Activity timeline
T1584.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-02 with 4 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1584.005 Botnet is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1584 Compromise Infrastructure. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 6 critical, 3 high, 3 medium.
Threats that use T1584.005 most often also use T1190 Exploit Public-Facing Application (10 threats), T1090.003 Multi-hop Proxy (6 threats), T1005 Data from Local System (5 threats), T1027 Obfuscated Files or Information (5 threats), T1041 Exfiltration Over C2 Channel (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1584.005; the most frequent are APT28 (1), INC Ransom (1), INC Ransom - G1032 (1), Lynx (1), Sandworm (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1584.005.
Threat actors using it
Tracked threats
12 tracked threats use T1584.005.
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Actionmedium
- Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitationcritical
- OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerabilitymedium
- UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653…high
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defensesmedium
- Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…critical
- APT31 Weaponizes Google Gemini AI for Automated Cyberattack Planningcritical
- Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…critical
- IPIDEA Residential Proxy Botnet Disruption by Googlehigh
Detection coverage
Threadlinqs maintains 9 detection rules mapped to T1584.005 (SPL 3, KQL 3, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1584 Compromise Infrastructure — 164 tracked threats at the technique level.