Activity timeline
T1074 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 47 reports, and 119 of the 120 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1074 Data Staged is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 120 of 2623 tracked threats (4.6%) to it; by severity that is 47 critical, 66 high, 6 medium.
Threats that use T1074 most often also use T1059 Command and Scripting Interpreter (93 threats), T1041 Exfiltration Over C2 Channel (83 threats), T1071 Application Layer Protocol (83 threats), T1082 System Information Discovery (79 threats), T1005 Data from Local System (74 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
61 tracked threat actors appear in the threats that use T1074; the most frequent are Scattered Spider (5), ShinyHunters (5), TeamPCP (5), UNC6240 (5), MuddyWater (4).
Data sources
Telemetry that can reveal T1074, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access, File Creation
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 120 tracked threats that use T1074.
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and…high
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…critical
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojancritical
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resiliencehigh
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Accessmedium
- MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals…high
- Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers…critical
- Iran Exploits SS7 Cellular Roaming Protocol and Commercial Ad-Tech Location Data to Track and Target US…high
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Datahigh
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransommedium
- Russian Intelligence Services Hijack Unsecured IP Cameras Across NATO, EU and Ukraine to Surveil Weapons…high
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…high
- OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production…high
- Executive Order 14415: Trump Administration Tightens Defense Supply Chain Oversight, Mandates Domestic…
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider…high
- ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stagehigh
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- Google Sites Phishing Campaign Delivers AMOS-Variant macOS Stealer (unix32385485) to Web3 Usershigh
- OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign…high
- CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)critical
- Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattackhigh
- macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App Replacementhigh
- ClickLock: New macOS Infostealer Uses ClickFix Lure and App-Killing LaunchAgents to Force Credential Entryhigh
- GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic Entitieshigh
- Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and…high
- OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Appshigh
Detection coverage
Threadlinqs maintains 34 detection rules mapped to T1074 (SPL 6, KQL 11, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1074.001 Local Data Staging — 66 tracked threats
- T1074.002 Remote Data Staging — 7 tracked threats