# T1588.007 Artificial Intelligence

> As of 2026-10-05, T1588.007 (Artificial Intelligence) appears in 21 tracked threats, first reported 2026-05-12 and most recently 2026-10-03, with linked actors including Hacktron AI, Outsider Enterprise, Scattered Spider; it most often appears alongside T1657 (Financial Theft).

- **Tracked threats:** 21 (4 critical, 12 high, 5 medium)
- **First seen:** 2026-05-12
- **Last seen:** 2026-10-03
- **Threat actors:** 4
- **Detection rules:** 27 (counts only; Blue tier and above)

## Key facts

- **ID:** T1588.007
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1588
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1588/007/

## Activity timeline

T1588.007 first appeared in tracked threats on 2026-05-12 and was most recently reported on 2026-10-03. The busiest month was 2026-08 with 9 reports, and 21 of the 21 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1588.007 Artificial Intelligence is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588). Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 4 critical, 12 high, 5 medium.

Threats that use T1588.007 most often also use [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (10 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (7 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (7 threats), [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (7 threats), [T1583.006 Web Services](https://intel.threadlinqs.com/technique/T1583.006) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1588.007; the most frequent are [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) (1), [Outsider Enterprise](https://intel.threadlinqs.com/actor/Outsider%20Enterprise) (1), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (1), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1588.007.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) — 1
- [Outsider Enterprise](https://intel.threadlinqs.com/actor/Outsider%20Enterprise) — 1
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1

## Tracked threats

21 tracked threats use T1588.007.

- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)](https://intel.threadlinqs.com/threat/TL-2026-2793) — high — 2026-09-29
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — high — 2026-09-29
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — high — 2026-09-19
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…](https://intel.threadlinqs.com/threat/TL-2026-2126) — high — 2026-08-23
- [Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)](https://intel.threadlinqs.com/threat/TL-2026-2109) — high — 2026-08-21
- [AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub…](https://intel.threadlinqs.com/threat/TL-2026-2042) — medium — 2026-08-17
- [MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generation](https://intel.threadlinqs.com/threat/TL-2026-2036) — high — 2026-08-16
- [Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug…](https://intel.threadlinqs.com/threat/TL-2026-2011) — medium — 2026-08-13
- ["Zoomsday" Flaws (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) Let One Zoom Meeting Participant Attack…](https://intel.threadlinqs.com/threat/TL-2026-2001) — critical — 2026-08-12
- [China-Linked Actor Uses Autonomous AI Agent Frameworks (Hermes, OpenClaw) to Breach Taiwan Government and…](https://intel.threadlinqs.com/threat/TL-2026-1997) — critical — 2026-08-12
- [BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection](https://intel.threadlinqs.com/threat/TL-2026-1964) — medium — 2026-08-09
- [CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1744) — high — 2026-07-28
- [Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts…](https://intel.threadlinqs.com/threat/TL-2026-1479) — high — 2026-07-18
- [Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…](https://intel.threadlinqs.com/threat/TL-2026-1347) — high — 2026-07-15
- [AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek)](https://intel.threadlinqs.com/threat/TL-2026-1129) — medium — 2026-07-05
- [Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photos](https://intel.threadlinqs.com/threat/TL-2026-1119) — medium — 2026-07-05
- [SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and…](https://intel.threadlinqs.com/threat/TL-2026-0498) — critical — 2026-05-12

## Related CVEs

CVEs referenced by the tracked threats that use T1588.007, most frequent first.

- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2025-7775](https://intel.threadlinqs.com/cve/CVE-2025-7775)
- [CVE-2026-53413](https://intel.threadlinqs.com/cve/CVE-2026-53413)

## Detection coverage

Threadlinqs maintains 27 detection rules mapped to T1588.007 (SPL 7, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

27 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588) — 363 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1588.007
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
