# T1608.004 Drive-by Target

> As of 2026-10-05, T1608.004 (Drive-by Target) appears in 18 tracked threats, first reported 2026-05-19 and most recently 2026-09-26, with linked actors including Sable Squirrel, UNC1549, UNC5142; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 18 (5 critical, 12 high, 1 medium)
- **First seen:** 2026-05-19
- **Last seen:** 2026-09-26
- **Threat actors:** 3
- **Detection rules:** 29 (counts only; Blue tier and above)

## Key facts

- **ID:** T1608.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1608
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1608/004/

## Activity timeline

T1608.004 first appeared in tracked threats on 2026-05-19 and was most recently reported on 2026-09-26. The busiest month was 2026-05 with 8 reports, and 18 of the 18 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1608.004 Drive-by Target is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608). Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 5 critical, 12 high, 1 medium.

Threats that use T1608.004 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (13 threats), [T1189 Drive-by Compromise](https://intel.threadlinqs.com/technique/T1189) (11 threats), [T1105 Ingress Tool Transfer](https://intel.threadlinqs.com/technique/T1105) (10 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (10 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1608.004; the most frequent are [Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel) (1), [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) (1), [UNC5142](https://intel.threadlinqs.com/actor/UNC5142) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1608.004.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1608.004, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel) — 1
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 1
- [UNC5142](https://intel.threadlinqs.com/actor/UNC5142) — 1

## Tracked threats

18 tracked threats use T1608.004.

- [Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…](https://intel.threadlinqs.com/threat/TL-2026-2662) — medium — 2026-09-26
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials](https://intel.threadlinqs.com/threat/TL-2026-2600) — critical — 2026-09-21
- [Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusion](https://intel.threadlinqs.com/threat/TL-2026-2326) — high — 2026-09-04
- [Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)](https://intel.threadlinqs.com/threat/TL-2026-2156) — critical — 2026-08-26
- [Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling…](https://intel.threadlinqs.com/threat/TL-2026-2022) — high — 2026-08-15
- [Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com /…](https://intel.threadlinqs.com/threat/TL-2026-0799) — high — 2026-06-15
- [DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma…](https://intel.threadlinqs.com/threat/TL-2026-0769) — high — 2026-06-10
- [CVE-2026-11645: Actively Exploited V8 Out-of-Bounds Memory Access Zero-Day in Google Chrome](https://intel.threadlinqs.com/threat/TL-2026-0740) — high — 2026-06-09
- [Google Chrome 149.0.7827.53 — 429 Vulnerabilities Patched (22 Critical); Critical ANGLE/GPU Memory-Safety…](https://intel.threadlinqs.com/threat/TL-2026-0720) — critical — 2026-06-08
- [ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via…](https://intel.threadlinqs.com/threat/TL-2026-0592) — high — 2026-05-26
- [Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…](https://intel.threadlinqs.com/threat/TL-2026-0581) — high — 2026-05-25
- [2 PhaaS 2 Furious — Chinese-Language Phishing-as-a-Service Ecosystem (UNC5814/Darcula, YY Lai Yu…](https://intel.threadlinqs.com/threat/TL-2026-0578) — high — 2026-05-25
- [Ghost CMS Content API SQL Injection CVE-2026-26980 — Large-Scale ClickFix Watering-Hole Campaign…](https://intel.threadlinqs.com/threat/TL-2026-0575) — critical — 2026-05-24
- [2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)](https://intel.threadlinqs.com/threat/TL-2026-0569) — high — 2026-05-22
- [Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI…](https://intel.threadlinqs.com/threat/TL-2026-0554) — critical — 2026-05-21
- [Unpatched Chromium Background Fetch / Service Worker Persistence Flaw — Silent Post-Close JavaScript…](https://intel.threadlinqs.com/threat/TL-2026-0552) — high — 2026-05-21
- [Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace\[.\]cloud Operation…](https://intel.threadlinqs.com/threat/TL-2026-0533) — high — 2026-05-19

## Related CVEs

CVEs referenced by the tracked threats that use T1608.004, most frequent first.

- [CVE-2026-10881](https://intel.threadlinqs.com/cve/CVE-2026-10881)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-85046](https://intel.threadlinqs.com/cve/CVE-2026-85046)
- [CVE-2026-9110](https://intel.threadlinqs.com/cve/CVE-2026-9110)
- [CVE-2026-9111](https://intel.threadlinqs.com/cve/CVE-2026-9111)
- [CVE-2026-9112](https://intel.threadlinqs.com/cve/CVE-2026-9112)
- [CVE-2026-9113](https://intel.threadlinqs.com/cve/CVE-2026-9113)
- [CVE-2026-9114](https://intel.threadlinqs.com/cve/CVE-2026-9114)
- [CVE-2026-9115](https://intel.threadlinqs.com/cve/CVE-2026-9115)
- [CVE-2026-9116](https://intel.threadlinqs.com/cve/CVE-2026-9116)
- [CVE-2026-9117](https://intel.threadlinqs.com/cve/CVE-2026-9117)
- [CVE-2026-9118](https://intel.threadlinqs.com/cve/CVE-2026-9118)
- [CVE-2026-9119](https://intel.threadlinqs.com/cve/CVE-2026-9119)
- [CVE-2026-9120](https://intel.threadlinqs.com/cve/CVE-2026-9120)
- [CVE-2026-9121](https://intel.threadlinqs.com/cve/CVE-2026-9121)
- [CVE-2026-9122](https://intel.threadlinqs.com/cve/CVE-2026-9122)
- [CVE-2026-9123](https://intel.threadlinqs.com/cve/CVE-2026-9123)
- [CVE-2026-9124](https://intel.threadlinqs.com/cve/CVE-2026-9124)
- [CVE-2026-9126](https://intel.threadlinqs.com/cve/CVE-2026-9126)

## Detection coverage

Threadlinqs maintains 29 detection rules mapped to T1608.004 (SPL 9, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

29 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608) — 250 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1608.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
