Activity timeline
T1041 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 316 reports, and 864 of the 865 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1041 Exfiltration Over C2 Channel is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 865 of 2623 tracked threats (33%) to it; by severity that is 289 critical, 521 high, 47 medium, 3 low.
Threats that use T1041 most often also use T1005 Data from Local System (639 threats), T1027 Obfuscated Files or Information (605 threats), T1082 System Information Discovery (599 threats), T1059 Command and Scripting Interpreter (489 threats), T1105 Ingress Tool Transfer (469 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
175 tracked threat actors appear in the threats that use T1041; the most frequent are APT38 (32), TeamPCP (31), Lazarus Group (22), Stardust Chollima (22), Sapphire Sleet (21).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1041.
Data sources
Telemetry that can reveal T1041, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 865 tracked threats that use T1041.
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalogcritical
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoorhigh
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnethigh
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…critical
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…high
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRighigh
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…critical
Detection coverage
Threadlinqs maintains 1245 detection rules mapped to T1041 (SPL 472, KQL 382, Sigma 391). Rule content is available to Blue tier accounts and above; this page shows counts only.