Activity timeline
T1583.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 29 reports, and 66 of the 67 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1583.004 Server is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1583 Acquire Infrastructure. Threadlinqs maps 67 of 2623 tracked threats (2.6%) to it; by severity that is 16 critical, 36 high, 14 medium.
Threats that use T1583.004 most often also use T1082 System Information Discovery (35 threats), T1027 Obfuscated Files or Information (34 threats), T1071.001 Web Protocols (34 threats), T1005 Data from Local System (32 threats), T1041 Exfiltration Over C2 Channel (30 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
31 tracked threat actors appear in the threats that use T1583.004; the most frequent are LockBit (2), ShinyHunters (2), TAG-179 (2), 1VPNS (1), ALPHV (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1583.004.
Data sources
Telemetry that can reveal T1583.004, per MITRE ATT&CK.
- Internet Scan — Response Content, Response Metadata
Threat actors using it
Tracked threats
The 30 most recent of 67 tracked threats that use T1583.004.
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…critical
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…medium
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…medium
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)high
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…high
- China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…high
- DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Networkmedium
- "City-Forum" Campaign Mass-Enumerates Salesforce Experience Cloud and ServiceNow Portals via Guest Accesshigh
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)critical
- Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Addressmedium
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)medium
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPshigh
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Paymentsmedium
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- Fastjson 1.x RCE (CVE-2026-16723) — Gadget-Free Deserialization Bypass Actively Exploited in Spring Boot…critical
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…high
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransommedium
- Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx[.]top)high
- Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…high
- SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machineshigh
- DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaignsmedium
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container Runtimehigh
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chainhigh
- AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Frameworkcritical
Detection coverage
Threadlinqs maintains 45 detection rules mapped to T1583.004 (SPL 14, KQL 15, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1583 Acquire Infrastructure — 611 tracked threats at the technique level.