Activity timeline
T1608.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-05 with 8 reports, and 18 of the 18 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1608.004 Drive-by Target is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1608 Stage Capabilities. Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 5 critical, 12 high, 1 medium.
Threats that use T1608.004 most often also use T1071.001 Web Protocols (13 threats), T1189 Drive-by Compromise (11 threats), T1105 Ingress Tool Transfer (10 threats), T1583.001 Domains (10 threats), T1027 Obfuscated Files or Information (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
3 tracked threat actors appear in the threats that use T1608.004; the most frequent are Sable Squirrel (1), UNC1549 (1), UNC5142 (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1608.004.
Data sources
Telemetry that can reveal T1608.004, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
18 tracked threats use T1608.004.
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…medium
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentialscritical
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)critical
- Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling…high
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com /…high
- DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma…high
- CVE-2026-11645: Actively Exploited V8 Out-of-Bounds Memory Access Zero-Day in Google Chromehigh
- Google Chrome 149.0.7827.53 — 429 Vulnerabilities Patched (22 Critical); Critical ANGLE/GPU Memory-Safety…critical
- ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via…high
- Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…high
- 2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu…high
- Ghost CMS Content API SQL Injection CVE-2026-26980 — Large-Scale ClickFix Watering-Hole Campaign…critical
- 2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)high
- Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI…critical
- Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript…high
- Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation…high
Detection coverage
Threadlinqs maintains 29 detection rules mapped to T1608.004 (SPL 9, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1608 Stage Capabilities — 250 tracked threats at the technique level.