# T1102 Web Service

> As of 2026-10-05, T1102 (Web Service) appears in 396 tracked threats, first reported 2026-01-19 and most recently 2026-09-14, with linked actors including TeamPCP, APT28, Contagious Interview; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 396 (89 critical, 268 high, 37 medium, 1 low)
- **First seen:** 2026-01-19
- **Last seen:** 2026-09-14
- **Threat actors:** 132
- **Detection rules:** 435 (counts only; Blue tier and above)

## Key facts

- **ID:** T1102
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1102/

## Activity timeline

T1102 first appeared in tracked threats on 2026-01-19 and was most recently reported on 2026-09-14. The busiest month was 2026-07 with 178 reports, and 396 of the 396 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1102 Web Service is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 396 of 2623 tracked threats (15.1%) to it; by severity that is 89 critical, 268 high, 37 medium, 1 low.

Threats that use T1102 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (282 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (243 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (237 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (230 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (229 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

132 tracked threat actors appear in the threats that use T1102; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (17), [APT28](https://intel.threadlinqs.com/actor/APT28) (11), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (11), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (10), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (9).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1102.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1102, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 17
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 11
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 11
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 10
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 9
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 8
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 6
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 5
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 5

## Tracked threats

The 30 most recent of 396 tracked threats that use T1102.

- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…](https://intel.threadlinqs.com/threat/TL-2026-2087) — critical — 2026-08-20
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Data](https://intel.threadlinqs.com/threat/TL-2026-1836) — medium — 2026-08-03
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skills](https://intel.threadlinqs.com/threat/TL-2026-1828) — low — 2026-08-03
- [Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…](https://intel.threadlinqs.com/threat/TL-2026-1816) — high — 2026-08-02
- [North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…](https://intel.threadlinqs.com/threat/TL-2026-1794) — high — 2026-07-31
- [GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs](https://intel.threadlinqs.com/threat/TL-2026-1768) — high — 2026-07-30
- [AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1811) — high — 2026-07-29
- [Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)](https://intel.threadlinqs.com/threat/TL-2026-1767) — critical — 2026-07-29
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28
- [Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and…](https://intel.threadlinqs.com/threat/TL-2026-1741) — high — 2026-07-28
- [Autonomous OpenAI Test Models (GPT-5.6 Sol + Unreleased Pre-Release Model) Breach Hugging Face Production…](https://intel.threadlinqs.com/threat/TL-2026-1739) — critical — 2026-07-28
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags…](https://intel.threadlinqs.com/threat/TL-2026-1735) — medium — 2026-07-28
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [Claude Code Symlink Flaw in Startup Memory Loader Enables Silent File Exfiltration via CLAUDE.md Imports](https://intel.threadlinqs.com/threat/TL-2026-1718) — medium — 2026-07-27
- [AWS SSM Agent Abused as a Living-off-the-Land Remote Access Trojan via Hybrid-Activation Hijacking and…](https://intel.threadlinqs.com/threat/TL-2026-1709) — medium — 2026-07-26
- [Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak…](https://intel.threadlinqs.com/threat/TL-2026-1708) — high — 2026-07-26
- [GitHub and PyPI Add Time-Based Defenses Against Supply-Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-1706) — 2026-07-26
- [SleeperGem: RubyGems Supply Chain Attack Uses Hijacked Dormant Maintainer Accounts to Weaponize…](https://intel.threadlinqs.com/threat/TL-2026-1703) — high — 2026-07-26
- [Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkit](https://intel.threadlinqs.com/threat/TL-2026-1754) — high — 2026-07-25
- [AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and…](https://intel.threadlinqs.com/threat/TL-2026-1686) — medium — 2026-07-25
- [InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)](https://intel.threadlinqs.com/threat/TL-2026-1679) — high — 2026-07-25

## Related CVEs

CVEs referenced by the tracked threats that use T1102, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2025-54068](https://intel.threadlinqs.com/cve/CVE-2025-54068)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2017-6742](https://intel.threadlinqs.com/cve/CVE-2017-6742)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2019-19006](https://intel.threadlinqs.com/cve/CVE-2019-19006)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-10189](https://intel.threadlinqs.com/cve/CVE-2020-10189)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)

## Detection coverage

Threadlinqs maintains 435 detection rules mapped to T1102 (SPL 141, KQL 142, Sigma 151, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

435 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1102.001 Dead Drop Resolver](https://intel.threadlinqs.com/technique/T1102.001) — 84 tracked threats
- [T1102.002 Bidirectional Communication](https://intel.threadlinqs.com/technique/T1102.002) — 139 tracked threats
- T1102.003 One-Way Communication — 5 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1102
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
