T1588.002: T1588.002
Essential information
- MITRE technique ID
T1588.002- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 04:08
- Modified
- 27/03/2026 01:11
- Author / Source
- The MITRE Corporation
Aliases
Tool
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (70)
-
TA2541 usesThe MITRE Corporation Confidence 100
[TA2541](https://attack.mitre.org/groups/G1018) is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. [TA2541](https://attack.mitre.org/groups/G1018) campaigns are typically high volume and…
First seen 01/01/1970 · Last seen 16/11/5138 · -
DPRK usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Trigona usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Mirai usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
WIRTE usesThe MITRE Corporation Confidence 100
[WIRTE](https://attack.mitre.org/groups/G0090) is a threat group that has been active since at least August 2018. [WIRTE](https://attack.mitre.org/groups/G0090) has targeted government, diplomatic, financial, military, legal, and technology organizations in the Middle…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[BITTER](https://attack.mitre.org/groups/G1002) is a suspected South Asian cyber espionage threat group that has been active since at least 2013. [BITTER](https://attack.mitre.org/groups/G1002) has targeted government, energy, and engineering organizations in Pakistan,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Telekopye usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT33](https://attack.mitre.org/groups/G0064) is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[LAPSUS$](https://attack.mitre.org/groups/G1004) is cyber criminal threat group that has been active since at least mid-2021. [LAPSUS$](https://attack.mitre.org/groups/G1004) specializes in large-scale social engineering and extortion operations, including destructive attacks without the…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Mallox usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Cobalt Group](https://attack.mitre.org/groups/G0080) is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (57)
-
Xeno RAT usesFamily
-
GOSHELL usesFamily
-
ShadowV2 usesFamily
-
MuddyViper usesFamily
-
NetSupport usesFamily
-
SYS01 usesFamily
-
Track2NFC usesFamily
-
AllaKore RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Mélofée usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
NGate usesFamily
-
PURESTEALER usesFamily
-
Neo-reGeorg - S1189 usesFamily
Reports (50)
-
14 MITREs 5 Observables
-
11 MITREs
-
19 MITREs 9 Malwares 103 Observables 1 APT
-
5 MITREs 1 Malware 34 Observables 1 APT
-
1 CVE 14 MITREs 1 Malware 1 Observable 1 APT
-
8 MITREs 1 Malware
-
8 MITREs 3 Malwares 8 Observables 1 APT
-
Two sides of the same coin related12 MITREs 3 Malwares 1 APT
-
8 MITREs 4 Malwares
-
13 MITREs 2 Malwares
-
Where to Find Aspiring Hackers related11 MITREs 7 Malwares 1 APT
-
13 MITREs 6 Malwares 6 Observables 1 APT
Vulnerabilities (CVE) (81)
Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must …
- Attack vector
- Adjacent
- Published
- 25/08/2025
- Modified
- 27/05/2026
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to …
- Attack vector
- Network
- Published
- 14/08/2025
- Modified
- 27/05/2026
Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or …
- Attack vector
- Network
- Complexity
- Low
- Published
- 18/09/2013
- Modified
- 27/05/2026
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a …
- Attack vector
- Network
- Published
- 12/11/2024
- Modified
- 27/05/2026
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out …
- Attack vector
- Local
- Published
- 20/12/2025
- Modified
- 30/12/2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This …
- Attack vector
- Network
- Published
- 07/02/2025
- Modified
- 21/12/2025
Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
- Attack vector
- Network
- Published
- 25/08/2025
- Modified
- 27/05/2026
A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of …
- Attack vector
- NETWORK
- Published
- 24/02/2025
- Modified
- 21/12/2025
Campaign (10)
-
Night Dragon uses
-
C0017 uses
-
ShadowRay uses
-
C0015 uses
-
Operation Spalax uses
-
C0010 uses
-
Operation Wocao uses
-
Cutting Edge uses
-
Operation CuckooBees uses
-
Triton Safety Instrumented System Attack uses