Sub-technique of T1587 Develop Capabilities.View on attack.mitre.org
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
During malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders.
As with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware.
Some aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of Web Services.
Rules on DetectionCode tagged with T1587.001.
| Rule | Level | Log source |
|---|---|---|
| ProxyLogon MSExchange OabVirtualDirectory | critical | windows / NULL |
| Potential Privilege Escalation To LOCAL SYSTEM | high | windows / process_creation |
| Potential PsExec Remote Execution | high | windows / process_creation |
| PsExec/PAExec Escalation to LOCAL SYSTEM | high | windows / process_creation |
| PUA - CsExec Execution | high | windows / process_creation |
| Uncommon File Created In Office Startup Folder | high | windows / file_event |
| VHD Image Download Via Browser | medium | windows / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco Secure Firewall - Possibly Compromised Host | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAoqin Dragon | Aoqin Dragon has used custom malware, including Mongall and Heyoka Backdoor, in their operations. |
| GroupAPT-C-36 | APT-C-36 has customized existing malware with new capabilities including njRAT, AsyncRAT, LimeRAT, and BitRAT. |
| GroupAPT29 | APT29 has used unique malware in many of their operations. |
| GroupCleaver | Cleaver has created customized tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging. |
| GroupContagious Interview | Contagious Interview has developed malware that utilizes Qt cross-platform framework to include BeaverTail. |
| GroupFIN13 | FIN13 has utilized custom malware to maintain persistence in a compromised environment. |
| GroupFIN7 | FIN7 has developed malware for use in operations, including the creation of infected removable media. |
| GroupIndrik Spider | Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day. |
| CampaignArcaneDoor | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner. |
| CampaignC0010 | For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP. |
| CampaignCostaRicto | For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT. |
| CampaignJuicy Mix | For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools. |
| CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| CampaignOperation Ghost | For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.