# T1199 Trusted Relationship

> As of 2026-10-05, T1199 (Trusted Relationship) appears in 319 tracked threats, first reported 2026-01-27 and most recently 2026-10-02, with linked actors including TeamPCP, ShinyHunters, APT38; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 319 (107 critical, 166 high, 37 medium, 3 low)
- **First seen:** 2026-01-27
- **Last seen:** 2026-10-02
- **Threat actors:** 107
- **Detection rules:** 366 (counts only; Blue tier and above)

## Key facts

- **ID:** T1199
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1199/

## Activity timeline

T1199 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 128 reports, and 319 of the 319 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1199 Trusted Relationship is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 319 of 2623 tracked threats (12.2%) to it; by severity that is 107 critical, 166 high, 37 medium, 3 low.

Threats that use T1199 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (158 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (158 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (151 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (136 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (134 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

107 tracked threat actors appear in the threats that use T1199; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (24), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (17), [APT38](https://intel.threadlinqs.com/actor/APT38) (8), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (8), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (8).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1199.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)

## Data sources

Telemetry that can reveal T1199, per MITRE ATT&CK.

- Application Log — Application Log Content
- Logon Session — Logon Session Creation, Logon Session Metadata
- Network Traffic — Network Traffic Content

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 24
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 17
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 8
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 8
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 8
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 6
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 6
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 6
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 5
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 5
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 5

## Tracked threats

The 30 most recent of 319 tracked threats that use T1199.

- [Frontline Education data breach via exploited third-party software vulnerability exposes school district…](https://intel.threadlinqs.com/threat/TL-2026-2844) — high — 2026-10-02
- [Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and…](https://intel.threadlinqs.com/threat/TL-2026-2821) — medium — 2026-10-01
- [Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles](https://intel.threadlinqs.com/threat/TL-2026-2799) — medium — 2026-09-30
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — high — 2026-09-26
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize…](https://intel.threadlinqs.com/threat/TL-2026-2629) — critical — 2026-09-23
- [BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection](https://intel.threadlinqs.com/threat/TL-2026-2610) — medium — 2026-09-21
- [Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel](https://intel.threadlinqs.com/threat/TL-2026-2609) — high — 2026-09-21
- [GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaign](https://intel.threadlinqs.com/threat/TL-2026-2588) — high — 2026-09-20
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [Revolut Discloses Data Breach via Government-Impersonation Social Engineering, Exposing Customer Financial…](https://intel.threadlinqs.com/threat/TL-2026-2498) — high — 2026-09-14
- [Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively…](https://intel.threadlinqs.com/threat/TL-2026-2486) — critical — 2026-09-13
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…](https://intel.threadlinqs.com/threat/TL-2026-2466) — critical — 2026-09-12
- [Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi…](https://intel.threadlinqs.com/threat/TL-2026-2446) — high — 2026-09-11
- [Trezor, BitBox, and CoinTracking Subscribers Targeted by Phishing After Brevo SAML SSO…](https://intel.threadlinqs.com/threat/TL-2026-2445) — high — 2026-09-11
- [Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)](https://intel.threadlinqs.com/threat/TL-2026-2432) — medium — 2026-09-10
- [Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During…](https://intel.threadlinqs.com/threat/TL-2026-2411) — critical — 2026-09-09
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV…](https://intel.threadlinqs.com/threat/TL-2026-2210) — critical — 2026-08-29
- [Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBI](https://intel.threadlinqs.com/threat/TL-2026-2186) — critical — 2026-08-28
- [AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627)](https://intel.threadlinqs.com/threat/TL-2026-2146) — high — 2026-08-25
- [GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)](https://intel.threadlinqs.com/threat/TL-2026-2130) — critical — 2026-08-24
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2125) — high — 2026-08-23
- [Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge](https://intel.threadlinqs.com/threat/TL-2026-2110) — medium — 2026-08-22
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software…](https://intel.threadlinqs.com/threat/TL-2026-2106) — medium — 2026-08-21
- [Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-2054) — high — 2026-08-18
- [ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of…](https://intel.threadlinqs.com/threat/TL-2026-2026) — high — 2026-08-16

## Related CVEs

CVEs referenced by the tracked threats that use T1199, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-30154](https://intel.threadlinqs.com/cve/CVE-2025-30154)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-25592](https://intel.threadlinqs.com/cve/CVE-2026-25592)
- [CVE-2026-26030](https://intel.threadlinqs.com/cve/CVE-2026-26030)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-48558](https://intel.threadlinqs.com/cve/CVE-2026-48558)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)

## Detection coverage

Threadlinqs maintains 366 detection rules mapped to T1199 (SPL 131, KQL 120, Sigma 115). Rule content is available to Blue tier accounts and above; this page shows counts only.

366 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1199
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
