Activity timeline
T1104 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 15 reports, and 22 of the 22 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1104 Multi-Stage Channels is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 22 of 2623 tracked threats (0.8%) to it; by severity that is 6 critical, 13 high, 3 medium.
Threats that use T1104 most often also use T1027 Obfuscated Files or Information (17 threats), T1105 Ingress Tool Transfer (16 threats), T1140 Deobfuscate/Decode Files or Information (16 threats), T1005 Data from Local System (14 threats), T1059 Command and Scripting Interpreter (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
13 tracked threat actors appear in the threats that use T1104; the most frequent are MuddyWater (2), TA578 - G1038 (2), UAT-11795 (2), Contagious Interview (1), Contagious Interview - G1052 (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1104.
Data sources
Telemetry that can reveal T1104, per MITRE ATT&CK.
- Network Traffic — Network Connection Creation, Network Traffic Flow
Threat actors using it
Tracked threats
22 tracked threats use T1104.
- QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Acceleratormedium
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessionshigh
- Hugging Face Breached by Autonomous AI Agent Exploiting Dataset Code-Execution Paths (No CVE Disclosed)high
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider…high
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversarymedium
- Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…medium
- Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo[.]org…high
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaignhigh
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and…high
- AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loadercritical
- AsyncAPI npm Supply Chain Compromise: GitHub Actions pull_request_target Exploit Deploys Miasma RAT to…critical
- AsyncAPI npm Supply-Chain Compromise via GitHub Actions Pwn Request Deploys 'M-Red-Team v6.4' /…critical
- 148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack…high
- SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operationshigh
- Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling…high
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com /…high
- DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware…high
- UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware…critical
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaigncritical
- CHAR Rust Backdoor + GhostFetch/GhostBackDoor/HTTP_VIP — Iran MOIS-Linked MuddyWater AI-Assisted Malware…critical
Detection coverage
Threadlinqs maintains 28 detection rules mapped to T1104 (SPL 10, KQL 12, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.