Activity timeline
T1583.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 17 reports, and 72 of the 72 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1583.003 Virtual Private Server is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1583 Acquire Infrastructure. Threadlinqs maps 72 of 2623 tracked threats (2.7%) to it; by severity that is 19 critical, 40 high, 12 medium.
Threats that use T1583.003 most often also use T1071.001 Web Protocols (36 threats), T1041 Exfiltration Over C2 Channel (30 threats), T1027 Obfuscated Files or Information (29 threats), T1005 Data from Local System (28 threats), T1036.005 Match Legitimate Resource Name or Location (25 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
52 tracked threat actors appear in the threats that use T1583.003; the most frequent are APT38 (3), NoName057(16) (3), 1VPNS (2), Cleaver (2), MiniMax (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1583.003.
Data sources
Telemetry that can reveal T1583.003, per MITRE ATT&CK.
- Internet Scan — Response Content, Response Metadata
Threat actors using it
Tracked threats
The 30 most recent of 72 tracked threats that use T1583.003.
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…critical
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Monthshigh
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networkshigh
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Modelscritical
- China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier…high
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypasscritical
- Coordinated GitHub API Enumeration and Access Token Abuse Campaignhigh
- DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Networkmedium
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…high
- AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627)high
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attackcritical
- CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russiahigh
- Linux Foundation Akrites Initiative: Coordinated Vulnerability Disclosure Platform for AI-Enabled…
- Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flowhigh
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…critical
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimihigh
- CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)high
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…high
- Critical FreeRDP Clipboard Virtual Channel Heap Buffer Overflow (GHSA-cj9v-h4hq-29jr, CVSS 9.4)critical
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet…medium
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaignhigh
Detection coverage
Threadlinqs maintains 65 detection rules mapped to T1583.003 (SPL 15, KQL 22, Sigma 27, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1583 Acquire Infrastructure — 611 tracked threats at the technique level.