Activity timeline
T1499.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 21 of the 21 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1499.003 Application Exhaustion Flood is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of T1499 Endpoint Denial of Service. Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 5 critical, 12 high, 4 medium.
Threats that use T1499.003 most often also use T1190 Exploit Public-Facing Application (15 threats), T1046 Network Service Discovery (9 threats), T1203 Exploitation for Client Execution (9 threats), T1499.004 Application or System Exploitation (9 threats), T1595.002 Vulnerability Scanning (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
2 tracked threat actors appear in the threats that use T1499.003; the most frequent are Handala Hack Team (1), NoName057(16) (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1499.003.
Data sources
Telemetry that can reveal T1499.003, per MITRE ATT&CK.
- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Sensor Health — Host Status
Threat actors using it
Tracked threats
21 tracked threats use T1499.003.
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)high
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth…critical
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…high
- 91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285critical
- CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)high
- GitLab Patches 13 Security Flaws (incl. CVE-2026-6267, CVE-2026-12436) Enabling Data Exposure, CI/CD…high
- OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerabilitymedium
- OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger)medium
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)medium
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…critical
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chainhigh
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690…critical
- 148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack…high
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity…high
- BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947)…high
- ABB B&R Automation Runtime SDM CVE-2025-3450 — Unauthenticated Network DoS via Improper Resource Lockingcritical
- Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript…high
- CVE-2026-44338 PraisonAI Unauthenticated API Bypass — Active Exploitation Within 4 Hours of Disclosure…high
- CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter…high
Detection coverage
Threadlinqs maintains 45 detection rules mapped to T1499.003 (SPL 16, KQL 14, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1499 Endpoint Denial of Service — 127 tracked threats at the technique level.