# T1071 Application Layer Protocol

> As of 2026-10-05, T1071 (Application Layer Protocol) appears in 859 tracked threats, first reported 2021-11-25 and most recently 2026-10-01, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 859 (319 critical, 474 high, 59 medium, 2 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-01
- **Threat actors:** 188
- **Detection rules:** 428 (counts only; Blue tier and above)

## Key facts

- **ID:** T1071
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1071/

## Activity timeline

T1071 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 277 reports, and 858 of the 859 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1071 Application Layer Protocol is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 859 of 2623 tracked threats (32.7%) to it; by severity that is 319 critical, 474 high, 59 medium, 2 low.

Threats that use T1071 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (656 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (567 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (522 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (501 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (498 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

188 tracked threat actors appear in the threats that use T1071; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (20), [APT38](https://intel.threadlinqs.com/actor/APT38) (19), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (17), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (16), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (14).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1071.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1071, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 20
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 19
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 17
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 16
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 14
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 13
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 13
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 11
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 11
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 11
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 9
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 9

## Tracked threats

The 30 most recent of 859 tracked threats that use T1071.

- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)](https://intel.threadlinqs.com/threat/TL-2026-2823) — critical — 2026-10-01
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…](https://intel.threadlinqs.com/threat/TL-2026-2773) — high — 2026-09-29
- [TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace](https://intel.threadlinqs.com/threat/TL-2026-2715) — medium — 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2688) — critical — 2026-09-27
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…](https://intel.threadlinqs.com/threat/TL-2026-2577) — high — 2026-09-19
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas](https://intel.threadlinqs.com/threat/TL-2026-2571) — high — 2026-09-18
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…](https://intel.threadlinqs.com/threat/TL-2026-2519) — high — 2026-09-15
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…](https://intel.threadlinqs.com/threat/TL-2026-2469) — medium — 2026-09-12
- [VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…](https://intel.threadlinqs.com/threat/TL-2026-2464) — high — 2026-09-12
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — high — 2026-09-11
- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security](https://intel.threadlinqs.com/threat/TL-2026-2434) — high — 2026-09-10
- [Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teams](https://intel.threadlinqs.com/threat/TL-2026-2430) — medium — 2026-09-10
- [Tropic Trooper Spear-Phishing Campaign Uses LNK Loader, DLL Side-Loading via Signed McAfee Binary, and…](https://intel.threadlinqs.com/threat/TL-2026-2427) — high — 2026-09-10
- [Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During…](https://intel.threadlinqs.com/threat/TL-2026-2411) — critical — 2026-09-09

## Related CVEs

CVEs referenced by the tracked threats that use T1071, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-48282](https://intel.threadlinqs.com/cve/CVE-2026-48282)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)

## Detection coverage

Threadlinqs maintains 428 detection rules mapped to T1071 (SPL 158, KQL 114, Sigma 155, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

428 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) — 690 tracked threats
- T1071.002 File Transfer Protocols — 7 tracked threats
- T1071.003 Mail Protocols — 8 tracked threats
- [T1071.004 DNS](https://intel.threadlinqs.com/technique/T1071.004) — 56 tracked threats
- T1071.005 Publish/Subscribe Protocols — 2 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1071
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
