Activity timeline
T1498 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 33 reports, and 69 of the 69 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1498 Network Denial of Service is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 69 of 2623 tracked threats (2.6%) to it; by severity that is 24 critical, 35 high, 10 medium.
Threats that use T1498 most often also use T1190 Exploit Public-Facing Application (52 threats), T1059 Command and Scripting Interpreter (41 threats), T1046 Network Service Discovery (39 threats), T1071 Application Layer Protocol (36 threats), T1027 Obfuscated Files or Information (32 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
19 tracked threat actors appear in the threats that use T1498; the most frequent are UAT-8616 (4), FSB Center 16 (3), Kontraktnik (3), Static Tundra (3), APT28 (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1498.
Data sources
Telemetry that can reveal T1498, per MITRE ATT&CK.
- Network Traffic — Network Traffic Flow
- Sensor Health — Host Status
Threat actors using it
Tracked threats
The 30 most recent of 69 tracked threats that use T1498.
- Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…medium
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Processhigh
- Dolphin X: AI-Powered Windows Infostealer/RAT Uses Behavioral Profiling to Prioritize High-Value Victimshigh
- HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling…high
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign…high
- Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panelhigh
- Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx[.]top)high
- Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Executioncritical
- NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack Frameworkmedium
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaignsmedium
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)medium
- HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte Payloadmedium
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…critical
- TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifactsmedium
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chainhigh
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandemcritical
- US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play…high
- XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting Linux SSH Servers via SSH Brute-Forcehigh
- Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS Botnetcritical
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171)…critical
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…medium
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…high
- FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…high
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static…high
- VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…medium
- Claude Mythos / Project Glasswing: Autonomous AI Vulnerability Discovery Compresses the Find-to-Exploit…high
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia…high
- CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)critical
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attackcritical
Detection coverage
Threadlinqs maintains 45 detection rules mapped to T1498 (SPL 12, KQL 12, Sigma 21). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1498.001 Direct Network Flood — 18 tracked threats
- T1498.002 Reflection Amplification — 6 tracked threats