Activity timeline
T1189 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 111 reports, and 276 of the 276 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1189 Drive-by Compromise is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 276 of 2623 tracked threats (10.5%) to it; by severity that is 62 critical, 188 high, 24 medium.
Threats that use T1189 most often also use T1005 Data from Local System (180 threats), T1082 System Information Discovery (177 threats), T1027 Obfuscated Files or Information (173 threats), T1041 Exfiltration Over C2 Channel (173 threats), T1105 Ingress Tool Transfer (138 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
74 tracked threat actors appear in the threats that use T1189; the most frequent are APT38 (10), Andariel (8), Lazarus Group (8), Sapphire Sleet (7), Stardust Chollima (7).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1189.
Data sources
Telemetry that can reveal T1189, per MITRE ATT&CK.
- Application Log — Application Log Content
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Content
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 276 tracked threats that use T1189.
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malwarecritical
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malwarehigh
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…critical
- NASA JPL AIT-GUI Missing Authentication and CSRF Flaw Allows Unauthenticated Spacecraft Command Injection…critical
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targetshigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flawscritical
- GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC…medium
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…high
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…high
- Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150…
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…critical
- Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…high
- Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape /…critical
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPshigh
- Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…critical
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…critical
- Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)high
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applicationshigh
- SourTrade Malvertising: ServiceWorker-Orchestrated In-Browser Assembly Builds a Unique Windows Executable…high
- SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker…high
- InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)high
- Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…high
- FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.aihigh
- ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…high
- Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) Malwarehigh
Detection coverage
Threadlinqs maintains 401 detection rules mapped to T1189 (SPL 142, KQL 130, Sigma 129). Rule content is available to Blue tier accounts and above; this page shows counts only.