Activity timeline
T1648 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-07.
How adversaries use it
T1648 Serverless Execution is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 4 critical, 8 high, 1 medium.
Threats that use T1648 most often also use T1078 Valid Accounts (10 threats), T1059 Command and Scripting Interpreter (9 threats), T1526 Cloud Service Discovery (8 threats), T1528 Steal Application Access Token (8 threats), T1552 Unsecured Credentials (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
5 tracked threat actors appear in the threats that use T1648; the most frequent are Handala (1), Handala Hack (1), Handala Hack Team (1), TeamPCP (1), Void Manticore (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1648.
Data sources
Telemetry that can reveal T1648, per MITRE ATT&CK.
- Application Log — Application Log Content
- Cloud Service — Cloud Service Modification
Threat actors using it
Tracked threats
13 tracked threats use T1648.
- Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLicritical
- Extortion Actor Pivots from Blocked Remote-Access Tool to Fake IT-Support Social Engineering for Data…medium
- China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations…high
- Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia…high
- Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model…high
- Pickle in the Middle: Vertex AI Model Upload Hijacking via GCS Bucket Squatting Enables Cross-Tenant RCE…high
- HazyBeacon (CL-STA-1020) — AWS Lambda Function URL Abuse for Covert C2 Against Southeast Asian Governmentshigh
- GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 / 18.10.7) — CVE-2026-4868 GitLab Duo AI Workflow…high
- Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltrationcritical
- Trivy Supply Chain Compromise — TeamPCP Credential-Stealing Malware Injected into CI/CD Pipelines…critical
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device…critical
- 175,000 Exposed Ollama LLM Hosts Enable AI Model Abusehigh
- LLMJacking: 175,000 Exposed Ollama AI Servers Targeted for Abusehigh
Detection coverage
Threadlinqs maintains 9 detection rules mapped to T1648 (SPL 2, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.