# T1573 Encrypted Channel

> As of 2026-10-05, T1573 (Encrypted Channel) appears in 364 tracked threats, first reported 2021-11-25 and most recently 2026-09-29, with linked actors including TeamPCP, Stardust Chollima, APT38; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 364 (111 critical, 228 high, 23 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-09-29
- **Threat actors:** 109
- **Detection rules:** 250 (counts only; Blue tier and above)

## Key facts

- **ID:** T1573
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1573/

## Activity timeline

T1573 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 99 reports, and 363 of the 364 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1573 Encrypted Channel is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 364 of 2623 tracked threats (13.9%) to it; by severity that is 111 critical, 228 high, 23 medium.

Threats that use T1573 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (304 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (278 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (278 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (253 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (248 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

109 tracked threat actors appear in the threats that use T1573; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (20), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (10), [APT38](https://intel.threadlinqs.com/actor/APT38) (9), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (9), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (8).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1573.

- [M1020 SSL/TLS Inspection](https://attack.mitre.org/mitigations/M1020/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1573, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 20
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 10
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 9
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 9
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 8
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 7
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 7
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 6
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 6
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 6
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 5
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 5

## Tracked threats

The 30 most recent of 364 tracked threats that use T1573.

- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — medium — 2026-09-14
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2431) — critical — 2026-09-10
- [QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-2397) — high — 2026-09-08
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…](https://intel.threadlinqs.com/threat/TL-2026-2396) — critical — 2026-09-08
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — critical — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel](https://intel.threadlinqs.com/threat/TL-2026-2311) — high — 2026-09-03
- [DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network](https://intel.threadlinqs.com/threat/TL-2026-2309) — medium — 2026-09-03
- [Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK](https://intel.threadlinqs.com/threat/TL-2026-2293) — high — 2026-09-02
- [ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…](https://intel.threadlinqs.com/threat/TL-2026-2285) — critical — 2026-09-01
- [ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2256) — high — 2026-08-31
- [Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2235) — high — 2026-08-30
- [TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industry](https://intel.threadlinqs.com/threat/TL-2026-2175) — high — 2026-08-28
- [MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…](https://intel.threadlinqs.com/threat/TL-2026-2163) — high — 2026-08-27
- [Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2158) — high — 2026-08-26
- [SmartApeSG ClickFix Campaign Delivering Two-Stage RAT Infection via Fake CAPTCHA Social Engineering on…](https://intel.threadlinqs.com/threat/TL-2026-2101) — high — 2026-08-21
- [SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2098) — high — 2026-08-21
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and…](https://intel.threadlinqs.com/threat/TL-2026-2091) — high — 2026-08-21
- [SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2090) — critical — 2026-08-20
- [Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…](https://intel.threadlinqs.com/threat/TL-2026-2089) — critical — 2026-08-20
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [WordlistLoader Delivering Amatera (ACR Stealer) via ClearFake FakeCaptcha Campaigns](https://intel.threadlinqs.com/threat/TL-2026-2367) — high — 2026-08-18

## Related CVEs

CVEs referenced by the tracked threats that use T1573, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-22205](https://intel.threadlinqs.com/cve/CVE-2021-22205)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-32435](https://intel.threadlinqs.com/cve/CVE-2023-32435)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)

## Detection coverage

Threadlinqs maintains 250 detection rules mapped to T1573 (SPL 108, KQL 65, Sigma 77). Rule content is available to Blue tier accounts and above; this page shows counts only.

250 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1573.001 Symmetric Cryptography](https://intel.threadlinqs.com/technique/T1573.001) — 155 tracked threats
- [T1573.002 Asymmetric Cryptography](https://intel.threadlinqs.com/technique/T1573.002) — 90 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1573
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
