# T1583 Acquire Infrastructure

> As of 2026-10-05, T1583 (Acquire Infrastructure) appears in 611 tracked threats, first reported 2021-11-25 and most recently 2026-09-27, with linked actors including TeamPCP, APT38, ShinyHunters; it most often appears alongside T1071 (Application Layer Protocol).

- **Tracked threats:** 611 (165 critical, 374 high, 65 medium, 2 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-09-27
- **Threat actors:** 173
- **Detection rules:** 106 (counts only; Blue tier and above)

## Key facts

- **ID:** T1583
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1583/

## Activity timeline

T1583 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 185 reports, and 610 of the 611 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1583 Acquire Infrastructure is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 611 of 2623 tracked threats (23.3%) to it; by severity that is 165 critical, 374 high, 65 medium, 2 low.

Threats that use T1583 most often also use [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (398 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (373 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (354 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (347 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (323 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

173 tracked threat actors appear in the threats that use T1583; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (17), [APT38](https://intel.threadlinqs.com/actor/APT38) (14), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (11), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (10), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (9).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1583.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1583, per MITRE ATT&CK.

- Domain Name — Active DNS, Domain Registration, Passive DNS
- Internet Scan — Response Content, Response Metadata

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 17
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 14
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 11
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 10
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 9
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 8
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 8
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 7
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 7
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 7
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 6

## Tracked threats

The 30 most recent of 611 tracked threats that use T1583.

- [Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2707) — medium — 2026-09-27
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel](https://intel.threadlinqs.com/threat/TL-2026-2609) — high — 2026-09-21
- [Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated](https://intel.threadlinqs.com/threat/TL-2026-2598) — high — 2026-09-21
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…](https://intel.threadlinqs.com/threat/TL-2026-2469) — medium — 2026-09-12
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique](https://intel.threadlinqs.com/threat/TL-2026-2441) — medium — 2026-09-11
- [ClickFix Lures Deploy MacSync Stealer to Bypass macOS Security](https://intel.threadlinqs.com/threat/TL-2026-2434) — high — 2026-09-10
- [Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teams](https://intel.threadlinqs.com/threat/TL-2026-2430) — medium — 2026-09-10
- [Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2416) — high — 2026-09-09
- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — critical — 2026-09-09
- [ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2338) — high — 2026-09-05
- [BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…](https://intel.threadlinqs.com/threat/TL-2026-2315) — high — 2026-09-03
- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…](https://intel.threadlinqs.com/threat/TL-2026-2304) — high — 2026-09-03
- [Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending Protocol](https://intel.threadlinqs.com/threat/TL-2026-2261) — critical — 2026-08-31
- [Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync…](https://intel.threadlinqs.com/threat/TL-2026-2241) — high — 2026-08-30
- [Cybercriminals Build Fake School Websites and Phishing Domains as Education-Sector Attacks Hit Record High](https://intel.threadlinqs.com/threat/TL-2026-2236) — medium — 2026-08-30
- [Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2235) — high — 2026-08-30
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industry](https://intel.threadlinqs.com/threat/TL-2026-2175) — high — 2026-08-28
- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…](https://intel.threadlinqs.com/threat/TL-2026-2170) — high — 2026-08-26
- [Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2158) — high — 2026-08-26
- [24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login…](https://intel.threadlinqs.com/threat/TL-2026-2150) — medium — 2026-08-26
- [AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhones](https://intel.threadlinqs.com/threat/TL-2026-2141) — high — 2026-08-24
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21

## Related CVEs

CVEs referenced by the tracked threats that use T1583, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2021-22205](https://intel.threadlinqs.com/cve/CVE-2021-22205)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)

## Detection coverage

Threadlinqs maintains 106 detection rules mapped to T1583 (SPL 33, KQL 32, Sigma 41). Rule content is available to Blue tier accounts and above; this page shows counts only.

106 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) — 314 tracked threats
- T1583.002 DNS Server — 5 tracked threats
- [T1583.003 Virtual Private Server](https://intel.threadlinqs.com/technique/T1583.003) — 72 tracked threats
- [T1583.004 Server](https://intel.threadlinqs.com/technique/T1583.004) — 67 tracked threats
- [T1583.005 Botnet](https://intel.threadlinqs.com/technique/T1583.005) — 19 tracked threats
- [T1583.006 Web Services](https://intel.threadlinqs.com/technique/T1583.006) — 178 tracked threats
- T1583.007 Serverless — 5 tracked threats
- [T1583.008 Malvertising](https://intel.threadlinqs.com/technique/T1583.008) — 35 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1583
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
