Activity timeline
T1588.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 21 of the 21 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1588.003 Code Signing Certificates is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1588 Obtain Capabilities. Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 3 critical, 18 high.
Threats that use T1588.003 most often also use T1553.002 Code Signing (20 threats), T1036.005 Match Legitimate Resource Name or Location (19 threats), T1071.001 Web Protocols (19 threats), T1204.002 Malicious File (18 threats), T1082 System Information Discovery (16 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1588.003; the most frequent are MuddyWater (2), UNC1549 (2), APT43 (1), Earth Lusca (1), Kimsuky (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1588.003.
Data sources
Telemetry that can reveal T1588.003, per MITRE ATT&CK.
- Malware Repository — Malware Metadata
Threat actors using it
Tracked threats
21 tracked threats use T1588.003.
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- D3F@ck Loader: JPHP-Based Malware-as-a-Service Loader Abuses Windows Defender Exclusions and…high
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…critical
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…high
- GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for…critical
- CrashStealer: Notarized Fake Apple CrashReporter App Steals macOS Keychain, Browser, and Crypto Wallet…high
- AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver…high
- 11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)high
- JDownloader Website Supply-Chain Compromise Distributes Trojanized Installers (Python RAT / Linux…high
- Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprintinghigh
- The BYOVD Epidemic: Attackers Weaponize Trusted Windows Drivers to Kill Security Softwarehigh
- Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installershigh
- DinDoor Deno-Based RAT — Fake AI/Audio Software on GitHub & SourceForge (ChatGPT/Claude/AutoTune/Kontakt)…high
- Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…high
- Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via…high
- Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation…high
- Seedworm (MuddyWater) Q1 2026 Global Espionage Campaign — DLL Sideloading via Signed Fortemedia and…high
- JDownloader Website Supply Chain Compromise — Trojanized Windows/Linux Installers Deploy Pyarmor-Obfuscated…high
- DAEMON Tools Lite Supply-Chain Compromise — Trojanized Signed Installers Deploy Multi-Stage Infostealer +…critical
- Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Thefthigh
- PlugX Meeting Invitation Campaign — China-Nexus MSBuild LOLBIN + GDATA DLL Sideloading, RC4 Encrypted C2…high
Detection coverage
Threadlinqs maintains 10 detection rules mapped to T1588.003 (SPL 3, KQL 3, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1588 Obtain Capabilities — 363 tracked threats at the technique level.