# T1018 Remote System Discovery

> As of 2026-10-05, T1018 (Remote System Discovery) appears in 206 tracked threats, first reported 2026-02-02 and most recently 2026-09-28, with linked actors including Akira, Cavern Manticore, MuddyWater; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 206 (82 critical, 102 high, 20 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-28
- **Threat actors:** 89
- **Detection rules:** 162 (counts only; Blue tier and above)

## Key facts

- **ID:** T1018
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1018/

## Activity timeline

T1018 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 77 reports, and 206 of the 206 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1018 Remote System Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 206 of 2623 tracked threats (7.9%) to it; by severity that is 82 critical, 102 high, 20 medium.

Threats that use T1018 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (126 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (105 threats), [T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021) (104 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (104 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (98 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

89 tracked threat actors appear in the threats that use T1018; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (5), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (4), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (4), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (4), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (4).

## Data sources

Telemetry that can reveal T1018, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation
- Process — Process Creation

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 5
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 4
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 4
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 4
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 4
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 3
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 3
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 3
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 3
- [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) — 3
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 3
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 3

## Tracked threats

The 30 most recent of 206 tracked threats that use T1018.

- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…](https://intel.threadlinqs.com/threat/TL-2026-2760) — high — 2026-09-28
- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-2505) — high — 2026-09-14
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2431) — critical — 2026-09-10
- [CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2415) — critical — 2026-09-09
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2354) — critical — 2026-09-06
- [Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teams](https://intel.threadlinqs.com/threat/TL-2026-2302) — high — 2026-09-02
- [CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosure](https://intel.threadlinqs.com/threat/TL-2026-2287) — critical — 2026-09-01
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…](https://intel.threadlinqs.com/threat/TL-2026-2265) — critical — 2026-08-31
- [TerminalFix Campaign Deploys Custom Python Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA, DLL…](https://intel.threadlinqs.com/threat/TL-2026-2260) — high — 2026-08-31
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers DLL Sideloading and Python Reverse-Tunnel…](https://intel.threadlinqs.com/threat/TL-2026-2237) — high — 2026-08-30
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [TerminalFix Campaign: ClickFix-Style Lure Deploys Steganographic DLL Sideload and Custom Reverse Tunnel in…](https://intel.threadlinqs.com/threat/TL-2026-2198) — high — 2026-08-28
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- [ADCS ESC1 Privilege Escalation: CISA AA26-237A Red Team Findings and CA Database Hunting Methodology](https://intel.threadlinqs.com/threat/TL-2026-2168) — high — 2026-08-27
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [SynkLoader: Modular Multi-Language Loader Deployed via Microsoft Teams Phishing, Likely Ransomware Precursor](https://intel.threadlinqs.com/threat/TL-2026-2131) — high — 2026-08-24
- [Ransom Busters — Rogue ransomware affiliate posing as recovery firm to intercept ransom payments](https://intel.threadlinqs.com/threat/TL-2026-2074) — high — 2026-08-19
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13

## Related CVEs

CVEs referenced by the tracked threats that use T1018, most frequent first.

- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)

## Detection coverage

Threadlinqs maintains 162 detection rules mapped to T1018 (SPL 49, KQL 59, Sigma 54). Rule content is available to Blue tier accounts and above; this page shows counts only.

162 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1018
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
