Threadlinqs IntelligenceStart free

ATT&CK techniqueCollection

T1039 Data from Network Shared Drive

CollectionEnterprise

As of 2026-10-05, T1039 (Data from Network Shared Drive) appears in 49 tracked threats, first reported 2026-02-02 and most recently 2026-08-28, with linked actors including Akira, FortiBleed operator, Luna Moth; it most often appears alongside T1018 (Remote System Discovery).

Tracked threats
4919 critical, 26 high, 3 medium, 1 low
First seen
2026-02-02
Last seen
2026-08-28
Threat actors
32In the threats using it
Detection rules
27Blue tier and above

Data as of:

Activity timeline

T1039 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-02 with 12 reports, and 49 of the 49 threats were reported in the twelve months to 2026-08.

How adversaries use it

T1039 Data from Network Shared Drive is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 49 of 2623 tracked threats (1.9%) to it; by severity that is 19 critical, 26 high, 3 medium, 1 low.

Threats that use T1039 most often also use T1018 Remote System Discovery (34 threats), T1078 Valid Accounts (30 threats), T1005 Data from Local System (29 threats), T1133 External Remote Services (29 threats), T1041 Exfiltration Over C2 Channel (28 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1039; the most frequent are Akira (3), FortiBleed operator (3), Luna Moth (3), Silent Ransom Group (3), Storm-1567 (3).

Data sources

Telemetry that can reveal T1039, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Access
  • Network Share — Network Share Access
  • Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

Threat actors using it

Tracked threats

The 30 most recent of 49 tracked threats that use T1039.

Detection coverage

Threadlinqs maintains 27 detection rules mapped to T1039 (SPL 8, KQL 13, Sigma 5, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

27 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans