Activity timeline
T1119 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 151 reports, and 299 of the 300 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1119 Automated Collection is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 300 of 2623 tracked threats (11.4%) to it; by severity that is 82 critical, 177 high, 38 medium.
Threats that use T1119 most often also use T1005 Data from Local System (157 threats), T1027 Obfuscated Files or Information (154 threats), T1041 Exfiltration Over C2 Channel (135 threats), T1082 System Information Discovery (135 threats), T1567 Exfiltration Over Web Service (133 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
95 tracked threat actors appear in the threats that use T1119; the most frequent are TeamPCP (10), APT28 (6), Contagious Interview (6), ShinyHunters (6), APT38 (5).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1119.
Data sources
Telemetry that can reveal T1119, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Script — Script Execution
- User Account — User Account Authentication
Threat actors using it
Tracked threats
The 30 most recent of 300 tracked threats that use T1119.
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials…critical
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Datahigh
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)high
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…high
- Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…high
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…high
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing…critical
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…medium
- Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpithigh
- GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…high
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Modelscritical
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leakhigh
- PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionhigh
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…high
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…critical
- Suspected China-Linked Actor Runs Near-Autonomous Multi-Agent AI Attack on Taiwan Government, Nuclear Safety…critical
- Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countrieshigh
- SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII…medium
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCShigh
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…high
Detection coverage
Threadlinqs maintains 339 detection rules mapped to T1119 (SPL 95, KQL 134, Sigma 110). Rule content is available to Blue tier accounts and above; this page shows counts only.