T1588.002: T1588.002
Essential information
- MITRE technique ID
T1588.002- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 04:08
- Modified
- 27/03/2026 01:11
- Author / Source
- The MITRE Corporation
Aliases
Tool
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (70)
-
Blue Mockingbird relatedThe MITRE Corporation Confidence 100
[Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created…
First seen 01/01/1970 · Last seen 16/11/5138 · -
CL-STA-1009 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Carbanak](https://attack.mitre.org/groups/G0008) is a cybercriminal group that has used [Carbanak](https://attack.mitre.org/software/S0030) malware to target financial institutions since at least 2013. [Carbanak](https://attack.mitre.org/groups/G0008) may be linked to groups tracked separately as [Cobalt…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Chimera relatedThe MITRE Corporation Confidence 100
[Chimera](https://attack.mitre.org/groups/G0114) is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline…
First seen 01/01/1970 · Last seen 16/11/5138 · -
China-nexus threat actors relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Chinese cybercriminal groups relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Cinnamon Tempest](https://attack.mitre.org/groups/G1021) is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked [Babuk](https://attack.mitre.org/software/S0638) source code. [Cinnamon…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Coquettte relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DarkHydrus relatedThe MITRE Corporation Confidence 100
[DarkHydrus](https://attack.mitre.org/groups/G0079) is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Dragonfly](https://attack.mitre.org/groups/G0035) is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical Infrastructure March 2022)(Citation: UK GOV FSB…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Earth Baxia relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Earth Lamia, Jackpot Panda relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (57)
-
Xeno RAT usesFamily
-
GOSHELL usesFamily
-
ShadowV2 usesFamily
-
MuddyViper usesFamily
-
NetSupport usesFamily
-
SYS01 usesFamily
-
Track2NFC usesFamily
-
AllaKore RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Mélofée usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
NGate usesFamily
-
PURESTEALER usesFamily
-
Neo-reGeorg - S1189 usesFamily
Reports (50)
-
AlienVault Confidence 100 20 MITREs 7 IOCs 7 Observables 1 APT
-
Threat landscape — Belgium relatedConfidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 Tools
-
Threat landscape — insurance relatedConfidence 100 199 MITREs 11 APTs
-
10 MITREs
-
AlienVault Confidence 100 14 MITREs 2 Malwares 21 IOCs 21 Observables 1 APT
-
AlienVault Confidence 100 20 MITREs 1 Malware 13 IOCs 13 Observables
-
3 CVEs 22 MITREs 5 Malwares 16 Observables 1 APT
-
AlienVault Confidence 100 16 MITREs 3 IOCs 3 Observables 1 APT
-
20 MITREs 2 Malwares 15 Observables 1 APT
-
20 MITREs 3 Malwares 7 Observables 1 APT
-
20 MITREs 7 Malwares 5 Observables 1 APT
-
12 CVEs 16 MITREs 2 Malwares 29 Observables 1 APT
Vulnerabilities (CVE) (81)
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys …
- Attack vector
- Local
- Published
- 04/03/2024
- Modified
- 21/12/2025
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …
- Attack vector
- Network
- Published
- 13/09/2024
- Modified
- 21/12/2025
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
- Attack vector
- Local
- Published
- 13/08/2025
- Modified
- 27/05/2026
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands …
- Attack vector
- Network
- Published
- 05/08/2025
- Modified
- 27/05/2026
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code …
- Attack vector
- Network
- Published
- 14/05/2025
- Modified
- 14/01/2026
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. …
- Attack vector
- Network
- Published
- 02/06/2023
- Modified
- 21/12/2025
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to …
- Attack vector
- Network
- Published
- 10/06/2025
- Modified
- 21/12/2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured …
- Attack vector
- Network
- Published
- 26/08/2025
- Modified
- 27/05/2026
The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the …
- Attack vector
- NETWORK
- Published
- 25/11/2025
- Modified
- 21/12/2025
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to …
- Attack vector
- Network
- Published
- 02/11/2023
- Modified
- 21/12/2025
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on …
- Published
- 23/12/2024
- Modified
- 24/12/2024
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
- Attack vector
- Network
- Published
- 13/08/2025
- Modified
- 27/05/2026
Campaign (10)
-
Night Dragon uses
-
C0017 uses
-
ShadowRay uses
-
C0015 uses
-
Operation Spalax uses
-
C0010 uses
-
Operation Wocao uses
-
Cutting Edge uses
-
Operation CuckooBees uses
-
Triton Safety Instrumented System Attack uses