# T1614 System Location Discovery

> As of 2026-10-05, T1614 (System Location Discovery) appears in 74 tracked threats, first reported 2026-01-01 and most recently 2026-09-30, with linked actors including TeamPCP, InCrease, Contagious Interview; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 74 (13 critical, 58 high, 3 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-09-30
- **Threat actors:** 38
- **Detection rules:** 41 (counts only; Blue tier and above)

## Key facts

- **ID:** T1614
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1614/

## Activity timeline

T1614 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 28 reports, and 74 of the 74 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1614 System Location Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 74 of 2623 tracked threats (2.8%) to it; by severity that is 13 critical, 58 high, 3 medium.

Threats that use T1614 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (62 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (61 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (49 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (47 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (46 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

38 tracked threat actors appear in the threats that use T1614; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (5), [InCrease](https://intel.threadlinqs.com/actor/InCrease) (3), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (2), [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) (2), [Mustard Tempest](https://intel.threadlinqs.com/actor/Mustard%20Tempest) (2).

## Data sources

Telemetry that can reveal T1614, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 5
- [InCrease](https://intel.threadlinqs.com/actor/InCrease) — 3
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 2
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 2
- [Mustard Tempest](https://intel.threadlinqs.com/actor/Mustard%20Tempest) — 2
- [Turla](https://intel.threadlinqs.com/actor/Turla) — 2
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 2
- [Y2K Operators](https://intel.threadlinqs.com/actor/Y2K%20Operators) — 2
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [Amadey](https://intel.threadlinqs.com/actor/Amadey) — 1
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 1
- [Contagious Interview cluster](https://intel.threadlinqs.com/actor/Contagious%20Interview%20cluster) — 1

## Tracked threats

The 30 most recent of 74 tracked threats that use T1614.

- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpit](https://intel.threadlinqs.com/threat/TL-2026-2490) — high — 2026-09-14
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts](https://intel.threadlinqs.com/threat/TL-2026-2296) — high — 2026-09-02
- [Void Dokkaebi Ships Cython-Compiled InvisibleFerret Malware as .pyd/.so Files to Evade Script Detection](https://intel.threadlinqs.com/threat/TL-2026-2145) — high — 2026-08-25
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [DeadLock Ransomware: Rust-Based Encryptor with Decentralized Recovery Infrastructure on Polygon and Session](https://intel.threadlinqs.com/threat/TL-2026-1981) — high — 2026-08-10
- [Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed…](https://intel.threadlinqs.com/threat/TL-2026-1895) — high — 2026-08-05
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1814) — high — 2026-07-29
- [Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…](https://intel.threadlinqs.com/threat/TL-2026-1805) — critical — 2026-07-28
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network Detection](https://intel.threadlinqs.com/threat/TL-2026-1661) — high — 2026-07-23
- [Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands](https://intel.threadlinqs.com/threat/TL-2026-1710) — medium — 2026-07-22
- [OTTERCOOKIE Malware Hidden in SVG Flag Images Backdoors Developers via Fake Coding Tests (Contagious…](https://intel.threadlinqs.com/threat/TL-2026-1581) — high — 2026-07-20
- [ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage](https://intel.threadlinqs.com/threat/TL-2026-1558) — high — 2026-07-20
- [TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain](https://intel.threadlinqs.com/threat/TL-2026-1557) — high — 2026-07-20
- [SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…](https://intel.threadlinqs.com/threat/TL-2026-1475) — high — 2026-07-18
- [Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer via Weaponized ThrottleStop Driver…](https://intel.threadlinqs.com/threat/TL-2026-1453) — high — 2026-07-17
- [TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chain](https://intel.threadlinqs.com/threat/TL-2026-1420) — high — 2026-07-16
- [Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…](https://intel.threadlinqs.com/threat/TL-2026-1403) — critical — 2026-07-16
- [TELEPUZ: New Modular Malware-as-a-Service Distributed via ClickFix Social Engineering](https://intel.threadlinqs.com/threat/TL-2026-1386) — high — 2026-07-16
- [Impersonated GitHub Brand Repositories Distribute BoryptGrab-Lineage Infostealer via DLL Side-Loading (Fake…](https://intel.threadlinqs.com/threat/TL-2026-1375) — high — 2026-07-15
- [SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-1292) — high — 2026-07-14
- [SnakeKeylogger Infostealer Delivered via Phishing Emails Disguised as Project Proposals (ASEC, JS→PowerShell…](https://intel.threadlinqs.com/threat/TL-2026-1255) — medium — 2026-07-13
- [UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket MFA-Bypass Credential-Phishing Campaign Targets…](https://intel.threadlinqs.com/threat/TL-2026-1223) — high — 2026-07-11

## Related CVEs

CVEs referenced by the tracked threats that use T1614, most frequent first.

- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-4967](https://intel.threadlinqs.com/cve/CVE-2023-4967)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-55183](https://intel.threadlinqs.com/cve/CVE-2025-55183)
- [CVE-2025-55184](https://intel.threadlinqs.com/cve/CVE-2025-55184)
- [CVE-2025-67779](https://intel.threadlinqs.com/cve/CVE-2025-67779)
- [CVE-2026-15718](https://intel.threadlinqs.com/cve/CVE-2026-15718)
- [CVE-2026-15719](https://intel.threadlinqs.com/cve/CVE-2026-15719)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-48318](https://intel.threadlinqs.com/cve/CVE-2026-48318)

## Detection coverage

Threadlinqs maintains 41 detection rules mapped to T1614 (SPL 10, KQL 16, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.

41 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1614.001 System Language Discovery](https://intel.threadlinqs.com/technique/T1614.001) — 27 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1614
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
