T1584.004: T1584.004
Essential information
- MITRE technique ID
T1584.004- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 02:56
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
Server
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (24)
-
TGR-STA-1030 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Sandworm usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Dragonfly](https://attack.mitre.org/groups/G0035) is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Horabot usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Leviathan](https://attack.mitre.org/groups/G0065) is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Earth Lusca](https://attack.mitre.org/groups/G1006) is a suspected China-based cyber espionage group that has been active since at least April 2019. [Earth Lusca](https://attack.mitre.org/groups/G1006) has targeted organizations in Australia, China, Hong Kong,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Squeamish Libra usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Secshow usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SolarMarker usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Volt Typhoon](https://attack.mitre.org/groups/G1017) is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021 primarily targeting critical infrastructure organizations in the US and…
First seen 01/01/1970 · Last seen 16/11/5138 · -
APT16 usesThe MITRE Corporation Confidence 100
[APT16](https://attack.mitre.org/groups/G0023) is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (57)
-
DynoWiper usesFamily
-
Sting wiper usesFamily
-
DNSChanger usesFamily
-
CaddyWiper - S0693 usesFamily
-
Behinder usesFamily
-
Qilin usesFamily
-
SOLOSHRED usesFamily
-
SwiftSlicer usesFamily
-
SharpNikoWiper usesFamily
-
Bulbature usesFamily
-
RansomBoggs usesFamily
-
Rust backdoor usesFamily
Reports (18)
-
3 CVEs 25 MITREs 2 Malwares 120 Observables
-
7 MITREs 1 Malware 14 Observables
-
8 MITREs 17 Observables 1 APT
-
1 CVE 16 MITREs 1 Malware 38 Observables 1 APT
-
16 MITREs 2 Malwares 45 Observables 1 APT
-
14 MITREs 10 Observables 1 APT
Vulnerabilities (CVE) (10)
ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
- Published
- 03/11/2021
- Modified
- 21/12/2025
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in …
- Published
- 03/11/2021
- Modified
- 21/12/2025
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle …
- Attack vector
- Network
- Complexity
- High
- Published
- 08/06/2026
- Modified
- 10/06/2026
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled …
- Attack vector
- Network
- Published
- 10/02/2023
- Modified
- 21/12/2025
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 21/12/2025
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker …
- Attack vector
- NETWORK
- Complexity
- LOW
- EPSS
- 0.0001 (P1.2%)
- Published
- 08/06/2026
- Modified
- 10/06/2026
Campaign (6)
-
Operation Sharpshooter uses
-
Outer Space uses
-
Operation Dream Job uses
-
Night Dragon uses
-
Anthropic AI-orchestrated Campaign uses
-
Juicy Mix uses
Course Of Action (1)
-
Pre-compromise mitigates