# T1082 System Information Discovery

> As of 2026-10-05, T1082 (System Information Discovery) appears in 1143 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including APT38, Sapphire Sleet, TeamPCP; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 1143 (369 critical, 700 high, 68 medium, 2 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 197
- **Detection rules:** 886 (counts only; Blue tier and above)

## Key facts

- **ID:** T1082
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1082/

## Activity timeline

T1082 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 369 reports, and 1142 of the 1143 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1082 System Information Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 1143 of 2623 tracked threats (43.6%) to it; by severity that is 369 critical, 700 high, 68 medium, 2 low.

Threats that use T1082 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (728 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (707 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (599 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (593 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (520 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

197 tracked threat actors appear in the threats that use T1082; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (33), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (29), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (28), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (27), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (20).

## Data sources

Telemetry that can reveal T1082, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 33
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 29
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 28
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 27
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 20
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 18
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 18
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 14
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 14
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 14
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 13
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 12

## Tracked threats

The 30 most recent of 1143 tracked threats that use T1082.

- [BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…](https://intel.threadlinqs.com/threat/TL-2026-2875) — high — 2026-10-03
- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https://intel.threadlinqs.com/threat/TL-2026-2840) — high — 2026-10-02
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer](https://intel.threadlinqs.com/threat/TL-2026-2699) — high — 2026-09-27
- [Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)](https://intel.threadlinqs.com/threat/TL-2026-2698) — high — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…](https://intel.threadlinqs.com/threat/TL-2026-2685) — high — 2026-09-27
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised](https://intel.threadlinqs.com/threat/TL-2026-2694) — medium — 2026-09-25
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses…](https://intel.threadlinqs.com/threat/TL-2026-2653) — critical — 2026-09-25
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin…](https://intel.threadlinqs.com/threat/TL-2026-2648) — high — 2026-09-25
- [Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…](https://intel.threadlinqs.com/threat/TL-2026-2647) — high — 2026-09-25
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25

## Related CVEs

CVEs referenced by the tracked threats that use T1082, most frequent first.

- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)

## Detection coverage

Threadlinqs maintains 886 detection rules mapped to T1082 (SPL 249, KQL 344, Sigma 293). Rule content is available to Blue tier accounts and above; this page shows counts only.

886 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1082
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
