# T1074 Data Staged

> As of 2026-10-05, T1074 (Data Staged) appears in 120 tracked threats, first reported 2021-11-25 and most recently 2026-08-04, with linked actors including Scattered Spider, ShinyHunters, TeamPCP; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 120 (47 critical, 66 high, 6 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-08-04
- **Threat actors:** 61
- **Detection rules:** 34 (counts only; Blue tier and above)

## Key facts

- **ID:** T1074
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1074/

## Activity timeline

T1074 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-08-04. The busiest month was 2026-07 with 47 reports, and 119 of the 120 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1074 Data Staged is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 120 of 2623 tracked threats (4.6%) to it; by severity that is 47 critical, 66 high, 6 medium.

Threats that use T1074 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (93 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (83 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (83 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (79 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (74 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

61 tracked threat actors appear in the threats that use T1074; the most frequent are [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (5), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (5), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (5), [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) (5), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (4).

## Data sources

Telemetry that can reveal T1074, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access, File Creation
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 5
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 5
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 5
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 5
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 4
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 4
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 4
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 4
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 4
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 3

## Tracked threats

The 30 most recent of 120 tracked threats that use T1074.

- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and…](https://intel.threadlinqs.com/threat/TL-2026-1834) — high — 2026-08-03
- [Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1807) — high — 2026-08-01
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — medium — 2026-07-27
- [MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals…](https://intel.threadlinqs.com/threat/TL-2026-1716) — high — 2026-07-27
- [Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers…](https://intel.threadlinqs.com/threat/TL-2026-1681) — critical — 2026-07-25
- [Iran Exploits SS7 Cellular Roaming Protocol and Commercial Ad-Tech Location Data to Track and Target US…](https://intel.threadlinqs.com/threat/TL-2026-1673) — high — 2026-07-24
- [Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data](https://intel.threadlinqs.com/threat/TL-2026-1654) — high — 2026-07-23
- [Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom](https://intel.threadlinqs.com/threat/TL-2026-1642) — medium — 2026-07-22
- [Russian Intelligence Services Hijack Unsecured IP Cameras Across NATO, EU and Ukraine to Surveil Weapons…](https://intel.threadlinqs.com/threat/TL-2026-1624) — high — 2026-07-22
- [Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…](https://intel.threadlinqs.com/threat/TL-2026-1615) — high — 2026-07-22
- [OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production…](https://intel.threadlinqs.com/threat/TL-2026-1603) — high — 2026-07-22
- [Executive Order 14415: Trump Administration Tightens Defense Supply Chain Oversight, Mandates Domestic…](https://intel.threadlinqs.com/threat/TL-2026-1700) — 2026-07-20
- [ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider…](https://intel.threadlinqs.com/threat/TL-2026-1572) — high — 2026-07-20
- [ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage](https://intel.threadlinqs.com/threat/TL-2026-1558) — high — 2026-07-20
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Google Sites Phishing Campaign Delivers AMOS-Variant macOS Stealer (unix32385485) to Web3 Users](https://intel.threadlinqs.com/threat/TL-2026-1495) — high — 2026-07-18
- [OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1441) — high — 2026-07-17
- [CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-1438) — critical — 2026-07-17
- [Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack](https://intel.threadlinqs.com/threat/TL-2026-1429) — high — 2026-07-17
- [macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App Replacement](https://intel.threadlinqs.com/threat/TL-2026-1494) — high — 2026-07-16
- [ClickLock: New macOS Infostealer Uses ClickFix Lure and App-Killing LaunchAgents to Force Credential Entry](https://intel.threadlinqs.com/threat/TL-2026-1421) — high — 2026-07-16
- [GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic Entities](https://intel.threadlinqs.com/threat/TL-2026-1415) — high — 2026-07-16
- [Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and…](https://intel.threadlinqs.com/threat/TL-2026-1388) — high — 2026-07-15
- [OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Apps](https://intel.threadlinqs.com/threat/TL-2026-1383) — high — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use T1074, most frequent first.

- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2016-7407](https://intel.threadlinqs.com/cve/CVE-2016-7407)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2017-7921](https://intel.threadlinqs.com/cve/CVE-2017-7921)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2019-11510](https://intel.threadlinqs.com/cve/CVE-2019-11510)
- [CVE-2019-11539](https://intel.threadlinqs.com/cve/CVE-2019-11539)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2020-5902](https://intel.threadlinqs.com/cve/CVE-2020-5902)
- [CVE-2020-8243](https://intel.threadlinqs.com/cve/CVE-2020-8243)
- [CVE-2021-22893](https://intel.threadlinqs.com/cve/CVE-2021-22893)
- [CVE-2021-22894](https://intel.threadlinqs.com/cve/CVE-2021-22894)
- [CVE-2021-22900](https://intel.threadlinqs.com/cve/CVE-2021-22900)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)

## Detection coverage

Threadlinqs maintains 34 detection rules mapped to T1074 (SPL 6, KQL 11, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

34 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1074.001 Local Data Staging](https://intel.threadlinqs.com/technique/T1074.001) — 66 tracked threats
- T1074.002 Remote Data Staging — 7 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1074
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
