# T1133 External Remote Services

> As of 2026-10-05, T1133 (External Remote Services) appears in 307 tracked threats, first reported 2026-01-25 and most recently 2026-10-03, with linked actors including Qilin, Static Tundra, LockBit; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 307 (128 critical, 136 high, 37 medium)
- **First seen:** 2026-01-25
- **Last seen:** 2026-10-03
- **Threat actors:** 86
- **Detection rules:** 416 (counts only; Blue tier and above)

## Key facts

- **ID:** T1133
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access, Persistence
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1133/

## Activity timeline

T1133 first appeared in tracked threats on 2026-01-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 111 reports, and 307 of the 307 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1133 External Remote Services is catalogued by MITRE ATT&CK under the Initial Access and Persistence tactics in the Enterprise matrix. Threadlinqs maps 307 of 2623 tracked threats (11.7%) to it; by severity that is 128 critical, 136 high, 37 medium.

Threats that use T1133 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (221 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (195 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (167 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (138 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (137 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

86 tracked threat actors appear in the threats that use T1133; the most frequent are [Qilin](https://intel.threadlinqs.com/actor/Qilin) (10), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (8), [LockBit](https://intel.threadlinqs.com/actor/LockBit) (6), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (6), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (6).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1133.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1133, per MITRE ATT&CK.

- Application Log — Application Log Content
- Logon Session — Logon Session Metadata
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 10
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 8
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 6
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 6
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 6
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 5
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 5
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 5
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 5
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 5
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 5
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 4

## Tracked threats

The 30 most recent of 307 tracked threats that use T1133.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369…](https://intel.threadlinqs.com/threat/TL-2026-2905) — high — 2026-10-02
- [WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)](https://intel.threadlinqs.com/threat/TL-2026-2813) — critical — 2026-09-30
- [Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…](https://intel.threadlinqs.com/threat/TL-2026-2805) — critical — 2026-09-30
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2688) — critical — 2026-09-27
- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…](https://intel.threadlinqs.com/threat/TL-2026-2678) — critical — 2026-09-26
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe…](https://intel.threadlinqs.com/threat/TL-2026-2640) — critical — 2026-09-24
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas](https://intel.threadlinqs.com/threat/TL-2026-2571) — high — 2026-09-18
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — medium — 2026-09-16
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2426) — high — 2026-09-10
- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…](https://intel.threadlinqs.com/threat/TL-2026-2420) — high — 2026-09-09
- [CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2415) — critical — 2026-09-09
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…](https://intel.threadlinqs.com/threat/TL-2026-2396) — critical — 2026-09-08
- [Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak](https://intel.threadlinqs.com/threat/TL-2026-2383) — high — 2026-09-07
- [CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2354) — critical — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…](https://intel.threadlinqs.com/threat/TL-2026-2325) — high — 2026-09-04
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01

## Related CVEs

CVEs referenced by the tracked threats that use T1133, most frequent first.

- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)

## Detection coverage

Threadlinqs maintains 416 detection rules mapped to T1133 (SPL 170, KQL 130, Sigma 114, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

416 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1133
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
