Activity timeline
T1565 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 70 reports, and 192 of the 192 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1565 Data Manipulation is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 192 of 2623 tracked threats (7.3%) to it; by severity that is 95 critical, 75 high, 16 medium, 1 low.
Threats that use T1565 most often also use T1059 Command and Scripting Interpreter (122 threats), T1190 Exploit Public-Facing Application (117 threats), T1005 Data from Local System (109 threats), T1071 Application Layer Protocol (88 threats), T1068 Exploitation for Privilege Escalation (86 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
44 tracked threat actors appear in the threats that use T1565; the most frequent are APT38 (4), Cyber Av3ngers (4), Lazarus Group (4), MuddyWater (3), Stardust Chollima (3).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1565.
Data sources
Telemetry that can reveal T1565, per MITRE ATT&CK.
- File — File Creation, File Deletion, File Metadata, File Modification
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Process — OS API Execution
Threat actors using it
Tracked threats
The 30 most recent of 192 tracked threats that use T1565.
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…critical
- Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCEcritical
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leakhigh
- Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)critical
- NASA JPL AIT-GUI Missing Authentication and CSRF Flaw Allows Unauthenticated Spacecraft Command Injection…critical
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…critical
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurecritical
- White House Authorizes Private US Companies to Conduct Offensive Cyber Operations Against Foreign Criminal…
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- Metabase Unauthenticated SQL Injection 0-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Admin Takeovercritical
- Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA…high
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applicationsmedium
- Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass…critical
- Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via…critical
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic…high
- Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data…high
- CVE-2026-58048 — cPanel & WHM Database Privilege Escalation via Database Rename (SQL Mode Loss)critical
- CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis…high
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command…critical
- EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack…medium
- XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and…critical
- GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC…medium
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass…high
- CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Databasecritical
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…critical
- Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory…high
- PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague /…high
- CVE-2026-66723: Missing Authorization in MWDB Core Remote Instances Proxy APIhigh
Detection coverage
Threadlinqs maintains 78 detection rules mapped to T1565 (SPL 26, KQL 23, Sigma 29). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1565.001 Stored Data Manipulation — 98 tracked threats
- T1565.002 Transmitted Data Manipulation — 15 tracked threats
- T1565.003 Runtime Data Manipulation — 1 tracked threat