# T1119 Automated Collection

> As of 2026-10-05, T1119 (Automated Collection) appears in 300 tracked threats, first reported 2021-11-25 and most recently 2026-10-04, with linked actors including TeamPCP, APT28, Contagious Interview; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 300 (82 critical, 177 high, 38 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-04
- **Threat actors:** 95
- **Detection rules:** 339 (counts only; Blue tier and above)

## Key facts

- **ID:** T1119
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1119/

## Activity timeline

T1119 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 151 reports, and 299 of the 300 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1119 Automated Collection is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 300 of 2623 tracked threats (11.4%) to it; by severity that is 82 critical, 177 high, 38 medium.

Threats that use T1119 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (157 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (154 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (135 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (135 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (133 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

95 tracked threat actors appear in the threats that use T1119; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (10), [APT28](https://intel.threadlinqs.com/actor/APT28) (6), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (6), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (6), [APT38](https://intel.threadlinqs.com/actor/APT38) (5).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1119.

- [M1029 Remote Data Storage](https://attack.mitre.org/mitigations/M1029/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)

## Data sources

Telemetry that can reveal T1119, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Script — Script Execution
- User Account — User Account Authentication

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 10
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 6
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 6
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 6
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 4
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 4
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 4
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 4
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 4
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 4

## Tracked threats

The 30 most recent of 300 tracked threats that use T1119.

- [Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty](https://intel.threadlinqs.com/threat/TL-2026-2908) — high — 2026-10-04
- [TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…](https://intel.threadlinqs.com/threat/TL-2026-2889) — high — 2026-10-04
- [Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials…](https://intel.threadlinqs.com/threat/TL-2026-2772) — critical — 2026-09-29
- [Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data](https://intel.threadlinqs.com/threat/TL-2026-2768) — high — 2026-09-29
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)](https://intel.threadlinqs.com/threat/TL-2026-2698) — high — 2026-09-27
- [Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…](https://intel.threadlinqs.com/threat/TL-2026-2661) — high — 2026-09-26
- [Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-2656) — high — 2026-09-26
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image…](https://intel.threadlinqs.com/threat/TL-2026-2566) — high — 2026-09-18
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing…](https://intel.threadlinqs.com/threat/TL-2026-2563) — critical — 2026-09-18
- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…](https://intel.threadlinqs.com/threat/TL-2026-2559) — medium — 2026-09-18
- [Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpit](https://intel.threadlinqs.com/threat/TL-2026-2490) — high — 2026-09-14
- [GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…](https://intel.threadlinqs.com/threat/TL-2026-2458) — high — 2026-09-12
- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — critical — 2026-09-09
- [Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak](https://intel.threadlinqs.com/threat/TL-2026-2383) — high — 2026-09-07
- [PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2380) — high — 2026-09-07
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…](https://intel.threadlinqs.com/threat/TL-2026-2065) — critical — 2026-08-19
- [Suspected China-Linked Actor Runs Near-Autonomous Multi-Agent AI Attack on Taiwan Government, Nuclear Safety…](https://intel.threadlinqs.com/threat/TL-2026-2063) — critical — 2026-08-18
- [Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countries](https://intel.threadlinqs.com/threat/TL-2026-2034) — high — 2026-08-16
- [SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII…](https://intel.threadlinqs.com/threat/TL-2026-2032) — medium — 2026-08-16
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS](https://intel.threadlinqs.com/threat/TL-2026-2028) — high — 2026-08-16
- ["TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's…](https://intel.threadlinqs.com/threat/TL-2026-2027) — high — 2026-08-16

## Related CVEs

CVEs referenced by the tracked threats that use T1119, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2016-7407](https://intel.threadlinqs.com/cve/CVE-2016-7407)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)

## Detection coverage

Threadlinqs maintains 339 detection rules mapped to T1119 (SPL 95, KQL 134, Sigma 110). Rule content is available to Blue tier accounts and above; this page shows counts only.

339 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1119
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
