# T1040 Network Sniffing

> As of 2026-10-05, T1040 (Network Sniffing) appears in 71 tracked threats, first reported 2026-02-02 and most recently 2026-09-30, with linked actors including Static Tundra, FSB Center 16, FortiBleed operator; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 71 (42 critical, 22 high, 6 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-30
- **Threat actors:** 21
- **Detection rules:** 50 (counts only; Blue tier and above)

## Key facts

- **ID:** T1040
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access, Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1040/

## Activity timeline

T1040 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 29 reports, and 71 of the 71 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1040 Network Sniffing is catalogued by MITRE ATT&CK under the Credential Access and Discovery tactics in the Enterprise matrix. Threadlinqs maps 71 of 2623 tracked threats (2.7%) to it; by severity that is 42 critical, 22 high, 6 medium.

Threats that use T1040 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (60 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (45 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (38 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (34 threats), [T1595 Active Scanning](https://intel.threadlinqs.com/technique/T1595) (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

21 tracked threat actors appear in the threats that use T1040; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (5), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (3), [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) (3), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) (3), [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) (3).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1040.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)

## Data sources

Telemetry that can reveal T1040, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 5
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 3
- [FortiBleed operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator) — 3
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 3
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 3
- [INC Ransomware](https://intel.threadlinqs.com/actor/INC%20Ransomware) — 2
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 2
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1

## Tracked threats

The 30 most recent of 71 tracked threats that use T1040.

- [Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…](https://intel.threadlinqs.com/threat/TL-2026-2805) — critical — 2026-09-30
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…](https://intel.threadlinqs.com/threat/TL-2026-2314) — critical — 2026-09-03
- [NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS…](https://intel.threadlinqs.com/threat/TL-2026-1927) — high — 2026-08-07
- [QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day…](https://intel.threadlinqs.com/threat/TL-2026-2893) — high — 2026-08-06
- [CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1812) — critical — 2026-08-01
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars](https://intel.threadlinqs.com/threat/TL-2026-1699) — high — 2026-07-25
- [CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…](https://intel.threadlinqs.com/threat/TL-2026-1507) — high — 2026-07-19
- [Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS…](https://intel.threadlinqs.com/threat/TL-2026-1500) — medium — 2026-07-18
- [SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1462) — critical — 2026-07-17
- [SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth…](https://intel.threadlinqs.com/threat/TL-2026-1382) — critical — 2026-07-15
- [FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171)…](https://intel.threadlinqs.com/threat/TL-2026-1312) — critical — 2026-07-14
- [US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…](https://intel.threadlinqs.com/threat/TL-2026-1290) — medium — 2026-07-14
- [Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1282) — critical — 2026-07-13
- [NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…](https://intel.threadlinqs.com/threat/TL-2026-1279) — critical — 2026-07-13
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…](https://intel.threadlinqs.com/threat/TL-2026-1277) — high — 2026-07-13
- [FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…](https://intel.threadlinqs.com/threat/TL-2026-1276) — high — 2026-07-13
- [CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static…](https://intel.threadlinqs.com/threat/TL-2026-1272) — high — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and…](https://intel.threadlinqs.com/threat/TL-2026-1220) — high — 2026-07-11
- [Six AirDrop and Quick Share Proximity File-Transfer Vulnerabilities (Apple, Google, Samsung) — 'Protocol…](https://intel.threadlinqs.com/threat/TL-2026-1197) — medium — 2026-07-10
- [Everest Ransomware: Triple Extortion via Encryption, Access Brokering, and Insider Recruitment](https://intel.threadlinqs.com/threat/TL-2026-1172) — high — 2026-07-10

## Related CVEs

CVEs referenced by the tracked threats that use T1040, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368)
- [CVE-2026-69525](https://intel.threadlinqs.com/cve/CVE-2026-69525)
- [CVE-2026-69730](https://intel.threadlinqs.com/cve/CVE-2026-69730)
- [CVE-2026-70352](https://intel.threadlinqs.com/cve/CVE-2026-70352)
- [CVE-2026-78510](https://intel.threadlinqs.com/cve/CVE-2026-78510)
- [CVE-2026-81963](https://intel.threadlinqs.com/cve/CVE-2026-81963)
- [CVE-2026-83711](https://intel.threadlinqs.com/cve/CVE-2026-83711)
- [CVE-2026-85880](https://intel.threadlinqs.com/cve/CVE-2026-85880)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-19006](https://intel.threadlinqs.com/cve/CVE-2019-19006)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)

## Detection coverage

Threadlinqs maintains 50 detection rules mapped to T1040 (SPL 19, KQL 17, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.

50 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1040
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
