Activity timeline
T1593 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 32 reports, and 79 of the 79 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1593 Search Open Websites/Domains is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix. Threadlinqs maps 79 of 2623 tracked threats (3%) to it; by severity that is 19 critical, 34 high, 24 medium.
Threats that use T1593 most often also use T1566 Phishing (48 threats), T1036 Masquerading (44 threats), T1583 Acquire Infrastructure (43 threats), T1585 Establish Accounts (42 threats), T1204 User Execution (39 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
35 tracked threat actors appear in the threats that use T1593; the most frequent are Scattered Spider (5), Scattered LAPSUS$ Hunters (4), ShinyHunters (4), The Com (4), UNC5537 (4).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1593.
Threat actors using it
Tracked threats
The 30 most recent of 79 tracked threats that use T1593.
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluationmedium
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…critical
- MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generationhigh
- AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape…high
- EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack…medium
- ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Datamedium
- Alleged Revolut Data Breach — Unverified Threat-Actor Claim of 75M-User Financial Dataset for Sale ($500…medium
- Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026high
- npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown'…high
- Approval Phishing: Cryptocurrency Wallet-Drain Scam Campaign Disrupted via Operations Spincaster, DeCloak…high
- InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)high
- Call of Duty Mobile 'Free Points' Phishing Scam Uses Real-Time Credential Relay to Hijack Activision Accountsmedium
- HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling…high
- Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) Malwarehigh
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)high
- Autonomous AI Agent (GPT-5.6 Sol) Chains Zero-Day and Stolen Credentials to Breach Hugging Face Production…critical
- Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…medium
- Gitea CVE-2026-58443: Authorization Bypass in Pull Request Update API Enables Private Repo Accesscritical
- FIFA World Cup 2026 Fraud Ecosystem: GHOST STADIUM Phishing, Mass Typosquatting, and Vidar/Lumma Infostealer…high
- GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG…high
- Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure…high
- North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag Imageshigh
- OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign…high
- PolinRider DPRK Supply-Chain Campaign: Confirmed GitHub Footprint Grows 6.5x Since March…high
- Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military…high
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…critical
- Coordinated GitHub API Enumeration and Access Token Abuse Campaign (Ghost Accounts + Compromised PAT/OAuth…medium
- Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and…high
- Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…high
Detection coverage
Threadlinqs maintains 32 detection rules mapped to T1593 (SPL 10, KQL 10, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1593.001 Social Media — 11 tracked threats
- T1593.002 Search Engines — 4 tracked threats
- T1593.003 Code Repositories — 10 tracked threats