# T1610 Deploy Container

> As of 2026-10-05, T1610 (Deploy Container) appears in 39 tracked threats, first reported 2026-02-24 and most recently 2026-09-27, with linked actors including TeamPCP, JADEPUFFER, Jade Sleet; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 39 (15 critical, 22 high, 2 medium)
- **First seen:** 2026-02-24
- **Last seen:** 2026-09-27
- **Threat actors:** 9
- **Detection rules:** 33 (counts only; Blue tier and above)

## Key facts

- **ID:** T1610
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1610/

## Activity timeline

T1610 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 17 reports, and 39 of the 39 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1610 Deploy Container is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 39 of 2623 tracked threats (1.5%) to it; by severity that is 15 critical, 22 high, 2 medium.

Threats that use T1610 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (25 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (24 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (22 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (22 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (21 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1610; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (8), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) (1), [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) (1), [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) (1), [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1610.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1610, per MITRE ATT&CK.

- Application Log — Application Log Content
- Container — Container Creation, Container Start
- Pod — Pod Creation, Pod Modification

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 8
- [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER) — 1
- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 1
- [PCPJack](https://intel.threadlinqs.com/actor/PCPJack) — 1
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1
- [Slow Pisces](https://intel.threadlinqs.com/actor/Slow%20Pisces) — 1
- [TraderTraitor](https://intel.threadlinqs.com/actor/TraderTraitor) — 1
- [Vect Ransomware](https://intel.threadlinqs.com/actor/Vect%20Ransomware) — 1

## Tracked threats

The 30 most recent of 39 tracked threats that use T1610.

- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [Cloudflare Containers cross-tenant residual disk data exposure via device-mapper thin-provisioning…](https://intel.threadlinqs.com/threat/TL-2026-2644) — high — 2026-09-24
- [Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…](https://intel.threadlinqs.com/threat/TL-2026-2639) — high — 2026-09-24
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [Fastjson RCE (≤ 1.2.83) — Active Exploitation Detected (ThreatBook XVE-2026-39684)](https://intel.threadlinqs.com/threat/TL-2026-1609) — high — 2026-07-22
- [Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red…](https://intel.threadlinqs.com/threat/TL-2026-1546) — high — 2026-07-19
- [SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo…](https://intel.threadlinqs.com/threat/TL-2026-1532) — high — 2026-07-19
- [Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkit](https://intel.threadlinqs.com/threat/TL-2026-1498) — high — 2026-07-18
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…](https://intel.threadlinqs.com/threat/TL-2026-1477) — high — 2026-07-18
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295)…](https://intel.threadlinqs.com/threat/TL-2026-1230) — high — 2026-07-11
- [Indirect Prompt Injection in AI Coding Agents Enables Reverse Shell via Malicious GitHub Repos (Mozilla 0DIN…](https://intel.threadlinqs.com/threat/TL-2026-1218) — high — 2026-07-11
- [CVE-2026-20251: Splunk Secure Gateway jsonpickle Deserialization RCE with Public PoC](https://intel.threadlinqs.com/threat/TL-2026-1203) — high — 2026-07-11
- [HalluSquatting: Attacker-Registered Hallucinated Resource Names Fueling Agentic Botnets](https://intel.threadlinqs.com/threat/TL-2026-1187) — medium — 2026-07-10
- [Threat Actors Mass-Probe Gitea Docker Deployments for CVE-2026-20896 Authentication Bypass Amid Exploitarium…](https://intel.threadlinqs.com/threat/TL-2026-1136) — critical — 2026-07-06
- [JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos…](https://intel.threadlinqs.com/threat/TL-2026-1083) — critical — 2026-07-02
- [CVE-2026-45659: Microsoft SharePoint Deserialization RCE Added to CISA KEV Despite 'Exploitation Less…](https://intel.threadlinqs.com/threat/TL-2026-1074) — high — 2026-07-02
- [CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromise](https://intel.threadlinqs.com/threat/TL-2026-1070) — high — 2026-07-02
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — high — 2026-07-02
- [Unpatched Unauthenticated RCE in Argo CD Repo-Server via Kustomize GenerateManifest gRPC Endpoint](https://intel.threadlinqs.com/threat/TL-2026-2423) — high — 2026-07-01
- [CISA KEV: Cisco Unified Communications Manager SSRF to Webshell (CVE-2026-20230) Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-0960) — critical — 2026-06-27
- [Miasma Supply-Chain Malware Abuses binding.gyp "Phantom Gyp" Trick and Bun Runtime to Steal Developer…](https://intel.threadlinqs.com/threat/TL-2026-1242) — high — 2026-06-26
- [Agentic Threat Actor Container Escape — AI Agent-Driven marimo CVE-2026-39987 RCE → Docker Socket → Host…](https://intel.threadlinqs.com/threat/TL-2026-0694) — critical — 2026-06-06
- [Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm…](https://intel.threadlinqs.com/threat/TL-2026-1234) — high — 2026-06-04
- [P2Pinfect Kubernetes Compromise — Exposed Redis Enables Persistent GKE Botnet Enrollment with Six-Month…](https://intel.threadlinqs.com/threat/TL-2026-0537) — high — 2026-05-21
- [Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days Disclosed](https://intel.threadlinqs.com/threat/TL-2026-1547) — high — 2026-05-15
- [NATS-as-C2: KeyHunter Distributed Worker Botnet Harvests Cloud Credentials and AI API Keys via Langflow RCE…](https://intel.threadlinqs.com/threat/TL-2026-0514) — high — 2026-05-14

## Related CVEs

CVEs referenced by the tracked threats that use T1610, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0543](https://intel.threadlinqs.com/cve/CVE-2022-0543)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2025-11953](https://intel.threadlinqs.com/cve/CVE-2025-11953)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-49844](https://intel.threadlinqs.com/cve/CVE-2025-49844)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-1357](https://intel.threadlinqs.com/cve/CVE-2026-1357)
- [CVE-2026-20896](https://intel.threadlinqs.com/cve/CVE-2026-20896)
- [CVE-2026-22874](https://intel.threadlinqs.com/cve/CVE-2026-22874)
- [CVE-2026-25038](https://intel.threadlinqs.com/cve/CVE-2026-25038)

## Detection coverage

Threadlinqs maintains 33 detection rules mapped to T1610 (SPL 9, KQL 12, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

33 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1610
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
