# T1588 Obtain Capabilities

> As of 2026-10-05, T1588 (Obtain Capabilities) appears in 363 tracked threats, first reported 2026-01-14 and most recently 2026-09-26, with linked actors including ShinyHunters, MuddyWater, The Com; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 363 (138 critical, 184 high, 34 medium, 2 low)
- **First seen:** 2026-01-14
- **Last seen:** 2026-09-26
- **Threat actors:** 122
- **Detection rules:** 31 (counts only; Blue tier and above)

## Key facts

- **ID:** T1588
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1588/

## Activity timeline

T1588 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 125 reports, and 363 of the 363 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1588 Obtain Capabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 363 of 2623 tracked threats (13.8%) to it; by severity that is 138 critical, 184 high, 34 medium, 2 low.

Threats that use T1588 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (236 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (232 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (196 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (192 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (190 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

122 tracked threat actors appear in the threats that use T1588; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (8), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (7), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (7), [APT28](https://intel.threadlinqs.com/actor/APT28) (6), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (6).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1588.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1588, per MITRE ATT&CK.

- Certificate — Certificate Registration
- Internet Scan — Response Content
- Malware Repository — Malware Content, Malware Metadata

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 8
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 7
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 7
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 6
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 6
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 6
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 6
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 6
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 5
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 5
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 5

## Tracked threats

The 30 most recent of 363 tracked threats that use T1588.

- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)](https://intel.threadlinqs.com/threat/TL-2026-2617) — critical — 2026-09-22
- [Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2456) — high — 2026-09-12
- [Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2416) — high — 2026-09-09
- [Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…](https://intel.threadlinqs.com/threat/TL-2026-2390) — high — 2026-09-08
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — high — 2026-09-06
- [ASCII Smuggling Phishing Campaign Uses Invisible Unicode Tags-Block Characters to Evade Filters, Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2338) — high — 2026-09-05
- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…](https://intel.threadlinqs.com/threat/TL-2026-2304) — high — 2026-09-03
- [ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via…](https://intel.threadlinqs.com/threat/TL-2026-2285) — critical — 2026-09-01
- [Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively Exploited](https://intel.threadlinqs.com/threat/TL-2026-2221) — critical — 2026-08-29
- [TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India](https://intel.threadlinqs.com/threat/TL-2026-2202) — high — 2026-08-29
- [Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-2162) — critical — 2026-08-27
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2076) — critical — 2026-08-19
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2005) — high — 2026-08-13
- [Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…](https://intel.threadlinqs.com/threat/TL-2026-1993) — high — 2026-08-12
- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — high — 2026-08-10
- [Metabase Unauthenticated SQL Injection 0-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1958) — critical — 2026-08-09
- [CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host](https://intel.threadlinqs.com/threat/TL-2026-1919) — high — 2026-08-06
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted…](https://intel.threadlinqs.com/threat/TL-2026-1885) — high — 2026-08-05
- [Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856…](https://intel.threadlinqs.com/threat/TL-2026-1884) — high — 2026-08-05
- [ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…](https://intel.threadlinqs.com/threat/TL-2026-1883) — critical — 2026-08-05
- [AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…](https://intel.threadlinqs.com/threat/TL-2026-1900) — critical — 2026-08-04
- [npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for…](https://intel.threadlinqs.com/threat/TL-2026-1866) — critical — 2026-08-04
- [NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825…](https://intel.threadlinqs.com/threat/TL-2026-1865) — critical — 2026-08-04
- [EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack…](https://intel.threadlinqs.com/threat/TL-2026-1850) — medium — 2026-08-03
- [Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolen](https://intel.threadlinqs.com/threat/TL-2026-1848) — critical — 2026-08-03

## Related CVEs

CVEs referenced by the tracked threats that use T1588, most frequent first.

- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-27690](https://intel.threadlinqs.com/cve/CVE-2026-27690)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-33824](https://intel.threadlinqs.com/cve/CVE-2026-33824)
- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368)
- [CVE-2026-44747](https://intel.threadlinqs.com/cve/CVE-2026-44747)
- [CVE-2026-44761](https://intel.threadlinqs.com/cve/CVE-2026-44761)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)

## Detection coverage

Threadlinqs maintains 31 detection rules mapped to T1588 (SPL 12, KQL 6, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

31 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1588.001 Malware](https://intel.threadlinqs.com/technique/T1588.001) — 38 tracked threats
- [T1588.002 Tool](https://intel.threadlinqs.com/technique/T1588.002) — 153 tracked threats
- [T1588.003 Code Signing Certificates](https://intel.threadlinqs.com/technique/T1588.003) — 21 tracked threats
- T1588.004 Digital Certificates — 6 tracked threats
- [T1588.005 Exploits](https://intel.threadlinqs.com/technique/T1588.005) — 129 tracked threats
- [T1588.006 Vulnerabilities](https://intel.threadlinqs.com/technique/T1588.006) — 125 tracked threats
- [T1588.007 Artificial Intelligence](https://intel.threadlinqs.com/technique/T1588.007) — 21 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1588
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
