# T1568 Dynamic Resolution

> As of 2026-10-05, T1568 (Dynamic Resolution) appears in 80 tracked threats, first reported 2026-01-01 and most recently 2026-09-28, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 80 (20 critical, 53 high, 6 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-09-28
- **Threat actors:** 32
- **Detection rules:** 87 (counts only; Blue tier and above)

## Key facts

- **ID:** T1568
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1568/

## Activity timeline

T1568 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 28 reports, and 80 of the 80 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1568 Dynamic Resolution is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 80 of 2623 tracked threats (3%) to it; by severity that is 20 critical, 53 high, 6 medium.

Threats that use T1568 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (75 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (66 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (62 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (60 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (54 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1568; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (4), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (4), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (4), [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) (3).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1568.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1568, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 4
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 4
- [KongTuke](https://intel.threadlinqs.com/actor/KongTuke) — 3
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 2
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [NetNut](https://intel.threadlinqs.com/actor/NetNut) — 2
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 2
- [APT27](https://intel.threadlinqs.com/actor/APT27) — 1

## Tracked threats

The 30 most recent of 80 tracked threats that use T1568.

- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against…](https://intel.threadlinqs.com/threat/TL-2026-2764) — high — 2026-09-28
- [MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL…](https://intel.threadlinqs.com/threat/TL-2026-2163) — high — 2026-08-27
- [SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targeting](https://intel.threadlinqs.com/threat/TL-2026-2104) — high — 2026-08-21
- [Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform…](https://intel.threadlinqs.com/threat/TL-2026-2089) — critical — 2026-08-20
- [Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2086) — critical — 2026-08-20
- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — high — 2026-08-10
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…](https://intel.threadlinqs.com/threat/TL-2026-1760) — critical — 2026-07-29
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28
- [Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience](https://intel.threadlinqs.com/threat/TL-2026-1738) — high — 2026-07-28
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — medium — 2026-07-27
- [FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai](https://intel.threadlinqs.com/threat/TL-2026-1669) — high — 2026-07-24
- [Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) Malware](https://intel.threadlinqs.com/threat/TL-2026-1662) — high — 2026-07-23
- [Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and…](https://intel.threadlinqs.com/threat/TL-2026-1658) — medium — 2026-07-23
- [Hugging Face Breached by Autonomous AI Agent Exploiting Dataset Code-Execution Paths (No CVE Disclosed)](https://intel.threadlinqs.com/threat/TL-2026-1576) — high — 2026-07-20
- [ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign](https://intel.threadlinqs.com/threat/TL-2026-1570) — high — 2026-07-20
- [Fake Game Downloads Deliver Amatera Stealer via Ren'Py Loader, MSBuild Abuse, and EtherHiding C2](https://intel.threadlinqs.com/threat/TL-2026-1569) — high — 2026-07-20
- [NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized…](https://intel.threadlinqs.com/threat/TL-2026-1559) — medium — 2026-07-20
- [HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API](https://intel.threadlinqs.com/threat/TL-2026-1555) — high — 2026-07-20
- [UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage…](https://intel.threadlinqs.com/threat/TL-2026-1527) — high — 2026-07-19
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chain](https://intel.threadlinqs.com/threat/TL-2026-1420) — high — 2026-07-16
- [The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWorm](https://intel.threadlinqs.com/threat/TL-2026-1418) — high — 2026-07-16
- [TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts](https://intel.threadlinqs.com/threat/TL-2026-1397) — medium — 2026-07-16
- [UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA campaign against Ukrainian devices with EtherHiding C2…](https://intel.threadlinqs.com/threat/TL-2026-2393) — critical — 2026-07-15
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — high — 2026-07-15
- [Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmations](https://intel.threadlinqs.com/threat/TL-2026-1252) — high — 2026-07-13
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)](https://intel.threadlinqs.com/threat/TL-2026-1192) — high — 2026-07-10

## Related CVEs

CVEs referenced by the tracked threats that use T1568, most frequent first.

- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2025-29635](https://intel.threadlinqs.com/cve/CVE-2025-29635)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2013-3307](https://intel.threadlinqs.com/cve/CVE-2013-3307)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2016-5681](https://intel.threadlinqs.com/cve/CVE-2016-5681)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2019-11510](https://intel.threadlinqs.com/cve/CVE-2019-11510)
- [CVE-2019-11539](https://intel.threadlinqs.com/cve/CVE-2019-11539)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2020-5902](https://intel.threadlinqs.com/cve/CVE-2020-5902)
- [CVE-2020-8243](https://intel.threadlinqs.com/cve/CVE-2020-8243)
- [CVE-2021-22205](https://intel.threadlinqs.com/cve/CVE-2021-22205)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-22893](https://intel.threadlinqs.com/cve/CVE-2021-22893)
- [CVE-2021-22894](https://intel.threadlinqs.com/cve/CVE-2021-22894)
- [CVE-2021-22900](https://intel.threadlinqs.com/cve/CVE-2021-22900)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-30952](https://intel.threadlinqs.com/cve/CVE-2021-30952)
- [CVE-2021-35394](https://intel.threadlinqs.com/cve/CVE-2021-35394)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)

## Detection coverage

Threadlinqs maintains 87 detection rules mapped to T1568 (SPL 33, KQL 27, Sigma 27). Rule content is available to Blue tier accounts and above; this page shows counts only.

87 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1568.001 Fast Flux DNS — 4 tracked threats
- [T1568.002 Domain Generation Algorithms](https://intel.threadlinqs.com/technique/T1568.002) — 27 tracked threats
- T1568.003 DNS Calculation — 2 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1568
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
