# T1608.002 Upload Tool

> As of 2026-10-05, T1608.002 (Upload Tool) appears in 11 tracked threats, first reported 2026-02-06 and most recently 2026-08-27, with linked actors including ClickLock Dev, UNC6692, Vanilla Tempest; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 11 (2 critical, 9 high)
- **First seen:** 2026-02-06
- **Last seen:** 2026-08-27
- **Threat actors:** 3

## Key facts

- **ID:** T1608.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1608
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1608/002/

## Activity timeline

T1608.002 first appeared in tracked threats on 2026-02-06 and was most recently reported on 2026-08-27. The busiest month was 2026-05 with 3 reports, and 11 of the 11 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1608.002 Upload Tool is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 9 high.

Threats that use T1608.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (8 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (7 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (7 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (6 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1608.002; the most frequent are [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (1), [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) (1), [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1608.002.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1608.002, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [UNC6692](https://intel.threadlinqs.com/actor/UNC6692) — 1
- [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest) — 1

## Tracked threats

11 tracked threats use T1608.002.

- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1744) — high — 2026-07-28
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers](https://intel.threadlinqs.com/threat/TL-2026-0822) — high — 2026-06-16
- [AccountDumpling — Vietnamese-Linked Facebook Business Hijacking Campaign Abusing Google AppSheet (~30,000…](https://intel.threadlinqs.com/threat/TL-2026-0453) — high — 2026-05-04
- [Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access Keys (Securelist, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0451) — high — 2026-05-04
- [AI Supply Chain Abuse — 575 Trojanized OpenClaw/ClawHub Skills + Hugging Face Malware Staging (Acronis TRU)](https://intel.threadlinqs.com/threat/TL-2026-0447) — high — 2026-05-01
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)](https://intel.threadlinqs.com/threat/TL-2026-0386) — high — 2026-04-17
- [AI Prompt Injection Attacks on Enterprise LLMs — CrowdStrike Taxonomy, Agentic Tool Chain Attacks, MCP…](https://intel.threadlinqs.com/threat/TL-2026-0128) — high — 2026-02-22
- [TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37…](https://intel.threadlinqs.com/threat/TL-2026-0109) — critical — 2026-02-06

## Related CVEs

CVEs referenced by the tracked threats that use T1608.002, most frequent first.

- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2023-49105](https://intel.threadlinqs.com/cve/CVE-2023-49105)
- [CVE-2024-28000](https://intel.threadlinqs.com/cve/CVE-2024-28000)
- [CVE-2026-34197](https://intel.threadlinqs.com/cve/CVE-2026-34197)

## Parent technique

[T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608) — 250 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1608.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
