# T1599 Network Boundary Bridging

> As of 2026-10-05, T1599 (Network Boundary Bridging) appears in 12 tracked threats, first reported 2026-03-07 and most recently 2026-09-21, with linked actors including APT28, FSB Center 16, NetNut; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 12 (5 critical, 7 high)
- **First seen:** 2026-03-07
- **Last seen:** 2026-09-21
- **Threat actors:** 6
- **Detection rules:** 17 (counts only; Blue tier and above)

## Key facts

- **ID:** T1599
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1599/

## Activity timeline

T1599 first appeared in tracked threats on 2026-03-07 and was most recently reported on 2026-09-21. The busiest month was 2026-07 with 6 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1599 Network Boundary Bridging is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 7 high.

Threats that use T1599 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (8 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (7 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (6 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (6 threats), [T1590 Gather Victim Network Information](https://intel.threadlinqs.com/technique/T1590) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1599; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (1), [NetNut](https://intel.threadlinqs.com/actor/NetNut) (1), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (1), [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) (1).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1599.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1043 Credential Access Protection](https://attack.mitre.org/mitigations/M1043/)

## Data sources

Telemetry that can reveal T1599, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 1
- [NetNut](https://intel.threadlinqs.com/actor/NetNut) — 1
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 1
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 1
- [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) — 1

## Tracked threats

12 tracked threats use T1599.

- [Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel](https://intel.threadlinqs.com/threat/TL-2026-2609) — high — 2026-09-21
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS…](https://intel.threadlinqs.com/threat/TL-2026-1927) — high — 2026-08-07
- [CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Database](https://intel.threadlinqs.com/threat/TL-2026-1802) — critical — 2026-07-31
- [Iran Exploits SS7 Cellular Roaming Protocol and Commercial Ad-Tech Location Data to Track and Target US…](https://intel.threadlinqs.com/threat/TL-2026-1673) — high — 2026-07-24
- [Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft…](https://intel.threadlinqs.com/threat/TL-2026-1497) — high — 2026-07-18
- [FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…](https://intel.threadlinqs.com/threat/TL-2026-1283) — high — 2026-07-13
- [FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…](https://intel.threadlinqs.com/threat/TL-2026-1276) — high — 2026-07-13
- [NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for…](https://intel.threadlinqs.com/threat/TL-2026-1112) — high — 2026-07-03
- [CVE-2026-7473: Arista EOS Tunnel Decapsulation Protocol-Confusion Bypass — No Vendor Patch, Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-1493) — critical — 2026-06-16
- [Cisco Catalyst SD-WAN CVE-2026-20182 — Critical Authentication Bypass Zero-Day Actively Exploited by…](https://intel.threadlinqs.com/threat/TL-2026-0516) — critical — 2026-05-14
- [Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769)](https://intel.threadlinqs.com/threat/TL-2026-0194) — critical — 2026-03-07

## Related CVEs

CVEs referenced by the tracked threats that use T1599, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2026-20182](https://intel.threadlinqs.com/cve/CVE-2026-20182)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-56181](https://intel.threadlinqs.com/cve/CVE-2026-56181)
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102)
- [CVE-2026-85103](https://intel.threadlinqs.com/cve/CVE-2026-85103)

## Detection coverage

Threadlinqs maintains 17 detection rules mapped to T1599 (SPL 6, KQL 5, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

17 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1599.001 Network Address Translation Traversal — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1599
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
