# T1499.003 Application Exhaustion Flood

> As of 2026-10-05, T1499.003 (Application Exhaustion Flood) appears in 21 tracked threats, first reported 2026-02-16 and most recently 2026-09-27, with linked actors including Handala Hack Team, NoName057(16); it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 21 (5 critical, 12 high, 4 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-27
- **Threat actors:** 2
- **Detection rules:** 45 (counts only; Blue tier and above)

## Key facts

- **ID:** T1499.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Parent:** T1499
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1499/003/

## Activity timeline

T1499.003 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 8 reports, and 21 of the 21 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1499.003 Application Exhaustion Flood is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of [T1499 Endpoint Denial of Service](https://intel.threadlinqs.com/technique/T1499). Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 5 critical, 12 high, 4 medium.

Threats that use T1499.003 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (15 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (9 threats), [T1203 Exploitation for Client Execution](https://intel.threadlinqs.com/technique/T1203) (9 threats), [T1499.004 Application or System Exploitation](https://intel.threadlinqs.com/technique/T1499.004) (9 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1499.003; the most frequent are [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) (1), [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1499.003.

- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1499.003, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Sensor Health — Host Status

## Threat actors using it

- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 1

## Tracked threats

21 tracked threats use T1499.003.

- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth…](https://intel.threadlinqs.com/threat/TL-2026-2159) — critical — 2026-08-26
- [Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…](https://intel.threadlinqs.com/threat/TL-2026-2154) — high — 2026-08-26
- [91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285](https://intel.threadlinqs.com/threat/TL-2026-2105) — critical — 2026-08-21
- [CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)](https://intel.threadlinqs.com/threat/TL-2026-1909) — high — 2026-08-06
- [GitLab Patches 13 Security Flaws (incl. CVE-2026-6267, CVE-2026-12436) Enabling Data Exposure, CI/CD…](https://intel.threadlinqs.com/threat/TL-2026-1806) — high — 2026-07-29
- [OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-1554) — medium — 2026-07-20
- [OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger)](https://intel.threadlinqs.com/threat/TL-2026-1471) — medium — 2026-07-18
- [OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)](https://intel.threadlinqs.com/threat/TL-2026-1459) — medium — 2026-07-17
- [Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…](https://intel.threadlinqs.com/threat/TL-2026-1403) — critical — 2026-07-16
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — high — 2026-07-15
- [SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690…](https://intel.threadlinqs.com/threat/TL-2026-1302) — critical — 2026-07-14
- [148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack…](https://intel.threadlinqs.com/threat/TL-2026-1296) — high — 2026-07-14
- [Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity…](https://intel.threadlinqs.com/threat/TL-2026-0866) — high — 2026-06-19
- [BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947)…](https://intel.threadlinqs.com/threat/TL-2026-0599) — high — 2026-05-27
- [ABB B&R Automation Runtime SDM CVE-2025-3450 — Unauthenticated Network DoS via Improper Resource Locking](https://intel.threadlinqs.com/threat/TL-2026-0593) — critical — 2026-05-26
- [Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript…](https://intel.threadlinqs.com/threat/TL-2026-0552) — high — 2026-05-21
- [CVE-2026-44338 PraisonAI Unauthenticated API Bypass — Active Exploitation Within 4 Hours of Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-0502) — high — 2026-05-12
- [CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter…](https://intel.threadlinqs.com/threat/TL-2026-0112) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1499.003, most frequent first.

- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2024-3393](https://intel.threadlinqs.com/cve/CVE-2024-3393)
- [CVE-2025-3450](https://intel.threadlinqs.com/cve/CVE-2025-3450)
- [CVE-2026-11622](https://intel.threadlinqs.com/cve/CVE-2026-11622)
- [CVE-2026-15718](https://intel.threadlinqs.com/cve/CVE-2026-15718)
- [CVE-2026-15719](https://intel.threadlinqs.com/cve/CVE-2026-15719)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-27690](https://intel.threadlinqs.com/cve/CVE-2026-27690)
- [CVE-2026-3039](https://intel.threadlinqs.com/cve/CVE-2026-3039)
- [CVE-2026-3592](https://intel.threadlinqs.com/cve/CVE-2026-3592)
- [CVE-2026-3593](https://intel.threadlinqs.com/cve/CVE-2026-3593)
- [CVE-2026-40128](https://intel.threadlinqs.com/cve/CVE-2026-40128)
- [CVE-2026-44338](https://intel.threadlinqs.com/cve/CVE-2026-44338)
- [CVE-2026-44747](https://intel.threadlinqs.com/cve/CVE-2026-44747)
- [CVE-2026-44748](https://intel.threadlinqs.com/cve/CVE-2026-44748)
- [CVE-2026-44761](https://intel.threadlinqs.com/cve/CVE-2026-44761)
- [CVE-2026-48318](https://intel.threadlinqs.com/cve/CVE-2026-48318)
- [CVE-2026-5946](https://intel.threadlinqs.com/cve/CVE-2026-5946)
- [CVE-2026-5947](https://intel.threadlinqs.com/cve/CVE-2026-5947)
- [CVE-2026-5950](https://intel.threadlinqs.com/cve/CVE-2026-5950)
- [CVE-2026-6267](https://intel.threadlinqs.com/cve/CVE-2026-6267)
- [CVE-2026-65182](https://intel.threadlinqs.com/cve/CVE-2026-65182)
- [CVE-2026-65637](https://intel.threadlinqs.com/cve/CVE-2026-65637)
- [CVE-2026-65927](https://intel.threadlinqs.com/cve/CVE-2026-65927)
- [CVE-2026-66422](https://intel.threadlinqs.com/cve/CVE-2026-66422)
- [CVE-2026-68525](https://intel.threadlinqs.com/cve/CVE-2026-68525)

## Detection coverage

Threadlinqs maintains 45 detection rules mapped to T1499.003 (SPL 16, KQL 14, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.

45 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1499 Endpoint Denial of Service](https://intel.threadlinqs.com/technique/T1499) — 127 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1499.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
