# T1498.001 Direct Network Flood

> As of 2026-10-05, T1498.001 (Direct Network Flood) appears in 18 tracked threats, first reported 2026-02-05 and most recently 2026-10-03, with linked actors including NoName057(16), Handala Hack, Handala Hack Team; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 18 (4 critical, 10 high, 4 medium)
- **First seen:** 2026-02-05
- **Last seen:** 2026-10-03
- **Threat actors:** 6
- **Detection rules:** 47 (counts only; Blue tier and above)

## Key facts

- **ID:** T1498.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Parent:** T1498
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1498/001/

## Activity timeline

T1498.001 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 9 reports, and 18 of the 18 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1498.001 Direct Network Flood is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of [T1498 Network Denial of Service](https://intel.threadlinqs.com/technique/T1498). Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 4 critical, 10 high, 4 medium.

Threats that use T1498.001 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (10 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (8 threats), [T1499.003 Application Exhaustion Flood](https://intel.threadlinqs.com/technique/T1499.003) (8 threats), [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1498.001; the most frequent are [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) (2), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (1), [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) (1), [MedusaLocker](https://intel.threadlinqs.com/actor/MedusaLocker) (1), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1498.001.

- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1498.001, per MITRE ATT&CK.

- Network Traffic — Network Traffic Flow
- Sensor Health — Host Status

## Threat actors using it

- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 2
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1
- [MedusaLocker](https://intel.threadlinqs.com/actor/MedusaLocker) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 1

## Tracked threats

18 tracked threats use T1498.001.

- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — high — 2026-10-03
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…](https://intel.threadlinqs.com/threat/TL-2026-2154) — high — 2026-08-26
- [CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…](https://intel.threadlinqs.com/threat/TL-2026-2097) — critical — 2026-08-21
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger)](https://intel.threadlinqs.com/threat/TL-2026-1471) — medium — 2026-07-18
- [OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)](https://intel.threadlinqs.com/threat/TL-2026-1459) — medium — 2026-07-17
- [313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…](https://intel.threadlinqs.com/threat/TL-2026-1374) — high — 2026-07-15
- [Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS Botnet](https://intel.threadlinqs.com/threat/TL-2026-1328) — critical — 2026-07-14
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…](https://intel.threadlinqs.com/threat/TL-2026-1309) — medium — 2026-07-14
- [148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy)](https://intel.threadlinqs.com/threat/TL-2026-1304) — high — 2026-07-14
- [148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack…](https://intel.threadlinqs.com/threat/TL-2026-1296) — high — 2026-07-14
- [CVE-2025-3248 & CVE-2026-5027: Langflow RCE and Path Traversal Chained for Flodrix Botnet Deployment](https://intel.threadlinqs.com/threat/TL-2026-1247) — critical — 2026-07-12
- [Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript…](https://intel.threadlinqs.com/threat/TL-2026-0552) — high — 2026-05-21
- [CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter…](https://intel.threadlinqs.com/threat/TL-2026-0112) — high — 2026-02-16
- [Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…](https://intel.threadlinqs.com/threat/TL-2026-0098) — critical — 2026-02-05

## Related CVEs

CVEs referenced by the tracked threats that use T1498.001, most frequent first.

- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2021-35394](https://intel.threadlinqs.com/cve/CVE-2021-35394)
- [CVE-2024-3393](https://intel.threadlinqs.com/cve/CVE-2024-3393)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2025-62593](https://intel.threadlinqs.com/cve/CVE-2025-62593)
- [CVE-2026-5027](https://intel.threadlinqs.com/cve/CVE-2026-5027)

## Detection coverage

Threadlinqs maintains 47 detection rules mapped to T1498.001 (SPL 21, KQL 10, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.

47 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1498 Network Denial of Service](https://intel.threadlinqs.com/technique/T1498) — 69 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1498.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
