Activity timeline
T1113 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 101 reports, and 330 of the 330 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1113 Screen Capture is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 330 of 2623 tracked threats (12.6%) to it; by severity that is 44 critical, 267 high, 18 medium.
Threats that use T1113 most often also use T1082 System Information Discovery (249 threats), T1027 Obfuscated Files or Information (242 threats), T1041 Exfiltration Over C2 Channel (218 threats), T1005 Data from Local System (202 threats), T1140 Deobfuscate/Decode Files or Information (190 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
99 tracked threat actors appear in the threats that use T1113; the most frequent are APT38 (12), Andariel (9), Lazarus Group (8), Sapphire Sleet (8), Stardust Chollima (8).
Data sources
Telemetry that can reveal T1113, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution
Threat actors using it
Tracked threats
The 30 most recent of 330 tracked threats that use T1113.
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…high
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…high
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…critical
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…high
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…high
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chainhigh
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2high
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…high
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Servicehigh
- PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionhigh
- APT-C-60 Spear-Phishing Campaign Delivering SpyGlace via Proton Drive, RAR/LNK and Legitimate Developer…high
- REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…high
- Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chainhigh
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…high
- Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teamshigh
- Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accountshigh
Detection coverage
Threadlinqs maintains 194 detection rules mapped to T1113 (SPL 40, KQL 79, Sigma 75). Rule content is available to Blue tier accounts and above; this page shows counts only.