Activity timeline
T1568.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-04 with 7 reports, and 27 of the 27 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1568.002 Domain Generation Algorithms is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1568 Dynamic Resolution. Threadlinqs maps 27 of 2623 tracked threats (1%) to it; by severity that is 8 critical, 17 high, 2 medium.
Threats that use T1568.002 most often also use T1071.001 Web Protocols (23 threats), T1082 System Information Discovery (19 threats), T1036.005 Match Legitimate Resource Name or Location (18 threats), T1204.002 Malicious File (17 threats), T1547.001 Registry Run Keys / Startup Folder (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
16 tracked threat actors appear in the threats that use T1568.002; the most frequent are APT38 (3), Sapphire Sleet (3), Stardust Chollima (3), Woodgnat (2), Akira (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1568.002.
Data sources
Telemetry that can reveal T1568.002, per MITRE ATT&CK.
- Network Traffic — Network Traffic Flow
Threat actors using it
Tracked threats
27 tracked threats use T1568.002.
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
- Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chainhigh
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaignsmedium
- StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M…high
- ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector…high
- Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and…high
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchershigh
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Brokerhigh
- Backdoor.Mistic (MLTBackdoor) — In-Memory BOF-Capable Backdoor Deployed by Woodgnat/KongTuke IAB Alongside…high
- ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…high
- UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching…critical
- Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via…critical
- NWHStealer Adopts Bun JavaScript Runtime for Distribution — Rust Infostealer via Bun-Bundled JS Loadershigh
- Mustang Panda LOTUSLITE v1.1 Espionage Campaign Targets Indian Banking (HDFC) and South Korean Policy Circleshigh
- UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…high
- FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 Apple App Store Apps (SparkKitty-linked…critical
- JanaWare Ransomware: Polymorphic Java RAT Campaign Targeting Turkey via Customized Adwindhigh
- Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)critical
- JanelaRAT 2026 Campaign: Updated Brazilian Banking Trojan Targeting Latin American Financial Sector via DLL…high
- Grandoreiro Banking Trojan Multi-Vector Campaign: ClickFix Delivery via canalmodup.com, Dual DLL Sideloading…high
- GRIDTIDE Backdoor — UNC2814 PRC-Nexus Global Espionage Campaign Targeting Telecoms & Governments via Google…critical
- Prometei Botnet (Linux/Prometei.B) — UPX-Packed Monero-Mining Bot with Cron/systemd Persistence, HTTP/DGA…medium
- Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…critical
Detection coverage
Threadlinqs maintains 74 detection rules mapped to T1568.002 (SPL 27, KQL 23, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1568 Dynamic Resolution — 80 tracked threats at the technique level.