Activity timeline
T1610 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 17 reports, and 39 of the 39 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1610 Deploy Container is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 39 of 2623 tracked threats (1.5%) to it; by severity that is 15 critical, 22 high, 2 medium.
Threats that use T1610 most often also use T1190 Exploit Public-Facing Application (25 threats), T1005 Data from Local System (24 threats), T1059 Command and Scripting Interpreter (22 threats), T1071 Application Layer Protocol (22 threats), T1105 Ingress Tool Transfer (21 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1610; the most frequent are TeamPCP (8), JADEPUFFER (1), Jade Sleet (1), Mini Shai-Hulud (1), PCPJack (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1610.
Data sources
Telemetry that can reveal T1610, per MITRE ATT&CK.
- Application Log — Application Log Content
- Container — Container Creation, Container Start
- Pod — Pod Creation, Pod Modification
Threat actors using it
Tracked threats
The 30 most recent of 39 tracked threats that use T1610.
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…high
- Cloudflare Containers cross-tenant residual disk data exposure via device-mapper thin-provisioning…high
- Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…high
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- Fastjson RCE (≤ 1.2.83) — Active Exploitation Detected (ThreatBook XVE-2026-39684)high
- Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red…high
- SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…high
- Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkithigh
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…high
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295)…high
- Indirect Prompt Injection in AI Coding Agents Enables Reverse Shell via Malicious GitHub Repos (Mozilla 0DIN…high
- CVE-2026-20251: Splunk Secure Gateway jsonpickle Deserialization RCE with Public PoChigh
- HalluSquatting: Attacker-Registered Hallucinated Resource Names Fueling Agentic Botnetsmedium
- Threat Actors Mass-Probe Gitea Docker Deployments for CVE-2026-20896 Authentication Bypass Amid Exploitarium…critical
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos…critical
- CVE-2026-45659: Microsoft SharePoint Deserialization RCE Added to CISA KEV Despite 'Exploitation Less…high
- CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromisehigh
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchershigh
- Unpatched Unauthenticated RCE in Argo CD Repo-Server via Kustomize GenerateManifest gRPC Endpointhigh
- CISA KEV: Cisco Unified Communications Manager SSRF to Webshell (CVE-2026-20230) Actively Exploitedcritical
- Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…high
- Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host…critical
- Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…high
- P2Pinfect Kubernetes Compromise — Exposed Redis Enables Persistent GKE Botnet Enrollment with Six-Month…high
- Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days Disclosedhigh
- NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests Cloud Credentials and AI API Keys via Langflow RCE…high
Detection coverage
Threadlinqs maintains 33 detection rules mapped to T1610 (SPL 9, KQL 12, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.