# T1584.004 Server

> As of 2026-10-05, T1584.004 (Server) appears in 41 tracked threats, first reported 2026-02-16 and most recently 2026-09-26, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 41 (11 critical, 27 high, 2 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-26
- **Threat actors:** 25
- **Detection rules:** 56 (counts only; Blue tier and above)

## Key facts

- **ID:** T1584.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1584
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1584/004/

## Activity timeline

T1584.004 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 14 reports, and 41 of the 41 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1584.004 Server is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584). Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 11 critical, 27 high, 2 medium.

Threats that use T1584.004 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (29 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (25 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (22 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (20 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

25 tracked threat actors appear in the threats that use T1584.004; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (5), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (5), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (5), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (4), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (4).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1584.004.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1584.004, per MITRE ATT&CK.

- Internet Scan — Response Content, Response Metadata

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 5
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 5
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Conti](https://intel.threadlinqs.com/actor/Conti) — 1

## Tracked threats

The 30 most recent of 41 tracked threats that use T1584.004.

- [ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Site](https://intel.threadlinqs.com/threat/TL-2026-2671) — critical — 2026-09-26
- [Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2664) — high — 2026-09-26
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…](https://intel.threadlinqs.com/threat/TL-2026-2561) — critical — 2026-09-18
- [N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU](https://intel.threadlinqs.com/threat/TL-2026-2537) — high — 2026-09-16
- [Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected](https://intel.threadlinqs.com/threat/TL-2026-2524) — critical — 2026-09-15
- [China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…](https://intel.threadlinqs.com/threat/TL-2026-2343) — high — 2026-09-05
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2273) — high — 2026-09-01
- [Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCE](https://intel.threadlinqs.com/threat/TL-2026-2157) — critical — 2026-08-26
- [Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…](https://intel.threadlinqs.com/threat/TL-2026-2126) — high — 2026-08-23
- [Password spraying attacks surge 155x as hackers exploit MFA gaps via Azure CLI / ROPC flow](https://intel.threadlinqs.com/threat/TL-2026-2071) — high — 2026-08-19
- [StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-2057) — high — 2026-08-18
- [Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side](https://intel.threadlinqs.com/threat/TL-2026-2002) — high — 2026-08-13
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…](https://intel.threadlinqs.com/threat/TL-2026-1797) — high — 2026-07-31
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…](https://intel.threadlinqs.com/threat/TL-2026-1777) — high — 2026-07-30
- [BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-1719) — high — 2026-07-27
- [Critical FreeRDP Clipboard Virtual Channel Heap Buffer Overflow (GHSA-cj9v-h4hq-29jr, CVSS 9.4)](https://intel.threadlinqs.com/threat/TL-2026-1689) — critical — 2026-07-25
- [Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT](https://intel.threadlinqs.com/threat/TL-2026-1552) — high — 2026-07-19
- [APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installer](https://intel.threadlinqs.com/threat/TL-2026-1526) — high — 2026-07-19
- [Operation Fake KickOff — Attackers Abuse Recruiters and SaaS to Harvest Corporate Google Workspace Credentials](https://intel.threadlinqs.com/threat/TL-2026-2395) — high — 2026-07-15
- [Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1161) — high — 2026-07-10
- [CISA BOD 26-04: Risk-Based Vulnerability Remediation and CISO Reporting Mandate for FCEB Agencies](https://intel.threadlinqs.com/threat/TL-2026-1134) — medium — 2026-07-06
- [Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…](https://intel.threadlinqs.com/threat/TL-2026-1095) — high — 2026-07-03
- [AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)](https://intel.threadlinqs.com/threat/TL-2026-1076) — high — 2026-07-02
- [Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading…](https://intel.threadlinqs.com/threat/TL-2026-1038) — high — 2026-07-01
- [ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion…](https://intel.threadlinqs.com/threat/TL-2026-1027) — high — 2026-07-01
- [Fake 'Beloved PBN Entegrasyonu' WordPress Plugin Drops Dual Webshells via Database Injection](https://intel.threadlinqs.com/threat/TL-2026-2205) — critical — 2026-06-16

## Related CVEs

CVEs referenced by the tracked threats that use T1584.004, most frequent first.

- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2022-2586](https://intel.threadlinqs.com/cve/CVE-2022-2586)
- [CVE-2023-0386](https://intel.threadlinqs.com/cve/CVE-2023-0386)
- [CVE-2023-20598](https://intel.threadlinqs.com/cve/CVE-2023-20598)
- [CVE-2023-44487](https://intel.threadlinqs.com/cve/CVE-2023-44487)
- [CVE-2023-4911](https://intel.threadlinqs.com/cve/CVE-2023-4911)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174)
- [CVE-2025-31277](https://intel.threadlinqs.com/cve/CVE-2025-31277)
- [CVE-2025-43510](https://intel.threadlinqs.com/cve/CVE-2025-43510)
- [CVE-2025-43520](https://intel.threadlinqs.com/cve/CVE-2025-43520)
- [CVE-2025-43529](https://intel.threadlinqs.com/cve/CVE-2025-43529)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-1281](https://intel.threadlinqs.com/cve/CVE-2026-1281)
- [CVE-2026-1340](https://intel.threadlinqs.com/cve/CVE-2026-1340)
- [CVE-2026-18431](https://intel.threadlinqs.com/cve/CVE-2026-18431)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-20700](https://intel.threadlinqs.com/cve/CVE-2026-20700)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-42608](https://intel.threadlinqs.com/cve/CVE-2026-42608)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-7482](https://intel.threadlinqs.com/cve/CVE-2026-7482)

## Detection coverage

Threadlinqs maintains 56 detection rules mapped to T1584.004 (SPL 19, KQL 18, Sigma 19). Rule content is available to Blue tier accounts and above; this page shows counts only.

56 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584) — 164 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1584.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
