# T1072 Software Deployment Tools

> As of 2026-10-05, T1072 (Software Deployment Tools) appears in 30 tracked threats, first reported 2026-02-12 and most recently 2026-09-22, with linked actors including Qilin, TeamPCP, Handala Hack; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 30 (16 critical, 11 high, 2 medium)
- **First seen:** 2026-02-12
- **Last seen:** 2026-09-22
- **Threat actors:** 18
- **Detection rules:** 36 (counts only; Blue tier and above)

## Key facts

- **ID:** T1072
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution, Lateral Movement
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1072/

## Activity timeline

T1072 first appeared in tracked threats on 2026-02-12 and was most recently reported on 2026-09-22. The busiest month was 2026-07 with 15 reports, and 30 of the 30 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1072 Software Deployment Tools is catalogued by MITRE ATT&CK under the Execution and Lateral Movement tactics in the Enterprise matrix. Threadlinqs maps 30 of 2623 tracked threats (1.1%) to it; by severity that is 16 critical, 11 high, 2 medium.

Threats that use T1072 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (21 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (19 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (17 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (16 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

18 tracked threat actors appear in the threats that use T1072; the most frequent are [Qilin](https://intel.threadlinqs.com/actor/Qilin) (3), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (2), [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) (2), [Safepay](https://intel.threadlinqs.com/actor/Safepay) (2).

## Mitigations

MITRE ATT&CK lists 10 mitigations for T1072.

- [M1015 Active Directory Configuration](https://attack.mitre.org/mitigations/M1015/)
- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1029 Remote Data Storage](https://attack.mitre.org/mitigations/M1029/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1072, per MITRE ATT&CK.

- Application Log — Application Log Content
- Process — Process Creation

## Threat actors using it

- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 2
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 2
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 2
- [Storm-1175](https://intel.threadlinqs.com/actor/Storm-1175) — 2
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Handala](https://intel.threadlinqs.com/actor/Handala) — 1
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1

## Tracked threats

30 tracked threats use T1072.

- [Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)](https://intel.threadlinqs.com/threat/TL-2026-2617) — critical — 2026-09-22
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-1773) — high — 2026-07-30
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-1725) — critical — 2026-07-27
- [France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1652) — high — 2026-07-23
- [Gitea CVE-2026-58443: Authorization Bypass in Pull Request Update API Enables Private Repo Access](https://intel.threadlinqs.com/threat/TL-2026-1587) — critical — 2026-07-21
- [HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)](https://intel.threadlinqs.com/threat/TL-2026-1567) — high — 2026-07-20
- [Critical Ubuntu Pro Client Vulnerability Enables Root Code Execution via Contract Server Spoofing…](https://intel.threadlinqs.com/threat/TL-2026-1564) — critical — 2026-07-20
- [Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)](https://intel.threadlinqs.com/threat/TL-2026-1487) — medium — 2026-07-18
- [Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…](https://intel.threadlinqs.com/threat/TL-2026-1453) — high — 2026-07-17
- [jscrambler npm Package Supply Chain Compromise (v8.14.0 Malicious Release)](https://intel.threadlinqs.com/threat/TL-2026-1233) — high — 2026-07-11
- [Dell Wyse Management Suite Critical RCE Chain (CVE-2026-41120, CVE-2026-49506)](https://intel.threadlinqs.com/threat/TL-2026-1204) — critical — 2026-07-11
- [SimpleHelp Authentication Bypass via Forged OIDC Tokens (CVE-2026-48558) Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1122) — critical — 2026-07-05
- [La Trobe University research: network-based detection of SMB shared-storage ransomware encryption](https://intel.threadlinqs.com/threat/TL-2026-1121) — 2026-07-05
- [FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies…](https://intel.threadlinqs.com/threat/TL-2026-1084) — high — 2026-07-02
- [TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)](https://intel.threadlinqs.com/threat/TL-2026-0981) — critical — 2026-06-28
- [Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become…](https://intel.threadlinqs.com/threat/TL-2026-0958) — high — 2026-06-27
- [Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1242) — high — 2026-06-26
- [Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…](https://intel.threadlinqs.com/threat/TL-2026-1234) — high — 2026-06-04
- [ConnectWise Automate CVE-2026-9089 — Improper Integrity Validation in Agent Plugin Loading and Self-Update…](https://intel.threadlinqs.com/threat/TL-2026-0588) — high — 2026-05-26
- [CISA KEV (2026-05-21): CVE-2025-34291 Langflow CORS Token Hijack-to-RCE & CVE-2026-34926 Trend Micro Apex…](https://intel.threadlinqs.com/threat/TL-2026-0551) — critical — 2026-05-21
- [Mini Shai-Hulud v3 — TanStack/UiPath/Mistral AI npm & PyPI Supply Chain Compromise (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-0499) — critical — 2026-05-12
- [Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)](https://intel.threadlinqs.com/threat/TL-2026-0326) — critical — 2026-04-06
- [Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defenses](https://intel.threadlinqs.com/threat/TL-2026-1467) — medium — 2026-04-02
- [Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker…](https://intel.threadlinqs.com/threat/TL-2026-0268) — critical — 2026-03-22
- [Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack](https://intel.threadlinqs.com/threat/TL-2026-0220) — critical — 2026-03-12
- [Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed…](https://intel.threadlinqs.com/threat/TL-2026-0139) — critical — 2026-02-24
- [Weaponized Signed RMM Tools via Fake Zoom/Teams/Meet Lures — Corporate Phishing Campaign](https://intel.threadlinqs.com/threat/TL-2026-0079) — critical — 2026-02-12

## Related CVEs

CVEs referenced by the tracked threats that use T1072, most frequent first.

- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2023-21529](https://intel.threadlinqs.com/cve/CVE-2023-21529)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27351](https://intel.threadlinqs.com/cve/CVE-2023-27351)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-27198](https://intel.threadlinqs.com/cve/CVE-2024-27198)
- [CVE-2024-27199](https://intel.threadlinqs.com/cve/CVE-2024-27199)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2025-10035](https://intel.threadlinqs.com/cve/CVE-2025-10035)
- [CVE-2025-31161](https://intel.threadlinqs.com/cve/CVE-2025-31161)
- [CVE-2025-34291](https://intel.threadlinqs.com/cve/CVE-2025-34291)
- [CVE-2025-52691](https://intel.threadlinqs.com/cve/CVE-2025-52691)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-11386](https://intel.threadlinqs.com/cve/CVE-2026-11386)
- [CVE-2026-16812](https://intel.threadlinqs.com/cve/CVE-2026-16812)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)
- [CVE-2026-23760](https://intel.threadlinqs.com/cve/CVE-2026-23760)
- [CVE-2026-34926](https://intel.threadlinqs.com/cve/CVE-2026-34926)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-48558](https://intel.threadlinqs.com/cve/CVE-2026-48558)
- [CVE-2026-86218](https://intel.threadlinqs.com/cve/CVE-2026-86218)
- [CVE-2026-9089](https://intel.threadlinqs.com/cve/CVE-2026-9089)
- [CVE-2026-93616](https://intel.threadlinqs.com/cve/CVE-2026-93616)

## Detection coverage

Threadlinqs maintains 36 detection rules mapped to T1072 (SPL 13, KQL 10, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

36 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1072
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
