# T1132 Data Encoding

> As of 2026-10-05, T1132 (Data Encoding) appears in 70 tracked threats, first reported 2026-02-02 and most recently 2026-09-11, with linked actors including APT38, APT-C-60, APT28; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 70 (12 critical, 53 high, 5 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-11
- **Threat actors:** 36
- **Detection rules:** 14 (counts only; Blue tier and above)

## Key facts

- **ID:** T1132
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1132/

## Activity timeline

T1132 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-11. The busiest month was 2026-06 with 23 reports, and 70 of the 70 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1132 Data Encoding is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 70 of 2623 tracked threats (2.7%) to it; by severity that is 12 critical, 53 high, 5 medium.

Threats that use T1132 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (63 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (60 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (60 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (53 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (53 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

36 tracked threat actors appear in the threats that use T1132; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (2), [APT36](https://intel.threadlinqs.com/actor/APT36) (2), [APT37](https://intel.threadlinqs.com/actor/APT37) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1132.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1132, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Calypso](https://intel.threadlinqs.com/actor/Calypso) — 2
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 2
- [Harvester](https://intel.threadlinqs.com/actor/Harvester) — 2
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2

## Tracked threats

The 30 most recent of 70 tracked threats that use T1132.

- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [Critical Microsoft Copilot CoSnitch Vulnerability (CVE-2026-24301) Enabled One-Click Data Theft From…](https://intel.threadlinqs.com/threat/TL-2026-2065) — critical — 2026-08-19
- [BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for…](https://intel.threadlinqs.com/threat/TL-2026-1858) — high — 2026-08-04
- [BINDCLOAK Backdoor Campaign Targeting Middle East Government Entities](https://intel.threadlinqs.com/threat/TL-2026-1844) — high — 2026-08-03
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29
- [Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…](https://intel.threadlinqs.com/threat/TL-2026-1760) — critical — 2026-07-29
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — medium — 2026-07-27
- [TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2](https://intel.threadlinqs.com/threat/TL-2026-1684) — high — 2026-07-23
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channel](https://intel.threadlinqs.com/threat/TL-2026-1656) — high — 2026-07-23
- [Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates…](https://intel.threadlinqs.com/threat/TL-2026-1606) — high — 2026-07-22
- [FakeGit Campaign: 7,600 Malicious GitHub Repos Push SmartLoader and StealC Malware via AI Tool Poisoning…](https://intel.threadlinqs.com/threat/TL-2026-1595) — high — 2026-07-21
- [TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities…](https://intel.threadlinqs.com/threat/TL-2026-1562) — high — 2026-07-20
- [HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API](https://intel.threadlinqs.com/threat/TL-2026-1555) — high — 2026-07-20
- [Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)](https://intel.threadlinqs.com/threat/TL-2026-1487) — medium — 2026-07-18
- [HTA-Based Cobalt Strike Downloader Script Analysis (CyberChef Deobfuscation)](https://intel.threadlinqs.com/threat/TL-2026-1482) — medium — 2026-07-18
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmations](https://intel.threadlinqs.com/threat/TL-2026-1252) — high — 2026-07-13
- [APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Services](https://intel.threadlinqs.com/threat/TL-2026-1249) — high — 2026-07-13
- [GhostCommit: PNG-Steganography Prompt Injection Bypasses AI Code Reviewers and Coding Agents to Exfiltrate…](https://intel.threadlinqs.com/threat/TL-2026-1231) — high — 2026-07-11
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [GNU Guix 'guix substitute' and 'guix pull' Vulnerabilities Enable Arbitrary File Write, Metadata Spoofing…](https://intel.threadlinqs.com/threat/TL-2026-1179) — high — 2026-07-10
- [Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials…](https://intel.threadlinqs.com/threat/TL-2026-1169) — high — 2026-07-10
- [Claude Cowork Sandbox Escape: RPC Parameter Bypass Enables Root Command Execution](https://intel.threadlinqs.com/threat/TL-2026-1115) — medium — 2026-07-02
- [ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1125) — high — 2026-07-01
- [ClickFix Campaign Deploying Potemkin Loader, RMMProject RAT, and EtherRAT - May 2026 Enterprise Compromise](https://intel.threadlinqs.com/threat/TL-2026-0972) — critical — 2026-06-28
- [Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling…](https://intel.threadlinqs.com/threat/TL-2026-0967) — high — 2026-06-28
- [Indirect Setup-Error Prompt Abuse: Clean GitHub Repo + Failing Python Package + DNS TXT Payload Tricks AI…](https://intel.threadlinqs.com/threat/TL-2026-0955) — high — 2026-06-27

## Related CVEs

CVEs referenced by the tracked threats that use T1132, most frequent first.

- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2019-11510](https://intel.threadlinqs.com/cve/CVE-2019-11510)
- [CVE-2019-11539](https://intel.threadlinqs.com/cve/CVE-2019-11539)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-5902](https://intel.threadlinqs.com/cve/CVE-2020-5902)
- [CVE-2020-8243](https://intel.threadlinqs.com/cve/CVE-2020-8243)
- [CVE-2021-22893](https://intel.threadlinqs.com/cve/CVE-2021-22893)
- [CVE-2021-22894](https://intel.threadlinqs.com/cve/CVE-2021-22894)
- [CVE-2021-22900](https://intel.threadlinqs.com/cve/CVE-2021-22900)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-36899](https://intel.threadlinqs.com/cve/CVE-2023-36899)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2025-0282](https://intel.threadlinqs.com/cve/CVE-2025-0282)
- [CVE-2025-22224](https://intel.threadlinqs.com/cve/CVE-2025-22224)
- [CVE-2025-22225](https://intel.threadlinqs.com/cve/CVE-2025-22225)
- [CVE-2025-22226](https://intel.threadlinqs.com/cve/CVE-2025-22226)
- [CVE-2025-32975](https://intel.threadlinqs.com/cve/CVE-2025-32975)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64328](https://intel.threadlinqs.com/cve/CVE-2025-64328)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)

## Detection coverage

Threadlinqs maintains 14 detection rules mapped to T1132 (SPL 4, KQL 5, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

14 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1132.001 Standard Encoding](https://intel.threadlinqs.com/technique/T1132.001) — 72 tracked threats
- [T1132.002 Non-Standard Encoding](https://intel.threadlinqs.com/technique/T1132.002) — 11 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1132
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
