Activity timeline
T1071.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 213 reports, and 690 of the 690 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1071.001 Web Protocols is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1071 Application Layer Protocol. Threadlinqs maps 690 of 2623 tracked threats (26.3%) to it; by severity that is 177 critical, 453 high, 58 medium.
Threats that use T1071.001 most often also use T1027 Obfuscated Files or Information (402 threats), T1082 System Information Discovery (395 threats), T1005 Data from Local System (372 threats), T1041 Exfiltration Over C2 Channel (329 threats), T1036.005 Match Legitimate Resource Name or Location (326 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
169 tracked threat actors appear in the threats that use T1071.001; the most frequent are APT38 (25), TeamPCP (20), Sapphire Sleet (18), Stardust Chollima (18), Lazarus Group (14).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1071.001.
Data sources
Telemetry that can reveal T1071.001, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 690 tracked threats that use T1071.001.
- Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass…high
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…high
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- CloudSyncD macOS Backdoor Delivered via Fake Zoom Installerhigh
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFAhigh
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishingmedium
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and…medium
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)high
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installershigh
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible…critical
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…high
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
Detection coverage
Threadlinqs maintains 2858 detection rules mapped to T1071.001 (SPL 1068, KQL 862, Sigma 925, other 3). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1071 Application Layer Protocol — 859 tracked threats at the technique level.