Activity timeline
T1080 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 10 reports, and 24 of the 24 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1080 Taint Shared Content is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 24 of 2623 tracked threats (0.9%) to it; by severity that is 11 critical, 11 high, 2 medium.
Threats that use T1080 most often also use T1059 Command and Scripting Interpreter (16 threats), T1005 Data from Local System (15 threats), T1027 Obfuscated Files or Information (14 threats), T1036 Masquerading (13 threats), T1071 Application Layer Protocol (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1080; the most frequent are Gamaredon (3), TeamPCP (3), Gamaredon Group (2), Chaotic Eclipse (1), Miasma operator (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1080.
Data sources
Telemetry that can reveal T1080, per MITRE ATT&CK.
- File — File Creation, File Modification
- Network Share — Network Share Access
- Process — Process Creation
Threat actors using it
Tracked threats
24 tracked threats use T1080.
- Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholinghigh
- GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruexmedium
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…critical
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- Spirals Ransomware: Rust-Based Double-Extortion Family Breaches South Asian IT Services Firm via IIS Web…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2…high
- Miasma Malware Supply Chain Attack Targets npm Packages, Go Module, and GitHub Actions CI/CD Pipelinescritical
- CVE-2026-8461 (PixelSmash): Heap Out-of-Bounds Write in FFmpeg libavcodec MagicYUV Decoderhigh
- Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model…high
- CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on…high
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection…high
- EndPoint (Midnight) Ransomware — Babuk-derived double-extortion targeting Windows, ESXi, and NAScritical
- Miasma / Shai-Hulud Supply-Chain Campaign Pushes Password-Stealing Malware via Compromised Microsoft GitHub…high
- Miasma Worm Compromises 73 Microsoft GitHub Repositories Across Azure, Azure-Samples, Microsoft &…critical
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver…high
- Notepad++ v8.9.6 — Critical Arbitrary Code Execution via config.xml commandLineInterpreter and shortcuts.xml…critical
- JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking…critical
- CISA KEV (2026-05-21): CVE-2025-34291 Langflow CORS Token Hijack-to-RCE & CVE-2026-34926 Trend Micro Apex…critical
- Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…critical
- Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…critical
- CVE-2026-32201: Microsoft SharePoint Server Zero-Day Spoofing Vulnerability via Improper Input Validation…critical
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payloadcritical
- GitHub Codespaces RCE via VS Code Configuration Fileshigh
Detection coverage
Threadlinqs maintains 34 detection rules mapped to T1080 (SPL 14, KQL 13, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.