# T1189 Drive-by Compromise

> As of 2026-10-05, T1189 (Drive-by Compromise) appears in 276 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including APT38, Andariel, Lazarus Group; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 276 (62 critical, 188 high, 24 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 74
- **Detection rules:** 401 (counts only; Blue tier and above)

## Key facts

- **ID:** T1189
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1189/

## Activity timeline

T1189 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 111 reports, and 276 of the 276 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1189 Drive-by Compromise is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 276 of 2623 tracked threats (10.5%) to it; by severity that is 62 critical, 188 high, 24 medium.

Threats that use T1189 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (180 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (177 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (173 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (173 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (138 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

74 tracked threat actors appear in the threats that use T1189; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (10), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (8), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (8), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (7), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (7).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1189.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1048 Application Isolation and Sandboxing](https://attack.mitre.org/mitigations/M1048/)
- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1189, per MITRE ATT&CK.

- Application Log — Application Log Content
- File — File Creation
- Network Traffic — Network Connection Creation, Network Traffic Content
- Process — Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 10
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 8
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 8
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 7
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 7
- [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge) — 3
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 3
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 3
- [Mustard Tempest](https://intel.threadlinqs.com/actor/Mustard%20Tempest) — 3
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 3
- [SmartApeSG](https://intel.threadlinqs.com/actor/SmartApeSG) — 3
- [UNC6353](https://intel.threadlinqs.com/actor/UNC6353) — 3

## Tracked threats

The 30 most recent of 276 tracked threats that use T1189.

- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusion](https://intel.threadlinqs.com/threat/TL-2026-2326) — high — 2026-09-04
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…](https://intel.threadlinqs.com/threat/TL-2026-2152) — critical — 2026-08-26
- [NASA JPL AIT-GUI Missing Authentication and CSRF Flaw Allows Unauthenticated Spacecraft Command Injection…](https://intel.threadlinqs.com/threat/TL-2026-2081) — critical — 2026-08-20
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws](https://intel.threadlinqs.com/threat/TL-2026-1931) — critical — 2026-08-07
- [GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC…](https://intel.threadlinqs.com/threat/TL-2026-1827) — medium — 2026-08-03
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…](https://intel.threadlinqs.com/threat/TL-2026-1800) — high — 2026-07-31
- [North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…](https://intel.threadlinqs.com/threat/TL-2026-1797) — high — 2026-07-31
- [Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150…](https://intel.threadlinqs.com/threat/TL-2026-1795) — 2026-07-31
- [State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…](https://intel.threadlinqs.com/threat/TL-2026-1780) — critical — 2026-07-31
- [Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-1775) — high — 2026-07-30
- [Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape /…](https://intel.threadlinqs.com/threat/TL-2026-1770) — critical — 2026-07-30
- [GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs](https://intel.threadlinqs.com/threat/TL-2026-1768) — high — 2026-07-30
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29
- [Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)](https://intel.threadlinqs.com/threat/TL-2026-1732) — high — 2026-07-27
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications](https://intel.threadlinqs.com/threat/TL-2026-1698) — high — 2026-07-25
- [SourTrade Malvertising: ServiceWorker-Orchestrated In-Browser Assembly Builds a Unique Windows Executable…](https://intel.threadlinqs.com/threat/TL-2026-1696) — high — 2026-07-25
- [SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker…](https://intel.threadlinqs.com/threat/TL-2026-1687) — high — 2026-07-25
- [InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)](https://intel.threadlinqs.com/threat/TL-2026-1679) — high — 2026-07-25
- [Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-1676) — high — 2026-07-24
- [FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai](https://intel.threadlinqs.com/threat/TL-2026-1669) — high — 2026-07-24
- [ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…](https://intel.threadlinqs.com/threat/TL-2026-1664) — high — 2026-07-24
- [Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) Malware](https://intel.threadlinqs.com/threat/TL-2026-1662) — high — 2026-07-23

## Related CVEs

CVEs referenced by the tracked threats that use T1189, most frequent first.

- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32435](https://intel.threadlinqs.com/cve/CVE-2023-32435)
- [CVE-2023-41990](https://intel.threadlinqs.com/cve/CVE-2023-41990)
- [CVE-2023-41991](https://intel.threadlinqs.com/cve/CVE-2023-41991)
- [CVE-2023-41993](https://intel.threadlinqs.com/cve/CVE-2023-41993)
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000)
- [CVE-2026-10881](https://intel.threadlinqs.com/cve/CVE-2026-10881)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-3909](https://intel.threadlinqs.com/cve/CVE-2026-3909)
- [CVE-2026-3910](https://intel.threadlinqs.com/cve/CVE-2026-3910)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2026-5281](https://intel.threadlinqs.com/cve/CVE-2026-5281)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2008-4250](https://intel.threadlinqs.com/cve/CVE-2008-4250)
- [CVE-2009-1537](https://intel.threadlinqs.com/cve/CVE-2009-1537)
- [CVE-2009-3459](https://intel.threadlinqs.com/cve/CVE-2009-3459)
- [CVE-2010-0249](https://intel.threadlinqs.com/cve/CVE-2010-0249)
- [CVE-2010-0806](https://intel.threadlinqs.com/cve/CVE-2010-0806)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)

## Detection coverage

Threadlinqs maintains 401 detection rules mapped to T1189 (SPL 142, KQL 130, Sigma 129). Rule content is available to Blue tier accounts and above; this page shows counts only.

401 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1189
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
