# T1588.002 Tool

> As of 2026-10-05, T1588.002 (Tool) appears in 153 tracked threats, first reported 2026-01-27 and most recently 2026-10-03, with linked actors including ShinyHunters, APT38, MuddyWater; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 153 (56 critical, 78 high, 12 medium)
- **First seen:** 2026-01-27
- **Last seen:** 2026-10-03
- **Threat actors:** 65
- **Detection rules:** 113 (counts only; Blue tier and above)

## Key facts

- **ID:** T1588.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1588
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1588/002/

## Activity timeline

T1588.002 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 48 reports, and 153 of the 153 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1588.002 Tool is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588). Threadlinqs maps 153 of 2623 tracked threats (5.8%) to it; by severity that is 56 critical, 78 high, 12 medium.

Threats that use T1588.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (67 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (67 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (64 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (55 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (54 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

65 tracked threat actors appear in the threats that use T1588.002; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (4), [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (3), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (3), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1588.002.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1588.002, per MITRE ATT&CK.

- Malware Repository — Malware Metadata

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 3
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 2
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 2
- [Balonx](https://intel.threadlinqs.com/actor/Balonx) — 2
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 2
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 2
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 2

## Tracked threats

The 30 most recent of 153 tracked threats that use T1588.002.

- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows](https://intel.threadlinqs.com/threat/TL-2026-2675) — high — 2026-09-26
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…](https://intel.threadlinqs.com/threat/TL-2026-2611) — critical — 2026-09-21
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector](https://intel.threadlinqs.com/threat/TL-2026-2425) — high — 2026-09-09
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…](https://intel.threadlinqs.com/threat/TL-2026-2352) — medium — 2026-09-06
- [Frontier AI Agents Compress Full Enterprise Intrusion Chain into Under 10 Hours (Unit 42 Investigation)](https://intel.threadlinqs.com/threat/TL-2026-2341) — high — 2026-09-05
- [Coordinated GitHub API Enumeration and Access Token Abuse Campaign](https://intel.threadlinqs.com/threat/TL-2026-2339) — high — 2026-09-05
- [Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception](https://intel.threadlinqs.com/threat/TL-2026-2294) — high — 2026-09-02
- [FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial…](https://intel.threadlinqs.com/threat/TL-2026-2286) — high — 2026-09-01
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending Protocol](https://intel.threadlinqs.com/threat/TL-2026-2261) — critical — 2026-08-31
- [Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…](https://intel.threadlinqs.com/threat/TL-2026-2223) — high — 2026-08-29
- [TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per Hour](https://intel.threadlinqs.com/threat/TL-2026-2190) — high — 2026-08-28
- [Snowflake GitHub Actions Workflow Injection Exposes Internal Jira Credentials](https://intel.threadlinqs.com/threat/TL-2026-2189) — high — 2026-08-28
- [Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBI](https://intel.threadlinqs.com/threat/TL-2026-2186) — critical — 2026-08-28
- [Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271…](https://intel.threadlinqs.com/threat/TL-2026-2185) — critical — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2176) — high — 2026-08-28
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…](https://intel.threadlinqs.com/threat/TL-2026-2143) — critical — 2026-08-25
- [CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta…](https://intel.threadlinqs.com/threat/TL-2026-2135) — high — 2026-08-24
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [Linux Foundation Akrites Initiative: Coordinated Vulnerability Disclosure Platform for AI-Enabled…](https://intel.threadlinqs.com/threat/TL-2026-2073) — 2026-08-19

## Related CVEs

CVEs referenced by the tracked threats that use T1588.002, most frequent first.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687)
- [CVE-2011-2523](https://intel.threadlinqs.com/cve/CVE-2011-2523)
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2019-12108](https://intel.threadlinqs.com/cve/CVE-2019-12108)
- [CVE-2019-12109](https://intel.threadlinqs.com/cve/CVE-2019-12109)
- [CVE-2019-12110](https://intel.threadlinqs.com/cve/CVE-2019-12110)
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-28951](https://intel.threadlinqs.com/cve/CVE-2020-28951)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)

## Detection coverage

Threadlinqs maintains 113 detection rules mapped to T1588.002 (SPL 33, KQL 40, Sigma 40). Rule content is available to Blue tier accounts and above; this page shows counts only.

113 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588) — 363 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1588.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
