Activity timeline
T1592 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 61 reports, and 153 of the 153 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1592 Gather Victim Host Information is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix. Threadlinqs maps 153 of 2623 tracked threats (5.8%) to it; by severity that is 74 critical, 63 high, 11 medium.
Threats that use T1592 most often also use T1190 Exploit Public-Facing Application (113 threats), T1595 Active Scanning (90 threats), T1059 Command and Scripting Interpreter (85 threats), T1082 System Information Discovery (81 threats), T1005 Data from Local System (77 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
34 tracked threat actors appear in the threats that use T1592; the most frequent are APT35 (2), BonJoviGoesHard (2), Cyber Av3ngers (2), DriveSurge (2), APT27 (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1592.
Data sources
Telemetry that can reveal T1592, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
The 30 most recent of 153 tracked threats that use T1592.
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…critical
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During…critical
- HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…critical
- Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively Exploitedcritical
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…critical
- Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Accesscritical
- Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…high
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Importscritical
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege…high
- CVE-2026-16812 — Critical Unauthenticated OS Command Injection in Arista VeloCloud Orchestrator Actively…critical
- EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack…medium
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolencritical
- Coldcard Firmware RNG Flaw Enables Coordinated Bitcoin Wallet Theft ($70.2M Drained)critical
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and…high
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass…high
- Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150…
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…critical
- Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory…high
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claimshigh
- CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memorycritical
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…critical
- US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…high
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Wiz's Atlas AI Vulnerability Researcher Uncovers Critical GitHub RCE (CVE-2026-3854) and 200+ Unknown OSS…critical
- Autonomous OpenAI Test Models (GPT-5.6 Sol + Unreleased Pre-Release Model) Breach Hugging Face Production…critical
- UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation Windowsmedium
- KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Carshigh
Detection coverage
Threadlinqs maintains 57 detection rules mapped to T1592 (SPL 19, KQL 22, Sigma 16). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1592.001 Hardware — 3 tracked threats
- T1592.002 Software — 68 tracked threats
- T1592.003 Firmware — 1 tracked threat
- T1592.004 Client Configurations — 17 tracked threats