Activity timeline
T1039 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-02 with 12 reports, and 49 of the 49 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1039 Data from Network Shared Drive is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 49 of 2623 tracked threats (1.9%) to it; by severity that is 19 critical, 26 high, 3 medium, 1 low.
Threats that use T1039 most often also use T1018 Remote System Discovery (34 threats), T1078 Valid Accounts (30 threats), T1005 Data from Local System (29 threats), T1133 External Remote Services (29 threats), T1041 Exfiltration Over C2 Channel (28 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
32 tracked threat actors appear in the threats that use T1039; the most frequent are Akira (3), FortiBleed operator (3), Luna Moth (3), Silent Ransom Group (3), Storm-1567 (3).
Data sources
Telemetry that can reveal T1039, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Network Share — Network Share Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 49 tracked threats that use T1039.
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusionhigh
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…high
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…high
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demandsmedium
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- GST Refund Phishing Delivers Remcos RAT via Multi-Stage .NET Bitmap-Steganography Infection Chainhigh
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…high
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operationscritical
- FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operationscritical
- SEO Poisoning Supply Chain Campaign Distributing Akira Ransomware via Trojanized Enterprise Softwarecritical
- CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…critical
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…critical
- FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls…high
- FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gatewayscritical
- FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials…critical
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and…high
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…high
- FortiBleed Campaign: Mass FortiGate SSL VPN / Admin Credential Exposure Affecting ~73,932 Fortinet Firewalls…critical
- Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by…critical
- UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration…high
- Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US…high
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- NightSpire Ransomware — Go-Based Encryptor with .nspire Extension, RDP-First Intrusions, and…high
- WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)high
- Foxconn North American Factories Cyberattack — Nitrogen Ransomware Claims 8 TB / 11M+ Documents Stolen…critical
Detection coverage
Threadlinqs maintains 27 detection rules mapped to T1039 (SPL 8, KQL 13, Sigma 5, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.