Activity timeline
T1498.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 9 reports, and 18 of the 18 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1498.001 Direct Network Flood is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of T1498 Network Denial of Service. Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 4 critical, 10 high, 4 medium.
Threats that use T1498.001 most often also use T1190 Exploit Public-Facing Application (10 threats), T1071.001 Web Protocols (9 threats), T1027 Obfuscated Files or Information (8 threats), T1499.003 Application Exhaustion Flood (8 threats), T1059.004 Unix Shell (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1498.001; the most frequent are NoName057(16) (2), Handala Hack (1), Handala Hack Team (1), MedusaLocker (1), Qilin (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1498.001.
Data sources
Telemetry that can reveal T1498.001, per MITRE ATT&CK.
- Network Traffic — Network Traffic Flow
- Sensor Health — Host Status
Threat actors using it
Tracked threats
18 tracked threats use T1498.001.
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394high
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Monthshigh
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…high
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…critical
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger)medium
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)medium
- 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…high
- Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS Botnetcritical
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…medium
- 148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy)high
- 148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack…high
- CVE-2025-3248 & CVE-2026-5027: Langflow RCE and Path Traversal Chained for Flodrix Botnet Deploymentcritical
- Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript…high
- CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter…high
- Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…critical
Detection coverage
Threadlinqs maintains 47 detection rules mapped to T1498.001 (SPL 21, KQL 10, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1498 Network Denial of Service — 69 tracked threats at the technique level.