Activity timeline
T1071 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 277 reports, and 858 of the 859 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1071 Application Layer Protocol is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 859 of 2623 tracked threats (32.7%) to it; by severity that is 319 critical, 474 high, 59 medium, 2 low.
Threats that use T1071 most often also use T1059 Command and Scripting Interpreter (656 threats), T1027 Obfuscated Files or Information (567 threats), T1036 Masquerading (522 threats), T1082 System Information Discovery (501 threats), T1005 Data from Local System (498 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
188 tracked threat actors appear in the threats that use T1071; the most frequent are TeamPCP (20), APT38 (19), Sapphire Sleet (17), Stardust Chollima (16), Lazarus Group (14).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1071.
Data sources
Telemetry that can reveal T1071, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 859 tracked threats that use T1071.
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)critical
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplacemedium
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitationcritical
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threatcritical
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…high
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansashigh
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…high
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…high
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonationhigh
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Techniquemedium
- SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attackshigh
- ClickFix Lures Deploy MacSync Stealer to Bypass macOS Securityhigh
- Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teamsmedium
- Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…high
- Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During…critical
Detection coverage
Threadlinqs maintains 428 detection rules mapped to T1071 (SPL 158, KQL 114, Sigma 155, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1071.001 Web Protocols — 690 tracked threats
- T1071.002 File Transfer Protocols — 7 tracked threats
- T1071.003 Mail Protocols — 8 tracked threats
- T1071.004 DNS — 56 tracked threats
- T1071.005 Publish/Subscribe Protocols — 2 tracked threats