Activity timeline
T1584.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 12 reports, and 25 of the 25 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1584.001 Domains is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1584 Compromise Infrastructure. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 1 critical, 19 high, 5 medium.
Threats that use T1584.001 most often also use T1071.001 Web Protocols (18 threats), T1204.002 Malicious File (15 threats), T1027 Obfuscated Files or Information (13 threats), T1036.005 Match Legitimate Resource Name or Location (13 threats), T1082 System Information Discovery (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
13 tracked threat actors appear in the threats that use T1584.001; the most frequent are APT38 (1), ClickLock Dev (1), Gamaredon (1), Sable Squirrel (1), Sapphire Sleet (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1584.001.
Data sources
Telemetry that can reveal T1584.001, per MITRE ATT&CK.
- Domain Name — Active DNS, Domain Registration, Passive DNS
Threat actors using it
Tracked threats
25 tracked threats use T1584.001.
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishingmedium
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…high
- Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…critical
- Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructurehigh
- Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling…high
- LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"medium
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and…medium
- Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…high
- "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…high
- Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abusehigh
- PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…high
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS Infostealerhigh
- China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations…high
- Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…high
- Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain…high
- Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire /…high
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…high
- Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailermedium
- Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…high
- JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…high
- .arpa TLD Abuse — IPv6 Reverse DNS Phishing, Dangling CNAME Hijacking via Hurricane Electric and Cloudflaremedium
- DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web…high
Detection coverage
Threadlinqs maintains 28 detection rules mapped to T1584.001 (SPL 9, KQL 9, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1584 Compromise Infrastructure — 164 tracked threats at the technique level.