# T1588.005 Exploits

> As of 2026-10-05, T1588.005 (Exploits) appears in 129 tracked threats, first reported 2026-02-16 and most recently 2026-09-28, with linked actors including ShinyHunters, UNC6353, APT28; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 129 (70 critical, 48 high, 9 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-28
- **Threat actors:** 20
- **Detection rules:** 109 (counts only; Blue tier and above)

## Key facts

- **ID:** T1588.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1588
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1588/005/

## Activity timeline

T1588.005 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 48 reports, and 129 of the 129 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1588.005 Exploits is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588). Threadlinqs maps 129 of 2623 tracked threats (4.9%) to it; by severity that is 70 critical, 48 high, 9 medium.

Threats that use T1588.005 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (92 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (70 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (69 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (62 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (59 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

20 tracked threat actors appear in the threats that use T1588.005; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (2), [UNC6353](https://intel.threadlinqs.com/actor/UNC6353) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT36](https://intel.threadlinqs.com/actor/APT36) (1), [APT43](https://intel.threadlinqs.com/actor/APT43) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1588.005.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 2
- [UNC6353](https://intel.threadlinqs.com/actor/UNC6353) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Anubis](https://intel.threadlinqs.com/actor/Anubis) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Cytrox](https://intel.threadlinqs.com/actor/Cytrox) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 1

## Tracked threats

The 30 most recent of 129 tracked threats that use T1588.005.

- [Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks](https://intel.threadlinqs.com/threat/TL-2026-2745) — high — 2026-09-28
- [Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)](https://intel.threadlinqs.com/threat/TL-2026-2717) — high — 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible…](https://intel.threadlinqs.com/threat/TL-2026-2690) — critical — 2026-09-27
- [Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…](https://intel.threadlinqs.com/threat/TL-2026-2672) — high — 2026-09-26
- [Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)](https://intel.threadlinqs.com/threat/TL-2026-2659) — high — 2026-09-26
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- ["LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…](https://intel.threadlinqs.com/threat/TL-2026-2572) — high — 2026-09-18
- [Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Root](https://intel.threadlinqs.com/threat/TL-2026-2557) — critical — 2026-09-18
- [CVE-2026-90894 ("ParaShells"): Parallels Desktop for Mac Local Privilege Escalation via Appliance Extract…](https://intel.threadlinqs.com/threat/TL-2026-2536) — high — 2026-09-16
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…](https://intel.threadlinqs.com/threat/TL-2026-2514) — high — 2026-09-15
- [CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument…](https://intel.threadlinqs.com/threat/TL-2026-2479) — high — 2026-09-13
- [CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2477) — high — 2026-09-13
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…](https://intel.threadlinqs.com/threat/TL-2026-2340) — critical — 2026-09-05
- [Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusion](https://intel.threadlinqs.com/threat/TL-2026-2326) — high — 2026-09-04
- [Second-Order SQL Injection in All-in-One WP Migration and Backup Plugin (CVE-2026-19949) Exposes 5M+…](https://intel.threadlinqs.com/threat/TL-2026-2301) — high — 2026-09-02
- [CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After Disclosure](https://intel.threadlinqs.com/threat/TL-2026-2287) — critical — 2026-09-01
- [HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege…](https://intel.threadlinqs.com/threat/TL-2026-2258) — medium — 2026-08-31
- [CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host…](https://intel.threadlinqs.com/threat/TL-2026-2220) — high — 2026-08-29
- [ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…](https://intel.threadlinqs.com/threat/TL-2026-2195) — critical — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28

## Related CVEs

CVEs referenced by the tracked threats that use T1588.005, most frequent first.

- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-42945](https://intel.threadlinqs.com/cve/CVE-2026-42945)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687)
- [CVE-2011-2523](https://intel.threadlinqs.com/cve/CVE-2011-2523)
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2019-12108](https://intel.threadlinqs.com/cve/CVE-2019-12108)
- [CVE-2019-12109](https://intel.threadlinqs.com/cve/CVE-2019-12109)
- [CVE-2019-12110](https://intel.threadlinqs.com/cve/CVE-2019-12110)
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111)
- [CVE-2020-17103](https://intel.threadlinqs.com/cve/CVE-2020-17103)
- [CVE-2020-28951](https://intel.threadlinqs.com/cve/CVE-2020-28951)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-48503](https://intel.threadlinqs.com/cve/CVE-2022-48503)
- [CVE-2023-32409](https://intel.threadlinqs.com/cve/CVE-2023-32409)
- [CVE-2023-32434](https://intel.threadlinqs.com/cve/CVE-2023-32434)
- [CVE-2023-38606](https://intel.threadlinqs.com/cve/CVE-2023-38606)

## Detection coverage

Threadlinqs maintains 109 detection rules mapped to T1588.005 (SPL 37, KQL 35, Sigma 37). Rule content is available to Blue tier accounts and above; this page shows counts only.

109 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588) — 363 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1588.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
