# T1048 Exfiltration Over Alternative Protocol

> As of 2026-10-05, T1048 (Exfiltration Over Alternative Protocol) appears in 155 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including APT28, BlueDelta, Forest Blizzard; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 155 (55 critical, 89 high, 10 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 84
- **Detection rules:** 166 (counts only; Blue tier and above)

## Key facts

- **ID:** T1048
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1048/

## Activity timeline

T1048 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 43 reports, and 155 of the 155 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1048 Exfiltration Over Alternative Protocol is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 155 of 2623 tracked threats (5.9%) to it; by severity that is 55 critical, 89 high, 10 medium.

Threats that use T1048 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (97 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (88 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (83 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (81 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (78 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

84 tracked threat actors appear in the threats that use T1048; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (5), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (4), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (4), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (4), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (4).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1048.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1057 Data Loss Prevention](https://attack.mitre.org/mitigations/M1057/)

## Data sources

Telemetry that can reveal T1048, per MITRE ATT&CK.

- Application Log — Application Log Content
- Cloud Storage — Cloud Storage Access
- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 5
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 4
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 4
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 4
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 3
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 3
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 3
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 2

## Tracked threats

The 30 most recent of 155 tracked threats that use T1048.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…](https://intel.threadlinqs.com/threat/TL-2026-2760) — high — 2026-09-28
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [Cloudflare Containers cross-tenant residual disk data exposure via device-mapper thin-provisioning…](https://intel.threadlinqs.com/threat/TL-2026-2644) — high — 2026-09-24
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial…](https://intel.threadlinqs.com/threat/TL-2026-2498) — high — 2026-09-14
- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — critical — 2026-09-09
- [Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During…](https://intel.threadlinqs.com/threat/TL-2026-2411) — critical — 2026-09-09
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier…](https://intel.threadlinqs.com/threat/TL-2026-2405) — high — 2026-09-08
- [Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak](https://intel.threadlinqs.com/threat/TL-2026-2383) — high — 2026-09-07
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — high — 2026-09-06
- [Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…](https://intel.threadlinqs.com/threat/TL-2026-2352) — medium — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)](https://intel.threadlinqs.com/threat/TL-2026-2212) — high — 2026-08-29
- [Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2229) — high — 2026-08-28
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — high — 2026-08-21
- [Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026](https://intel.threadlinqs.com/threat/TL-2026-2078) — medium — 2026-08-20
- [Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…](https://intel.threadlinqs.com/threat/TL-2026-2031) — high — 2026-08-16
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…](https://intel.threadlinqs.com/threat/TL-2026-1959) — critical — 2026-08-09
- [Odysseus AI Workspace Remote Code Execution via Authorization Bypass — GHSA-xwhc-f36c-v5vm (CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-1921) — critical — 2026-08-06
- [Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…](https://intel.threadlinqs.com/threat/TL-2026-1918) — high — 2026-08-06
- [OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications](https://intel.threadlinqs.com/threat/TL-2026-1913) — medium — 2026-08-06
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp…](https://intel.threadlinqs.com/threat/TL-2026-1891) — critical — 2026-08-05
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…](https://intel.threadlinqs.com/threat/TL-2026-1868) — high — 2026-08-04
- [CVE-2026-58048 — cPanel & WHM Database Privilege Escalation via Database Rename (SQL Mode Loss)](https://intel.threadlinqs.com/threat/TL-2026-1862) — critical — 2026-08-04
- [Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolen](https://intel.threadlinqs.com/threat/TL-2026-1848) — critical — 2026-08-03

## Related CVEs

CVEs referenced by the tracked threats that use T1048, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)

## Detection coverage

Threadlinqs maintains 166 detection rules mapped to T1048 (SPL 59, KQL 53, Sigma 54). Rule content is available to Blue tier accounts and above; this page shows counts only.

166 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol — 2 tracked threats
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol — 8 tracked threats
- [T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol](https://intel.threadlinqs.com/technique/T1048.003) — 27 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1048
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
