Activity timeline
T1570 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 77 reports, and 172 of the 172 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1570 Lateral Tool Transfer is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 172 of 2623 tracked threats (6.6%) to it; by severity that is 76 critical, 83 high, 9 medium.
Threats that use T1570 most often also use T1059 Command and Scripting Interpreter (105 threats), T1027 Obfuscated Files or Information (102 threats), T1190 Exploit Public-Facing Application (100 threats), T1005 Data from Local System (99 threats), T1082 System Information Discovery (89 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
72 tracked threat actors appear in the threats that use T1570; the most frequent are TeamPCP (6), Sandworm (5), Cavern Manticore (4), Qilin (4), Static Tundra (4).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1570.
Data sources
Telemetry that can reveal T1570, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation, File Metadata
- Named Pipe — Named Pipe Metadata
- Network Share — Network Share Access
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 172 tracked threats that use T1570.
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)critical
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operationshigh
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)critical
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devicescritical
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interceptionhigh
- UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…critical
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Wormcritical
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surgemedium
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)high
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defenderhigh
- N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…high
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…high
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…critical
- AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scalemedium
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command…critical
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- BlackTech Deploys BlueShell Linux Backdoor Against Japanese Organizationshigh
- ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge Fivefold to 3,000+ Entries; PromptSpy Debuts as…medium
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…critical
Detection coverage
Threadlinqs maintains 163 detection rules mapped to T1570 (SPL 46, KQL 62, Sigma 55). Rule content is available to Blue tier accounts and above; this page shows counts only.