Threadlinqs IntelligenceStart free

ATT&CK techniqueImpact

T1496 Resource Hijacking

ImpactEnterprise

As of 2026-10-05, T1496 (Resource Hijacking) appears in 162 tracked threats, first reported 2026-02-02 and most recently 2026-09-30, with linked actors including TeamPCP, GlassWorm, GlassWorm Operator; it most often appears alongside T1059 (Command and Scripting Interpreter).

Tracked threats
16271 critical, 78 high, 13 medium
First seen
2026-02-02
Last seen
2026-09-30
Threat actors
32In the threats using it
Detection rules
178Blue tier and above

Data as of:

Activity timeline

T1496 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 33 reports, and 162 of the 162 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1496 Resource Hijacking is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 162 of 2623 tracked threats (6.2%) to it; by severity that is 71 critical, 78 high, 13 medium.

Threats that use T1496 most often also use T1059 Command and Scripting Interpreter (98 threats), T1027 Obfuscated Files or Information (95 threats), T1005 Data from Local System (93 threats), T1190 Exploit Public-Facing Application (93 threats), T1082 System Information Discovery (89 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1496; the most frequent are TeamPCP (7), GlassWorm (3), GlassWorm Operator (3), APT43 (2), INJ3CTOR3 (2).

Data sources

Telemetry that can reveal T1496, per MITRE ATT&CK.

  • Application Log — Application Log Content
  • Cloud Service — Cloud Service Modification
  • Command — Command Execution
  • File — File Creation
  • Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
  • Process — Process Creation
  • Sensor Health — Host Status

Threat actors using it

Tracked threats

The 30 most recent of 162 tracked threats that use T1496.

Detection coverage

Threadlinqs maintains 178 detection rules mapped to T1496 (SPL 57, KQL 54, Sigma 67). Rule content is available to Blue tier accounts and above; this page shows counts only.

178 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1496.001 Compute Hijacking — 2 tracked threats
  • T1496.002 Bandwidth Hijacking — 2 tracked threats
  • T1496.003 SMS Pumping — 0 tracked threats
  • T1496.004 Cloud Service Hijacking — 3 tracked threats