# T1030 Data Transfer Size Limits

> As of 2026-10-05, T1030 (Data Transfer Size Limits) appears in 20 tracked threats, first reported 2026-02-16 and most recently 2026-09-22, with linked actors including APT38, APT44, BlackSuit affiliate; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 20 (6 critical, 9 high, 5 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-22
- **Threat actors:** 16
- **Detection rules:** 23 (counts only; Blue tier and above)

## Key facts

- **ID:** T1030
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1030/

## Activity timeline

T1030 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-22. The busiest month was 2026-06 with 6 reports, and 20 of the 20 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1030 Data Transfer Size Limits is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 6 critical, 9 high, 5 medium.

Threats that use T1030 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (16 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (12 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (11 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (11 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

16 tracked threat actors appear in the threats that use T1030; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [APT44](https://intel.threadlinqs.com/actor/APT44) (1), [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) (1), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1030.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1030, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [Nitrogen](https://intel.threadlinqs.com/actor/Nitrogen) — 1
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1

## Tracked threats

20 tracked threats use T1030.

- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…](https://intel.threadlinqs.com/threat/TL-2026-2615) — medium — 2026-09-22
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for Active Directory Enumeration and S3…](https://intel.threadlinqs.com/threat/TL-2026-1152) — medium — 2026-07-09
- [Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…](https://intel.threadlinqs.com/threat/TL-2026-1137) — high — 2026-07-06
- [Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17…](https://intel.threadlinqs.com/threat/TL-2026-0986) — critical — 2026-06-28
- [macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…](https://intel.threadlinqs.com/threat/TL-2026-0923) — high — 2026-06-23
- [Mastra NPM Packages Trojanized with Malicious Dependency Injection - 116 Packages Compromised](https://intel.threadlinqs.com/threat/TL-2026-0977) — critical — 2026-06-17
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [ServiceNow Scripted REST Resource Unauthenticated Access - /api/now/related_list_edit/create](https://intel.threadlinqs.com/threat/TL-2026-0980) — critical — 2026-06-09
- [Stock Exchange Executive Mailbox Espionage — Five-Month Intrusion via Masquerading SYSTEM Binaries…](https://intel.threadlinqs.com/threat/TL-2026-0672) — high — 2026-06-03
- [Nimbus RAT: Java-based Remote Access Trojan Delivered via Microsoft Teams Vishing, Quick Assist, and Google…](https://intel.threadlinqs.com/threat/TL-2026-0847) — high — 2026-05-28
- [SHub Reaper - macOS Stealer Variant Bypasses Tahoe 26.4 Terminal Mitigation via applescript:// URL Scheme…](https://intel.threadlinqs.com/threat/TL-2026-0526) — high — 2026-05-18
- [GemStuffer Campaign — RubyGems Registry Abused as Exfiltration Channel for UK Local Government Data](https://intel.threadlinqs.com/threat/TL-2026-0505) — high — 2026-05-13
- [PCPJack Worm — Cloud Credential Theft Framework Evicting TeamPCP Infections (CVE-2025-29927, CVE-2025-55182…](https://intel.threadlinqs.com/threat/TL-2026-0478) — critical — 2026-05-07
- [GRIDTIDE Backdoor — PRC-Nexus UNC2814 Global Telecom & Government Espionage via Google Sheets C2](https://intel.threadlinqs.com/threat/TL-2026-0168) — critical — 2026-03-02
- [State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database…](https://intel.threadlinqs.com/threat/TL-2026-0111) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1030, most frequent first.

- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-1357](https://intel.threadlinqs.com/cve/CVE-2026-1357)

## Detection coverage

Threadlinqs maintains 23 detection rules mapped to T1030 (SPL 10, KQL 6, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

23 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1030
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
