Activity timeline
T1584.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 14 reports, and 41 of the 41 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1584.004 Server is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1584 Compromise Infrastructure. Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 11 critical, 27 high, 2 medium.
Threats that use T1584.004 most often also use T1071.001 Web Protocols (29 threats), T1005 Data from Local System (25 threats), T1027 Obfuscated Files or Information (22 threats), T1082 System Information Discovery (20 threats), T1036.005 Match Legitimate Resource Name or Location (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
25 tracked threat actors appear in the threats that use T1584.004; the most frequent are APT38 (5), Sapphire Sleet (5), Stardust Chollima (5), Andariel (4), Lazarus Group (4).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1584.004.
Data sources
Telemetry that can reveal T1584.004, per MITRE ATT&CK.
- Internet Scan — Response Content, Response Metadata
Threat actors using it
Tracked threats
The 30 most recent of 41 tracked threats that use T1584.004.
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Sitecritical
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…critical
- N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EUhigh
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affectedcritical
- China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…high
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…high
- Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCEcritical
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flowhigh
- StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…high
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…high
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…high
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…high
- Critical FreeRDP Clipboard Virtual Channel Heap Buffer Overflow (GHSA-cj9v-h4hq-29jr, CVSS 9.4)critical
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAThigh
- APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installerhigh
- Operation Fake KickOff — Attackers Abuse Recruiters and SaaS to Harvest Corporate Google Workspace Credentialshigh
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…high
- CISA BOD 26-04: Risk-Based Vulnerability Remediation and CISO Reporting Mandate for FCEB Agenciesmedium
- Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…high
- AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)high
- Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading…high
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion…high
- Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual Webshells via Database Injectioncritical
Detection coverage
Threadlinqs maintains 56 detection rules mapped to T1584.004 (SPL 19, KQL 18, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1584 Compromise Infrastructure — 164 tracked threats at the technique level.