# T1016 System Network Configuration Discovery

> As of 2026-10-05, T1016 (System Network Configuration Discovery) appears in 239 tracked threats, first reported 2026-02-02 and most recently 2026-09-29, with linked actors including APT28, MuddyWater, APT38; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 239 (81 critical, 138 high, 20 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-29
- **Threat actors:** 100
- **Detection rules:** 109 (counts only; Blue tier and above)

## Key facts

- **ID:** T1016
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1016/

## Activity timeline

T1016 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 121 reports, and 239 of the 239 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1016 System Network Configuration Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 239 of 2623 tracked threats (9.1%) to it; by severity that is 81 critical, 138 high, 20 medium.

Threats that use T1016 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (175 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (162 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (155 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (148 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (145 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

100 tracked threat actors appear in the threats that use T1016; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (9), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (9), [APT38](https://intel.threadlinqs.com/actor/APT38) (7), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (6), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (6).

## Data sources

Telemetry that can reveal T1016, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation
- Script — Script Execution

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 9
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 9
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 7
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 6
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 6
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 5
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 5
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 4
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 4
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 4
- [Turla](https://intel.threadlinqs.com/actor/Turla) — 4
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 3

## Tracked threats

The 30 most recent of 239 tracked threats that use T1016.

- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator](https://intel.threadlinqs.com/threat/TL-2026-1864) — medium — 2026-08-04
- [1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)](https://intel.threadlinqs.com/threat/TL-2026-1837) — high — 2026-08-03
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…](https://intel.threadlinqs.com/threat/TL-2026-1820) — medium — 2026-08-02
- [1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)](https://intel.threadlinqs.com/threat/TL-2026-1791) — medium — 2026-07-31
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [Tax Season Phishing and Malware Campaign Targets Indian Taxpayers via Fake Income Tax Department Notices](https://intel.threadlinqs.com/threat/TL-2026-1769) — high — 2026-07-30
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28
- [AutoIT Payload Injector Delivers VIPKeylogger via Phishing/RAR Chain into charmap.exe](https://intel.threadlinqs.com/threat/TL-2026-1740) — medium — 2026-07-28
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls](https://intel.threadlinqs.com/threat/TL-2026-1720) — high — 2026-07-27
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkit](https://intel.threadlinqs.com/threat/TL-2026-1754) — high — 2026-07-25
- [Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-1676) — high — 2026-07-24
- [TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2](https://intel.threadlinqs.com/threat/TL-2026-1684) — high — 2026-07-23
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network Detection](https://intel.threadlinqs.com/threat/TL-2026-1661) — high — 2026-07-23
- [UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malware](https://intel.threadlinqs.com/threat/TL-2026-1657) — high — 2026-07-23
- [Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channel](https://intel.threadlinqs.com/threat/TL-2026-1656) — high — 2026-07-23

## Related CVEs

CVEs referenced by the tracked threats that use T1016, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)

## Detection coverage

Threadlinqs maintains 109 detection rules mapped to T1016 (SPL 28, KQL 44, Sigma 37). Rule content is available to Blue tier accounts and above; this page shows counts only.

109 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1016.001 Internet Connection Discovery — 6 tracked threats
- T1016.002 Wi-Fi Discovery — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1016
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
