T1572 - Protocol Tunneling - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
18
occurrences
First Seen
March 9, 2026
Last Seen
July 23, 2026

T1572 - Protocol Tunneling is a mitre_attack tracked by ThreatCluster, appearing in 18 threat clusters built from 18 intelligence report mentions.

T1572 - Protocol Tunneling is a mitre_attack tracked across 18 threat clusters and 18 intelligence report mentions on ThreatCluster. First observed March 9, 2026; most recent activity July 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • China-Nexus Hackers Breached Hospital X-Rays, Embassy, and Congress With New ... — Techtimes · July 23, 2026
  • New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications — Infosecurity-Magazine · July 20, 2026
  • Iranian hackers use new modular C2 framework against Israeli organizations — Feeds.Feedburner · July 6, 2026
  • Microsoft device telemetry key to unmasking alleged Scattered Spider hacker — Itnews.Au · July 5, 2026
  • AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery — Cybersecuritynews · July 2, 2026
  • Prevent data exfiltration: AWS egress controls for cloud workloads — Aws.Amazon · June 22, 2026
  • LATAM Infrastructure Hit by Fortinet and Ivanti Exploits — Infosecurity-Magazine · June 18, 2026
  • Interlock and Rhysida: AI in the Ransomware Ecosystem — Socprime · June 17, 2026

Frequently asked questions

What is T1572 - Protocol Tunneling?

T1572 - Protocol Tunneling is a mitre_attack tracked by ThreatCluster, appearing in 18 threat clusters built from 18 intelligence report mentions.

Is T1572 - Protocol Tunneling still active?

The most recent intelligence report mentioning T1572 - Protocol Tunneling on ThreatCluster is dated July 23, 2026. Activity was first observed March 9, 2026, giving a tracked span from then to July 23, 2026.

What is T1572 - Protocol Tunneling associated with?

Across ThreatCluster reporting, T1572 - Protocol Tunneling most frequently co-occurs with Banished Kitten, Cavern Manticore, China-Nexus Hackers, Cl-sta-0049, Cl-unk-1068, among 12 tracked related entities.

What are the latest developments involving T1572 - Protocol Tunneling?

The most significant recent cluster is “Operation Escaneo Targets Latin American Critical Infrastructure” (4 articles · Updated June 18, 2026). T1572 - Protocol Tunneling appears across 18 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1572 - Protocol Tunneling?

T1572 - Protocol Tunneling appears in 18 intelligence report mentions across 18 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown