# T1482 Domain Trust Discovery

> As of 2026-10-05, T1482 (Domain Trust Discovery) appears in 90 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including Akira, LockBit, Storm-1567; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 90 (28 critical, 55 high, 5 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 51
- **Detection rules:** 64 (counts only; Blue tier and above)

## Key facts

- **ID:** T1482
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1482/

## Activity timeline

T1482 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 35 reports, and 90 of the 90 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1482 Domain Trust Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 90 of 2623 tracked threats (3.4%) to it; by severity that is 28 critical, 55 high, 5 medium.

Threats that use T1482 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (49 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (48 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (47 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (45 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (41 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

51 tracked threat actors appear in the threats that use T1482; the most frequent are [Akira](https://intel.threadlinqs.com/actor/Akira) (4), [LockBit](https://intel.threadlinqs.com/actor/LockBit) (4), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (4), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (4), [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) (3).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1482.

- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1482, per MITRE ATT&CK.

- Command — Command Execution
- Network Traffic — Network Traffic Content
- Process — OS API Execution, Process Creation
- Script — Script Execution

## Threat actors using it

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 4
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 4
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 4
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 4
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 3
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 2
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 2

## Tracked threats

The 30 most recent of 90 tracked threats that use T1482.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat](https://intel.threadlinqs.com/threat/TL-2026-2702) — critical — 2026-09-26
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…](https://intel.threadlinqs.com/threat/TL-2026-2304) — high — 2026-09-03
- [TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…](https://intel.threadlinqs.com/threat/TL-2026-2265) — critical — 2026-08-31
- [TerminalFix Campaign Deploys Custom Python Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA, DLL…](https://intel.threadlinqs.com/threat/TL-2026-2260) — high — 2026-08-31
- [TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers DLL Sideloading and Python Reverse-Tunnel…](https://intel.threadlinqs.com/threat/TL-2026-2237) — high — 2026-08-30
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked…](https://intel.threadlinqs.com/threat/TL-2026-2199) — high — 2026-08-29
- [TerminalFix Campaign: ClickFix-Style Lure Deploys Steganographic DLL Sideload and Custom Reverse Tunnel in…](https://intel.threadlinqs.com/threat/TL-2026-2198) — high — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69%…](https://intel.threadlinqs.com/threat/TL-2026-1983) — medium — 2026-08-11
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…](https://intel.threadlinqs.com/threat/TL-2026-1917) — high — 2026-08-06
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops…](https://intel.threadlinqs.com/threat/TL-2026-1680) — critical — 2026-07-25
- [BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1678) — high — 2026-07-24
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23
- [Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network Detection](https://intel.threadlinqs.com/threat/TL-2026-1661) — high — 2026-07-23
- [Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert Channel](https://intel.threadlinqs.com/threat/TL-2026-1656) — high — 2026-07-23
- [DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)](https://intel.threadlinqs.com/threat/TL-2026-1647) — high — 2026-07-23
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…](https://intel.threadlinqs.com/threat/TL-2026-1551) — high — 2026-07-19
- [GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG…](https://intel.threadlinqs.com/threat/TL-2026-1508) — high — 2026-07-19
- [Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…](https://intel.threadlinqs.com/threat/TL-2026-1496) — high — 2026-07-18

## Related CVEs

CVEs referenced by the tracked threats that use T1482, most frequent first.

- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2026-23666](https://intel.threadlinqs.com/cve/CVE-2026-23666)
- [CVE-2026-32157](https://intel.threadlinqs.com/cve/CVE-2026-32157)
- [CVE-2026-32190](https://intel.threadlinqs.com/cve/CVE-2026-32190)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-33114](https://intel.threadlinqs.com/cve/CVE-2026-33114)
- [CVE-2026-33115](https://intel.threadlinqs.com/cve/CVE-2026-33115)
- [CVE-2026-33824](https://intel.threadlinqs.com/cve/CVE-2026-33824)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-33826](https://intel.threadlinqs.com/cve/CVE-2026-33826)
- [CVE-2026-33827](https://intel.threadlinqs.com/cve/CVE-2026-33827)
- [CVE-2026-41089](https://intel.threadlinqs.com/cve/CVE-2026-41089)
- [CVE-2012-1823](https://intel.threadlinqs.com/cve/CVE-2012-1823)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2017-11317](https://intel.threadlinqs.com/cve/CVE-2017-11317)
- [CVE-2017-3506](https://intel.threadlinqs.com/cve/CVE-2017-3506)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)

## Detection coverage

Threadlinqs maintains 64 detection rules mapped to T1482 (SPL 22, KQL 26, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.

64 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1482
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
