Activity timeline
T1057 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 117 reports, and 366 of the 367 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1057 Process Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 367 of 2623 tracked threats (14%) to it; by severity that is 102 critical, 248 high, 17 medium.
Threats that use T1057 most often also use T1082 System Information Discovery (300 threats), T1027 Obfuscated Files or Information (261 threats), T1005 Data from Local System (216 threats), T1041 Exfiltration Over C2 Channel (207 threats), T1140 Deobfuscate/Decode Files or Information (205 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
108 tracked threat actors appear in the threats that use T1057; the most frequent are APT38 (17), Sapphire Sleet (16), Stardust Chollima (15), TeamPCP (9), Lazarus Group (8).
Data sources
Telemetry that can reveal T1057, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 367 tracked threats that use T1057.
- BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)high
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…critical
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operatorsmedium
- PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Huntinghigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attackshigh
- CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…critical
- PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionhigh
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitationcritical
- FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoChigh
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
Detection coverage
Threadlinqs maintains 226 detection rules mapped to T1057 (SPL 54, KQL 93, Sigma 79). Rule content is available to Blue tier accounts and above; this page shows counts only.