Activity timeline
T1132 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 23 reports, and 70 of the 70 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1132 Data Encoding is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 70 of 2623 tracked threats (2.7%) to it; by severity that is 12 critical, 53 high, 5 medium.
Threats that use T1132 most often also use T1027 Obfuscated Files or Information (63 threats), T1059 Command and Scripting Interpreter (60 threats), T1071 Application Layer Protocol (60 threats), T1036 Masquerading (53 threats), T1041 Exfiltration Over C2 Channel (53 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
36 tracked threat actors appear in the threats that use T1132; the most frequent are APT38 (3), APT-C-60 (2), APT28 (2), APT36 (2), APT37 (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1132.
Data sources
Telemetry that can reveal T1132, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
The 30 most recent of 70 tracked threats that use T1132.
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Techniquemedium
- Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…critical
- BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for…high
- BINDCLOAK Backdoor Campaign Targeting Middle East Government Entitieshigh
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…critical
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…critical
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resiliencehigh
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Accessmedium
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
- Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channelhigh
- Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates…high
- FakeGit Campaign: 7,600 Malicious GitHub Repos Push SmartLoader and StealC Malware via AI Tool Poisoning…high
- TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities…high
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)medium
- HTA-Based Cobalt Strike Downloader Script Analysis (CyberChef Deobfuscation)medium
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmationshigh
- APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Serviceshigh
- GhostCommit: PNG-Steganography Prompt Injection Bypasses AI Code Reviewers and Coding Agents to Exfiltrate…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing…high
- Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials…high
- Claude Cowork Sandbox Escape: RPC Parameter Bypass Enables Root Command Executionmedium
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchershigh
- ClickFix Campaign Deploying Potemkin Loader, RMMProject RAT, and EtherRAT - May 2026 Enterprise Compromisecritical
- Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling…high
- Indirect Setup-Error Prompt Abuse: Clean GitHub Repo + Failing Python Package + DNS TXT Payload Tricks AI…high
Detection coverage
Threadlinqs maintains 14 detection rules mapped to T1132 (SPL 4, KQL 5, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1132.001 Standard Encoding — 72 tracked threats
- T1132.002 Non-Standard Encoding — 11 tracked threats