# T1132.001 Standard Encoding

> As of 2026-10-05, T1132.001 (Standard Encoding) appears in 72 tracked threats, first reported 2026-02-16 and most recently 2026-10-03, with linked actors including APT38, UAT-11795, Cavern Manticore; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 72 (15 critical, 51 high, 6 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-03
- **Threat actors:** 31
- **Detection rules:** 153 (counts only; Blue tier and above)

## Key facts

- **ID:** T1132.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1132
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1132/001/

## Activity timeline

T1132.001 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 31 reports, and 72 of the 72 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1132.001 Standard Encoding is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1132 Data Encoding](https://intel.threadlinqs.com/technique/T1132). Threadlinqs maps 72 of 2623 tracked threats (2.7%) to it; by severity that is 15 critical, 51 high, 6 medium.

Threats that use T1132.001 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (60 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (59 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (53 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (52 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (49 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

31 tracked threat actors appear in the threats that use T1132.001; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) (3), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (2), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1132.001.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1132.001, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 2
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 2
- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 1
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1

## Tracked threats

The 30 most recent of 72 tracked threats that use T1132.001.

- [Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…](https://intel.threadlinqs.com/threat/TL-2026-2868) — high — 2026-10-03
- [CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https://intel.threadlinqs.com/threat/TL-2026-2840) — high — 2026-10-02
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…](https://intel.threadlinqs.com/threat/TL-2026-2615) — medium — 2026-09-22
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [Snowflake GitHub Actions Workflow Injection Exposes Internal Jira Credentials](https://intel.threadlinqs.com/threat/TL-2026-2189) — high — 2026-08-28
- [D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…](https://intel.threadlinqs.com/threat/TL-2026-2147) — high — 2026-08-25
- [Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detection](https://intel.threadlinqs.com/threat/TL-2026-2145) — high — 2026-08-25
- [SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…](https://intel.threadlinqs.com/threat/TL-2026-2136) — medium — 2026-08-24
- [APT-C-60 Spear-Phishing Campaign Against Japanese Recruiters Using VHDX/LNK and SpyGlace Malware](https://intel.threadlinqs.com/threat/TL-2026-2134) — high — 2026-08-24
- [GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)](https://intel.threadlinqs.com/threat/TL-2026-2130) — critical — 2026-08-24
- [Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command](https://intel.threadlinqs.com/threat/TL-2026-1813) — medium — 2026-08-02
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber…](https://intel.threadlinqs.com/threat/TL-2026-2747) — high — 2026-07-30
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker…](https://intel.threadlinqs.com/threat/TL-2026-1687) — high — 2026-07-25
- [TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)](https://intel.threadlinqs.com/threat/TL-2026-1651) — high — 2026-07-23
- [Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugal](https://intel.threadlinqs.com/threat/TL-2026-1619) — medium — 2026-07-22
- [ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign](https://intel.threadlinqs.com/threat/TL-2026-1570) — high — 2026-07-20
- [Fake Game Downloads Deliver Amatera Stealer via Ren'Py Loader, MSBuild Abuse, and EtherHiding C2](https://intel.threadlinqs.com/threat/TL-2026-1569) — high — 2026-07-20
- [HollowGraph Malware Abuses Microsoft Graph API and M365 Calendar Events (Future-Dated 2050) for Stealthy…](https://intel.threadlinqs.com/threat/TL-2026-1561) — high — 2026-07-20
- [HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API](https://intel.threadlinqs.com/threat/TL-2026-1555) — high — 2026-07-20
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18

## Related CVEs

CVEs referenced by the tracked threats that use T1132.001, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-30154](https://intel.threadlinqs.com/cve/CVE-2025-30154)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-88773](https://intel.threadlinqs.com/cve/CVE-2026-88773)
- [CVE-2026-88774](https://intel.threadlinqs.com/cve/CVE-2026-88774)
- [CVE-2026-88775](https://intel.threadlinqs.com/cve/CVE-2026-88775)
- [CVE-2026-88776](https://intel.threadlinqs.com/cve/CVE-2026-88776)
- [CVE-2026-88777](https://intel.threadlinqs.com/cve/CVE-2026-88777)
- [CVE-2026-88778](https://intel.threadlinqs.com/cve/CVE-2026-88778)

## Detection coverage

Threadlinqs maintains 153 detection rules mapped to T1132.001 (SPL 62, KQL 35, Sigma 56). Rule content is available to Blue tier accounts and above; this page shows counts only.

153 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1132 Data Encoding](https://intel.threadlinqs.com/technique/T1132) — 70 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1132.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
