Activity timeline
T1608.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 9 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1608.006 SEO Poisoning is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1608 Stage Capabilities. Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 3 critical, 21 high, 1 medium.
Threats that use T1608.006 most often also use T1583.001 Domains (21 threats), T1071.001 Web Protocols (19 threats), T1204.002 Malicious File (17 threats), T1036.005 Match Legitimate Resource Name or Location (14 threats), T1027 Obfuscated Files or Information (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
13 tracked threat actors appear in the threats that use T1608.006; the most frequent are Storm-2755 (2), APT38 (1), Akira (1), Andariel (1), Ghost Stadium (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1608.006.
Data sources
Telemetry that can reveal T1608.006, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
25 tracked threats use T1608.006.
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…critical
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…high
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)high
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromisehigh
- Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East…high
- Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RATcritical
- Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquattinghigh
- Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…high
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPshigh
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…medium
- BoryptGrab Infostealer Campaign Abuses ~292 Fake GitHub Repos Impersonating Legitimate Softwarehigh
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)critical
- Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installershigh
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com /…high
- WeedHack MaaS Infostealer — Trojanized Minecraft Mods/Clients via YouTube + SEO Poisoning, 36-Browser &…high
- Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…high
- SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to Deliver In-Memory PowerShell Infostealer…high
- Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace[.]cloud Operation…high
- Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian…high
- Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Thefthigh
- Tesseract OCR Typosquat Campaign — ClickFix Multi-Stage Malware Targeting Developers via Fake OCR Tool Sites…high
Detection coverage
Threadlinqs maintains 38 detection rules mapped to T1608.006 (SPL 10, KQL 11, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1608 Stage Capabilities — 250 tracked threats at the technique level.