Activity timeline
T1072 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 15 reports, and 30 of the 30 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1072 Software Deployment Tools is catalogued by MITRE ATT&CK under the Execution and Lateral Movement tactics in the Enterprise matrix. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 16 critical, 11 high, 2 medium.
Threats that use T1072 most often also use T1005 Data from Local System (21 threats), T1059 Command and Scripting Interpreter (19 threats), T1190 Exploit Public-Facing Application (17 threats), T1027 Obfuscated Files or Information (16 threats), T1078 Valid Accounts (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
18 tracked threat actors appear in the threats that use T1072; the most frequent are Qilin (3), TeamPCP (3), Handala Hack (2), Mini Shai-Hulud (2), Safepay (2).
Mitigations
MITRE ATT&CK lists 10 mitigations for T1072.
Data sources
Telemetry that can reveal T1072, per MITRE ATT&CK.
- Application Log — Application Log Content
- Process — Process Creation
Threat actors using it
Tracked threats
30 tracked threats use T1072.
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXihigh
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…critical
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…critical
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign…high
- Gitea CVE-2026-58443: Authorization Bypass in Pull Request Update API Enables Private Repo Accesscritical
- HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)high
- Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing…critical
- Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)medium
- Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…high
- jscrambler npm Package Supply Chain Compromise (v8.14.0 Malicious Release)high
- Dell Wyse Management Suite Critical RCE Chain (CVE-2026-41120, CVE-2026-49506)critical
- SimpleHelp Authentication Bypass via Forged OIDC Tokens (CVE-2026-48558) Actively Exploited, Added to CISA KEVcritical
- La Trobe University research: network-based detection of SMB shared-storage ransomware encryption
- FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies…high
- TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)critical
- Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become…high
- Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…high
- Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…high
- ConnectWise Automate CVE-2026-9089 — Improper Integrity Validation in Agent Plugin Loading and Self-Update…high
- CISA KEV (2026-05-21): CVE-2025-34291 Langflow CORS Token Hijack-to-RCE & CVE-2026-34926 Trend Micro Apex…critical
- Mini Shai-Hulud v3 — TanStack/UiPath/Mistral AI npm & PyPI Supply Chain Compromise (TeamPCP)critical
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)critical
- Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defensesmedium
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker…critical
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attackcritical
- Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed…critical
- Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures — Corporate Phishing Campaigncritical
Detection coverage
Threadlinqs maintains 36 detection rules mapped to T1072 (SPL 13, KQL 10, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.