# T1592.002 Software

> As of 2026-10-05, T1592.002 (Software) appears in 68 tracked threats, first reported 2026-03-18 and most recently 2026-09-27, with linked actors including Hacktron AI, ShinyHunters; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 68 (38 critical, 14 high, 12 medium)
- **First seen:** 2026-03-18
- **Last seen:** 2026-09-27
- **Threat actors:** 2
- **Detection rules:** 74 (counts only; Blue tier and above)

## Key facts

- **ID:** T1592.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1592
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1592/002/

## Activity timeline

T1592.002 first appeared in tracked threats on 2026-03-18 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 27 reports, and 68 of the 68 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1592.002 Software is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1592 Gather Victim Host Information](https://intel.threadlinqs.com/technique/T1592). Threadlinqs maps 68 of 2623 tracked threats (2.6%) to it; by severity that is 38 critical, 14 high, 12 medium.

Threats that use T1592.002 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (54 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (50 threats), [T1588.006 Vulnerabilities](https://intel.threadlinqs.com/technique/T1588.006) (39 threats), [T1588.005 Exploits](https://intel.threadlinqs.com/technique/T1588.005) (34 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (29 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1592.002; the most frequent are [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) (1), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1592.002.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1592.002, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1

## Tracked threats

The 30 most recent of 68 tracked threats that use T1592.002.

- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Site](https://intel.threadlinqs.com/threat/TL-2026-2671) — critical — 2026-09-26
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…](https://intel.threadlinqs.com/threat/TL-2026-2658) — medium — 2026-09-25
- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — medium — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access](https://intel.threadlinqs.com/threat/TL-2026-2568) — high — 2026-09-18
- [Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Root](https://intel.threadlinqs.com/threat/TL-2026-2557) — critical — 2026-09-18
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending Protocol](https://intel.threadlinqs.com/threat/TL-2026-2261) — critical — 2026-08-31
- [GiveWP WordPress Donation Plugin Flaw (CVE-2026-82222) Lets Attackers Execute Server Commands](https://intel.threadlinqs.com/threat/TL-2026-2188) — critical — 2026-08-28
- [Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth…](https://intel.threadlinqs.com/threat/TL-2026-2159) — critical — 2026-08-26
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…](https://intel.threadlinqs.com/threat/TL-2026-2152) — critical — 2026-08-26
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [CVE-2026-15748: Forminator WordPress Plugin Arbitrary File Upload Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2052) — critical — 2026-08-17
- [Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…](https://intel.threadlinqs.com/threat/TL-2026-2048) — critical — 2026-08-17
- [CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenames](https://intel.threadlinqs.com/threat/TL-2026-2043) — medium — 2026-08-17
- [Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2037) — critical — 2026-08-13
- [Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…](https://intel.threadlinqs.com/threat/TL-2026-1993) — high — 2026-08-12
- [Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1985) — critical — 2026-08-11
- [Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1980) — critical — 2026-08-10
- [Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flaw](https://intel.threadlinqs.com/threat/TL-2026-1965) — medium — 2026-08-10
- [AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-1961) — high — 2026-08-09
- [Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilities](https://intel.threadlinqs.com/threat/TL-2026-1928) — high — 2026-08-07
- [Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses](https://intel.threadlinqs.com/threat/TL-2026-1829) — critical — 2026-08-03
- [Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Files](https://intel.threadlinqs.com/threat/TL-2026-1817) — high — 2026-08-02
- [CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)](https://intel.threadlinqs.com/threat/TL-2026-1799) — critical — 2026-07-31
- [Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service…](https://intel.threadlinqs.com/threat/TL-2026-1781) — high — 2026-07-31
- [Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape /…](https://intel.threadlinqs.com/threat/TL-2026-1770) — critical — 2026-07-30

## Related CVEs

CVEs referenced by the tracked threats that use T1592.002, most frequent first.

- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687)
- [CVE-2011-2523](https://intel.threadlinqs.com/cve/CVE-2011-2523)
- [CVE-2019-12108](https://intel.threadlinqs.com/cve/CVE-2019-12108)
- [CVE-2019-12109](https://intel.threadlinqs.com/cve/CVE-2019-12109)
- [CVE-2019-12110](https://intel.threadlinqs.com/cve/CVE-2019-12110)
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111)
- [CVE-2020-28951](https://intel.threadlinqs.com/cve/CVE-2020-28951)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-1218](https://intel.threadlinqs.com/cve/CVE-2025-1218)
- [CVE-2025-14181](https://intel.threadlinqs.com/cve/CVE-2025-14181)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-3450](https://intel.threadlinqs.com/cve/CVE-2025-3450)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2025-67649](https://intel.threadlinqs.com/cve/CVE-2025-67649)
- [CVE-2026-10881](https://intel.threadlinqs.com/cve/CVE-2026-10881)
- [CVE-2026-11374](https://intel.threadlinqs.com/cve/CVE-2026-11374)
- [CVE-2026-11622](https://intel.threadlinqs.com/cve/CVE-2026-11622)
- [CVE-2026-15681](https://intel.threadlinqs.com/cve/CVE-2026-15681)
- [CVE-2026-15682](https://intel.threadlinqs.com/cve/CVE-2026-15682)
- [CVE-2026-15748](https://intel.threadlinqs.com/cve/CVE-2026-15748)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-17545](https://intel.threadlinqs.com/cve/CVE-2026-17545)
- [CVE-2026-19478](https://intel.threadlinqs.com/cve/CVE-2026-19478)
- [CVE-2026-19489](https://intel.threadlinqs.com/cve/CVE-2026-19489)
- [CVE-2026-19490](https://intel.threadlinqs.com/cve/CVE-2026-19490)
- [CVE-2026-19650](https://intel.threadlinqs.com/cve/CVE-2026-19650)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-20349](https://intel.threadlinqs.com/cve/CVE-2026-20349)

## Detection coverage

Threadlinqs maintains 74 detection rules mapped to T1592.002 (SPL 24, KQL 22, Sigma 28). Rule content is available to Blue tier accounts and above; this page shows counts only.

74 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1592 Gather Victim Host Information](https://intel.threadlinqs.com/technique/T1592) — 153 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1592.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
