Activity timeline
T1584.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 12 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1584.006 Web Services is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1584 Compromise Infrastructure. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 7 critical, 15 high, 3 medium.
Threats that use T1584.006 most often also use T1027 Obfuscated Files or Information (14 threats), T1140 Deobfuscate/Decode Files or Information (14 threats), T1036.005 Match Legitimate Resource Name or Location (13 threats), T1071.001 Web Protocols (13 threats), T1005 Data from Local System (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
15 tracked threat actors appear in the threats that use T1584.006; the most frequent are APT-C-60 (1), APT36 (1), APT37 (1), Earth Lusca (1), Handala Hack (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1584.006.
Data sources
Telemetry that can reveal T1584.006, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
25 tracked threats use T1584.006.
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentialscritical
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)medium
- Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructurehigh
- Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channelhigh
- AI-Accelerated WordPress Plugin Vulnerability Research Surfaces 16 Unreported Bugs Across Dozens of Pluginshigh
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…critical
- Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)high
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoorcritical
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…critical
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…medium
- Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to…high
- Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process…high
- SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…high
- Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account…high
- Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader…critical
- Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users…high
- Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Brokerhigh
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…high
- Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installershigh
- Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailermedium
- Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packagescritical
- CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX…critical
Detection coverage
Threadlinqs maintains 29 detection rules mapped to T1584.006 (SPL 9, KQL 7, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1584 Compromise Infrastructure — 164 tracked threats at the technique level.