Activity timeline
T1480 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 14 reports, and 63 of the 63 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1480 Execution Guardrails is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 63 of 2623 tracked threats (2.4%) to it; by severity that is 15 critical, 44 high, 4 medium.
Threats that use T1480 most often also use T1027 Obfuscated Files or Information (54 threats), T1082 System Information Discovery (40 threats), T1059 Command and Scripting Interpreter (39 threats), T1071 Application Layer Protocol (38 threats), T1005 Data from Local System (36 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
37 tracked threat actors appear in the threats that use T1480; the most frequent are APT38 (4), APT28 (3), Andariel (3), BlueDelta (3), Forest Blizzard (3).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1480.
Data sources
Telemetry that can reveal T1480, per MITRE ATT&CK.
- Command — Command Execution
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 63 tracked threats that use T1480.
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…high
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonationhigh
- Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2high
- StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitationcritical
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targetshigh
- Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…medium
- Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…high
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege…high
- QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Acceleratormedium
- BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for…high
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…critical
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Callshigh
- npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown'…high
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demandsmedium
- Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates…high
- TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities…high
- SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accountshigh
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag Imageshigh
- ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History…high
- SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operationshigh
- Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials…high
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A)high
- SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscationcritical
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2…high
- CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection…high
Detection coverage
Threadlinqs maintains 37 detection rules mapped to T1480 (SPL 11, KQL 12, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1480.001 Environmental Keying — 14 tracked threats
- T1480.002 Mutual Exclusion — 1 tracked threat