# T1584.008 Network Devices

> As of 2026-10-05, T1584.008 (Network Devices) appears in 11 tracked threats, first reported 2026-06-20 and most recently 2026-10-03, with linked actors including APT28, BlueDelta, Cyber Av3ngers; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 11 (2 critical, 8 high, 1 medium)
- **First seen:** 2026-06-20
- **Last seen:** 2026-10-03
- **Threat actors:** 9
- **Detection rules:** 21 (counts only; Blue tier and above)

## Key facts

- **ID:** T1584.008
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1584
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1584/008/

## Activity timeline

T1584.008 first appeared in tracked threats on 2026-06-20 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 4 reports, and 11 of the 11 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1584.008 Network Devices is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 8 high, 1 medium.

Threats that use T1584.008 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (6 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (6 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (4 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (4 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (4 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1584.008; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (1), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) (1), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (1), [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) (1).

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1
- [UNC2452](https://intel.threadlinqs.com/actor/UNC2452) — 1
- [UNC6508](https://intel.threadlinqs.com/actor/UNC6508) — 1

## Tracked threats

11 tracked threats use T1584.008.

- [BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…](https://intel.threadlinqs.com/threat/TL-2026-2875) — high — 2026-10-03
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [FBI, DOJ, and RCMP Seize NightmareStresser DDoS-for-Hire Domains in Latest Operation PowerOFF Action](https://intel.threadlinqs.com/threat/TL-2026-2549) — medium — 2026-09-17
- [BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2](https://intel.threadlinqs.com/threat/TL-2026-2520) — high — 2026-09-15
- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — critical — 2026-09-03
- [Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2058) — high — 2026-08-18
- [CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign](https://intel.threadlinqs.com/threat/TL-2026-2765) — high — 2026-07-31
- [FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable…](https://intel.threadlinqs.com/threat/TL-2026-2375) — high — 2026-07-13
- [UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653…](https://intel.threadlinqs.com/threat/TL-2026-1257) — high — 2026-07-13
- [CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)](https://intel.threadlinqs.com/threat/TL-2026-1188) — critical — 2026-07-10
- [UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North…](https://intel.threadlinqs.com/threat/TL-2026-0891) — high — 2026-06-20

## Related CVEs

CVEs referenced by the tracked threats that use T1584.008, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)

## Detection coverage

Threadlinqs maintains 21 detection rules mapped to T1584.008 (SPL 7, KQL 7, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

21 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1584 Compromise Infrastructure](https://intel.threadlinqs.com/technique/T1584) — 164 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1584.008
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
