Threadlinqs IntelligenceStart free

ATT&CK techniqueResource Development

T1608.005 Link Target

Resource DevelopmentEnterpriseSub-technique

As of 2026-10-05, T1608.005 (Link Target) appears in 39 tracked threats, first reported 2026-02-16 and most recently 2026-09-29, with linked actors including Kali365, APT44, Ghost Stadium; it most often appears alongside T1566.002 (Spearphishing Link).

Tracked threats
391 critical, 21 high, 16 medium, 1 low
First seen
2026-02-16
Last seen
2026-09-29
Threat actors
9In the threats using it
Detection rules
76Blue tier and above

Data as of:

Activity timeline

T1608.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 12 reports, and 39 of the 39 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1608.005 Link Target is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1608 Stage Capabilities. Threadlinqs maps 39 of 2623 tracked threats (1.5%) to it; by severity that is 1 critical, 21 high, 16 medium, 1 low.

Threats that use T1608.005 most often also use T1566.002 Spearphishing Link (34 threats), T1583.001 Domains (29 threats), T1204.001 Malicious Link (28 threats), T1684.001 Impersonation (27 threats), T1583.006 Web Services (22 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1608.005; the most frequent are Kali365 (2), APT44 (1), Ghost Stadium (1), Kali365 PhaaS operators (1), Outsider Enterprise (1).

Mitigations

MITRE ATT&CK lists 1 mitigation for T1608.005.

Data sources

Telemetry that can reveal T1608.005, per MITRE ATT&CK.

  • Internet Scan — Response Content

Threat actors using it

Tracked threats

The 30 most recent of 39 tracked threats that use T1608.005.

Detection coverage

Threadlinqs maintains 76 detection rules mapped to T1608.005 (SPL 22, KQL 24, Sigma 30). Rule content is available to Blue tier accounts and above; this page shows counts only.

76 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Parent technique

T1608 Stage Capabilities — 250 tracked threats at the technique level.