# T1584.005 Botnet

> As of 2026-10-05, T1584.005 (Botnet) appears in 12 tracked threats, first reported 2026-02-03 and most recently 2026-09-26, with linked actors including APT28, INC Ransom, INC Ransom - G1032; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 12 (6 critical, 3 high, 3 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-09-26
- **Threat actors:** 6
- **Detection rules:** 9 (counts only; Blue tier and above)

## Key facts

- **ID:** T1584.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1584
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1584/005/

## Activity timeline

T1584.005 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-09-26. The busiest month was 2026-02 with 4 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1584.005 Botnet is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584). Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 6 critical, 3 high, 3 medium.

Threats that use T1584.005 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (10 threats), [T1090.003 Multi-hop Proxy](https://intel.threadlinqs.com/technique/T1090.003) (6 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (5 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (5 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1584.005; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) (1), [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) (1), [Lynx](https://intel.threadlinqs.com/actor/Lynx) (1), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1584.005.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) — 1

## Tracked threats

12 tracked threats use T1584.005.

- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…](https://intel.threadlinqs.com/threat/TL-2026-2595) — high — 2026-09-21
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2037) — critical — 2026-08-13
- [OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-1554) — medium — 2026-07-20
- [UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653…](https://intel.threadlinqs.com/threat/TL-2026-1257) — high — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [Residential Proxy Rotation Networks Defeat IP-Reputation-Based Defenses](https://intel.threadlinqs.com/threat/TL-2026-1467) — medium — 2026-04-02
- [Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon…](https://intel.threadlinqs.com/threat/TL-2026-0123) — critical — 2026-02-21
- [APT31 Weaponizes Google Gemini AI for Automated Cyberattack Planning](https://intel.threadlinqs.com/threat/TL-2026-0085) — critical — 2026-02-15
- [Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…](https://intel.threadlinqs.com/threat/TL-2026-0098) — critical — 2026-02-05
- [IPIDEA Residential Proxy Botnet Disruption by Google](https://intel.threadlinqs.com/threat/TL-2026-0042) — high — 2026-02-03

## Related CVEs

CVEs referenced by the tracked threats that use T1584.005, most frequent first.

- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-65660](https://intel.threadlinqs.com/cve/CVE-2026-65660)
- [CVE-2026-67276](https://intel.threadlinqs.com/cve/CVE-2026-67276)
- [CVE-2026-67277](https://intel.threadlinqs.com/cve/CVE-2026-67277)
- [CVE-2026-67278](https://intel.threadlinqs.com/cve/CVE-2026-67278)
- [CVE-2026-67279](https://intel.threadlinqs.com/cve/CVE-2026-67279)
- [CVE-2026-67281](https://intel.threadlinqs.com/cve/CVE-2026-67281)
- [CVE-2026-86060](https://intel.threadlinqs.com/cve/CVE-2026-86060)

## Detection coverage

Threadlinqs maintains 9 detection rules mapped to T1584.005 (SPL 3, KQL 3, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

9 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584) — 164 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1584.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
