# T1591.004 Identify Roles

> As of 2026-10-05, T1591.004 (Identify Roles) appears in 16 tracked threats, first reported 2026-06-28 and most recently 2026-09-26, with linked actors including APT38, Sapphire Sleet, SideCopy; it most often appears alongside T1566.002 (Spearphishing Link).

- **Tracked threats:** 16 (1 critical, 12 high, 3 medium)
- **First seen:** 2026-06-28
- **Last seen:** 2026-09-26
- **Threat actors:** 6
- **Detection rules:** 22 (counts only; Blue tier and above)

## Key facts

- **ID:** T1591.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1591
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1591/004/

## Activity timeline

T1591.004 first appeared in tracked threats on 2026-06-28 and was most recently reported on 2026-09-26. The busiest month was 2026-08 with 7 reports, and 16 of the 16 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1591.004 Identify Roles is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1591 Gather Victim Org Information](https://intel.threadlinqs.com/technique/T1591). Threadlinqs maps 16 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 12 high, 3 medium.

Threats that use T1591.004 most often also use [T1566.002 Spearphishing Link](https://intel.threadlinqs.com/technique/T1566.002) (9 threats), [T1204.001 Malicious Link](https://intel.threadlinqs.com/technique/T1204.001) (8 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (8 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (7 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

6 tracked threat actors appear in the threats that use T1591.004; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (1), [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) (1), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (1), [Storm-2992](https://intel.threadlinqs.com/actor/Storm-2992) (1).

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [Storm-2992](https://intel.threadlinqs.com/actor/Storm-2992) — 1
- [UNC6508](https://intel.threadlinqs.com/actor/UNC6508) — 1

## Tracked threats

16 tracked threats use T1591.004.

- [Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows](https://intel.threadlinqs.com/threat/TL-2026-2675) — high — 2026-09-26
- [Microsoft-Led Coalition Takes Down EvilTokens AI-Powered Phishing-as-a-Service Platform (Storm-2992)](https://intel.threadlinqs.com/threat/TL-2026-2614) — high — 2026-09-22
- [Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)](https://intel.threadlinqs.com/threat/TL-2026-2451) — medium — 2026-09-11
- ["Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs](https://intel.threadlinqs.com/threat/TL-2026-2322) — high — 2026-09-03
- [Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry](https://intel.threadlinqs.com/threat/TL-2026-2088) — high — 2026-08-20
- [Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains](https://intel.threadlinqs.com/threat/TL-2026-2050) — high — 2026-08-17
- [UAC-0145 (Sandworm/APT44) Trojanizes WireGuard VPN Client 'SopraVPN' via Fake IT Recruitment Scheme](https://intel.threadlinqs.com/threat/TL-2026-1994) — high — 2026-08-12
- [BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection](https://intel.threadlinqs.com/threat/TL-2026-1964) — medium — 2026-08-09
- [Ransomware Extortion Campaigns Shift Targeting to Mid-Level IT and Business Managers, Zscaler ThreatLabz Finds](https://intel.threadlinqs.com/threat/TL-2026-1957) — medium — 2026-08-09
- [Ransomware Gangs Shift Targeting from Executives to Mid-Level IT/Finance Managers (Zscaler ThreatLabz…](https://intel.threadlinqs.com/threat/TL-2026-1955) — high — 2026-08-09
- [Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334…](https://intel.threadlinqs.com/threat/TL-2026-2897) — high — 2026-08-06
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1428) — high — 2026-07-16
- [Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account…](https://intel.threadlinqs.com/threat/TL-2026-1139) — high — 2026-07-06
- [Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…](https://intel.threadlinqs.com/threat/TL-2026-1095) — high — 2026-07-03
- [Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign](https://intel.threadlinqs.com/threat/TL-2026-0984) — critical — 2026-06-28

## Related CVEs

CVEs referenced by the tracked threats that use T1591.004, most frequent first.

- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)

## Detection coverage

Threadlinqs maintains 22 detection rules mapped to T1591.004 (SPL 7, KQL 8, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

22 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1591 Gather Victim Org Information](https://intel.threadlinqs.com/technique/T1591) — 92 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1591.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
