Activity timeline
T1132.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 31 reports, and 72 of the 72 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1132.001 Standard Encoding is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1132 Data Encoding. Threadlinqs maps 72 of 2623 tracked threats (2.7%) to it; by severity that is 15 critical, 51 high, 6 medium.
Threats that use T1132.001 most often also use T1027 Obfuscated Files or Information (60 threats), T1071.001 Web Protocols (59 threats), T1036.005 Match Legitimate Resource Name or Location (53 threats), T1082 System Information Discovery (52 threats), T1140 Deobfuscate/Decode Files or Information (49 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
31 tracked threat actors appear in the threats that use T1132.001; the most frequent are APT38 (3), UAT-11795 (3), Cavern Manticore (2), MuddyWater (2), Sapphire Sleet (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1132.001.
Data sources
Telemetry that can reveal T1132.001, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
The 30 most recent of 72 tracked threats that use T1132.001.
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- CloudSyncD macOS Backdoor Delivered via Fake Zoom Installerhigh
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- Snowflake GitHub Actions Workflow Injection Exposes Internal Jira Credentialshigh
- D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…high
- Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detectionhigh
- SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…medium
- APT-C-60 Spear-Phishing Campaign Against Japanese Recruiters Using VHDX/LNK and SpyGlace Malwarehigh
- GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)critical
- Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Commandmedium
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber…high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker…high
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
- Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugalmedium
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaignhigh
- Fake Game Downloads Deliver Amatera Stealer via Ren'Py Loader, MSBuild Abuse, and EtherHiding C2high
- HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy…high
- HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph APIhigh
- Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…medium
Detection coverage
Threadlinqs maintains 153 detection rules mapped to T1132.001 (SPL 62, KQL 35, Sigma 56). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1132 Data Encoding — 70 tracked threats at the technique level.