# T1049 System Network Connections Discovery

> As of 2026-10-05, T1049 (System Network Connections Discovery) appears in 44 tracked threats, first reported 2026-02-02 and most recently 2026-09-14, with linked actors including ALPHV, BlackCat, Cavern Manticore; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 44 (10 critical, 31 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-14
- **Threat actors:** 21
- **Detection rules:** 24 (counts only; Blue tier and above)

## Key facts

- **ID:** T1049
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1049/

## Activity timeline

T1049 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-14. The busiest month was 2026-07 with 22 reports, and 44 of the 44 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1049 System Network Connections Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 44 of 2623 tracked threats (1.7%) to it; by severity that is 10 critical, 31 high, 2 medium.

Threats that use T1049 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (32 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (32 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (28 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (27 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (26 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

21 tracked threat actors appear in the threats that use T1049; the most frequent are [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (2), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (2), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) (1).

## Data sources

Telemetry that can reveal T1049, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 2
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 2
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 1
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [LockBit 5.0](https://intel.threadlinqs.com/actor/LockBit%205.0) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1

## Tracked threats

The 30 most recent of 44 tracked threats that use T1049.

- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain](https://intel.threadlinqs.com/threat/TL-2026-2457) — high — 2026-09-12
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for…](https://intel.threadlinqs.com/threat/TL-2026-1858) — high — 2026-08-04
- [BINDCLOAK Backdoor Campaign Targeting Middle East Government Entities](https://intel.threadlinqs.com/threat/TL-2026-1844) — high — 2026-08-03
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East…](https://intel.threadlinqs.com/threat/TL-2026-1582) — high — 2026-07-21
- [TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities…](https://intel.threadlinqs.com/threat/TL-2026-1562) — high — 2026-07-20
- [HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset…](https://intel.threadlinqs.com/threat/TL-2026-1528) — high — 2026-07-19
- [COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware…](https://intel.threadlinqs.com/threat/TL-2026-1510) — high — 2026-07-19
- [CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code…](https://intel.threadlinqs.com/threat/TL-2026-1507) — high — 2026-07-19
- [Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1404) — critical — 2026-07-16
- [Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…](https://intel.threadlinqs.com/threat/TL-2026-1379) — high — 2026-07-15
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — high — 2026-07-15
- [June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…](https://intel.threadlinqs.com/threat/TL-2026-1353) — medium — 2026-07-15
- [Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…](https://intel.threadlinqs.com/threat/TL-2026-1166) — medium — 2026-07-10
- [Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…](https://intel.threadlinqs.com/threat/TL-2026-1137) — high — 2026-07-06
- [Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No…](https://intel.threadlinqs.com/threat/TL-2026-1109) — 2026-07-05
- [SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1101) — high — 2026-07-03
- [AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery…](https://intel.threadlinqs.com/threat/TL-2026-1114) — high — 2026-07-02
- [FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx…](https://intel.threadlinqs.com/threat/TL-2026-1090) — critical — 2026-07-02
- [Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret…](https://intel.threadlinqs.com/threat/TL-2026-1029) — high — 2026-07-01
- [Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling…](https://intel.threadlinqs.com/threat/TL-2026-0967) — high — 2026-06-28
- [CISA KEV: Cisco Unified Communications Manager SSRF to Webshell (CVE-2026-20230) Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-0960) — critical — 2026-06-27
- [Sinobi Ransomware: Curve-25519/AES-128-CTR Encryption with Shadow Copy and Backup Destruction (Lynx/INC…](https://intel.threadlinqs.com/threat/TL-2026-0892) — high — 2026-06-21

## Related CVEs

CVEs referenced by the tracked threats that use T1049, most frequent first.

- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-36899](https://intel.threadlinqs.com/cve/CVE-2023-36899)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)

## Detection coverage

Threadlinqs maintains 24 detection rules mapped to T1049 (SPL 4, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

24 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1049
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
