Activity timeline
T1102.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 24 reports, and 84 of the 84 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1102.001 Dead Drop Resolver is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1102 Web Service. Threadlinqs maps 84 of 2623 tracked threats (3.2%) to it; by severity that is 11 critical, 65 high, 7 medium.
Threats that use T1102.001 most often also use T1071.001 Web Protocols (74 threats), T1027 Obfuscated Files or Information (61 threats), T1204.002 Malicious File (54 threats), T1082 System Information Discovery (48 threats), T1005 Data from Local System (45 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
26 tracked threat actors appear in the threats that use T1102.001; the most frequent are TeamPCP (7), Contagious Interview (4), Lazarus Group (3), UNC5342 (3), APT38 (2).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1102.001.
Data sources
Telemetry that can reveal T1102.001, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 84 tracked threats that use T1102.001.
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and…medium
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…medium
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…high
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcphigh
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentialscritical
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2high
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…high
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…high
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…critical
- Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channelhigh
- Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chainhigh
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
- TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industryhigh
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…high
- HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2high
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent…high
- Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usagemedium
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breachhigh
- Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…high
- ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…high
- Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…medium
- Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistencemedium
- StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…
- D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…high
- ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealerhigh
- APT-C-60 Spear-Phishing Campaign Against Japanese Recruiters Using VHDX/LNK and SpyGlace Malwarehigh
Detection coverage
Threadlinqs maintains 253 detection rules mapped to T1102.001 (SPL 98, KQL 72, Sigma 83). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1102 Web Service — 396 tracked threats at the technique level.