# T1080 Taint Shared Content

> As of 2026-10-05, T1080 (Taint Shared Content) appears in 24 tracked threats, first reported 2026-02-16 and most recently 2026-09-01, with linked actors including Gamaredon, TeamPCP, Gamaredon Group; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 24 (11 critical, 11 high, 2 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-01
- **Threat actors:** 9
- **Detection rules:** 34 (counts only; Blue tier and above)

## Key facts

- **ID:** T1080
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1080/

## Activity timeline

T1080 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-01. The busiest month was 2026-06 with 10 reports, and 24 of the 24 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1080 Taint Shared Content is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 24 of 2623 tracked threats (0.9%) to it; by severity that is 11 critical, 11 high, 2 medium.

Threats that use T1080 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (16 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (15 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (14 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (13 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1080; the most frequent are [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (3), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3), [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) (2), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1), [Miasma operator](https://intel.threadlinqs.com/actor/Miasma%20operator) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1080.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1049 Antivirus/Antimalware](https://attack.mitre.org/mitigations/M1049/)
- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)

## Data sources

Telemetry that can reveal T1080, per MITRE ATT&CK.

- File — File Creation, File Modification
- Network Share — Network Share Access
- Process — Process Creation

## Threat actors using it

- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 2
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Miasma operator](https://intel.threadlinqs.com/actor/Miasma%20operator) — 1
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 1
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 1

## Tracked threats

24 tracked threats use T1080.

- [Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing](https://intel.threadlinqs.com/threat/TL-2026-2284) — high — 2026-09-01
- [GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex](https://intel.threadlinqs.com/threat/TL-2026-2059) — medium — 2026-08-18
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Spirals Ransomware: Rust-Based Double-Extortion Family Breaches South Asian IT Services Firm via IIS Web…](https://intel.threadlinqs.com/threat/TL-2026-1410) — high — 2026-07-16
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2…](https://intel.threadlinqs.com/threat/TL-2026-0968) — high — 2026-06-28
- [Miasma Malware Supply Chain Attack Targets npm Packages, Go Module, and GitHub Actions CI/CD Pipelines](https://intel.threadlinqs.com/threat/TL-2026-0963) — critical — 2026-06-27
- [CVE-2026-8461 (PixelSmash): Heap Out-of-Bounds Write in FFmpeg libavcodec MagicYUV Decoder](https://intel.threadlinqs.com/threat/TL-2026-0906) — high — 2026-06-22
- [Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model…](https://intel.threadlinqs.com/threat/TL-2026-0880) — high — 2026-06-19
- [CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on…](https://intel.threadlinqs.com/threat/TL-2026-0872) — high — 2026-06-19
- [CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection…](https://intel.threadlinqs.com/threat/TL-2026-0835) — high — 2026-06-17
- [EndPoint (Midnight) Ransomware — Babuk-derived double-extortion targeting Windows, ESXi, and NAS](https://intel.threadlinqs.com/threat/TL-2026-0742) — critical — 2026-06-09
- [Miasma / Shai-Hulud Supply-Chain Campaign Pushes Password-Stealing Malware via Compromised Microsoft GitHub…](https://intel.threadlinqs.com/threat/TL-2026-0733) — high — 2026-06-09
- [Miasma Worm Compromises 73 Microsoft GitHub Repositories Across Azure, Azure-Samples, Microsoft &…](https://intel.threadlinqs.com/threat/TL-2026-0719) — critical — 2026-06-08
- [Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver…](https://intel.threadlinqs.com/threat/TL-2026-0653) — high — 2026-06-02
- [Notepad++ v8.9.6 — Critical Arbitrary Code Execution via config.xml commandLineInterpreter and shortcuts.xml…](https://intel.threadlinqs.com/threat/TL-2026-0613) — critical — 2026-05-28
- [JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking…](https://intel.threadlinqs.com/threat/TL-2026-0607) — critical — 2026-05-27
- [CISA KEV (2026-05-21): CVE-2025-34291 Langflow CORS Token Hijack-to-RCE & CVE-2026-34926 Trend Micro Apex…](https://intel.threadlinqs.com/threat/TL-2026-0551) — critical — 2026-05-21
- [Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…](https://intel.threadlinqs.com/threat/TL-2026-0548) — critical — 2026-05-21
- [Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…](https://intel.threadlinqs.com/threat/TL-2026-0547) — critical — 2026-05-21
- [CVE-2026-32201: Microsoft SharePoint Server Zero-Day Spoofing Vulnerability via Improper Input Validation…](https://intel.threadlinqs.com/threat/TL-2026-0366) — critical — 2026-04-15
- [TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload](https://intel.threadlinqs.com/threat/TL-2026-0304) — critical — 2026-03-31
- [GitHub Codespaces RCE via VS Code Configuration Files](https://intel.threadlinqs.com/threat/TL-2026-0100) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1080, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-34291](https://intel.threadlinqs.com/cve/CVE-2025-34291)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-34926](https://intel.threadlinqs.com/cve/CVE-2026-34926)
- [CVE-2026-48770](https://intel.threadlinqs.com/cve/CVE-2026-48770)
- [CVE-2026-48778](https://intel.threadlinqs.com/cve/CVE-2026-48778)
- [CVE-2026-48800](https://intel.threadlinqs.com/cve/CVE-2026-48800)
- [CVE-2026-50656](https://intel.threadlinqs.com/cve/CVE-2026-50656)
- [CVE-2026-8461](https://intel.threadlinqs.com/cve/CVE-2026-8461)

## Detection coverage

Threadlinqs maintains 34 detection rules mapped to T1080 (SPL 14, KQL 13, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

34 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1080
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
