# T1583.004 Server

> As of 2026-10-05, T1583.004 (Server) appears in 67 tracked threats, first reported 2021-11-25 and most recently 2026-09-27, with linked actors including LockBit, ShinyHunters, TAG-179; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 67 (16 critical, 36 high, 14 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-09-27
- **Threat actors:** 31
- **Detection rules:** 45 (counts only; Blue tier and above)

## Key facts

- **ID:** T1583.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1583
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1583/004/

## Activity timeline

T1583.004 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 29 reports, and 66 of the 67 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1583.004 Server is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583). Threadlinqs maps 67 of 2623 tracked threats (2.6%) to it; by severity that is 16 critical, 36 high, 14 medium.

Threats that use T1583.004 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (35 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (34 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (34 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (32 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (30 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

31 tracked threat actors appear in the threats that use T1583.004; the most frequent are [LockBit](https://intel.threadlinqs.com/actor/LockBit) (2), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (2), [TAG-179](https://intel.threadlinqs.com/actor/TAG-179) (2), [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) (1), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1583.004.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1583.004, per MITRE ATT&CK.

- Internet Scan — Response Content, Response Metadata

## Threat actors using it

- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 2
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [TAG-179](https://intel.threadlinqs.com/actor/TAG-179) — 2
- [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) — 1
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 1
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 1
- [Clop](https://intel.threadlinqs.com/actor/Clop) — 1
- [Conti](https://intel.threadlinqs.com/actor/Conti) — 1

## Tracked threats

The 30 most recent of 67 tracked threats that use T1583.004.

- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…](https://intel.threadlinqs.com/threat/TL-2026-2658) — medium — 2026-09-25
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)](https://intel.threadlinqs.com/threat/TL-2026-2529) — high — 2026-09-15
- [VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…](https://intel.threadlinqs.com/threat/TL-2026-2464) — high — 2026-09-12
- [China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…](https://intel.threadlinqs.com/threat/TL-2026-2343) — high — 2026-09-05
- [DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network](https://intel.threadlinqs.com/threat/TL-2026-2309) — medium — 2026-09-03
- ["City-Forum" Campaign Mass-Enumerates Salesforce Experience Cloud and ServiceNow Portals via Guest Access](https://intel.threadlinqs.com/threat/TL-2026-1999) — high — 2026-08-12
- [SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1984) — critical — 2026-08-11
- [Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Address](https://intel.threadlinqs.com/threat/TL-2026-1975) — medium — 2026-08-10
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)](https://intel.threadlinqs.com/threat/TL-2026-1791) — medium — 2026-07-31
- [GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs](https://intel.threadlinqs.com/threat/TL-2026-1768) — high — 2026-07-30
- [Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments](https://intel.threadlinqs.com/threat/TL-2026-1765) — medium — 2026-07-29
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [Fastjson 1.x RCE (CVE-2026-16723) — Gadget-Free Deserialization Bypass Actively Exploited in Spring Boot…](https://intel.threadlinqs.com/threat/TL-2026-1682) — critical — 2026-07-25
- [Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…](https://intel.threadlinqs.com/threat/TL-2026-1643) — high — 2026-07-22
- [Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom](https://intel.threadlinqs.com/threat/TL-2026-1642) — medium — 2026-07-22
- [Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx\[.\]top)](https://intel.threadlinqs.com/threat/TL-2026-1621) — high — 2026-07-22
- [Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1580) — high — 2026-07-20
- [SleeperGem Supply-Chain Campaign Uses Three Malicious RubyGems Packages to Backdoor Developer Machines](https://intel.threadlinqs.com/threat/TL-2026-1575) — high — 2026-07-20
- [DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1485) — medium — 2026-07-18
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…](https://intel.threadlinqs.com/threat/TL-2026-1455) — high — 2026-07-17
- [LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container Runtime](https://intel.threadlinqs.com/threat/TL-2026-1367) — high — 2026-07-15
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — high — 2026-07-15
- [AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework](https://intel.threadlinqs.com/threat/TL-2026-1360) — critical — 2026-07-15

## Related CVEs

CVEs referenced by the tracked threats that use T1583.004, most frequent first.

- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2025-1218](https://intel.threadlinqs.com/cve/CVE-2025-1218)
- [CVE-2025-14181](https://intel.threadlinqs.com/cve/CVE-2025-14181)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)

## Detection coverage

Threadlinqs maintains 45 detection rules mapped to T1583.004 (SPL 14, KQL 15, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.

45 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) — 611 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1583.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
