T1588.002: T1588.002
Essential information
- MITRE technique ID
T1588.002- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 04:08
- Modified
- 27/03/2026 01:11
- Author / Source
- The MITRE Corporation
Aliases
Tool
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (70)
-
Blue Mockingbird relatedThe MITRE Corporation Confidence 100
[Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created…
First seen 01/01/1970 · Last seen 16/11/5138 · -
CL-STA-1009 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Carbanak](https://attack.mitre.org/groups/G0008) is a cybercriminal group that has used [Carbanak](https://attack.mitre.org/software/S0030) malware to target financial institutions since at least 2013. [Carbanak](https://attack.mitre.org/groups/G0008) may be linked to groups tracked separately as [Cobalt…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Chimera relatedThe MITRE Corporation Confidence 100
[Chimera](https://attack.mitre.org/groups/G0114) is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline…
First seen 01/01/1970 · Last seen 16/11/5138 · -
China-nexus threat actors relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Chinese cybercriminal groups relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Cinnamon Tempest](https://attack.mitre.org/groups/G1021) is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked [Babuk](https://attack.mitre.org/software/S0638) source code. [Cinnamon…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Coquettte relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DarkHydrus relatedThe MITRE Corporation Confidence 100
[DarkHydrus](https://attack.mitre.org/groups/G0079) is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Dragonfly](https://attack.mitre.org/groups/G0035) is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Earth Baxia relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Earth Lamia, Jackpot Panda relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (57)
-
Xeno RAT usesFamily
-
GOSHELL usesFamily
-
ShadowV2 usesFamily
-
MuddyViper usesFamily
-
NetSupport usesFamily
-
SYS01 usesFamily
-
Track2NFC usesFamily
-
AllaKore RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Mélofée usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
NGate usesFamily
-
PURESTEALER usesFamily
-
Neo-reGeorg - S1189 usesFamily
Reports (50)
-
AlienVault Confidence 100 20 MITREs 7 IOCs 7 Observables 1 APT
-
Threat landscape — Belgium relatedConfidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 Tools
-
Threat landscape — insurance relatedConfidence 100 199 MITREs 11 APTs
-
10 MITREs
-
AlienVault Confidence 100 14 MITREs 2 Malwares 21 IOCs 21 Observables 1 APT
-
AlienVault Confidence 100 20 MITREs 1 Malware 13 IOCs 13 Observables
-
3 CVEs 22 MITREs 5 Malwares 16 Observables 1 APT
-
AlienVault Confidence 100 16 MITREs 3 IOCs 3 Observables 1 APT
-
20 MITREs 2 Malwares 15 Observables 1 APT
-
20 MITREs 3 Malwares 7 Observables 1 APT
-
20 MITREs 7 Malwares 5 Observables 1 APT
-
12 CVEs 16 MITREs 2 Malwares 29 Observables 1 APT
Vulnerabilities (CVE) (81)
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute …
- Attack vector
- ADJACENT_NETWORK
- Published
- 11/07/2025
- Modified
- 16/03/2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially …
- Attack vector
- NETWORK
- Published
- 22/08/2025
- Modified
- 21/12/2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be …
- Attack vector
- Network
- Published
- 16/06/2025
- Modified
- 21/12/2025
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service …
- Published
- 05/08/2025
- Modified
- 27/05/2026
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code …
- Attack vector
- Network
- Published
- 28/07/2025
- Modified
- 21/12/2025
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be …
- Published
- 05/08/2025
- Modified
- 27/05/2026
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If …
- Attack vector
- Network
- Published
- 19/09/2024
- Modified
- 21/12/2025
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary …
- Attack vector
- NETWORK
- Complexity
- Low
- Published
- 28/08/2025
- Modified
- 18/06/2026
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions …
- Attack vector
- NETWORK
- Published
- 23/08/2022
- Modified
- 21/12/2025
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing …
- Attack vector
- NETWORK
- Published
- 13/04/2024
- Modified
- 21/12/2025
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON …
- Attack vector
- NETWORK
- Published
- 06/01/2023
- Modified
- 21/12/2025
Campaign (10)
-
Night Dragon uses
-
C0017 uses
-
ShadowRay uses
-
C0015 uses
-
Operation Spalax uses
-
C0010 uses
-
Operation Wocao uses
-
Cutting Edge uses
-
Operation CuckooBees uses
-
Triton Safety Instrumented System Attack uses