# T1039 Data from Network Shared Drive

> As of 2026-10-05, T1039 (Data from Network Shared Drive) appears in 49 tracked threats, first reported 2026-02-02 and most recently 2026-08-28, with linked actors including Akira, FortiBleed operator, Luna Moth; it most often appears alongside T1018 (Remote System Discovery).

- **Tracked threats:** 49 (19 critical, 26 high, 3 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-08-28
- **Threat actors:** 32
- **Detection rules:** 27 (counts only; Blue tier and above)

## Key facts

- **ID:** T1039
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1039/

## Activity timeline

T1039 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-08-28. The busiest month was 2026-02 with 12 reports, and 49 of the 49 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1039 Data from Network Shared Drive is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 49 of 2623 tracked threats (1.9%) to it; by severity that is 19 critical, 26 high, 3 medium, 1 low.

Threats that use T1039 most often also use [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (34 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (30 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (29 threats), [T1133 External Remote Services](https://intel.threadlinqs.com/technique/T1133) (29 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (28 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1039; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (3), [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) (3), [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) (3), [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) (3), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (3).

## Data sources

Telemetry that can reveal T1039, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Network Share — Network Share Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 3
- [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) — 3
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 3
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 3
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 3
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [DeadLock](https://intel.threadlinqs.com/actor/DeadLock) — 2
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 2
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 2
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 2
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 2
- [Nitrogen](https://intel.threadlinqs.com/actor/Nitrogen) — 2

## Tracked threats

The 30 most recent of 49 tracked threats that use T1039.

- [Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2176) — high — 2026-08-28
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [GST Refund Phishing Delivers Remcos RAT via Multi-Stage .NET Bitmap-Steganography Infection Chain](https://intel.threadlinqs.com/threat/TL-2026-1443) — high — 2026-07-17
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…](https://intel.threadlinqs.com/threat/TL-2026-1137) — high — 2026-07-06
- [FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1118) — critical — 2026-07-05
- [FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1085) — critical — 2026-07-02
- [SEO Poisoning Supply Chain Campaign Distributing Akira Ransomware via Trojanized Enterprise Software](https://intel.threadlinqs.com/threat/TL-2026-1004) — critical — 2026-06-30
- [CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…](https://intel.threadlinqs.com/threat/TL-2026-1000) — critical — 2026-06-30
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [FortiBleed: Russian-Speaking Initial Access Broker Weaponizes FortiOS 'diagnose sniffer packet'…](https://intel.threadlinqs.com/threat/TL-2026-0927) — critical — 2026-06-24
- [FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls…](https://intel.threadlinqs.com/threat/TL-2026-0918) — high — 2026-06-23
- [FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN Gateways](https://intel.threadlinqs.com/threat/TL-2026-0916) — critical — 2026-06-23
- [FortiBleed Campaign: Custom FortigateSniffer Abuses FortiOS 'diagnose sniffer packet' to Harvest Credentials…](https://intel.threadlinqs.com/threat/TL-2026-0907) — critical — 2026-06-22
- [FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and…](https://intel.threadlinqs.com/threat/TL-2026-0895) — high — 2026-06-21
- [FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN…](https://intel.threadlinqs.com/threat/TL-2026-0882) — high — 2026-06-19
- [FortiBleed Campaign: Mass FortiGate SSL VPN / Admin Credential Exposure Affecting ~73,932 Fortinet Firewalls…](https://intel.threadlinqs.com/threat/TL-2026-0868) — critical — 2026-06-13
- [Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by…](https://intel.threadlinqs.com/threat/TL-2026-0718) — critical — 2026-06-08
- [UNC3753 (Silent Ransom Group / Luna Moth) Escalation — Physical Office Intrusion & USB Data Exfiltration…](https://intel.threadlinqs.com/threat/TL-2026-0707) — high — 2026-06-07
- [Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US…](https://intel.threadlinqs.com/threat/TL-2026-0612) — high — 2026-05-28
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…](https://intel.threadlinqs.com/threat/TL-2026-0610) — high — 2026-05-27
- [NightSpire Ransomware — Go-Based Encryptor with .nspire Extension, RDP-First Intrusions, and…](https://intel.threadlinqs.com/threat/TL-2026-0571) — high — 2026-05-23
- [WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)](https://intel.threadlinqs.com/threat/TL-2026-0531) — high — 2026-05-19
- [Foxconn North American Factories Cyberattack — Nitrogen Ransomware Claims 8 TB / 11M+ Documents Stolen…](https://intel.threadlinqs.com/threat/TL-2026-0511) — critical — 2026-05-13

## Related CVEs

CVEs referenced by the tracked threats that use T1039, most frequent first.

- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)

## Detection coverage

Threadlinqs maintains 27 detection rules mapped to T1039 (SPL 8, KQL 13, Sigma 5, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

27 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1039
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
