# T1041 Exfiltration Over C2 Channel

> As of 2026-10-05, T1041 (Exfiltration Over C2 Channel) appears in 865 tracked threats, first reported 2021-11-25 and most recently 2026-09-29, with linked actors including APT38, TeamPCP, Lazarus Group; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 865 (289 critical, 521 high, 47 medium, 3 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-09-29
- **Threat actors:** 175
- **Detection rules:** 1245 (counts only; Blue tier and above)

## Key facts

- **ID:** T1041
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1041/

## Activity timeline

T1041 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 316 reports, and 864 of the 865 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1041 Exfiltration Over C2 Channel is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 865 of 2623 tracked threats (33%) to it; by severity that is 289 critical, 521 high, 47 medium, 3 low.

Threats that use T1041 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (639 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (605 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (599 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (489 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (469 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

175 tracked threat actors appear in the threats that use T1041; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (32), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (31), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (22), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (22), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (21).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1041.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1057 Data Loss Prevention](https://attack.mitre.org/mitigations/M1057/)

## Data sources

Telemetry that can reveal T1041, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 32
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 31
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 22
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 22
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 21
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 19
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 15
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 15
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 14
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 12
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 12
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 12

## Tracked threats

The 30 most recent of 865 tracked threats that use T1041.

- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — critical — 2026-09-14
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2173) — high — 2026-08-27
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21
- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…](https://intel.threadlinqs.com/threat/TL-2026-2087) — critical — 2026-08-20
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…](https://intel.threadlinqs.com/threat/TL-2026-2079) — critical — 2026-08-20
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…](https://intel.threadlinqs.com/threat/TL-2026-2006) — high — 2026-08-13
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — high — 2026-08-10
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…](https://intel.threadlinqs.com/threat/TL-2026-1872) — critical — 2026-08-04

## Related CVEs

CVEs referenced by the tracked threats that use T1041, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)

## Detection coverage

Threadlinqs maintains 1245 detection rules mapped to T1041 (SPL 472, KQL 382, Sigma 391). Rule content is available to Blue tier accounts and above; this page shows counts only.

1245 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1041
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
