Activity timeline
T1091 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 8 reports, and 38 of the 38 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1091 Replication Through Removable Media is catalogued by MITRE ATT&CK under the Initial Access and Lateral Movement tactics in the Enterprise matrix. Threadlinqs maps 38 of 2623 tracked threats (1.4%) to it; by severity that is 8 critical, 24 high, 5 medium, 1 low.
Threats that use T1091 most often also use T1082 System Information Discovery (24 threats), T1005 Data from Local System (21 threats), T1027 Obfuscated Files or Information (20 threats), T1083 File and Directory Discovery (17 threats), T1059 Command and Scripting Interpreter (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
14 tracked threat actors appear in the threats that use T1091; the most frequent are Gamaredon (4), APT28 (2), APT36 (2), Gamaredon Group (2), Mustang Panda (2).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1091.
Data sources
Telemetry that can reveal T1091, per MITRE ATT&CK.
- Drive — Drive Creation
- File — File Access, File Creation
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 38 tracked threats that use T1091.
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…medium
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…medium
- Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholinghigh
- Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plotlow
- UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…critical
- GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruexmedium
- StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…high
- Pixel 10 VPU Driver mmap Boundary-Check Flaw Enables Root Exploit Chain (CVE-2025-54957)critical
- GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG…high
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS…high
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)high
- Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flashhigh
- Blackfield (BlackFL) Ransomware Demands $2 Million from Nidec Chaun-Choung Technology Corporation (Nidec…high
- Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw…high
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2…high
- usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB…high
- usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) deviceshigh
- usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…critical
- CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2…high
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver…high
- Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US…high
- DeepLoad Fileless Loader — ClickFix Delivery, APC Injection into LockAppHost.exe, USB .lnk Worm and…high
- ExifTool macOS Command Injection CVE-2026-3102 — Malicious Image Metadata Triggers system() Sink via…high
- YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC…critical
- ZionSiphon — Ideologically Motivated .NET OT Malware Targeting Israeli Water & Desalination Infrastructure…critical
- CVE-2026-32202 — Windows Shell Protection Mechanism Failure: NTLM Authentication Coercion via Auto-Parsed…critical
Detection coverage
Threadlinqs maintains 54 detection rules mapped to T1091 (SPL 18, KQL 21, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.