Activity timeline
T1583 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 185 reports, and 610 of the 611 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1583 Acquire Infrastructure is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 611 of 2623 tracked threats (23.3%) to it; by severity that is 165 critical, 374 high, 65 medium, 2 low.
Threats that use T1583 most often also use T1071 Application Layer Protocol (398 threats), T1027 Obfuscated Files or Information (373 threats), T1036 Masquerading (354 threats), T1059 Command and Scripting Interpreter (347 threats), T1005 Data from Local System (323 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
173 tracked threat actors appear in the threats that use T1583; the most frequent are TeamPCP (17), APT38 (14), ShinyHunters (11), Stardust Chollima (10), Lazarus Group (9).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1583.
Data sources
Telemetry that can reveal T1583, per MITRE ATT&CK.
- Domain Name — Active DNS, Domain Registration, Passive DNS
- Internet Scan — Response Content, Response Metadata
Threat actors using it
Tracked threats
The 30 most recent of 611 tracked threats that use T1583.
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…medium
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…high
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnelhigh
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltratedhigh
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonationhigh
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Techniquemedium
- ClickFix Lures Deploy MacSync Stealer to Bypass macOS Securityhigh
- Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teamsmedium
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypasshigh
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Modelscritical
- ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…high
- BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…high
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending Protocolcritical
- Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync…high
- Cybercriminals Build Fake School Websites and Phishing Domains as Education-Sector Attacks Hit Record Highmedium
- Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…high
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industryhigh
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoorhigh
- 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login…medium
- AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhoneshigh
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnethigh
Detection coverage
Threadlinqs maintains 106 detection rules mapped to T1583 (SPL 33, KQL 32, Sigma 41). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1583.001 Domains — 314 tracked threats
- T1583.002 DNS Server — 5 tracked threats
- T1583.003 Virtual Private Server — 72 tracked threats
- T1583.004 Server — 67 tracked threats
- T1583.005 Botnet — 19 tracked threats
- T1583.006 Web Services — 178 tracked threats
- T1583.007 Serverless — 5 tracked threats
- T1583.008 Malvertising — 35 tracked threats