Activity timeline
T1602 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 14 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1602 Data from Configuration Repository is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 13 critical, 10 high, 2 medium.
Threats that use T1602 most often also use T1190 Exploit Public-Facing Application (22 threats), T1595 Active Scanning (18 threats), T1059 Command and Scripting Interpreter (16 threats), T1046 Network Service Discovery (15 threats), T1552 Unsecured Credentials (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
2 tracked threat actors appear in the threats that use T1602; the most frequent are Static Tundra (4), FSB Center 16 (2).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1602.
Data sources
Telemetry that can reveal T1602, per MITRE ATT&CK.
- Network Traffic — Network Connection Creation, Network Traffic Content
Threat actors using it
Tracked threats
25 tracked threats use T1602.
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PIImedium
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…critical
- CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEVcritical
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171)…critical
- Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositorieshigh
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…high
- Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructurecritical
- Internet-Wide Reconnaissance Scans Target MCP Servers and Claude/Cursor AI-Agent Credentialsmedium
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…high
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…high
- JetBrains Marketplace Supply Chain Attack: 15 Malicious AI-Assistant Plugins Exfiltrate DeepSeek/OpenAI API…high
- CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission…critical
- CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instancescritical
- Cisco Catalyst Center Unauthenticated Path Traversal / Arbitrary File Read Vulnerability (CVE-2026-20191)high
- CVE-2026-4020: Gravity SMTP WordPress Plugin Unauthenticated System-Report Credential Disclosure (Actively…high
- GitHub Enterprise Server 3.20.3 — Pre-Auth SSRF in Upload Endpoint (CVE-2026-9312) + Bundled "Dirty Frag"…critical
- Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…high
- F5 BIG-IP Edge Appliance Abused for SSH Pivot → Confluence RCE → CVE-2025-33073 Kerberos Relay to Active…high
- Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security…critical
- Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973…high
- PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series &…critical
- Firestarter Malware Persists on Cisco ASA/Firepower Through Firmware Updates (CVE-2025-20333…critical
- Nginx UI Authentication Bypass via Unauthenticated MCP Endpoint (CVE-2026-33032)critical
- CVE-2026-20093: Cisco IMC Authentication Bypass — Unauthenticated Admin Access via Password Change…critical
Detection coverage
Threadlinqs maintains 16 detection rules mapped to T1602 (SPL 8, KQL 5, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1602.001 SNMP (MIB Dump) — 2 tracked threats
- T1602.002 Network Device Configuration Dump — 9 tracked threats