Activity timeline
T1049 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 22 reports, and 44 of the 44 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1049 System Network Connections Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 44 of 2623 tracked threats (1.7%) to it; by severity that is 10 critical, 31 high, 2 medium.
Threats that use T1049 most often also use T1027 Obfuscated Files or Information (32 threats), T1082 System Information Discovery (32 threats), T1005 Data from Local System (28 threats), T1140 Deobfuscate/Decode Files or Information (27 threats), T1105 Ingress Tool Transfer (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
21 tracked threat actors appear in the threats that use T1049; the most frequent are ALPHV (2), BlackCat (2), Cavern Manticore (2), APT38 (1), Cl0p (1).
Data sources
Telemetry that can reveal T1049, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 44 tracked threats that use T1049.
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for…high
- BINDCLOAK Backdoor Campaign Targeting Middle East Government Entitieshigh
- OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Thefthigh
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…high
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East…high
- TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities…high
- HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset…high
- COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware…high
- CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…high
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoorcritical
- Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…high
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chainhigh
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…medium
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…medium
- Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…high
- Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No…
- SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strikehigh
- AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery…high
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx…critical
- Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret…high
- Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling…high
- CISA KEV: Cisco Unified Communications Manager SSRF to Webshell (CVE-2026-20230) Actively Exploitedcritical
- Sinobi Ransomware: Curve-25519/AES-128-CTR Encryption with Shadow Copy and Backup Destruction (Lynx/INC…high
Detection coverage
Threadlinqs maintains 24 detection rules mapped to T1049 (SPL 4, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.