# T1584.001 Domains

> As of 2026-10-05, T1584.001 (Domains) appears in 25 tracked threats, first reported 2026-01-14 and most recently 2026-10-01, with linked actors including APT38, ClickLock Dev, Gamaredon; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 25 (1 critical, 19 high, 5 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-01
- **Threat actors:** 13
- **Detection rules:** 28 (counts only; Blue tier and above)

## Key facts

- **ID:** T1584.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1584
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1584/001/

## Activity timeline

T1584.001 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 12 reports, and 25 of the 25 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1584.001 Domains is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584). Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 1 critical, 19 high, 5 medium.

Threats that use T1584.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (18 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (15 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (13 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (13 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

13 tracked threat actors appear in the threats that use T1584.001; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (1), [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (1), [Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel) (1), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1584.001.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1584.001, per MITRE ATT&CK.

- Domain Name — Active DNS, Domain Registration, Passive DNS

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 1
- [Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [Storm-1167](https://intel.threadlinqs.com/actor/Storm-1167) — 1
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 1
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 1
- [UNC6508](https://intel.threadlinqs.com/actor/UNC6508) — 1
- [UTA0304](https://intel.threadlinqs.com/actor/UTA0304) — 1

## Tracked threats

25 tracked threats use T1584.001.

- [ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing](https://intel.threadlinqs.com/threat/TL-2026-2826) — medium — 2026-10-01
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2554) — high — 2026-09-17
- [Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…](https://intel.threadlinqs.com/threat/TL-2026-2373) — critical — 2026-09-07
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — high — 2026-09-07
- [Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling…](https://intel.threadlinqs.com/threat/TL-2026-2022) — high — 2026-08-15
- [LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation"](https://intel.threadlinqs.com/threat/TL-2026-1818) — medium — 2026-08-02
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and…](https://intel.threadlinqs.com/threat/TL-2026-1686) — medium — 2026-07-25
- [Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-1676) — high — 2026-07-24
- ["The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365)…](https://intel.threadlinqs.com/threat/TL-2026-1593) — high — 2026-07-21
- [Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abuse](https://intel.threadlinqs.com/threat/TL-2026-1492) — high — 2026-07-18
- [PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…](https://intel.threadlinqs.com/threat/TL-2026-1416) — high — 2026-07-16
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS Infostealer](https://intel.threadlinqs.com/threat/TL-2026-1384) — high — 2026-07-15
- [China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations…](https://intel.threadlinqs.com/threat/TL-2026-1354) — high — 2026-07-15
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain…](https://intel.threadlinqs.com/threat/TL-2026-1050) — high — 2026-07-01
- [Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire /…](https://intel.threadlinqs.com/threat/TL-2026-1031) — high — 2026-07-01
- [EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…](https://intel.threadlinqs.com/threat/TL-2026-0888) — high — 2026-06-20
- [Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer](https://intel.threadlinqs.com/threat/TL-2026-1245) — medium — 2026-06-15
- [Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…](https://intel.threadlinqs.com/threat/TL-2026-0583) — high — 2026-05-25
- [JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…](https://intel.threadlinqs.com/threat/TL-2026-0490) — high — 2026-05-09
- [.arpa TLD Abuse — IPv6 Reverse DNS Phishing, Dangling CNAME Hijacking via Hurricane Electric and Cloudflare](https://intel.threadlinqs.com/threat/TL-2026-0154) — medium — 2026-02-28
- [DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web…](https://intel.threadlinqs.com/threat/TL-2026-0092) — high — 2026-01-14

## Related CVEs

CVEs referenced by the tracked threats that use T1584.001, most frequent first.

- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-7028](https://intel.threadlinqs.com/cve/CVE-2023-7028)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)

## Detection coverage

Threadlinqs maintains 28 detection rules mapped to T1584.001 (SPL 9, KQL 9, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

28 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584) — 164 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1584.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
