# T1587.004 Exploits

> As of 2026-10-05, T1587.004 (Exploits) appears in 122 tracked threats, first reported 2026-02-05 and most recently 2026-09-30, with linked actors including APT28, Hacktron AI, Nightmare Eclipse; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 122 (63 critical, 49 high, 7 medium)
- **First seen:** 2026-02-05
- **Last seen:** 2026-09-30
- **Threat actors:** 17
- **Detection rules:** 78 (counts only; Blue tier and above)

## Key facts

- **ID:** T1587.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1587
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1587/004/

## Activity timeline

T1587.004 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 36 reports, and 122 of the 122 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1587.004 Exploits is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1587 Develop Capabilities](https://intel.threadlinqs.com/technique/T1587). Threadlinqs maps 122 of 2623 tracked threats (4.7%) to it; by severity that is 63 critical, 49 high, 7 medium.

Threats that use T1587.004 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (76 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (61 threats), [T1203 Exploitation for Client Execution](https://intel.threadlinqs.com/technique/T1203) (55 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (53 threats), [T1588.006 Vulnerabilities](https://intel.threadlinqs.com/technique/T1588.006) (53 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

17 tracked threat actors appear in the threats that use T1587.004; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (2), [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) (2), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (2), [UAT-9686](https://intel.threadlinqs.com/actor/UAT-9686) (2), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1587.004.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) — 2
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 2
- [UAT-9686](https://intel.threadlinqs.com/actor/UAT-9686) — 2
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1
- [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse) — 1

## Tracked threats

The 30 most recent of 122 tracked threats that use T1587.004.

- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…](https://intel.threadlinqs.com/threat/TL-2026-2818) — critical — 2026-09-30
- [Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks](https://intel.threadlinqs.com/threat/TL-2026-2745) — high — 2026-09-28
- [Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)](https://intel.threadlinqs.com/threat/TL-2026-2698) — high — 2026-09-27
- [Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…](https://intel.threadlinqs.com/threat/TL-2026-2662) — medium — 2026-09-26
- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — medium — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)](https://intel.threadlinqs.com/threat/TL-2026-2613) — medium — 2026-09-22
- [Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install](https://intel.threadlinqs.com/threat/TL-2026-2597) — critical — 2026-09-21
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — critical — 2026-09-19
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…](https://intel.threadlinqs.com/threat/TL-2026-2572) — high — 2026-09-18
- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — high — 2026-09-18
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — critical — 2026-09-14
- [CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2477) — high — 2026-09-13
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…](https://intel.threadlinqs.com/threat/TL-2026-2466) — critical — 2026-09-12
- [VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…](https://intel.threadlinqs.com/threat/TL-2026-2464) — high — 2026-09-12
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…](https://intel.threadlinqs.com/threat/TL-2026-2340) — critical — 2026-09-05
- [OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and…](https://intel.threadlinqs.com/threat/TL-2026-2332) — critical — 2026-09-04
- [Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusion](https://intel.threadlinqs.com/threat/TL-2026-2326) — high — 2026-09-04
- [HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege…](https://intel.threadlinqs.com/threat/TL-2026-2258) — medium — 2026-08-31
- [Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…](https://intel.threadlinqs.com/threat/TL-2026-2223) — high — 2026-08-29
- [CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host…](https://intel.threadlinqs.com/threat/TL-2026-2220) — high — 2026-08-29
- [Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchains](https://intel.threadlinqs.com/threat/TL-2026-2194) — critical — 2026-08-28
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)](https://intel.threadlinqs.com/threat/TL-2026-2156) — critical — 2026-08-26
- [Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Host](https://intel.threadlinqs.com/threat/TL-2026-2121) — critical — 2026-08-23

## Related CVEs

CVEs referenced by the tracked threats that use T1587.004, most frequent first.

- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2022-48503](https://intel.threadlinqs.com/cve/CVE-2022-48503)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)
- [CVE-2023-43000](https://intel.threadlinqs.com/cve/CVE-2023-43000)
- [CVE-2023-49105](https://intel.threadlinqs.com/cve/CVE-2023-49105)
- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)
- [CVE-2024-23222](https://intel.threadlinqs.com/cve/CVE-2024-23222)
- [CVE-2024-28000](https://intel.threadlinqs.com/cve/CVE-2024-28000)
- [CVE-2024-3393](https://intel.threadlinqs.com/cve/CVE-2024-3393)
- [CVE-2025-1094](https://intel.threadlinqs.com/cve/CVE-2025-1094)
- [CVE-2025-31718](https://intel.threadlinqs.com/cve/CVE-2025-31718)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-3450](https://intel.threadlinqs.com/cve/CVE-2025-3450)
- [CVE-2025-40552](https://intel.threadlinqs.com/cve/CVE-2025-40552)
- [CVE-2025-40553](https://intel.threadlinqs.com/cve/CVE-2025-40553)
- [CVE-2025-40554](https://intel.threadlinqs.com/cve/CVE-2025-40554)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-68461](https://intel.threadlinqs.com/cve/CVE-2025-68461)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-10881](https://intel.threadlinqs.com/cve/CVE-2026-10881)
- [CVE-2026-11622](https://intel.threadlinqs.com/cve/CVE-2026-11622)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)

## Detection coverage

Threadlinqs maintains 78 detection rules mapped to T1587.004 (SPL 24, KQL 23, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.

78 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1587 Develop Capabilities](https://intel.threadlinqs.com/technique/T1587) — 402 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1587.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
