# T1602 Data from Configuration Repository

> As of 2026-10-05, T1602 (Data from Configuration Repository) appears in 25 tracked threats, first reported 2026-04-04 and most recently 2026-09-22, with linked actors including Static Tundra, FSB Center 16; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 25 (13 critical, 10 high, 2 medium)
- **First seen:** 2026-04-04
- **Last seen:** 2026-09-22
- **Threat actors:** 2
- **Detection rules:** 16 (counts only; Blue tier and above)

## Key facts

- **ID:** T1602
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1602/

## Activity timeline

T1602 first appeared in tracked threats on 2026-04-04 and was most recently reported on 2026-09-22. The busiest month was 2026-07 with 14 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1602 Data from Configuration Repository is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 13 critical, 10 high, 2 medium.

Threats that use T1602 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (22 threats), [T1595 Active Scanning](https://intel.threadlinqs.com/technique/T1595) (18 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (16 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (15 threats), [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1602; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (4), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (2).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1602.

- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1602, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 4
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2

## Tracked threats

25 tracked threats use T1602.

- [Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)](https://intel.threadlinqs.com/threat/TL-2026-2617) — critical — 2026-09-22
- [CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PII](https://intel.threadlinqs.com/threat/TL-2026-1796) — medium — 2026-07-31
- [CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-1725) — critical — 2026-07-27
- [CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1650) — critical — 2026-07-23
- [FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171)…](https://intel.threadlinqs.com/threat/TL-2026-1312) — critical — 2026-07-14
- [Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositories](https://intel.threadlinqs.com/threat/TL-2026-1307) — high — 2026-07-14
- [FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…](https://intel.threadlinqs.com/threat/TL-2026-1283) — high — 2026-07-13
- [Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1282) — critical — 2026-07-13
- [Internet-Wide Reconnaissance Scans Target MCP Servers and Claude/Cursor AI-Agent Credentials](https://intel.threadlinqs.com/threat/TL-2026-1278) — medium — 2026-07-13
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…](https://intel.threadlinqs.com/threat/TL-2026-1277) — high — 2026-07-13
- [FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…](https://intel.threadlinqs.com/threat/TL-2026-1276) — high — 2026-07-13
- [JetBrains Marketplace Supply Chain Attack: 15 Malicious AI-Assistant Plugins Exfiltrate DeepSeek/OpenAI API…](https://intel.threadlinqs.com/threat/TL-2026-1246) — high — 2026-07-11
- [CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission…](https://intel.threadlinqs.com/threat/TL-2026-1089) — critical — 2026-07-02
- [CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances](https://intel.threadlinqs.com/threat/TL-2026-1073) — critical — 2026-07-02
- [Cisco Catalyst Center Unauthenticated Path Traversal / Arbitrary File Read Vulnerability (CVE-2026-20191)](https://intel.threadlinqs.com/threat/TL-2026-1071) — high — 2026-07-02
- [CVE-2026-4020: Gravity SMTP WordPress Plugin Unauthenticated System-Report Credential Disclosure (Actively…](https://intel.threadlinqs.com/threat/TL-2026-0875) — high — 2026-06-19
- [GitHub Enterprise Server 3.20.3 — Pre-Auth SSRF in Upload Endpoint (CVE-2026-9312) + Bundled "Dirty Frag"…](https://intel.threadlinqs.com/threat/TL-2026-0605) — critical — 2026-05-27
- [Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…](https://intel.threadlinqs.com/threat/TL-2026-0596) — high — 2026-05-26
- [F5 BIG-IP Edge Appliance Abused for SSH Pivot → Confluence RCE → CVE-2025-33073 Kerberos Relay to Active…](https://intel.threadlinqs.com/threat/TL-2026-0572) — high — 2026-05-23
- [Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security…](https://intel.threadlinqs.com/threat/TL-2026-0563) — critical — 2026-05-22
- [Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973…](https://intel.threadlinqs.com/threat/TL-2026-0477) — high — 2026-05-07
- [PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series &…](https://intel.threadlinqs.com/threat/TL-2026-0465) — critical — 2026-05-06
- [Firestarter Malware Persists on Cisco ASA/Firepower Through Firmware Updates (CVE-2025-20333…](https://intel.threadlinqs.com/threat/TL-2026-0422) — critical — 2026-04-24
- [Nginx UI Authentication Bypass via Unauthenticated MCP Endpoint (CVE-2026-33032)](https://intel.threadlinqs.com/threat/TL-2026-0388) — critical — 2026-04-17
- [CVE-2026-20093: Cisco IMC Authentication Bypass — Unauthenticated Admin Access via Password Change…](https://intel.threadlinqs.com/threat/TL-2026-0316) — critical — 2026-04-04

## Related CVEs

CVEs referenced by the tracked threats that use T1602, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2026-33032](https://intel.threadlinqs.com/cve/CVE-2026-33032)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-0300](https://intel.threadlinqs.com/cve/CVE-2026-0300)
- [CVE-2026-16232](https://intel.threadlinqs.com/cve/CVE-2026-16232)
- [CVE-2026-16812](https://intel.threadlinqs.com/cve/CVE-2026-16812)
- [CVE-2026-17059](https://intel.threadlinqs.com/cve/CVE-2026-17059)
- [CVE-2026-20093](https://intel.threadlinqs.com/cve/CVE-2026-20093)
- [CVE-2026-20191](https://intel.threadlinqs.com/cve/CVE-2026-20191)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-33000](https://intel.threadlinqs.com/cve/CVE-2026-33000)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-34911](https://intel.threadlinqs.com/cve/CVE-2026-34911)
- [CVE-2026-43284](https://intel.threadlinqs.com/cve/CVE-2026-43284)
- [CVE-2026-43500](https://intel.threadlinqs.com/cve/CVE-2026-43500)
- [CVE-2026-5921](https://intel.threadlinqs.com/cve/CVE-2026-5921)
- [CVE-2026-62144](https://intel.threadlinqs.com/cve/CVE-2026-62144)
- [CVE-2026-62145](https://intel.threadlinqs.com/cve/CVE-2026-62145)
- [CVE-2026-6973](https://intel.threadlinqs.com/cve/CVE-2026-6973)
- [CVE-2026-8606](https://intel.threadlinqs.com/cve/CVE-2026-8606)
- [CVE-2026-9312](https://intel.threadlinqs.com/cve/CVE-2026-9312)

## Detection coverage

Threadlinqs maintains 16 detection rules mapped to T1602 (SPL 8, KQL 5, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

16 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1602.001 SNMP (MIB Dump) — 2 tracked threats
- T1602.002 Network Device Configuration Dump — 9 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1602
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
