# T1583.003 Virtual Private Server

> As of 2026-10-05, T1583.003 (Virtual Private Server) appears in 72 tracked threats, first reported 2026-01-27 and most recently 2026-10-04, with linked actors including APT38, NoName057(16), 1VPNS; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 72 (19 critical, 40 high, 12 medium)
- **First seen:** 2026-01-27
- **Last seen:** 2026-10-04
- **Threat actors:** 52
- **Detection rules:** 65 (counts only; Blue tier and above)

## Key facts

- **ID:** T1583.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1583
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1583/003/

## Activity timeline

T1583.003 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 17 reports, and 72 of the 72 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1583.003 Virtual Private Server is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583). Threadlinqs maps 72 of 2623 tracked threats (2.7%) to it; by severity that is 19 critical, 40 high, 12 medium.

Threats that use T1583.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (36 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (30 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (29 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (28 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (25 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

52 tracked threat actors appear in the threats that use T1583.003; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) (3), [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) (2), [Cleaver](https://intel.threadlinqs.com/actor/Cleaver) (2), [MiniMax](https://intel.threadlinqs.com/actor/MiniMax) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1583.003.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1583.003, per MITRE ATT&CK.

- Internet Scan — Response Content, Response Metadata

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 3
- [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) — 2
- [Cleaver](https://intel.threadlinqs.com/actor/Cleaver) — 2
- [MiniMax](https://intel.threadlinqs.com/actor/MiniMax) — 2
- [Moonshot AI](https://intel.threadlinqs.com/actor/Moonshot%20AI) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 2
- [StepFun](https://intel.threadlinqs.com/actor/StepFun) — 2
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1

## Tracked threats

The 30 most recent of 72 tracked threats that use T1583.003.

- [Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty](https://intel.threadlinqs.com/threat/TL-2026-2908) — high — 2026-10-04
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…](https://intel.threadlinqs.com/threat/TL-2026-2678) — critical — 2026-09-26
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks](https://intel.threadlinqs.com/threat/TL-2026-2471) — high — 2026-09-12
- [Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…](https://intel.threadlinqs.com/threat/TL-2026-2469) — medium — 2026-09-12
- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — critical — 2026-09-09
- [China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier…](https://intel.threadlinqs.com/threat/TL-2026-2405) — high — 2026-09-08
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [Coordinated GitHub API Enumeration and Access Token Abuse Campaign](https://intel.threadlinqs.com/threat/TL-2026-2339) — high — 2026-09-05
- [DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network](https://intel.threadlinqs.com/threat/TL-2026-2309) — medium — 2026-09-03
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…](https://intel.threadlinqs.com/threat/TL-2026-2154) — high — 2026-08-26
- [AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627)](https://intel.threadlinqs.com/threat/TL-2026-2146) — high — 2026-08-25
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-2083) — critical — 2026-08-20
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [Linux Foundation Akrites Initiative: Coordinated Vulnerability Disclosure Platform for AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2073) — 2026-08-19
- [Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flow](https://intel.threadlinqs.com/threat/TL-2026-2071) — high — 2026-08-19
- [AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…](https://intel.threadlinqs.com/threat/TL-2026-2070) — critical — 2026-08-19
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)](https://intel.threadlinqs.com/threat/TL-2026-1909) — high — 2026-08-06
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…](https://intel.threadlinqs.com/threat/TL-2026-1693) — high — 2026-07-25
- [Critical FreeRDP Clipboard Virtual Channel Heap Buffer Overflow (GHSA-cj9v-h4hq-29jr, CVSS 9.4)](https://intel.threadlinqs.com/threat/TL-2026-1689) — critical — 2026-07-25
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet…](https://intel.threadlinqs.com/threat/TL-2026-1394) — medium — 2026-07-16
- ["Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign](https://intel.threadlinqs.com/threat/TL-2026-1356) — high — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use T1583.003, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2023-49105](https://intel.threadlinqs.com/cve/CVE-2023-49105)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-28000](https://intel.threadlinqs.com/cve/CVE-2024-28000)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2025-7443](https://intel.threadlinqs.com/cve/CVE-2025-7443)

## Detection coverage

Threadlinqs maintains 65 detection rules mapped to T1583.003 (SPL 15, KQL 22, Sigma 27, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

65 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) — 611 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1583.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
