Activity timeline
T1583.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-02 with 6 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1583.005 Botnet is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1583 Acquire Infrastructure. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 3 critical, 8 high, 7 medium.
Threats that use T1583.005 most often also use T1071.001 Web Protocols (12 threats), T1027 Obfuscated Files or Information (9 threats), T1082 System Information Discovery (7 threats), T1190 Exploit Public-Facing Application (7 threats), T1036.005 Match Legitimate Resource Name or Location (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
12 tracked threat actors appear in the threats that use T1583.005; the most frequent are APT28 (1), Black Basta (1), Conti (1), Handala Hack (1), Handala Hack Team (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1583.005.
Threat actors using it
Tracked threats
19 tracked threats use T1583.005.
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networkshigh
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…high
- FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malwarehigh
- OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerabilitymedium
- 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…high
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…medium
- GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor…high
- Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% of Global RDP Internet Scanningmedium
- Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defensesmedium
- Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaScritical
- Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch…critical
- SystemBC Malware Resurges with 10K+ Infectionshigh
- Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel…high
- Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…critical
- IPIDEA Residential Proxy Botnet Disruption by Googlehigh
Detection coverage
Threadlinqs maintains 25 detection rules mapped to T1583.005 (SPL 7, KQL 9, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1583 Acquire Infrastructure — 611 tracked threats at the technique level.