Activity timeline
T1518.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 51 reports, and 114 of the 114 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1518.001 Security Software Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of T1518 Software Discovery. Threadlinqs maps 114 of 2623 tracked threats (4.3%) to it; by severity that is 13 critical, 89 high, 12 medium.
Threats that use T1518.001 most often also use T1082 System Information Discovery (91 threats), T1071.001 Web Protocols (77 threats), T1027 Obfuscated Files or Information (73 threats), T1036.005 Match Legitimate Resource Name or Location (70 threats), T1685 Disable or Modify Tools (70 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
48 tracked threat actors appear in the threats that use T1518.001; the most frequent are APT38 (3), Sapphire Sleet (3), SideCopy (3), Stardust Chollima (3), UAT-11795 (3).
Data sources
Telemetry that can reveal T1518.001, per MITRE ATT&CK.
- Command — Command Execution
- Firewall — Firewall Enumeration, Firewall Metadata
- Process — OS API Execution, Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 114 tracked threats that use T1518.001.
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…critical
- BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustionmedium
- BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)medium
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)high
- CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)critical
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2high
- BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…high
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injectionmedium
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breachhigh
- SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…medium
- Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlighthigh
- Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…high
- SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governmentshigh
- Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malwarehigh
- VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defensesmedium
- HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)high
- Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAThigh
- Kynx Stealer: MaaS Infostealer Targeting Crypto Wallets, Gaming Platforms, and AI Coding Toolscritical
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…high
- DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganographyhigh
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…medium
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Thefthigh
Detection coverage
Threadlinqs maintains 171 detection rules mapped to T1518.001 (SPL 42, KQL 70, Sigma 59). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1518 Software Discovery — 340 tracked threats at the technique level.