Activity timeline
T1016 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 121 reports, and 239 of the 239 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1016 System Network Configuration Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 239 of 2623 tracked threats (9.1%) to it; by severity that is 81 critical, 138 high, 20 medium.
Threats that use T1016 most often also use T1082 System Information Discovery (175 threats), T1027 Obfuscated Files or Information (162 threats), T1041 Exfiltration Over C2 Channel (155 threats), T1105 Ingress Tool Transfer (148 threats), T1005 Data from Local System (145 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
100 tracked threat actors appear in the threats that use T1016; the most frequent are APT28 (9), MuddyWater (9), APT38 (7), Sapphire Sleet (6), Stardust Chollima (6).
Data sources
Telemetry that can reveal T1016, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 239 tracked threats that use T1016.
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnethigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Acceleratormedium
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)high
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoorhigh
- Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…medium
- 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)medium
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- Tax Season Phishing and Malware Campaign Targets Indian Taxpayers via Fake Income Tax Department Noticeshigh
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Processhigh
- AutoIT Payload Injector Delivers VIPKeylogger via Phishing/RAR Chain into charmap.exemedium
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resiliencehigh
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Callshigh
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkithigh
- Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…high
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network Detectionhigh
- UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malwarehigh
- Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channelhigh
Detection coverage
Threadlinqs maintains 109 detection rules mapped to T1016 (SPL 28, KQL 44, Sigma 37). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1016.001 Internet Connection Discovery — 6 tracked threats
- T1016.002 Wi-Fi Discovery — 0 tracked threats