# T1568.002 Domain Generation Algorithms

> As of 2026-10-05, T1568.002 (Domain Generation Algorithms) appears in 27 tracked threats, first reported 2026-02-05 and most recently 2026-09-21, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 27 (8 critical, 17 high, 2 medium)
- **First seen:** 2026-02-05
- **Last seen:** 2026-09-21
- **Threat actors:** 16
- **Detection rules:** 74 (counts only; Blue tier and above)

## Key facts

- **ID:** T1568.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1568
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1568/002/

## Activity timeline

T1568.002 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-09-21. The busiest month was 2026-04 with 7 reports, and 27 of the 27 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1568.002 Domain Generation Algorithms is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1568 Dynamic Resolution](https://intel.threadlinqs.com/technique/T1568). Threadlinqs maps 27 of 2623 tracked threats (1%) to it; by severity that is 8 critical, 17 high, 2 medium.

Threats that use T1568.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (23 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (19 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (18 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (17 threats), [T1547.001 Registry Run Keys / Startup Folder](https://intel.threadlinqs.com/technique/T1547.001) (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

16 tracked threat actors appear in the threats that use T1568.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (3), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (3), [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat) (2), [Akira](https://intel.threadlinqs.com/actor/Akira) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1568.002.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1568.002, per MITRE ATT&CK.

- Network Traffic — Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 3
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 3
- [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [DarkSpectre](https://intel.threadlinqs.com/actor/DarkSpectre) — 1
- [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge) — 1
- [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) — 1
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 1
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1

## Tracked threats

27 tracked threats use T1568.002.

- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — high — 2026-09-21
- [Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain](https://intel.threadlinqs.com/threat/TL-2026-2305) — high — 2026-09-03
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1485) — medium — 2026-07-18
- [StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M…](https://intel.threadlinqs.com/threat/TL-2026-1221) — high — 2026-07-11
- [ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector…](https://intel.threadlinqs.com/threat/TL-2026-1127) — high — 2026-07-05
- [Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and…](https://intel.threadlinqs.com/threat/TL-2026-1079) — high — 2026-07-02
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — high — 2026-07-02
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Broker](https://intel.threadlinqs.com/threat/TL-2026-2277) — high — 2026-06-24
- [Backdoor.Mistic (MLTBackdoor) — In-Memory BOF-Capable Backdoor Deployed by Woodgnat/KongTuke IAB Alongside…](https://intel.threadlinqs.com/threat/TL-2026-0933) — high — 2026-06-24
- [ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…](https://intel.threadlinqs.com/threat/TL-2026-0817) — high — 2026-06-16
- [UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching…](https://intel.threadlinqs.com/threat/TL-2026-0564) — critical — 2026-05-22
- [Backdoored node-ipc npm Releases (9.1.6, 9.2.3, 12.0.1) — Credential Stealer with DNS Exfiltration via…](https://intel.threadlinqs.com/threat/TL-2026-0518) — critical — 2026-05-15
- [NWHStealer Adopts Bun JavaScript Runtime for Distribution — Rust Infostealer via Bun-Bundled JS Loaders](https://intel.threadlinqs.com/threat/TL-2026-0470) — high — 2026-05-06
- [Mustang Panda LOTUSLITE v1.1 Espionage Campaign Targets Indian Banking (HDFC) and South Korean Policy Circles](https://intel.threadlinqs.com/threat/TL-2026-0430) — high — 2026-04-27
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT /…](https://intel.threadlinqs.com/threat/TL-2026-0415) — high — 2026-04-23
- [FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 Apple App Store Apps (SparkKitty-linked…](https://intel.threadlinqs.com/threat/TL-2026-0395) — critical — 2026-04-20
- [JanaWare Ransomware: Polymorphic Java RAT Campaign Targeting Turkey via Customized Adwind](https://intel.threadlinqs.com/threat/TL-2026-0368) — high — 2026-04-15
- [Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)](https://intel.threadlinqs.com/threat/TL-2026-0361) — critical — 2026-04-14
- [JanelaRAT 2026 Campaign: Updated Brazilian Banking Trojan Targeting Latin American Financial Sector via DLL…](https://intel.threadlinqs.com/threat/TL-2026-0353) — high — 2026-04-13
- [Grandoreiro Banking Trojan Multi-Vector Campaign: ClickFix Delivery via canalmodup.com, Dual DLL Sideloading…](https://intel.threadlinqs.com/threat/TL-2026-2069) — high — 2026-04-08
- [GRIDTIDE Backdoor — UNC2814 PRC-Nexus Global Espionage Campaign Targeting Telecoms & Governments via Google…](https://intel.threadlinqs.com/threat/TL-2026-0144) — critical — 2026-02-25
- [Prometei Botnet (Linux/Prometei.B) — UPX-Packed Monero-Mining Bot with Cron/systemd Persistence, HTTP/DGA…](https://intel.threadlinqs.com/threat/TL-2026-1490) — medium — 2026-02-20
- [Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…](https://intel.threadlinqs.com/threat/TL-2026-0098) — critical — 2026-02-05

## Related CVEs

CVEs referenced by the tracked threats that use T1568.002, most frequent first.

- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)

## Detection coverage

Threadlinqs maintains 74 detection rules mapped to T1568.002 (SPL 27, KQL 23, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.

74 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1568 Dynamic Resolution](https://intel.threadlinqs.com/technique/T1568) — 80 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1568.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
