Activity timeline
T1565.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 31 reports, and 98 of the 98 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1565.001 Stored Data Manipulation is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of T1565 Data Manipulation. Threadlinqs maps 98 of 2623 tracked threats (3.7%) to it; by severity that is 58 critical, 30 high, 9 medium, 1 low.
Threats that use T1565.001 most often also use T1190 Exploit Public-Facing Application (72 threats), T1213 Data from Information Repositories (49 threats), T1005 Data from Local System (45 threats), T1059 Command and Scripting Interpreter (42 threats), T1082 System Information Discovery (42 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
14 tracked threat actors appear in the threats that use T1565.001; the most frequent are APT38 (2), Andariel (2), Lazarus Group (2), Contagious Interview cluster (1), Jade Sleet (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1565.001.
Data sources
Telemetry that can reveal T1565.001, per MITRE ATT&CK.
- File — File Creation, File Deletion, File Modification
Threat actors using it
Tracked threats
The 30 most recent of 98 tracked threats that use T1565.001.
- Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection…critical
- Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…high
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…high
- Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses…critical
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation…critical
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…critical
- CVE-2026-27540: Unauthenticated Arbitrary File Upload in WooCommerce Wholesale Lead Capture Plugin Actively…critical
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Pluginhigh
- TELUS Warns Customers of 16-Month Account Takeover Breach via Compromised Credentialsmedium
- Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices…high
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injectionmedium
- DeepSeek Harness Authentication Bypass Lets Sandboxed AI Agents Escape via Single Command (CVE-2026-82533)critical
- CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)critical
- Second-Order SQL Injection in All-in-One WP Migration and Backup Plugin (CVE-2026-19949) Exposes 5M+…high
- Active Exploitation of Sangoma Switchvox Unauthenticated SQL Injection (CVE-2026-9586) Deploying Reverse…critical
- Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending Protocolcritical
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…critical
- Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchainscritical
- GiveWP WordPress Donation Plugin Flaw (CVE-2026-82222) Lets Attackers Execute Server Commandscritical
- 91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285critical
- Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)critical
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurecritical
- Oracle August 2026 CSPU: Nine Vulnerabilities in Agile Engineering Data Management 6.2.1, Including…critical
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…critical
- Unpatched GeoServer Zero-Day SQL Injection in jsonArrayContains (GHSA-mqjf-5f49-2fjh) Enables…critical
- Critical Metabase Zero-Day (CVE-2026-72898): Unauthenticated SQL Injection Grants Admin Access, Exploited in…critical
Detection coverage
Threadlinqs maintains 260 detection rules mapped to T1565.001 (SPL 82, KQL 87, Sigma 91). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1565 Data Manipulation — 192 tracked threats at the technique level.