T1588: T1588
Essential information
- MITRE technique ID
T1588- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 03:56
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
Obtain Capabilities
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (54)
-
The MITRE Corporation Confidence 100
[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
PoisonSeed usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
PrintSteal usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Sniper Dz usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
UNC5174 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PlushDaemon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
FAMOUS CHOLLIMA usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Paper Werewolf usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lorenz usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Worok usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (73)
-
RustBucket usesFamily
-
UnmarshalPwn usesFamily
-
InvisibleFerret usesFamily
-
GoldKefu usesFamily
-
sparrow.jpg usesFamily
-
Supershell usesFamily
-
BlackCat uses
-
Remus usesFamily
-
Chily uses
-
SHATTEREDGLASS usesFamily
-
CreepySnail usesFamily The MITRE Corporation Confidence 100
[CreepySnail](https://attack.mitre.org/software/S1024) is a custom PowerShell implant that has been used by [POLONIUM](https://attack.mitre.org/groups/G1005) since at least 2022.(Citation: Microsoft POLONIUM June 2022)
First seen 01/01/1970 · Last seen 16/11/5138 · -
MegaCreep uses
Reports (50)
-
10 MITREs 23 Observables
-
5 MITREs 1 Malware 20 Observables 1 APT
-
16 MITREs 7 Malwares
-
1 CVE 13 MITREs 1 Malware 40 Observables
-
8 MITREs 4 Malwares 39 Observables 1 APT
-
14 MITREs 1 Malware 12 Observables
-
11 MITREs 1 APT
-
12 MITREs 19 Observables 1 APT
-
6 CVEs 31 MITREs 92 Observables 1 APT
-
18 MITREs 2 Malwares 1 APT
-
10 MITREs 28 Observables 1 APT
-
12 MITREs 1 Malware 52 Observables 1 APT
Vulnerabilities (CVE) (72)
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
- Published
- 21/08/2024
- Modified
- 20/12/2025
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an …
- Attack vector
- Network
- Complexity
- High
- Published
- 18/12/2021
- Modified
- 29/05/2026
The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
- Published
- 27/06/2022
- Modified
- 20/12/2025
Microsoft Exchange Server Remote Code Execution Vulnerability
- Attack vector
- NETWORK
- Published
- 14/07/2021
- Modified
- 20/12/2025
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part …
- Attack vector
- NETWORK
- Published
- 26/07/2024
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 29/05/2026
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
- Published
- 09/12/2025
- Modified
- 21/12/2025
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
- Attack vector
- Adjacent
- Published
- 01/05/2023
- Modified
- 21/12/2025
Attack patterns (MITRE) (3)
Course Of Action (1)
-
Pre-compromise mitigates