# T1480 Execution Guardrails

> As of 2026-10-05, T1480 (Execution Guardrails) appears in 63 tracked threats, first reported 2026-02-12 and most recently 2026-10-04, with linked actors including APT38, APT28, Andariel; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 63 (15 critical, 44 high, 4 medium)
- **First seen:** 2026-02-12
- **Last seen:** 2026-10-04
- **Threat actors:** 37
- **Detection rules:** 37 (counts only; Blue tier and above)

## Key facts

- **ID:** T1480
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1480/

## Activity timeline

T1480 first appeared in tracked threats on 2026-02-12 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 14 reports, and 63 of the 63 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1480 Execution Guardrails is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 63 of 2623 tracked threats (2.4%) to it; by severity that is 15 critical, 44 high, 4 medium.

Threats that use T1480 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (54 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (40 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (39 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (38 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (36 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

37 tracked threat actors appear in the threats that use T1480; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [APT28](https://intel.threadlinqs.com/actor/APT28) (3), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (3), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (3), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (3).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1480.

- [M1055 Do Not Mitigate](https://attack.mitre.org/mitigations/M1055/)

## Data sources

Telemetry that can reveal T1480, per MITRE ATT&CK.

- Command — Command Execution
- Process — Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 3
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 3
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 3
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 2
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 2
- [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) — 2
- [GlassWorm Operator](https://intel.threadlinqs.com/actor/GlassWorm%20Operator) — 2
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 2

## Tracked threats

The 30 most recent of 63 tracked threats that use T1480.

- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…](https://intel.threadlinqs.com/threat/TL-2026-2875) — high — 2026-10-03
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2](https://intel.threadlinqs.com/threat/TL-2026-2368) — high — 2026-09-07
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — critical — 2026-09-06
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…](https://intel.threadlinqs.com/threat/TL-2026-1983) — medium — 2026-08-11
- [Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…](https://intel.threadlinqs.com/threat/TL-2026-1918) — high — 2026-08-06
- [OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege…](https://intel.threadlinqs.com/threat/TL-2026-1887) — high — 2026-08-05
- [QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator](https://intel.threadlinqs.com/threat/TL-2026-1864) — medium — 2026-08-04
- [BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for…](https://intel.threadlinqs.com/threat/TL-2026-1858) — high — 2026-08-04
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls](https://intel.threadlinqs.com/threat/TL-2026-1720) — high — 2026-07-27
- [npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown'…](https://intel.threadlinqs.com/threat/TL-2026-1714) — high — 2026-07-27
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates…](https://intel.threadlinqs.com/threat/TL-2026-1606) — high — 2026-07-22
- [TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities…](https://intel.threadlinqs.com/threat/TL-2026-1562) — high — 2026-07-20
- [SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accounts](https://intel.threadlinqs.com/threat/TL-2026-1514) — high — 2026-07-19
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag Images](https://intel.threadlinqs.com/threat/TL-2026-1452) — high — 2026-07-17
- [ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History…](https://intel.threadlinqs.com/threat/TL-2026-1289) — high — 2026-07-14
- [SystemBC (Coroxy / DroxiDat) Malware: Multi-Purpose SOCKS5/Tor Proxy Backdoor Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1227) — high — 2026-07-11
- [Infostealer Campaigns (Lumma, RedLine, StealC) Harvesting AI Coding Agent and Developer Platform Credentials…](https://intel.threadlinqs.com/threat/TL-2026-1169) — high — 2026-07-10
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A)](https://intel.threadlinqs.com/threat/TL-2026-1033) — high — 2026-07-01
- [SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1005) — critical — 2026-06-30
- [Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2…](https://intel.threadlinqs.com/threat/TL-2026-0968) — high — 2026-06-28
- [CVE-2026-50656: RoguePlanet Microsoft Defender Zero-Day Local Privilege Escalation (Malware Protection…](https://intel.threadlinqs.com/threat/TL-2026-0835) — high — 2026-06-17

## Related CVEs

CVEs referenced by the tracked threats that use T1480, most frequent first.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2024-21338](https://intel.threadlinqs.com/cve/CVE-2024-21338)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-7971](https://intel.threadlinqs.com/cve/CVE-2024-7971)
- [CVE-2025-15556](https://intel.threadlinqs.com/cve/CVE-2025-15556)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)
- [CVE-2025-69263](https://intel.threadlinqs.com/cve/CVE-2025-69263)
- [CVE-2025-69264](https://intel.threadlinqs.com/cve/CVE-2025-69264)
- [CVE-2026-1281](https://intel.threadlinqs.com/cve/CVE-2026-1281)
- [CVE-2026-1340](https://intel.threadlinqs.com/cve/CVE-2026-1340)

## Detection coverage

Threadlinqs maintains 37 detection rules mapped to T1480 (SPL 11, KQL 12, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.

37 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1480.001 Environmental Keying](https://intel.threadlinqs.com/technique/T1480.001) — 14 tracked threats
- T1480.002 Mutual Exclusion — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1480
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
