T1588: T1588
Essential information
- MITRE technique ID
T1588- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 03:56
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
Obtain Capabilities
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (54)
-
VexTrio usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
I-SOON usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[POLONIUM](https://attack.mitre.org/groups/G1005) is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
GreedyBear usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ShadowSyndicate usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ShinyHunters usesAlienVault Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 · -
Vice Society usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
NoName057(16) usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Bitter APT Group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ALPHV, LockBit, CL0P, relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (73)
-
RustBucket usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
UnmarshalPwn usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
InvisibleFerret usesThe MITRE Corporation Confidence 100
[InvisibleFerret](https://attack.mitre.org/software/S1245) is a modular python malware that is leveraged for data exfiltration and remote access capabilities.(Citation: ESET Contagious Interview BeaverTail InvisibleFerret February 2025)(Citation: Zscaler ContagiousInterview BeaverTail InvisibleFerret November…
First seen 01/01/1970 · Last seen 16/11/5138 · -
GoldKefu usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
sparrow.jpg usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Supershell usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
BlackCat usesFamily The MITRE Corporation Confidence 100
[BlackCat](https://attack.mitre.org/software/S1068) is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First observed November 2021, [BlackCat](https://attack.mitre.org/software/S1068) has been used to target multiple sectors and…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Remus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Chily usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SHATTEREDGLASS usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
CreepySnail usesFamily The MITRE Corporation Confidence 100
[CreepySnail](https://attack.mitre.org/software/S1024) is a custom PowerShell implant that has been used by [POLONIUM](https://attack.mitre.org/groups/G1005) since at least 2022.(Citation: Microsoft POLONIUM June 2022)
First seen 01/01/1970 · Last seen 16/11/5138 · -
MegaCreep usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (50)
-
10 MITREs 23 Observables
-
5 MITREs 1 Malware 20 Observables 1 APT
-
16 MITREs 7 Malwares
-
1 CVE 13 MITREs 1 Malware 40 Observables
-
8 MITREs 4 Malwares 39 Observables 1 APT
-
14 MITREs 1 Malware 12 Observables
-
11 MITREs 1 APT
-
12 MITREs 19 Observables 1 APT
-
6 CVEs 31 MITREs 92 Observables 1 APT
-
18 MITREs 2 Malwares 1 APT
-
10 MITREs 28 Observables 1 APT
-
12 MITREs 1 Malware 52 Observables 1 APT
Vulnerabilities (CVE) (72)
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Exchange Server Elevation of Privilege Vulnerability
- Attack vector
- ADJACENT_NETWORK
- Published
- 14/07/2021
- Modified
- 20/12/2025
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways …
- Attack vector
- Network
- Published
- 30/05/2024
- Modified
- 04/03/2026
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) …
- Attack vector
- Network
- Published
- 13/02/2024
- Modified
- 27/05/2026
Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.
- Attack vector
- NETWORK
- Published
- 21/08/2024
- Modified
- 14/01/2026
Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.
- Published
- 18/01/2022
- Modified
- 20/12/2025
ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, …
- Attack vector
- Network
- Published
- 22/02/2024
- Modified
- 28/02/2026
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker …
- Attack vector
- Network
- Published
- 16/10/2023
- Modified
- 21/12/2025
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the …
- Published
- 03/11/2021
- Modified
- 20/12/2025
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link …
- Published
- 03/09/2025
- Modified
- 08/04/2026
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
- Attack vector
- Network
- Published
- 10/12/2021
- Modified
- 27/05/2026
Attack patterns (MITRE) (3)
Course Of Action (1)
-
Pre-compromise mitigates