T1007 - System Service Discovery - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
May 14, 2026
Last Seen
August 2, 2026

T1007 - System Service Discovery is a mitre_attack tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

T1007 - System Service Discovery is a mitre_attack tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed May 14, 2026; most recent activity August 2, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • BleepingComputer summarised the finding — www.bleepingcomputer.com · August 2, 2026
  • Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor — Darktrace · May 14, 2026

Frequently asked questions

What is T1007 - System Service Discovery?

T1007 - System Service Discovery is a mitre_attack tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

Is T1007 - System Service Discovery still active?

The most recent intelligence report mentioning T1007 - System Service Discovery on ThreatCluster is dated August 2, 2026. Activity was first observed May 14, 2026, giving a tracked span from then to August 2, 2026.

What is T1007 - System Service Discovery associated with?

Across ThreatCluster reporting, T1007 - System Service Discovery most frequently co-occurs with Twill Typhoon, Malware, Langflow, MiniMax, Sogou Pinyin, among 12 tracked related entities.

What are the latest developments involving T1007 - System Service Discovery?

The most significant recent cluster is “Chinese APT Campaign Targets Asia-Pacific with FDMTP Backdoor” (3 articles · Updated May 14, 2026). T1007 - System Service Discovery appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1007 - System Service Discovery?

T1007 - System Service Discovery appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown