# T1210 Exploitation of Remote Services

> As of 2026-10-05, T1210 (Exploitation of Remote Services) appears in 223 tracked threats, first reported 2026-01-25 and most recently 2026-09-27, with linked actors including Static Tundra, FSB Center 16, JADEPUFFER; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 223 (141 critical, 64 high, 15 medium)
- **First seen:** 2026-01-25
- **Last seen:** 2026-09-27
- **Threat actors:** 40
- **Detection rules:** 301 (counts only; Blue tier and above)

## Key facts

- **ID:** T1210
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1210/

## Activity timeline

T1210 first appeared in tracked threats on 2026-01-25 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 115 reports, and 223 of the 223 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1210 Exploitation of Remote Services is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 223 of 2623 tracked threats (8.5%) to it; by severity that is 141 critical, 64 high, 15 medium.

Threats that use T1210 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (204 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (160 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (154 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (135 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (118 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

40 tracked threat actors appear in the threats that use T1210; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (5), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (3), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (3), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (3), [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) (3).

## Mitigations

MITRE ATT&CK lists 8 mitigations for T1210.

- [M1016 Vulnerability Scanning](https://attack.mitre.org/mitigations/M1016/)
- [M1019 Threat Intelligence Program](https://attack.mitre.org/mitigations/M1019/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)
- [M1048 Application Isolation and Sandboxing](https://attack.mitre.org/mitigations/M1048/)
- [M1050 Exploit Protection](https://attack.mitre.org/mitigations/M1050/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1210, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 5
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 3
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 3
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 3
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 3
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2
- [NetNut](https://intel.threadlinqs.com/actor/NetNut) — 2
- [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) — 2
- [UTA0533](https://intel.threadlinqs.com/actor/UTA0533) — 2
- [APT27](https://intel.threadlinqs.com/actor/APT27) — 1
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1

## Tracked threats

The 30 most recent of 223 tracked threats that use T1210.

- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — critical — 2026-09-19
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — critical — 2026-09-14
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…](https://intel.threadlinqs.com/threat/TL-2026-2314) — critical — 2026-09-03
- [UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…](https://intel.threadlinqs.com/threat/TL-2026-2196) — critical — 2026-08-28
- [Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-2162) — critical — 2026-08-27
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…](https://intel.threadlinqs.com/threat/TL-2026-2107) — critical — 2026-08-22
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1985) — critical — 2026-08-11
- [SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1984) — critical — 2026-08-11
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- [CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1812) — critical — 2026-08-01
- [Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1807) — high — 2026-08-01
- [CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Database](https://intel.threadlinqs.com/threat/TL-2026-1802) — critical — 2026-07-31
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…](https://intel.threadlinqs.com/threat/TL-2026-1790) — critical — 2026-07-31
- [CosmosEscape: Platform-Wide Cosmos Master Key Exposure via Gremlin API Sandbox Escape in Azure Cosmos DB](https://intel.threadlinqs.com/threat/TL-2026-1784) — critical — 2026-07-31
- [CVE-2026-66723: Missing Authorization in MWDB Core Remote Instances Proxy API](https://intel.threadlinqs.com/threat/TL-2026-1821) — high — 2026-07-29
- [Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)](https://intel.threadlinqs.com/threat/TL-2026-1767) — critical — 2026-07-29
- [Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…](https://intel.threadlinqs.com/threat/TL-2026-1764) — critical — 2026-07-29
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [CVE-2026-6516: Unauthenticated Remote Code Execution in ManageEngine ADAudit Plus (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1756) — critical — 2026-07-29
- [CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-1755) — critical — 2026-07-29
- [US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…](https://intel.threadlinqs.com/threat/TL-2026-1751) — high — 2026-07-29
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28

## Related CVEs

CVEs referenced by the tracked threats that use T1210, most frequent first.

- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-33824](https://intel.threadlinqs.com/cve/CVE-2026-33824)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2026-33827](https://intel.threadlinqs.com/cve/CVE-2026-33827)
- [CVE-2026-41089](https://intel.threadlinqs.com/cve/CVE-2026-41089)
- [CVE-2026-48276](https://intel.threadlinqs.com/cve/CVE-2026-48276)
- [CVE-2026-48277](https://intel.threadlinqs.com/cve/CVE-2026-48277)
- [CVE-2026-48281](https://intel.threadlinqs.com/cve/CVE-2026-48281)
- [CVE-2026-48282](https://intel.threadlinqs.com/cve/CVE-2026-48282)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)

## Detection coverage

Threadlinqs maintains 301 detection rules mapped to T1210 (SPL 91, KQL 101, Sigma 109). Rule content is available to Blue tier accounts and above; this page shows counts only.

301 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1210
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
