

- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)

## Detection coverage

Threadlinqs maintains 19 detection rules mapped to T1010 (SPL 4, KQL 10, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

19 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1010
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
