Activity timeline
T1588.007 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 9 reports, and 21 of the 21 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1588.007 Artificial Intelligence is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1588 Obtain Capabilities. Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 4 critical, 12 high, 5 medium.
Threats that use T1588.007 most often also use T1657 Financial Theft (10 threats), T1190 Exploit Public-Facing Application (7 threats), T1204.001 Malicious Link (7 threats), T1566.002 Spearphishing Link (7 threats), T1583.006 Web Services (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1588.007; the most frequent are Hacktron AI (1), Outsider Enterprise (1), Scattered Spider (1), ShinyHunters (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1588.007.
Threat actors using it
Tracked threats
21 tracked threats use T1588.007.
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…high
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)high
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verificationhigh
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)high
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)high
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub…medium
- MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generationhigh
- Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug…medium
- "Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack…critical
- China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and…critical
- BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detectionmedium
- CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege…high
- Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts…high
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…high
- AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek)medium
- Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photosmedium
- SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and…critical
Detection coverage
Threadlinqs maintains 27 detection rules mapped to T1588.007 (SPL 7, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1588 Obtain Capabilities — 363 tracked threats at the technique level.