T1583.004: T1583.004
Essential information
- MITRE technique ID
T1583.004- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 02:48
- Modified
- 11/05/2026 12:26
- Author / Source
- The MITRE Corporation
Aliases
Server
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (27)
-
Roaming Mantis usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures…
First seen 01/01/1970 · Last seen 16/11/5138 · -
TGR-STA-1030 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
APT-C-60 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active…
First seen 01/01/1970 · Last seen 16/11/5138 · -
ransomhouse usesRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 · -
Predator usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Contagious Interview](https://attack.mitre.org/groups/G1052) is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials.…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Squeamish Libra usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Intellexa usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SolarMarker usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (55)
-
ShadowPad - S0596 usesFamily
-
BeaverTail usesFamily
-
Rhysida usesFamily
-
MintsLoader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PyInstaller usesFamily
-
Rescoms usesFamily
-
Remcos - S0332 usesFamily
-
Neo-reGeorg - S1189 usesFamily
-
Behinder usesFamily
-
Karkadann uses
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
HemiGate usesFamily
Reports (14)
-
14 MITREs 1 Observable
-
Global Corporate Web related5 MITREs 1 Malware 1 Observable 1 APT
-
13 MITREs 6 Malwares 6 Observables 1 APT
-
21 MITREs 3 Malwares 12 Observables 1 APT
-
18 MITREs 8 Malwares 12 Observables 1 APT
-
15 MITREs 3 Malwares 43 Observables 1 APT
-
6 MITREs 4 Malwares 102 Observables 1 APT
-
10 MITREs 1 Malware 103 Observables 1 APT
-
18 MITREs 3 Malwares 17 Observables 1 APT
-
14 MITREs 4 Malwares 106 Observables 1 APT
-
4 MITREs 1 Malware 16 Observables 1 APT
-
5 CVEs 6 MITREs 1 Malware 5 Observables 1 APT
Vulnerabilities (CVE) (8)
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 21/12/2025
A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor …
- Attack vector
- LOCAL
- Published
- 30/09/2024
- Modified
- 21/12/2025
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to …
- Attack vector
- LOCAL
- Published
- 15/08/2024
- Modified
- 21/12/2025
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in …
- Published
- 03/11/2021
- Modified
- 21/12/2025
wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.
- Attack vector
- NETWORK
- Published
- 23/03/2022
- Modified
- 21/12/2025
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load …
- Attack vector
- Local
- Published
- 03/09/2024
- Modified
- 21/12/2025
Course Of Action (1)
-
Pre-compromise mitigates
Campaign (4)
-
Night Dragon uses
-
Operation Dream Job uses
-
Operation Honeybee uses
-
Operation Wocao uses