# T1135 Network Share Discovery

> As of 2026-10-05, T1135 (Network Share Discovery) appears in 85 tracked threats, first reported 2026-02-02 and most recently 2026-09-27, with linked actors including Cavern Manticore, ALPHV, BlackCat; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 85 (17 critical, 59 high, 9 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-27
- **Threat actors:** 46
- **Detection rules:** 64 (counts only; Blue tier and above)

## Key facts

- **ID:** T1135
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1135/

## Activity timeline

T1135 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 39 reports, and 85 of the 85 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1135 Network Share Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 85 of 2623 tracked threats (3.2%) to it; by severity that is 17 critical, 59 high, 9 medium.

Threats that use T1135 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (55 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (53 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (51 threats), [T1486 Data Encrypted for Impact](https://intel.threadlinqs.com/technique/T1486) (50 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (48 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

46 tracked threat actors appear in the threats that use T1135; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (6), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (3), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (3), [Chaos](https://intel.threadlinqs.com/actor/Chaos) (3), [DevMan](https://intel.threadlinqs.com/actor/DevMan) (3).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1135.

- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)

## Data sources

Telemetry that can reveal T1135, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 6
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 3
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 3
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 3
- [DevMan](https://intel.threadlinqs.com/actor/DevMan) — 3
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 3
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 3
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 2
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 2
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 2

## Tracked threats

The 30 most recent of 85 tracked threats that use T1135.

- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms](https://intel.threadlinqs.com/threat/TL-2026-2127) — high — 2026-08-24
- [Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…](https://intel.threadlinqs.com/threat/TL-2026-2103) — high — 2026-08-21
- [Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script Relay](https://intel.threadlinqs.com/threat/TL-2026-2053) — high — 2026-08-17
- [Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)](https://intel.threadlinqs.com/threat/TL-2026-2045) — high — 2026-08-17
- [Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…](https://intel.threadlinqs.com/threat/TL-2026-1983) — medium — 2026-08-11
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…](https://intel.threadlinqs.com/threat/TL-2026-1917) — high — 2026-08-06
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused](https://intel.threadlinqs.com/threat/TL-2026-1683) — medium — 2026-07-25
- [DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops…](https://intel.threadlinqs.com/threat/TL-2026-1680) — critical — 2026-07-25
- [ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…](https://intel.threadlinqs.com/threat/TL-2026-1664) — high — 2026-07-24
- [TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2](https://intel.threadlinqs.com/threat/TL-2026-1684) — high — 2026-07-23
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channel](https://intel.threadlinqs.com/threat/TL-2026-1656) — high — 2026-07-23
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan…](https://intel.threadlinqs.com/threat/TL-2026-1639) — high — 2026-07-22
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [HOLLOWGRAPH: Microsoft 365 Calendar-Based C2 Malware Targeting Israeli Organizations (Cavern Manticore)](https://intel.threadlinqs.com/threat/TL-2026-1567) — high — 2026-07-20
- [HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API](https://intel.threadlinqs.com/threat/TL-2026-1555) — high — 2026-07-20
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo\[.\]org…](https://intel.threadlinqs.com/threat/TL-2026-1483) — high — 2026-07-18

## Related CVEs

CVEs referenced by the tracked threats that use T1135, most frequent first.

- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)

## Detection coverage

Threadlinqs maintains 64 detection rules mapped to T1135 (SPL 23, KQL 24, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

64 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1135
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
