# T1120 Peripheral Device Discovery

> As of 2026-10-05, T1120 (Peripheral Device Discovery) appears in 34 tracked threats, first reported 2026-02-02 and most recently 2026-07-31, with linked actors including UNC1549, APT28, APT36; it most often appears alongside T1041 (Exfiltration Over C2 Channel).

- **Tracked threats:** 34 (6 critical, 25 high, 3 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-07-31
- **Threat actors:** 24
- **Detection rules:** 15 (counts only; Blue tier and above)

## Key facts

- **ID:** T1120
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1120/

## Activity timeline

T1120 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-07-31. The busiest month was 2026-07 with 15 reports, and 34 of the 34 threats were reported in the twelve months to 2026-07.

## How adversaries use it

T1120 Peripheral Device Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 34 of 2623 tracked threats (1.3%) to it; by severity that is 6 critical, 25 high, 3 medium.

Threats that use T1120 most often also use [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (24 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (24 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (20 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (20 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

24 tracked threat actors appear in the threats that use T1120; the most frequent are [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT36](https://intel.threadlinqs.com/actor/APT36) (1), [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [APT38](https://intel.threadlinqs.com/actor/APT38) (1).

## Data sources

Telemetry that can reveal T1120, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge) — 1
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 1

## Tracked threats

The 30 most recent of 34 tracked threats that use T1120.

- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…](https://intel.threadlinqs.com/threat/TL-2026-1751) — high — 2026-07-29
- [Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and…](https://intel.threadlinqs.com/threat/TL-2026-1741) — high — 2026-07-28
- [CVE-2026-42980: Windows NT OS Kernel Local Privilege Escalation via WMI Integer Underflow (Public PoC)](https://intel.threadlinqs.com/threat/TL-2026-1707) — high — 2026-07-26
- [KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization](https://intel.threadlinqs.com/threat/TL-2026-1701) — high — 2026-07-25
- [KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars](https://intel.threadlinqs.com/threat/TL-2026-1699) — high — 2026-07-25
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware…](https://intel.threadlinqs.com/threat/TL-2026-1510) — high — 2026-07-19
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Apps](https://intel.threadlinqs.com/threat/TL-2026-1383) — high — 2026-07-15
- [OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)](https://intel.threadlinqs.com/threat/TL-2026-1363) — critical — 2026-07-15
- [Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force…](https://intel.threadlinqs.com/threat/TL-2026-1240) — high — 2026-07-11
- [GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot…](https://intel.threadlinqs.com/threat/TL-2026-1167) — high — 2026-07-10
- [CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1061) — high — 2026-07-02
- [Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA)](https://intel.threadlinqs.com/threat/TL-2026-1058) — medium — 2026-07-02
- [Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1015) — critical — 2026-06-30
- [RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1006) — critical — 2026-06-30
- [Multi-Stage Steganographic Loader Campaign Deploying Remcos RAT and Diverse Stealer Payloads (K7 Labs, June…](https://intel.threadlinqs.com/threat/TL-2026-0896) — high — 2026-06-21
- [Sinobi Ransomware: Curve-25519/AES-128-CTR Encryption with Shadow Copy and Backup Destruction (Lynx/INC…](https://intel.threadlinqs.com/threat/TL-2026-0892) — high — 2026-06-21
- [ScarCruft (APT37) Deploys Python-Based NarwhalRAT via Fake Microsoft Account Security Alerts and LNK-in-ZIP…](https://intel.threadlinqs.com/threat/TL-2026-0890) — high — 2026-06-20
- [Airoha Bluetooth SoC Authentication Bypass & RACE Protocol Abuse (CVE-2025-20700/20701/20702) Enables…](https://intel.threadlinqs.com/threat/TL-2026-0850) — high — 2026-06-18
- [DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware…](https://intel.threadlinqs.com/threat/TL-2026-0724) — high — 2026-06-09
- [Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver…](https://intel.threadlinqs.com/threat/TL-2026-0653) — high — 2026-06-02
- [Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote…](https://intel.threadlinqs.com/threat/TL-2026-0626) — high — 2026-05-29
- [Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…](https://intel.threadlinqs.com/threat/TL-2026-0581) — high — 2026-05-25
- [Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via…](https://intel.threadlinqs.com/threat/TL-2026-0562) — high — 2026-05-22
- [MuddyWater (Seedworm) Iranian APT Masquerades as Chaos Ransomware — Microsoft Teams Social Engineering…](https://intel.threadlinqs.com/threat/TL-2026-0468) — high — 2026-05-06
- [GopherWhisper — China-Aligned APT Targeting Mongolian Government with Go-Based Burrow Malware Toolkit…](https://intel.threadlinqs.com/threat/TL-2026-0419) — high — 2026-04-24
- [Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation…](https://intel.threadlinqs.com/threat/TL-2026-0266) — critical — 2026-03-21
- [PureLog Stealer Multi-Stage Fileless Campaign Using Copyright Infringement Lures](https://intel.threadlinqs.com/threat/TL-2026-0252) — high — 2026-03-20

## Related CVEs

CVEs referenced by the tracked threats that use T1120, most frequent first.

- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1781](https://intel.threadlinqs.com/cve/CVE-2024-1781)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-20700](https://intel.threadlinqs.com/cve/CVE-2025-20700)
- [CVE-2025-20701](https://intel.threadlinqs.com/cve/CVE-2025-20701)
- [CVE-2025-20702](https://intel.threadlinqs.com/cve/CVE-2025-20702)
- [CVE-2025-2894](https://intel.threadlinqs.com/cve/CVE-2025-2894)
- [CVE-2025-29635](https://intel.threadlinqs.com/cve/CVE-2025-29635)
- [CVE-2025-35027](https://intel.threadlinqs.com/cve/CVE-2025-35027)
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704)
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)
- [CVE-2025-60017](https://intel.threadlinqs.com/cve/CVE-2025-60017)
- [CVE-2025-60250](https://intel.threadlinqs.com/cve/CVE-2025-60250)
- [CVE-2025-60251](https://intel.threadlinqs.com/cve/CVE-2025-60251)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-27509](https://intel.threadlinqs.com/cve/CVE-2026-27509)
- [CVE-2026-27510](https://intel.threadlinqs.com/cve/CVE-2026-27510)
- [CVE-2026-42980](https://intel.threadlinqs.com/cve/CVE-2026-42980)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)

## Detection coverage

Threadlinqs maintains 15 detection rules mapped to T1120 (SPL 3, KQL 3, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.

15 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1120
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
