T1588.001 Malware
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
In addition to downloading free malware from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware development, criminal marketplaces (including Malware-as-a-Service, or MaaS), or from individuals. In addition to purchasing malware, adversaries may steal and repurpose malware from third-party entities (including other adversaries).
| Item | Value |
|---|---|
| ID | T1588.001 |
| Sub-techniques | T1588.001, T1588.002, T1588.003, T1588.004, T1588.005, T1588.006, T1588.007 |
| Tactics | TA0042 |
| Platforms | PRE |
| Version | 1.1 |
| Created | 01 October 2020 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| G0138 | Andariel | Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations.12 |
| G0006 | APT1 | APT1 used publicly available malware for privilege escalation.8 |
| G0143 | Aquatic Panda | Aquatic Panda has acquired and used njRAT in its operations.9 |
| G0135 | BackdoorDiplomacy | BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.17 |
| C0015 | C0015 | For C0015, the threat actors used Cobalt Strike and Conti ransomware.24 |
| G1006 | Earth Lusca | Earth Lusca has acquired and used a variety of malware, including Cobalt Strike.16 |
| G1003 | Ember Bear | Ember Bear has acquired malware and related tools from dark web forums.5 |
| C0007 | FunnyDream | For FunnyDream, the threat actors used a new backdoor named FunnyDream.23 |
| C0050 | J-magic Campaign | During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor.22 |
| G1004 | LAPSUS$ | LAPSUS$ acquired and used the Redline password stealer in their operations.6 |
| G0140 | LazyScripter | LazyScripter has used a variety of open-source remote access Trojans for its operations.10 |
| G1014 | LuminousMoth | LuminousMoth has obtained and used malware such as Cobalt Strike.32 |
| G1013 | Metador | Metador has used unique malware in their operations, including metaMain and Mafalda.7 |
| C0002 | Night Dragon | During Night Dragon, threat actors used Trojans from underground hacker websites.20 |
| C0005 | Operation Spalax | For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT.21 |
| G1015 | Scattered Spider | Scattered Spider has obtained malware to use at multiple stages of operations including information stealers, remote access tools, and ransomware.1918 |
| G1018 | TA2541 | TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories.4 |
| G0092 | TA505 | TA505 has used malware such as Azorult and Cobalt Strike in their operations.13 |
| G0010 | Turla | Turla has used malware obtained after compromising other threat actors, such as OilRig.1514 |
| G1048 | UNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA.11 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1056 | Pre-compromise | This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. |
References
-
FireEye. (2014). SUPPLY CHAIN ANALYSIS: From Quartermaster to SunshopFireEye. Retrieved March 6, 2017. ↩
-
Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022. ↩
-
Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022. ↩
-
Larson, S. and Wise, J. (2022, February 15). Charting TA2541’s Flight. Retrieved September 12, 2023. ↩
-
US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024. ↩
-
MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022. ↩
-
Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023. ↩
-
Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016. ↩
-
Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022. ↩
-
Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024. ↩
-
Punsaen Boonyakarn, Shawn Chew, Logeswaran Nadarajan, Mathew Potaczek, Jakub Jozwiak, and Alex Marvi. (2024, June 18). Cloaked and Covert: Uncovering UNC3886 Espionage Operations. Retrieved September 24, 2024. ↩
-
FSI. (2017, July 27). Campaign Rifle - Andariel, the Maiden of Anguish. Retrieved September 12, 2024. ↩
-
Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022. ↩
-
Insikt Group. (2020, March 12). Swallowing the Snake’s Tail: Tracking Turla Infrastructure. Retrieved September 16, 2024. ↩
-
NSA/NCSC. (2019, October 21). Cybersecurity Advisory: Turla Group Exploits Iranian APT To Expand Coverage Of Victims. Retrieved October 16, 2020. ↩
-
Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022. ↩
-
Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021 ↩
-
Check Point Team. (2025, July 7). Exposing Scattered Spider: New Indicators Highlight Growing Threat to Enterprises and Aviation. Retrieved October 13, 2025. ↩
-
Mandiant Incident Response. (2025, May 6). Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines. Retrieved October 13, 2025. ↩
-
McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018. ↩
-
M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022. ↩
-
Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025. ↩
-
Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022. ↩
-
DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022. ↩