Activity timeline
T1588.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 18 reports, and 38 of the 38 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1588.001 Malware is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1588 Obtain Capabilities. Threadlinqs maps 38 of 2623 tracked threats (1.4%) to it; by severity that is 9 critical, 21 high, 7 medium.
Threats that use T1588.001 most often also use T1005 Data from Local System (23 threats), T1071.001 Web Protocols (22 threats), T1082 System Information Discovery (22 threats), T1027 Obfuscated Files or Information (21 threats), T1041 Exfiltration Over C2 Channel (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
32 tracked threat actors appear in the threats that use T1588.001; the most frequent are 1VPNS (2), APT10 (1), APT28 (1), APT32 (1), APT37 (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1588.001.
Data sources
Telemetry that can reveal T1588.001, per MITRE ATT&CK.
- Malware Repository — Malware Content, Malware Metadata
Threat actors using it
Tracked threats
The 30 most recent of 38 tracked threats that use T1588.001.
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…high
- Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…high
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accountshigh
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…critical
- CVE-2026-70329: Microsoft Outlook Remote Code Execution via Integer Overflowhigh
- Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscationhigh
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of…high
- Joyfill npm Packages Compromised with Blockchain C2 Loadermedium
- Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)critical
- ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales…medium
- OTTERCOOKIE Malware Hidden in SVG Flag Images Backdoors Developers via Fake Coding Tests (Contagious…high
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign…high
- Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Productionhigh
- PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…high
- AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Frameworkcritical
- Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS Botnetcritical
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…high
- US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operationsmedium
- OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy…medium
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain…medium
- Zhipu AI's GLM-5.2 Matches Export-Controlled Claude Mythos on IDOR Vulnerability Detection
- Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)medium
- Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abusehigh
- Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader…critical
- StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)high
- Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service…high
- CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day Exploited In-the-Wild Against Ukrainian Entities…high
Detection coverage
Threadlinqs maintains 16 detection rules mapped to T1588.001 (SPL 1, KQL 6, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1588 Obtain Capabilities — 363 tracked threats at the technique level.