# T1593.003 Code Repositories

> As of 2026-10-05, T1593.003 (Code Repositories) appears in 10 tracked threats, first reported 2026-05-04 and most recently 2026-09-26, with linked actors including N, ShinyHunters; it most often appears alongside T1078.004 (Cloud Accounts).

- **Tracked threats:** 10 (5 critical, 2 high, 2 medium)
- **First seen:** 2026-05-04
- **Last seen:** 2026-09-26
- **Threat actors:** 2
- **Detection rules:** 15 (counts only; Blue tier and above)

## Key facts

- **ID:** T1593.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1593
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1593/003/

## Activity timeline

T1593.003 first appeared in tracked threats on 2026-05-04 and was most recently reported on 2026-09-26. The busiest month was 2026-08 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1593.003 Code Repositories is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1593 Search Open Websites/Domains](https://intel.threadlinqs.com/technique/T1593). Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 5 critical, 2 high, 2 medium.

Threats that use T1593.003 most often also use [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (6 threats), [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (6 threats), [T1526 Cloud Service Discovery](https://intel.threadlinqs.com/technique/T1526) (5 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (5 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (4 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1593.003; the most frequent are [N](https://intel.threadlinqs.com/actor/N) (1), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1593.003.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Threat actors using it

- [N](https://intel.threadlinqs.com/actor/N) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1

## Tracked threats

10 tracked threats use T1593.003.

- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation](https://intel.threadlinqs.com/threat/TL-2026-2607) — medium — 2026-09-21
- [Coordinated GitHub API Enumeration and Access Token Abuse Campaign](https://intel.threadlinqs.com/threat/TL-2026-2339) — high — 2026-09-05
- [Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchains](https://intel.threadlinqs.com/threat/TL-2026-2194) — critical — 2026-08-28
- [Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)](https://intel.threadlinqs.com/threat/TL-2026-2009) — medium — 2026-08-13
- [Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1835) — critical — 2026-08-03
- [COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1822) — critical — 2026-08-02
- [Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809…](https://intel.threadlinqs.com/threat/TL-2026-1705) — critical — 2026-07-26
- [CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability…](https://intel.threadlinqs.com/threat/TL-2026-1419) — 2026-07-16
- [Amazon SES Weaponized for Phishing & BEC via Leaked AWS IAM Access Keys (Securelist, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0451) — high — 2026-05-04

## Detection coverage

Threadlinqs maintains 15 detection rules mapped to T1593.003 (SPL 6, KQL 4, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

15 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1593 Search Open Websites/Domains](https://intel.threadlinqs.com/technique/T1593) — 79 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1593.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
