Activity timeline
T1205 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 10 reports, and 22 of the 22 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1205 Traffic Signaling is catalogued by MITRE ATT&CK under the Persistence and Stealth (formerly Defense Evasion) and Command and Control tactics in the Enterprise matrix. Threadlinqs maps 22 of 2623 tracked threats (0.8%) to it; by severity that is 12 critical, 8 high, 1 medium.
Threats that use T1205 most often also use T1059 Command and Scripting Interpreter (14 threats), T1190 Exploit Public-Facing Application (14 threats), T1041 Exfiltration Over C2 Channel (13 threats), T1027 Obfuscated Files or Information (12 threats), T1036 Masquerading (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
14 tracked threat actors appear in the threats that use T1205; the most frequent are Static Tundra (2), APT28 (1), APT38 (1), Black Basta (1), Conti (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1205.
Data sources
Telemetry that can reveal T1205, per MITRE ATT&CK.
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
- Process — Process Creation
Threat actors using it
Tracked threats
22 tracked threats use T1205.
- SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loadingmedium
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail…high
- Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig'…high
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoorcritical
- Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed…high
- CISA Adds CVE-2026-46817 (Oracle E-Business Suite Payments Unauthenticated Takeover) and CVE-2023-4346 (KNX…critical
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…critical
- Daxin Returns: China-Linked Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Backdoorcritical
- AsyncAPI npm Supply Chain Compromise: GitHub Actions pull_request_target Exploit Deploys Miasma RAT to…critical
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…critical
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…high
- Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)
- FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) &…high
- Firestarter Malware Persists on Cisco ASA/Firepower Through Firmware Updates (CVE-2025-20333…critical
- VoidLink Linux Rootkit Framework — eBPF + LKM Hybrid Persistence with ICMP C2high
- UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware…critical
- Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769)critical
- RESURGE Passive Rootkit — Ivanti Connect Secure CVE-2025-0282 Exploitation, CRC32 TLS Fingerprint C2, Covert…critical
- Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel…high
- IPIDEA Residential Proxy Botnet Disruption by Googlehigh
Detection coverage
Threadlinqs maintains 18 detection rules mapped to T1205 (SPL 7, KQL 4, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1205.001 Port Knocking — 2 tracked threats
- T1205.002 Socket Filters — 3 tracked threats