# T1498 Network Denial of Service

> As of 2026-10-05, T1498 (Network Denial of Service) appears in 69 tracked threats, first reported 2026-02-03 and most recently 2026-08-02, with linked actors including UAT-8616, FSB Center 16, Kontraktnik; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 69 (24 critical, 35 high, 10 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-08-02
- **Threat actors:** 19
- **Detection rules:** 45 (counts only; Blue tier and above)

## Key facts

- **ID:** T1498
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1498/

## Activity timeline

T1498 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-08-02. The busiest month was 2026-07 with 33 reports, and 69 of the 69 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1498 Network Denial of Service is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 69 of 2623 tracked threats (2.6%) to it; by severity that is 24 critical, 35 high, 10 medium.

Threats that use T1498 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (52 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (41 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (39 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (36 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (32 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

19 tracked threat actors appear in the threats that use T1498; the most frequent are [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) (4), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (3), [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) (3), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (3), [APT28](https://intel.threadlinqs.com/actor/APT28) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1498.

- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1498, per MITRE ATT&CK.

- Network Traffic — Network Traffic Flow
- Sensor Health — Host Status

## Threat actors using it

- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 4
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 3
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 3
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [NetNut](https://intel.threadlinqs.com/actor/NetNut) — 2
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 2
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 2
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1
- [Earth Lamia](https://intel.threadlinqs.com/actor/Earth%20Lamia) — 1

## Tracked threats

The 30 most recent of 69 tracked threats that use T1498.

- [Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…](https://intel.threadlinqs.com/threat/TL-2026-1824) — medium — 2026-08-02
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28
- [Dolphin X: AI-Powered Windows Infostealer/RAT Uses Behavioral Profiling to Prioritize High-Value Victims](https://intel.threadlinqs.com/threat/TL-2026-1672) — high — 2026-07-24
- [HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling…](https://intel.threadlinqs.com/threat/TL-2026-1671) — high — 2026-07-24
- [France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1652) — high — 2026-07-23
- [Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel](https://intel.threadlinqs.com/threat/TL-2026-1695) — high — 2026-07-22
- [Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx\[.\]top)](https://intel.threadlinqs.com/threat/TL-2026-1621) — high — 2026-07-22
- [Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Execution](https://intel.threadlinqs.com/threat/TL-2026-1617) — critical — 2026-07-22
- [NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack Framework](https://intel.threadlinqs.com/threat/TL-2026-1592) — medium — 2026-07-21
- [DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1485) — medium — 2026-07-18
- [OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)](https://intel.threadlinqs.com/threat/TL-2026-1459) — medium — 2026-07-17
- [HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte Payload](https://intel.threadlinqs.com/threat/TL-2026-1457) — medium — 2026-07-17
- [Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…](https://intel.threadlinqs.com/threat/TL-2026-1403) — critical — 2026-07-16
- [TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts](https://intel.threadlinqs.com/threat/TL-2026-1397) — medium — 2026-07-16
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — high — 2026-07-15
- [SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem](https://intel.threadlinqs.com/threat/TL-2026-1357) — critical — 2026-07-15
- [US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play…](https://intel.threadlinqs.com/threat/TL-2026-1355) — high — 2026-07-15
- [XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting Linux SSH Servers via SSH Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1345) — high — 2026-07-14
- [Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS Botnet](https://intel.threadlinqs.com/threat/TL-2026-1328) — critical — 2026-07-14
- [FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171)…](https://intel.threadlinqs.com/threat/TL-2026-1312) — critical — 2026-07-14
- [US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB…](https://intel.threadlinqs.com/threat/TL-2026-1290) — medium — 2026-07-14
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…](https://intel.threadlinqs.com/threat/TL-2026-1277) — high — 2026-07-13
- [FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install…](https://intel.threadlinqs.com/threat/TL-2026-1276) — high — 2026-07-13
- [CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static…](https://intel.threadlinqs.com/threat/TL-2026-1272) — high — 2026-07-13
- [VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…](https://intel.threadlinqs.com/threat/TL-2026-1261) — medium — 2026-07-13
- [Claude Mythos / Project Glasswing: Autonomous AI Vulnerability Discovery Compresses the Find-to-Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1253) — high — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [Lone Attacker Uses AI-Assisted Workflows to Breach Large AWS Cloud Environment in 72 Hours (Sygnia…](https://intel.threadlinqs.com/threat/TL-2026-1182) — high — 2026-07-10
- [CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1159) — critical — 2026-07-10
- [JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack](https://intel.threadlinqs.com/threat/TL-2026-1117) — critical — 2026-07-05

## Related CVEs

CVEs referenced by the tracked threats that use T1498, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687)
- [CVE-2011-2523](https://intel.threadlinqs.com/cve/CVE-2011-2523)
- [CVE-2017-6742](https://intel.threadlinqs.com/cve/CVE-2017-6742)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-12108](https://intel.threadlinqs.com/cve/CVE-2019-12108)
- [CVE-2019-12109](https://intel.threadlinqs.com/cve/CVE-2019-12109)
- [CVE-2019-12110](https://intel.threadlinqs.com/cve/CVE-2019-12110)
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111)
- [CVE-2020-28951](https://intel.threadlinqs.com/cve/CVE-2020-28951)
- [CVE-2021-22205](https://intel.threadlinqs.com/cve/CVE-2021-22205)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-35394](https://intel.threadlinqs.com/cve/CVE-2021-35394)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-34048](https://intel.threadlinqs.com/cve/CVE-2023-34048)

## Detection coverage

Threadlinqs maintains 45 detection rules mapped to T1498 (SPL 12, KQL 12, Sigma 21). Rule content is available to Blue tier accounts and above; this page shows counts only.

45 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1498.001 Direct Network Flood](https://intel.threadlinqs.com/technique/T1498.001) — 18 tracked threats
- T1498.002 Reflection Amplification — 6 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1498
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
