Activity timeline
T1120 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 15 reports, and 34 of the 34 threats were reported in the twelve months to 2026-07.
How adversaries use it
T1120 Peripheral Device Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 34 of 2623 tracked threats (1.3%) to it; by severity that is 6 critical, 25 high, 3 medium.
Threats that use T1120 most often also use T1041 Exfiltration Over C2 Channel (24 threats), T1082 System Information Discovery (24 threats), T1027 Obfuscated Files or Information (20 threats), T1059 Command and Scripting Interpreter (20 threats), T1005 Data from Local System (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
24 tracked threat actors appear in the threats that use T1120; the most frequent are UNC1549 (2), APT28 (1), APT36 (1), APT37 (1), APT38 (1).
Data sources
Telemetry that can reveal T1120, per MITRE ATT&CK.
- Command — Command Execution
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 34 tracked threats that use T1120.
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…high
- Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and…high
- CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)high
- KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilizationhigh
- KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Carshigh
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…high
- COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware…high
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Appshigh
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)critical
- Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force…high
- GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot…high
- CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitationhigh
- Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA)medium
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdowncritical
- RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitationcritical
- Multi-Stage Steganographic Loader Campaign Deploying Remcos RAT and Diverse Stealer Payloads (K7 Labs, June…high
- Sinobi Ransomware: Curve-25519/AES-128-CTR Encryption with Shadow Copy and Backup Destruction (Lynx/INC…high
- ScarCruft (APT37) Deploys Python-Based NarwhalRAT via Fake Microsoft Account Security Alerts and LNK-in-ZIP…high
- Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables…high
- DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware…high
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver…high
- Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…high
- Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…high
- Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via…high
- MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering…high
- GopherWhisper — China-Aligned APT Targeting Mongolian Government with Go-Based Burrow Malware Toolkit…high
- Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation…critical
- PureLog Stealer Multi-Stage Fileless Campaign Using Copyright Infringement Lureshigh
Detection coverage
Threadlinqs maintains 15 detection rules mapped to T1120 (SPL 3, KQL 3, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.