T1564.013 - Bind Mounts - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
July 30, 2026
Last Seen
July 30, 2026

T1564.013 - Bind Mounts is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

T1564.013 - Bind Mounts is a mitre_attack tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed July 30, 2026; most recent activity July 30, 2026.

Related Threat Clusters

  • Covert Linux XMRig Campaign Exploits PAM for Cryptomining

    In July 2026, a sophisticated cryptomining campaign utilizing XMRig was discovered, targeting Linux systems. The attackers exploited trusted access through third-party relationships, allowing them to infiltrate networks…

    2 articles · Updated July 30, 2026

Recent Intelligence Reports

  • XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys ... — Group-Ib · July 30, 2026

Frequently asked questions

What is T1564.013 - Bind Mounts?

T1564.013 - Bind Mounts is a mitre_attack tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Is T1564.013 - Bind Mounts still active?

The most recent intelligence report mentioning T1564.013 - Bind Mounts on ThreatCluster is dated July 30, 2026.

What is T1564.013 - Bind Mounts associated with?

Across ThreatCluster reporting, T1564.013 - Bind Mounts most frequently co-occurs with Botnet, Malware, V25 (Generation 26) Campaign Family, XMRig, T1036 - Masquerading, among 8 tracked related entities.

What are the latest developments involving T1564.013 - Bind Mounts?

The most significant recent cluster is “Covert Linux XMRig Campaign Exploits PAM for Cryptomining” (2 articles · Updated July 30, 2026). T1564.013 - Bind Mounts appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on T1564.013 - Bind Mounts?

T1564.013 - Bind Mounts appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown