Activity timeline
T1020 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 57 reports, and 130 of the 130 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1020 Automated Exfiltration is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 130 of 2623 tracked threats (5%) to it; by severity that is 46 critical, 74 high, 9 medium.
Threats that use T1020 most often also use T1005 Data from Local System (74 threats), T1027 Obfuscated Files or Information (66 threats), T1059 Command and Scripting Interpreter (60 threats), T1078 Valid Accounts (57 threats), T1082 System Information Discovery (57 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
68 tracked threat actors appear in the threats that use T1020; the most frequent are TeamPCP (6), Cavern Manticore (4), Scattered Spider (4), ShinyHunters (4), UNC6671 (3).
Data sources
Telemetry that can reveal T1020, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
- Script — Script Execution
Threat actors using it
Tracked threats
The 30 most recent of 130 tracked threats that use T1020.
- Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attackscritical
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Datahigh
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During…critical
- Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…critical
- TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per Hourhigh
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firmshigh
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2critical
- Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…critical
- Suspected China-Linked Actor Runs Near-Autonomous Multi-Agent AI Attack on Taiwan Government, Nuclear Safety…critical
- "City-Forum" Campaign Mass-Enumerates Salesforce Experience Cloud and ServiceNow Portals via Guest Accesshigh
- Suspected China-Linked Actor Runs Near-Autonomous AI Agent Campaign (Hermes/OpenClaw) Against Taiwan…critical
- China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and…critical
- Head Mare APT Exploits Unpatched TrueConf Server Flaws to Deploy PhantomCore and PhantomGraph Backdoorscritical
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…high
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data…high
- Unauthenticated Metabase SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework and Tally…critical
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijackinghigh
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis…high
- Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)high
- XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and…critical
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaignhigh
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- Anthropic AI Agent Publishes Live Credential-Stealing Malware as PyPI Package "anthropickit"high
- OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Thefthigh
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- CVE-2026-6516: Unauthenticated Remote Code Execution in ManageEngine ADAudit Plus (CVSS 10.0)critical
Detection coverage
Threadlinqs maintains 163 detection rules mapped to T1020 (SPL 49, KQL 51, Sigma 63). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1020.001 Traffic Duplication — 0 tracked threats