Activity timeline
T1048.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 9 reports, and 27 of the 27 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix, as a sub-technique of T1048 Exfiltration Over Alternative Protocol. Threadlinqs maps 27 of 2623 tracked threats (1%) to it; by severity that is 14 critical, 12 high, 1 medium.
Threats that use T1048.003 most often also use T1190 Exploit Public-Facing Application (19 threats), T1071.001 Web Protocols (17 threats), T1027 Obfuscated Files or Information (15 threats), T1005 Data from Local System (14 threats), T1036.005 Match Legitimate Resource Name or Location (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
13 tracked threat actors appear in the threats that use T1048.003; the most frequent are Safepay (2), Static Tundra (2), APT28 (1), BlueDelta (1), BonJoviGoesHard (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1048.003.
Data sources
Telemetry that can reveal T1048.003, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
27 tracked threats use T1048.003.
- SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforcehigh
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…high
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- RovoBlast: One-Click rovoChatPrompt Parameter-to-Prompt Injection in Atlassian Rovo Exposes Confluence…critical
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…high
- CVE-2025-54068 Exploited in Large-Scale Laravel Livewire Credential Theft Campaigncritical
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)critical
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…medium
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…high
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…critical
- FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022…high
- @injectivelabs/sdk-ts Supply Chain Backdoor — Wallet Credential Theft Disguised as Telemetrycritical
- Operation Endgame: Global Law Enforcement Takedown Disrupts SocGholish, Amadey, and StealC…high
- Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…critical
- Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via…critical
- BerriAI LiteLLM Unauthenticated SQL Injection in Proxy API Key Verification (CVE-2026-42208) — CVSS 9.8…critical
- Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and…high
- LMDeploy SSRF in load_image() Vision-Language Module (CVE-2026-33626) — Actively Exploited Within 13 Hours…high
- Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube)high
- QEMU Virtualization Abuse for PayoutsKing Ransomware Delivery & Evasionhigh
- Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation…critical
- BeyondTrust Remote Support & PRA Pre-Authentication Remote Code Execution via OS Command Injection…critical
- Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider…high
- BeyondTrust Pre-Auth RCE (CVE-2026-1731) — CVSS 9.9, CISA KEV, WebSocket Command Injection, VShell/SparkRAT…critical
Detection coverage
Threadlinqs maintains 80 detection rules mapped to T1048.003 (SPL 26, KQL 27, Sigma 27). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1048 Exfiltration Over Alternative Protocol — 155 tracked threats at the technique level.