# T1583.006 Web Services

> As of 2026-10-05, T1583.006 (Web Services) appears in 178 tracked threats, first reported 2026-01-01 and most recently 2026-10-03, with linked actors including APT38, Lazarus Group, APT28; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 178 (13 critical, 132 high, 31 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-10-03
- **Threat actors:** 73
- **Detection rules:** 236 (counts only; Blue tier and above)

## Key facts

- **ID:** T1583.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1583
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1583/006/

## Activity timeline

T1583.006 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 49 reports, and 178 of the 178 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1583.006 Web Services is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583). Threadlinqs maps 178 of 2623 tracked threats (6.8%) to it; by severity that is 13 critical, 132 high, 31 medium.

Threats that use T1583.006 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (101 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (87 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (83 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (76 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (74 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

73 tracked threat actors appear in the threats that use T1583.006; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (5), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (5), [APT28](https://intel.threadlinqs.com/actor/APT28) (4), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (4), [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) (4).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1583.006.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1583.006, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 4
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 4
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 3
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 3
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 3
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 3
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 3
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 2
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 2

## Tracked threats

The 30 most recent of 178 tracked threats that use T1583.006.

- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2873) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach](https://intel.threadlinqs.com/threat/TL-2026-2842) — medium — 2026-10-01
- [Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and…](https://intel.threadlinqs.com/threat/TL-2026-2821) — medium — 2026-10-01
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled…](https://intel.threadlinqs.com/threat/TL-2026-2785) — medium — 2026-09-29
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…](https://intel.threadlinqs.com/threat/TL-2026-2773) — high — 2026-09-29
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…](https://intel.threadlinqs.com/threat/TL-2026-2673) — high — 2026-09-26
- [Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)](https://intel.threadlinqs.com/threat/TL-2026-2659) — high — 2026-09-26
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users](https://intel.threadlinqs.com/threat/TL-2026-2651) — high — 2026-09-25
- [UK establishes National Centre for Information Defence to counter Russian state disinformation operations](https://intel.threadlinqs.com/threat/TL-2026-2638) — high — 2026-09-24
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systems](https://intel.threadlinqs.com/threat/TL-2026-2612) — medium — 2026-09-22
- [Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install](https://intel.threadlinqs.com/threat/TL-2026-2597) — critical — 2026-09-21
- [Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…](https://intel.threadlinqs.com/threat/TL-2026-2595) — high — 2026-09-21
- [North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via…](https://intel.threadlinqs.com/threat/TL-2026-2581) — high — 2026-09-19
- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — high — 2026-09-18
- [Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google…](https://intel.threadlinqs.com/threat/TL-2026-2567) — medium — 2026-09-18
- [Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details](https://intel.threadlinqs.com/threat/TL-2026-2562) — medium — 2026-09-18
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data](https://intel.threadlinqs.com/threat/TL-2026-2550) — high — 2026-09-17
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via…](https://intel.threadlinqs.com/threat/TL-2026-2548) — medium — 2026-09-17
- [N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU](https://intel.threadlinqs.com/threat/TL-2026-2537) — high — 2026-09-16
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15

## Related CVEs

CVEs referenced by the tracked threats that use T1583.006, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-11371](https://intel.threadlinqs.com/cve/CVE-2025-11371)
- [CVE-2025-14611](https://intel.threadlinqs.com/cve/CVE-2025-14611)
- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-30208](https://intel.threadlinqs.com/cve/CVE-2025-30208)
- [CVE-2025-30406](https://intel.threadlinqs.com/cve/CVE-2025-30406)
- [CVE-2025-54068](https://intel.threadlinqs.com/cve/CVE-2025-54068)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-15718](https://intel.threadlinqs.com/cve/CVE-2026-15718)
- [CVE-2026-15719](https://intel.threadlinqs.com/cve/CVE-2026-15719)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-33824](https://intel.threadlinqs.com/cve/CVE-2026-33824)
- [CVE-2026-34197](https://intel.threadlinqs.com/cve/CVE-2026-34197)
- [CVE-2026-39987](https://intel.threadlinqs.com/cve/CVE-2026-39987)
- [CVE-2026-48318](https://intel.threadlinqs.com/cve/CVE-2026-48318)
- [CVE-2026-70125](https://intel.threadlinqs.com/cve/CVE-2026-70125)

## Detection coverage

Threadlinqs maintains 236 detection rules mapped to T1583.006 (SPL 70, KQL 71, Sigma 95). Rule content is available to Blue tier accounts and above; this page shows counts only.

236 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) — 611 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1583.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
