# T1648 Serverless Execution

> As of 2026-10-05, T1648 (Serverless Execution) appears in 13 tracked threats, first reported 2026-02-02 and most recently 2026-07-24, with linked actors including Handala, Handala Hack, Handala Hack Team; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 13 (4 critical, 8 high, 1 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-07-24
- **Threat actors:** 5
- **Detection rules:** 9 (counts only; Blue tier and above)

## Key facts

- **ID:** T1648
- **Framework:** MITRE ATT&CK
- **Tactics:** Execution
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1648/

## Activity timeline

T1648 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-07-24. The busiest month was 2026-07 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-07.

## How adversaries use it

T1648 Serverless Execution is catalogued by MITRE ATT&CK under the Execution tactic in the Enterprise matrix. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 4 critical, 8 high, 1 medium.

Threats that use T1648 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (10 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (9 threats), [T1526 Cloud Service Discovery](https://intel.threadlinqs.com/technique/T1526) (8 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (8 threats), [T1552 Unsecured Credentials](https://intel.threadlinqs.com/technique/T1552) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

5 tracked threat actors appear in the threats that use T1648; the most frequent are [Handala](https://intel.threadlinqs.com/actor/Handala) (1), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (1), [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) (1), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (1), [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1648.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1036 Account Use Policies](https://attack.mitre.org/mitigations/M1036/)

## Data sources

Telemetry that can reveal T1648, per MITRE ATT&CK.

- Application Log — Application Log Content
- Cloud Service — Cloud Service Modification

## Threat actors using it

- [Handala](https://intel.threadlinqs.com/actor/Handala) — 1
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 1

## Tracked threats

13 tracked threats use T1648.

- [Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLi](https://intel.threadlinqs.com/threat/TL-2026-1666) — critical — 2026-07-24
- [Extortion Actor Pivots from Blocked Remote-Access Tool to Fake IT-Support Social Engineering for Data…](https://intel.threadlinqs.com/threat/TL-2026-1359) — medium — 2026-07-15
- [China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations…](https://intel.threadlinqs.com/threat/TL-2026-1354) — high — 2026-07-15
- [Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia…](https://intel.threadlinqs.com/threat/TL-2026-1182) — high — 2026-07-10
- [Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model…](https://intel.threadlinqs.com/threat/TL-2026-0880) — high — 2026-06-19
- [Pickle in the Middle: Vertex AI Model Upload Hijacking via GCS Bucket Squatting Enables Cross-Tenant RCE…](https://intel.threadlinqs.com/threat/TL-2026-0825) — high — 2026-06-16
- [HazyBeacon (CL-STA-1020) — AWS Lambda Function URL Abuse for Covert C2 Against Southeast Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-0684) — high — 2026-06-05
- [GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 / 18.10.7) — CVE-2026-4868 GitLab Duo AI Workflow…](https://intel.threadlinqs.com/threat/TL-2026-0634) — high — 2026-05-30
- [Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0529) — critical — 2026-05-19
- [Trivy Supply Chain Compromise — TeamPCP Credential-Stealing Malware Injected into CI/CD Pipelines…](https://intel.threadlinqs.com/threat/TL-2026-0280) — critical — 2026-03-24
- [Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device…](https://intel.threadlinqs.com/threat/TL-2026-0237) — critical — 2026-03-16
- [175,000 Exposed Ollama LLM Hosts Enable AI Model Abuse](https://intel.threadlinqs.com/threat/TL-2026-0047) — high — 2026-02-03
- [LLMJacking: 175,000 Exposed Ollama AI Servers Targeted for Abuse](https://intel.threadlinqs.com/threat/TL-2026-0012) — high — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1648, most frequent first.

- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)

## Detection coverage

Threadlinqs maintains 9 detection rules mapped to T1648 (SPL 2, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

9 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1648
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
