# T1583.005 Botnet

> As of 2026-10-05, T1583.005 (Botnet) appears in 19 tracked threats, first reported 2026-02-03 and most recently 2026-09-26, with linked actors including APT28, Black Basta, Conti; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 19 (3 critical, 8 high, 7 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-09-26
- **Threat actors:** 12
- **Detection rules:** 25 (counts only; Blue tier and above)

## Key facts

- **ID:** T1583.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1583
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1583/005/

## Activity timeline

T1583.005 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-09-26. The busiest month was 2026-02 with 6 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1583.005 Botnet is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583). Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 3 critical, 8 high, 7 medium.

Threats that use T1583.005 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (12 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (9 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (7 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (7 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

12 tracked threat actors appear in the threats that use T1583.005; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) (1), [Conti](https://intel.threadlinqs.com/actor/Conti) (1), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (1), [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1583.005.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1
- [Conti](https://intel.threadlinqs.com/actor/Conti) — 1
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1
- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) — 1
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 1

## Tracked threats

19 tracked threats use T1583.005.

- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks](https://intel.threadlinqs.com/threat/TL-2026-2471) — high — 2026-09-12
- [Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…](https://intel.threadlinqs.com/threat/TL-2026-2469) — medium — 2026-09-12
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…](https://intel.threadlinqs.com/threat/TL-2026-2154) — high — 2026-08-26
- [FakeGit Campaign Uses 7,600 GitHub Repositories with AgentBaiting to Spread SmartLoader & StealC Malware](https://intel.threadlinqs.com/threat/TL-2026-1565) — high — 2026-07-20
- [OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-1554) — medium — 2026-07-20
- [313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…](https://intel.threadlinqs.com/threat/TL-2026-1374) — high — 2026-07-15
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…](https://intel.threadlinqs.com/threat/TL-2026-1309) — medium — 2026-07-14
- [GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor…](https://intel.threadlinqs.com/threat/TL-2026-0617) — high — 2026-05-28
- [Concentrated 21-IP Cluster (AS213438/ColocaTel) Behind ~50% of Global RDP Internet Scanning](https://intel.threadlinqs.com/threat/TL-2026-1466) — medium — 2026-04-10
- [Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defenses](https://intel.threadlinqs.com/threat/TL-2026-1467) — medium — 2026-04-02
- [Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaS](https://intel.threadlinqs.com/threat/TL-2026-0151) — critical — 2026-02-27
- [Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch…](https://intel.threadlinqs.com/threat/TL-2026-0121) — critical — 2026-02-16
- [SystemBC Malware Resurges with 10K+ Infections](https://intel.threadlinqs.com/threat/TL-2026-0101) — high — 2026-02-16
- [Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel…](https://intel.threadlinqs.com/threat/TL-2026-0099) — high — 2026-02-16
- [Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…](https://intel.threadlinqs.com/threat/TL-2026-0098) — critical — 2026-02-05
- [IPIDEA Residential Proxy Botnet Disruption by Google](https://intel.threadlinqs.com/threat/TL-2026-0042) — high — 2026-02-03

## Related CVEs

CVEs referenced by the tracked threats that use T1583.005, most frequent first.

- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2026-1281](https://intel.threadlinqs.com/cve/CVE-2026-1281)
- [CVE-2026-1340](https://intel.threadlinqs.com/cve/CVE-2026-1340)

## Detection coverage

Threadlinqs maintains 25 detection rules mapped to T1583.005 (SPL 7, KQL 9, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.

25 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) — 611 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1583.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
