Activity timeline
T1588.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 48 reports, and 153 of the 153 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1588.002 Tool is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1588 Obtain Capabilities. Threadlinqs maps 153 of 2623 tracked threats (5.8%) to it; by severity that is 56 critical, 78 high, 12 medium.
Threats that use T1588.002 most often also use T1071.001 Web Protocols (67 threats), T1190 Exploit Public-Facing Application (67 threats), T1005 Data from Local System (64 threats), T1041 Exfiltration Over C2 Channel (55 threats), T1027 Obfuscated Files or Information (54 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
65 tracked threat actors appear in the threats that use T1588.002; the most frequent are ShinyHunters (4), APT38 (3), MuddyWater (3), Scattered Spider (3), TeamPCP (3).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1588.002.
Data sources
Telemetry that can reveal T1588.002, per MITRE ATT&CK.
- Malware Repository — Malware Metadata
Threat actors using it
Tracked threats
The 30 most recent of 153 tracked threats that use T1588.002.
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…high
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rowshigh
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)critical
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…critical
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)high
- Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connectorhigh
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypasscritical
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…medium
- Frontier AI Agents Compress Full Enterprise Intrusion Chain into Under 10 Hours (Unit 42 Investigation)high
- Coordinated GitHub API Enumeration and Access Token Abuse Campaignhigh
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interceptionhigh
- FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…high
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending Protocolcritical
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…high
- TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per Hourhigh
- Snowflake GitHub Actions Workflow Injection Exposes Internal Jira Credentialshigh
- Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBIcritical
- Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…critical
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusionhigh
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…critical
- CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…high
- CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russiahigh
- Linux Foundation Akrites Initiative: Coordinated Vulnerability Disclosure Platform for AI-Enabled…
Detection coverage
Threadlinqs maintains 113 detection rules mapped to T1588.002 (SPL 33, KQL 40, Sigma 40). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1588 Obtain Capabilities — 363 tracked threats at the technique level.