# T1584.006 Web Services

> As of 2026-10-05, T1584.006 (Web Services) appears in 25 tracked threats, first reported 2026-04-10 and most recently 2026-09-26, with linked actors including APT-C-60, APT36, APT37; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 25 (7 critical, 15 high, 3 medium)
- **First seen:** 2026-04-10
- **Last seen:** 2026-09-26
- **Threat actors:** 15
- **Detection rules:** 29 (counts only; Blue tier and above)

## Key facts

- **ID:** T1584.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1584
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1584/006/

## Activity timeline

T1584.006 first appeared in tracked threats on 2026-04-10 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 12 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1584.006 Web Services is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584). Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 7 critical, 15 high, 3 medium.

Threats that use T1584.006 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (14 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (14 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (13 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (13 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

15 tracked threat actors appear in the threats that use T1584.006; the most frequent are [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) (1), [APT36](https://intel.threadlinqs.com/actor/APT36) (1), [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) (1), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1584.006.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1584.006, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60) — 1
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1
- [REvil](https://intel.threadlinqs.com/actor/REvil) — 1
- [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) — 1
- [Storm-2372](https://intel.threadlinqs.com/actor/Storm-2372) — 1
- [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945) — 1
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 1
- [UTA0304](https://intel.threadlinqs.com/actor/UTA0304) — 1
- [UTA0307](https://intel.threadlinqs.com/actor/UTA0307) — 1

## Tracked threats

25 tracked threats use T1584.006.

- [Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)](https://intel.threadlinqs.com/threat/TL-2026-2659) — high — 2026-09-26
- [EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials](https://intel.threadlinqs.com/threat/TL-2026-2600) — critical — 2026-09-21
- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…](https://intel.threadlinqs.com/threat/TL-2026-2527) — high — 2026-09-15
- [Trezor Warns of Phishing Attacks After Third-Party Email Provider Breach ("STM32 Entropy Vulnerability" Lure)](https://intel.threadlinqs.com/threat/TL-2026-2432) — medium — 2026-09-10
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — high — 2026-09-07
- [Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel](https://intel.threadlinqs.com/threat/TL-2026-2311) — high — 2026-09-03
- [AI-Accelerated WordPress Plugin Vulnerability Research Surfaces 16 Unreported Bugs Across Dozens of Plugins](https://intel.threadlinqs.com/threat/TL-2026-2021) — high — 2026-08-15
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…](https://intel.threadlinqs.com/threat/TL-2026-1649) — critical — 2026-07-23
- [Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)](https://intel.threadlinqs.com/threat/TL-2026-1521) — high — 2026-07-19
- [Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1404) — critical — 2026-07-16
- [Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…](https://intel.threadlinqs.com/threat/TL-2026-1403) — critical — 2026-07-16
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…](https://intel.threadlinqs.com/threat/TL-2026-1309) — medium — 2026-07-14
- [Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to…](https://intel.threadlinqs.com/threat/TL-2026-1297) — high — 2026-07-14
- [Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process…](https://intel.threadlinqs.com/threat/TL-2026-1285) — high — 2026-07-13
- [SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr…](https://intel.threadlinqs.com/threat/TL-2026-1284) — high — 2026-07-13
- [Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account…](https://intel.threadlinqs.com/threat/TL-2026-1139) — high — 2026-07-06
- [Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader…](https://intel.threadlinqs.com/threat/TL-2026-1077) — critical — 2026-07-02
- [Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users…](https://intel.threadlinqs.com/threat/TL-2026-1046) — high — 2026-07-01
- [Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Broker](https://intel.threadlinqs.com/threat/TL-2026-2277) — high — 2026-06-24
- [EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing…](https://intel.threadlinqs.com/threat/TL-2026-0888) — high — 2026-06-20
- [Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers](https://intel.threadlinqs.com/threat/TL-2026-0822) — high — 2026-06-16
- [Compromised RD Session Host Used to Stage Boots-Themed Phishing Campaign via Gammadyne Mailer](https://intel.threadlinqs.com/threat/TL-2026-1245) — medium — 2026-06-15
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [CPUID Supply Chain Compromise — Trojanized CPU-Z 2.19, HWMonitor 1.63, PerfMonitor 2, and powerMAX…](https://intel.threadlinqs.com/threat/TL-2026-0347) — critical — 2026-04-10

## Related CVEs

CVEs referenced by the tracked threats that use T1584.006, most frequent first.

- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2026-15718](https://intel.threadlinqs.com/cve/CVE-2026-15718)
- [CVE-2026-15719](https://intel.threadlinqs.com/cve/CVE-2026-15719)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-48318](https://intel.threadlinqs.com/cve/CVE-2026-48318)
- [CVE-2026-70125](https://intel.threadlinqs.com/cve/CVE-2026-70125)

## Detection coverage

Threadlinqs maintains 29 detection rules mapped to T1584.006 (SPL 9, KQL 7, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

29 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584) — 164 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1584.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
