# T1102.001 Dead Drop Resolver

> As of 2026-10-05, T1102.001 (Dead Drop Resolver) appears in 84 tracked threats, first reported 2026-02-24 and most recently 2026-10-01, with linked actors including TeamPCP, Contagious Interview, Lazarus Group; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 84 (11 critical, 65 high, 7 medium)
- **First seen:** 2026-02-24
- **Last seen:** 2026-10-01
- **Threat actors:** 26
- **Detection rules:** 253 (counts only; Blue tier and above)

## Key facts

- **ID:** T1102.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1102
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1102/001/

## Activity timeline

T1102.001 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-10-01. The busiest month was 2026-08 with 24 reports, and 84 of the 84 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1102.001 Dead Drop Resolver is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1102 Web Service](https://intel.threadlinqs.com/technique/T1102). Threadlinqs maps 84 of 2623 tracked threats (3.2%) to it; by severity that is 11 critical, 65 high, 7 medium.

Threats that use T1102.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (74 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (61 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (54 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (48 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (45 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

26 tracked threat actors appear in the threats that use T1102.001; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (7), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (4), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (3), [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) (3), [APT38](https://intel.threadlinqs.com/actor/APT38) (2).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1102.001.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1102.001, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 7
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 4
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3
- [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 2
- [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) — 2
- [GlassWorm Operators](https://intel.threadlinqs.com/actor/GlassWorm%20Operators) — 2
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 2
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 2
- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 1

## Tracked threats

The 30 most recent of 84 tracked threats that use T1102.001.

- [Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and…](https://intel.threadlinqs.com/threat/TL-2026-2821) — medium — 2026-10-01
- [PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…](https://intel.threadlinqs.com/threat/TL-2026-2785) — medium — 2026-09-29
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp](https://intel.threadlinqs.com/threat/TL-2026-2605) — high — 2026-09-21
- [EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials](https://intel.threadlinqs.com/threat/TL-2026-2600) — critical — 2026-09-21
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2](https://intel.threadlinqs.com/threat/TL-2026-2547) — high — 2026-09-17
- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…](https://intel.threadlinqs.com/threat/TL-2026-2544) — high — 2026-09-16
- [Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…](https://intel.threadlinqs.com/threat/TL-2026-2484) — high — 2026-09-13
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport…](https://intel.threadlinqs.com/threat/TL-2026-2387) — critical — 2026-09-08
- [Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel](https://intel.threadlinqs.com/threat/TL-2026-2311) — high — 2026-09-03
- [Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain](https://intel.threadlinqs.com/threat/TL-2026-2305) — high — 2026-09-03
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02
- [TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry](https://intel.threadlinqs.com/threat/TL-2026-2295) — high — 2026-09-02
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2273) — high — 2026-09-01
- [HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2](https://intel.threadlinqs.com/threat/TL-2026-2251) — high — 2026-08-31
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent…](https://intel.threadlinqs.com/threat/TL-2026-2249) — high — 2026-08-30
- [Commodity Infostealers Hijacking Claude Login Sessions to Drain Account Usage](https://intel.threadlinqs.com/threat/TL-2026-2234) — medium — 2026-08-30
- [Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach](https://intel.threadlinqs.com/threat/TL-2026-2219) — high — 2026-08-29
- [Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…](https://intel.threadlinqs.com/threat/TL-2026-2214) — high — 2026-08-29
- [ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…](https://intel.threadlinqs.com/threat/TL-2026-2199) — high — 2026-08-29
- [Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake…](https://intel.threadlinqs.com/threat/TL-2026-2280) — medium — 2026-08-28
- [Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistence](https://intel.threadlinqs.com/threat/TL-2026-2149) — medium — 2026-08-26
- [StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…](https://intel.threadlinqs.com/threat/TL-2026-2160) — 2026-08-25
- [D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…](https://intel.threadlinqs.com/threat/TL-2026-2147) — high — 2026-08-25
- [ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer](https://intel.threadlinqs.com/threat/TL-2026-2142) — high — 2026-08-25
- [APT-C-60 Spear-Phishing Campaign Against Japanese Recruiters Using VHDX/LNK and SpyGlace Malware](https://intel.threadlinqs.com/threat/TL-2026-2134) — high — 2026-08-24

## Related CVEs

CVEs referenced by the tracked threats that use T1102.001, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2022-2586](https://intel.threadlinqs.com/cve/CVE-2022-2586)
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386)
- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2023-4911](https://intel.threadlinqs.com/cve/CVE-2023-4911)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)

## Detection coverage

Threadlinqs maintains 253 detection rules mapped to T1102.001 (SPL 98, KQL 72, Sigma 83). Rule content is available to Blue tier accounts and above; this page shows counts only.

253 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1102 Web Service](https://intel.threadlinqs.com/technique/T1102) — 396 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1102.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
