Activity timeline
T1588 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 125 reports, and 363 of the 363 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1588 Obtain Capabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 363 of 2623 tracked threats (13.8%) to it; by severity that is 138 critical, 184 high, 34 medium, 2 low.
Threats that use T1588 most often also use T1059 Command and Scripting Interpreter (236 threats), T1071 Application Layer Protocol (232 threats), T1005 Data from Local System (196 threats), T1583 Acquire Infrastructure (192 threats), T1190 Exploit Public-Facing Application (190 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
122 tracked threat actors appear in the threats that use T1588; the most frequent are ShinyHunters (8), MuddyWater (7), The Com (7), APT28 (6), Scattered LAPSUS$ Hunters (6).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1588.
Data sources
Telemetry that can reveal T1588, per MITRE ATT&CK.
- Certificate — Certificate Registration
- Internet Scan — Response Content
- Malware Repository — Malware Content, Malware Metadata
Threat actors using it
Tracked threats
The 30 most recent of 363 tracked threats that use T1588.
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonationhigh
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypasshigh
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…high
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortionhigh
- ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…high
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…critical
- Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively Exploitedcritical
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and Indiahigh
- Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…critical
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurecritical
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaignhigh
- Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…high
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRighigh
- Metabase Unauthenticated SQL Injection 0-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Admin Takeovercritical
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Hosthigh
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted…high
- Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856…high
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…critical
- AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…critical
- npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for…critical
- NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825…critical
- EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack…medium
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolencritical
Detection coverage
Threadlinqs maintains 31 detection rules mapped to T1588 (SPL 12, KQL 6, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1588.001 Malware — 38 tracked threats
- T1588.002 Tool — 153 tracked threats
- T1588.003 Code Signing Certificates — 21 tracked threats
- T1588.004 Digital Certificates — 6 tracked threats
- T1588.005 Exploits — 129 tracked threats
- T1588.006 Vulnerabilities — 125 tracked threats
- T1588.007 Artificial Intelligence — 21 tracked threats