TA488
MITRE G0134Also known as CL-STA-1114
Reports
3
First seen
Jul 23, 2026
Last seen
Aug 7, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×3T1003 OS Credential Dumping ×2T1041 Exfiltration Over C2 Channel ×2T1486 Data Encrypted for Impact ×1T1567.001 Exfiltration Over Web Service: Exfiltration to Cloud Storage ×1T1059.007 Command and Scripting Interpreter: JavaScript ×1T1566 Phishing ×1T1105 Ingress Tool Transfer ×1T1047 Windows Management Instrumentation ×1T1087.002 Account Discovery: Domain Account ×1T1555 Credentials from Password Stores ×1T1090 Proxy ×1
Indicators
cve ×24
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-66376 (exploited)CVE-2026-42897 (exploited)CVE-2017-17215 (exploited)CVE-2017-5259 (exploited)CVE-2018-0802 (exploited)CVE-2018-14558 (exploited)CVE-2020-22653 (exploited)CVE-2020-22658 (exploited)CVE-2020-25499 (exploited)CVE-2020-8515 (exploited)CVE-2022-35733 (exploited)CVE-2013-3307 (exploited)CVE-2024-42009 (exploited)CVE-2025-28137 (exploited)CVE-2025-3248 (exploited)CVE-2025-34152 (exploited)CVE-2025-49113 (exploited)CVE-2025-55182 (exploited)CVE-2025-9491 (exploited)CVE-2025-9528 (exploited)
Recent reports
Critical