# T1105 Ingress Tool Transfer

> As of 2026-10-05, T1105 (Ingress Tool Transfer) appears in 730 tracked threats, first reported 2021-11-25 and most recently 2026-10-04, with linked actors including APT38, TeamPCP, Lazarus Group; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 730 (237 critical, 450 high, 39 medium, 2 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-04
- **Threat actors:** 162
- **Detection rules:** 1332 (counts only; Blue tier and above)

## Key facts

- **ID:** T1105
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1105/

## Activity timeline

T1105 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 253 reports, and 728 of the 730 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1105 Ingress Tool Transfer is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 730 of 2623 tracked threats (27.8%) to it; by severity that is 237 critical, 450 high, 39 medium, 2 low.

Threats that use T1105 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (529 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (520 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (469 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (465 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (418 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

162 tracked threat actors appear in the threats that use T1105; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (29), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (25), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (21), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (21), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (20).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1105.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1105, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 29
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 25
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 21
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 21
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 20
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 18
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 18
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 13
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 12
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 12
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 11
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 11

## Tracked threats

The 30 most recent of 730 tracked threats that use T1105.

- [CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2896) — high — 2026-10-04
- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — high — 2026-09-29
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)](https://intel.threadlinqs.com/threat/TL-2026-2617) — critical — 2026-09-22
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — critical — 2026-09-14
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…](https://intel.threadlinqs.com/threat/TL-2026-2185) — critical — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — critical — 2026-08-28
- [BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2173) — high — 2026-08-27
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-2162) — critical — 2026-08-27
- [Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCE](https://intel.threadlinqs.com/threat/TL-2026-2157) — critical — 2026-08-26

## Related CVEs

CVEs referenced by the tracked threats that use T1105, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-48282](https://intel.threadlinqs.com/cve/CVE-2026-48282)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48276](https://intel.threadlinqs.com/cve/CVE-2026-48276)
- [CVE-2026-48277](https://intel.threadlinqs.com/cve/CVE-2026-48277)
- [CVE-2026-48281](https://intel.threadlinqs.com/cve/CVE-2026-48281)

## Detection coverage

Threadlinqs maintains 1332 detection rules mapped to T1105 (SPL 469, KQL 448, Sigma 415). Rule content is available to Blue tier accounts and above; this page shows counts only.

1332 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1105
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
