Activity timeline
T1584 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 71 reports, and 164 of the 164 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1584 Compromise Infrastructure is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 164 of 2623 tracked threats (6.3%) to it; by severity that is 32 critical, 108 high, 19 medium, 2 low.
Threats that use T1584 most often also use T1027 Obfuscated Files or Information (113 threats), T1071 Application Layer Protocol (110 threats), T1036 Masquerading (106 threats), T1583 Acquire Infrastructure (101 threats), T1059 Command and Scripting Interpreter (100 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
72 tracked threat actors appear in the threats that use T1584; the most frequent are APT28 (5), TeamPCP (5), APT38 (4), Sandworm (4), Static Tundra (4).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1584.
Data sources
Telemetry that can reveal T1584, per MITRE ATT&CK.
- Domain Name — Active DNS, Domain Registration, Passive DNS
- Internet Scan — Response Content, Response Metadata
Threat actors using it
Tracked threats
The 30 most recent of 164 tracked threats that use T1584.
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukrainehigh
- SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…high
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During…critical
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and…high
- ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…critical
- Cybercriminals Build Fake School Websites and Phishing Domains as Education-Sector Attacks Hit Record Highmedium
- Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…critical
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnethigh
- DeadLock Ransomware: Rust-Based Encryptor with Decentralized Recovery Infrastructure on Polygon and Sessionhigh
- BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Adminsmedium
- WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5…high
- CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for…
- AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat…high
- Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…high
- 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)medium
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…critical
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…critical
- Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…high
- CubePilot Drone Autopilot Vendor Hit by DNS Hijacking, Enabling Traffic Interception and Fraudulent TLS…high
- Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect)high
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Callshigh
- Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak…high
- SourTrade Malvertising: ServiceWorker-Orchestrated In-Browser Assembly Builds a Unique Windows Executable…high
- Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers…critical
- Google Threat Intelligence Group Unifies Threat Actor Naming Under New Cryptonym Systemlow
- FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.aihigh
Detection coverage
Threadlinqs maintains 64 detection rules mapped to T1584 (SPL 19, KQL 19, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1584.001 Domains — 25 tracked threats
- T1584.002 DNS Server — 3 tracked threats
- T1584.003 Virtual Private Server — 2 tracked threats
- T1584.004 Server — 41 tracked threats
- T1584.005 Botnet — 12 tracked threats
- T1584.006 Web Services — 25 tracked threats
- T1584.007 Serverless — 0 tracked threats
- T1584.008 Network Devices — 11 tracked threats