Activity timeline
T1583.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 49 reports, and 178 of the 178 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1583.006 Web Services is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1583 Acquire Infrastructure. Threadlinqs maps 178 of 2623 tracked threats (6.8%) to it; by severity that is 13 critical, 132 high, 31 medium.
Threats that use T1583.006 most often also use T1071.001 Web Protocols (101 threats), T1036.005 Match Legitimate Resource Name or Location (87 threats), T1566.002 Spearphishing Link (83 threats), T1204.002 Malicious File (76 threats), T1027 Obfuscated Files or Information (74 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
73 tracked threat actors appear in the threats that use T1583.006; the most frequent are APT38 (5), Lazarus Group (5), APT28 (4), Andariel (4), UNC1549 (4).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1583.006.
Data sources
Telemetry that can reveal T1583.006, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
The 30 most recent of 178 tracked threats that use T1583.006.
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breachmedium
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and…medium
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…medium
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Thefthigh
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…high
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usershigh
- UK establishes National Centre for Information Defence to counter Russian state disinformation operationshigh
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…high
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Installcritical
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…high
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Accesshigh
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…medium
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Detailsmedium
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Datahigh
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…medium
- N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EUhigh
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…high
Detection coverage
Threadlinqs maintains 236 detection rules mapped to T1583.006 (SPL 70, KQL 71, Sigma 95). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1583 Acquire Infrastructure — 611 tracked threats at the technique level.