Activity timeline
T1105 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 253 reports, and 728 of the 730 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1105 Ingress Tool Transfer is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 730 of 2623 tracked threats (27.8%) to it; by severity that is 237 critical, 450 high, 39 medium, 2 low.
Threats that use T1105 most often also use T1027 Obfuscated Files or Information (529 threats), T1082 System Information Discovery (520 threats), T1041 Exfiltration Over C2 Channel (469 threats), T1005 Data from Local System (465 threats), T1059 Command and Scripting Interpreter (418 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
162 tracked threat actors appear in the threats that use T1105; the most frequent are APT38 (29), TeamPCP (25), Lazarus Group (21), Sapphire Sleet (21), Stardust Chollima (20).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1105.
Data sources
Telemetry that can reveal T1105, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 730 tracked threats that use T1105.
- CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Cataloghigh
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…critical
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…high
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)critical
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalogcritical
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…critical
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Executioncritical
- BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoorhigh
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…critical
- Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCEcritical
Detection coverage
Threadlinqs maintains 1332 detection rules mapped to T1105 (SPL 469, KQL 448, Sigma 415). Rule content is available to Blue tier accounts and above; this page shows counts only.