Activity timeline
T1608 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 67 reports, and 250 of the 250 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1608 Stage Capabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 250 of 2623 tracked threats (9.5%) to it; by severity that is 52 critical, 166 high, 30 medium, 1 low.
Threats that use T1608 most often also use T1583 Acquire Infrastructure (191 threats), T1027 Obfuscated Files or Information (185 threats), T1036 Masquerading (179 threats), T1204 User Execution (178 threats), T1071 Application Layer Protocol (175 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
93 tracked threat actors appear in the threats that use T1608; the most frequent are TeamPCP (9), WageMole (7), APT28 (6), APT38 (6), Contagious Interview (6).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1608.
Data sources
Telemetry that can reveal T1608, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
The 30 most recent of 250 tracked threats that use T1608.
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…medium
- GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaignhigh
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Datahigh
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teamsmedium
- Cybercriminals Build Fake School Websites and Phishing Domains as Education-Sector Attacks Hit Record Highmedium
- Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…high
- Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofinghigh
- 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login…medium
- AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhoneshigh
- BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Adminsmedium
- TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bankhigh
- Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accountshigh
- FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructurecritical
- AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…critical
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolencritical
- ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Datamedium
- NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skillslow
- Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…high
- Anthropic AI Agent Publishes Live Credential-Stealing Malware as PyPI Package "anthropickit"high
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVDhigh
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…critical
- Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…high
- Tax Season Phishing and Malware Campaign Targets Indian Taxpayers via Fake Income Tax Department Noticeshigh
- Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…critical
- AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Thefthigh
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…critical
Detection coverage
Threadlinqs maintains 57 detection rules mapped to T1608 (SPL 17, KQL 16, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1608.001 Upload Malware — 142 tracked threats
- T1608.002 Upload Tool — 11 tracked threats
- T1608.003 Install Digital Certificate — 2 tracked threats
- T1608.004 Drive-by Target — 18 tracked threats
- T1608.005 Link Target — 39 tracked threats
- T1608.006 SEO Poisoning — 25 tracked threats