# T1518 Software Discovery

> As of 2026-10-05, T1518 (Software Discovery) appears in 340 tracked threats, first reported 2026-02-02 and most recently 2026-09-22, with linked actors including APT38, Stardust Chollima, Sapphire Sleet; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 340 (104 critical, 205 high, 22 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-22
- **Threat actors:** 74
- **Detection rules:** 125 (counts only; Blue tier and above)

## Key facts

- **ID:** T1518
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1518/

## Activity timeline

T1518 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-22. The busiest month was 2026-07 with 165 reports, and 340 of the 340 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1518 Software Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 340 of 2623 tracked threats (13%) to it; by severity that is 104 critical, 205 high, 22 medium, 1 low.

Threats that use T1518 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (239 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (235 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (217 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (210 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (203 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

74 tracked threat actors appear in the threats that use T1518; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (13), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (12), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (10), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (8), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (6).

## Data sources

Telemetry that can reveal T1518, per MITRE ATT&CK.

- Command — Command Execution
- Firewall — Firewall Enumeration, Firewall Metadata
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 13
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 12
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 10
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 8
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 4
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 4
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 4
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 4
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 3

## Tracked threats

The 30 most recent of 340 tracked threats that use T1518.

- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Plugin](https://intel.threadlinqs.com/threat/TL-2026-2523) — high — 2026-09-15
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…](https://intel.threadlinqs.com/threat/TL-2026-2196) — critical — 2026-08-28
- [MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…](https://intel.threadlinqs.com/threat/TL-2026-2163) — high — 2026-08-27
- [Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2158) — high — 2026-08-26
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…](https://intel.threadlinqs.com/threat/TL-2026-2152) — critical — 2026-08-26
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21
- [SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2090) — critical — 2026-08-20
- [Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…](https://intel.threadlinqs.com/threat/TL-2026-2089) — critical — 2026-08-20
- [Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2086) — critical — 2026-08-20
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026](https://intel.threadlinqs.com/threat/TL-2026-2078) — medium — 2026-08-20
- [Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-2008) — high — 2026-08-13
- [SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local…](https://intel.threadlinqs.com/threat/TL-2026-1949) — high — 2026-08-09
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…](https://intel.threadlinqs.com/threat/TL-2026-1917) — high — 2026-08-06
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projects](https://intel.threadlinqs.com/threat/TL-2026-1870) — high — 2026-08-04
- [AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale](https://intel.threadlinqs.com/threat/TL-2026-1867) — medium — 2026-08-04
- [Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)](https://intel.threadlinqs.com/threat/TL-2026-1846) — high — 2026-08-03
- [BINDCLOAK Backdoor Campaign Targeting Middle East Government Entities](https://intel.threadlinqs.com/threat/TL-2026-1844) — high — 2026-08-03
- [Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass…](https://intel.threadlinqs.com/threat/TL-2026-1807) — high — 2026-08-01
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150…](https://intel.threadlinqs.com/threat/TL-2026-1795) — 2026-07-31
- [Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…](https://intel.threadlinqs.com/threat/TL-2026-1790) — critical — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31

## Related CVEs

CVEs referenced by the tracked threats that use T1518, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2026-27690](https://intel.threadlinqs.com/cve/CVE-2026-27690)
- [CVE-2026-44747](https://intel.threadlinqs.com/cve/CVE-2026-44747)
- [CVE-2026-44761](https://intel.threadlinqs.com/cve/CVE-2026-44761)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32435](https://intel.threadlinqs.com/cve/CVE-2023-32435)
- [CVE-2023-41990](https://intel.threadlinqs.com/cve/CVE-2023-41990)
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-40128](https://intel.threadlinqs.com/cve/CVE-2026-40128)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-46331](https://intel.threadlinqs.com/cve/CVE-2026-46331)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2026-48317](https://intel.threadlinqs.com/cve/CVE-2026-48317)
- [CVE-2026-48323](https://intel.threadlinqs.com/cve/CVE-2026-48323)
- [CVE-2026-48326](https://intel.threadlinqs.com/cve/CVE-2026-48326)
- [CVE-2026-48330](https://intel.threadlinqs.com/cve/CVE-2026-48330)
- [CVE-2026-48331](https://intel.threadlinqs.com/cve/CVE-2026-48331)
- [CVE-2026-48333](https://intel.threadlinqs.com/cve/CVE-2026-48333)
- [CVE-2026-48448](https://intel.threadlinqs.com/cve/CVE-2026-48448)

## Detection coverage

Threadlinqs maintains 125 detection rules mapped to T1518 (SPL 30, KQL 64, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.

125 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1518.001 Security Software Discovery](https://intel.threadlinqs.com/technique/T1518.001) — 114 tracked threats
- T1518.002 Backup Software Discovery — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1518
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
