Activity timeline
T1591.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 7 reports, and 16 of the 16 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1591.004 Identify Roles is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1591 Gather Victim Org Information. Threadlinqs maps 16 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 12 high, 3 medium.
Threats that use T1591.004 most often also use T1566.002 Spearphishing Link (9 threats), T1204.001 Malicious Link (8 threats), T1583.001 Domains (8 threats), T1036.005 Match Legitimate Resource Name or Location (7 threats), T1657 Financial Theft (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1591.004; the most frequent are APT38 (1), Sapphire Sleet (1), SideCopy (1), Stardust Chollima (1), Storm-2992 (1).
Threat actors using it
Tracked threats
16 tracked threats use T1591.004.
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rowshigh
- Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)high
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)medium
- "Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAshigh
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicryhigh
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chainshigh
- UAC-0145 (Sandworm/APT44) Trojanizes WireGuard VPN Client 'SopraVPN' via Fake IT Recruitment Schemehigh
- BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detectionmedium
- Ransomware Extortion Campaigns Shift Targeting to Mid-Level IT and Business Managers, Zscaler ThreatLabz Findsmedium
- Ransomware Gangs Shift Targeting from Executives to Mid-Level IT/Finance Managers (Zscaler ThreatLabz…high
- Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334…high
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Executionhigh
- Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account…high
- Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…high
- Kali365/Octopi365 Device Code Phishing-as-a-Service Campaigncritical
Detection coverage
Threadlinqs maintains 22 detection rules mapped to T1591.004 (SPL 7, KQL 8, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1591 Gather Victim Org Information — 92 tracked threats at the technique level.