# T1132.002 Non-Standard Encoding

> As of 2026-10-05, T1132.002 (Non-Standard Encoding) appears in 11 tracked threats, first reported 2026-05-15 and most recently 2026-09-20, with linked actors including Cavern Manticore, PolinRider, UNC1549; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 11 (1 critical, 8 high, 2 medium)
- **First seen:** 2026-05-15
- **Last seen:** 2026-09-20
- **Threat actors:** 4
- **Detection rules:** 19 (counts only; Blue tier and above)

## Key facts

- **ID:** T1132.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1132
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1132/002/

## Activity timeline

T1132.002 first appeared in tracked threats on 2026-05-15 and was most recently reported on 2026-09-20. The busiest month was 2026-07 with 5 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1132.002 Non-Standard Encoding is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1132 Data Encoding](https://intel.threadlinqs.com/technique/T1132). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 8 high, 2 medium.

Threats that use T1132.002 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (9 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (8 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1132.002; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [PolinRider](https://intel.threadlinqs.com/actor/PolinRider) (1), [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) (1), [Y2K Operators](https://intel.threadlinqs.com/actor/Y2K%20Operators) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1132.002.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1132.002, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [PolinRider](https://intel.threadlinqs.com/actor/PolinRider) — 1
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 1
- [Y2K Operators](https://intel.threadlinqs.com/actor/Y2K%20Operators) — 1

## Tracked threats

11 tracked threats use T1132.002.

- [PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography…](https://intel.threadlinqs.com/threat/TL-2026-2593) — medium — 2026-09-20
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2273) — high — 2026-09-01
- [Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to…](https://intel.threadlinqs.com/threat/TL-2026-2217) — high — 2026-08-29
- [D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…](https://intel.threadlinqs.com/threat/TL-2026-2147) — high — 2026-08-25
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [Joyfill npm Packages Compromised with Blockchain C2 Loader](https://intel.threadlinqs.com/threat/TL-2026-1771) — medium — 2026-07-30
- [LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container Runtime](https://intel.threadlinqs.com/threat/TL-2026-1367) — high — 2026-07-15
- [Millenium RAT v4: C++ Rewrite Fuels Y2K Operators' MaaS Campaign (62,289 Devices, 160+ Countries)](https://intel.threadlinqs.com/threat/TL-2026-1222) — high — 2026-07-11
- [Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…](https://intel.threadlinqs.com/threat/TL-2026-1137) — high — 2026-07-06
- [Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…](https://intel.threadlinqs.com/threat/TL-2026-0581) — high — 2026-05-25
- [Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via…](https://intel.threadlinqs.com/threat/TL-2026-0518) — critical — 2026-05-15

## Related CVEs

CVEs referenced by the tracked threats that use T1132.002, most frequent first.

- [CVE-2022-2586](https://intel.threadlinqs.com/cve/CVE-2022-2586)
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386)
- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487)
- [CVE-2023-4911](https://intel.threadlinqs.com/cve/CVE-2023-4911)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)

## Detection coverage

Threadlinqs maintains 19 detection rules mapped to T1132.002 (SPL 9, KQL 5, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

19 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1132 Data Encoding](https://intel.threadlinqs.com/technique/T1132) — 70 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1132.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
