# T1608.006 SEO Poisoning

> As of 2026-10-05, T1608.006 (SEO Poisoning) appears in 25 tracked threats, first reported 2026-03-01 and most recently 2026-09-23, with linked actors including Storm-2755, APT38, Akira; it most often appears alongside T1583.001 (Domains).

- **Tracked threats:** 25 (3 critical, 21 high, 1 medium)
- **First seen:** 2026-03-01
- **Last seen:** 2026-09-23
- **Threat actors:** 13
- **Detection rules:** 38 (counts only; Blue tier and above)

## Key facts

- **ID:** T1608.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1608
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1608/006/

## Activity timeline

T1608.006 first appeared in tracked threats on 2026-03-01 and was most recently reported on 2026-09-23. The busiest month was 2026-08 with 9 reports, and 25 of the 25 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1608.006 SEO Poisoning is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608). Threadlinqs maps 25 of 2623 tracked threats (1%) to it; by severity that is 3 critical, 21 high, 1 medium.

Threats that use T1608.006 most often also use [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (21 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (19 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (17 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (14 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

13 tracked threat actors appear in the threats that use T1608.006; the most frequent are [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (1), [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1608.006.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1608.006, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Ghost Stadium](https://intel.threadlinqs.com/actor/Ghost%20Stadium) — 1
- [GrayBravo](https://intel.threadlinqs.com/actor/GrayBravo) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 1
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 1
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 1
- [UNC1549](https://intel.threadlinqs.com/actor/UNC1549) — 1
- [Unnamed](https://intel.threadlinqs.com/actor/Unnamed) — 1

## Tracked threats

25 tracked threats use T1608.006.

- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…](https://intel.threadlinqs.com/threat/TL-2026-2631) — high — 2026-09-23
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…](https://intel.threadlinqs.com/threat/TL-2026-2561) — critical — 2026-09-18
- [Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…](https://intel.threadlinqs.com/threat/TL-2026-2126) — high — 2026-08-23
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…](https://intel.threadlinqs.com/threat/TL-2026-2120) — high — 2026-08-23
- [Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)](https://intel.threadlinqs.com/threat/TL-2026-2109) — high — 2026-08-21
- [Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side](https://intel.threadlinqs.com/threat/TL-2026-2002) — high — 2026-08-13
- [Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise](https://intel.threadlinqs.com/threat/TL-2026-1970) — high — 2026-08-10
- [Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East…](https://intel.threadlinqs.com/threat/TL-2026-1944) — high — 2026-08-08
- [Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RAT](https://intel.threadlinqs.com/threat/TL-2026-1896) — critical — 2026-08-05
- [Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquatting](https://intel.threadlinqs.com/threat/TL-2026-1845) — high — 2026-08-03
- [Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…](https://intel.threadlinqs.com/threat/TL-2026-1816) — high — 2026-08-02
- [GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs](https://intel.threadlinqs.com/threat/TL-2026-1768) — high — 2026-07-30
- [June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…](https://intel.threadlinqs.com/threat/TL-2026-1353) — medium — 2026-07-15
- [BoryptGrab Infostealer Campaign Abuses ~292 Fake GitHub Repos Impersonating Legitimate Software](https://intel.threadlinqs.com/threat/TL-2026-1338) — high — 2026-07-14
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — critical — 2026-06-29
- [Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers](https://intel.threadlinqs.com/threat/TL-2026-0822) — high — 2026-06-16
- [Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com /…](https://intel.threadlinqs.com/threat/TL-2026-0799) — high — 2026-06-15
- [WeedHack MaaS Infostealer — Trojanized Minecraft Mods/Clients via YouTube + SEO Poisoning, 36-Browser &…](https://intel.threadlinqs.com/threat/TL-2026-0665) — high — 2026-06-02
- [Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via…](https://intel.threadlinqs.com/threat/TL-2026-0581) — high — 2026-05-25
- [SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to Deliver In-Memory PowerShell Infostealer…](https://intel.threadlinqs.com/threat/TL-2026-0546) — high — 2026-05-21
- [Fox Tempest Malware-Signing-as-a-Service (MSaaS) — Microsoft DCU Disrupts signspace\[.\]cloud Operation…](https://intel.threadlinqs.com/threat/TL-2026-0533) — high — 2026-05-19
- [Storm-2755 'Payroll Pirate' Campaign: AiTM Phishing and Workday Account Hijacking Targeting Canadian…](https://intel.threadlinqs.com/threat/TL-2026-0346) — high — 2026-04-10
- [Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0218) — high — 2026-03-12
- [Tesseract OCR Typosquat Campaign — ClickFix Multi-Stage Malware Targeting Developers via Fake OCR Tool Sites…](https://intel.threadlinqs.com/threat/TL-2026-0162) — high — 2026-03-01

## Related CVEs

CVEs referenced by the tracked threats that use T1608.006, most frequent first.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)

## Detection coverage

Threadlinqs maintains 38 detection rules mapped to T1608.006 (SPL 10, KQL 11, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

38 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608) — 250 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1608.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
