Malware

T1587.001

Sub-technique of T1587 Develop Capabilities.View on attack.mitre.org

About this technique

Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.

During malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders.

As with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware.

Some aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of Web Services.

Detection rules8

Rules on DetectionCode tagged with T1587.001.

Sigma7

RuleLevelLog source
ProxyLogon MSExchange OabVirtualDirectorycriticalwindows / NULL
Potential Privilege Escalation To LOCAL SYSTEMhighwindows / process_creation
Potential PsExec Remote Executionhighwindows / process_creation
PsExec/PAExec Escalation to LOCAL SYSTEMhighwindows / process_creation
PUA - CsExec Executionhighwindows / process_creation
Uncommon File Created In Office Startup Folderhighwindows / file_event
VHD Image Download Via Browsermediumwindows / file_event

Splunk1

RuleTypeRiskData source
Cisco Secure Firewall - Possibly Compromised HostAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event

Groups26

Show 2 more

Software0

None recorded.

Campaigns16

Procedure examples42

Groups26

Used byProcedure example
GroupAoqin Dragon

Aoqin Dragon has used custom malware, including Mongall and Heyoka Backdoor, in their operations.

GroupAPT-C-36

APT-C-36 has customized existing malware with new capabilities including njRAT, AsyncRAT, LimeRAT, and BitRAT.

GroupAPT29

APT29 has used unique malware in many of their operations.

GroupCleaver

Cleaver has created customized tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging.

GroupContagious Interview

Contagious Interview has developed malware that utilizes Qt cross-platform framework to include BeaverTail.

GroupFIN13

FIN13 has utilized custom malware to maintain persistence in a compromised environment.

GroupFIN7

FIN7 has developed malware for use in operations, including the creation of infected removable media.

GroupIndrik Spider

Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker.

View all 26 groups examples

Campaigns16

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day.

CampaignArcaneDoor

ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner.

CampaignC0010

For C0010, UNC3890 actors used unique malware, including SUGARUSH and SUGARDUMP.

CampaignCostaRicto

For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT.

CampaignJuicy Mix

For Juicy Mix, OilRig improved on Solar by developing the Mango backdoor.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools.

CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.

CampaignOperation Ghost

For Operation Ghost, APT29 used new strains of malware including FatDuke, MiniDuke, RegDuke, and PolyglotDuke.

View all 16 campaigns examples

References8

  1. ActiveMalwareEnergy Open source
    Dan Goodin. (2014, June 30). Active malware operation let attackers sabotage US energy industry. Retrieved March 9, 2017.
  2. FBI Flash FIN7 USB Open source
    The Record. (2022, January 7). FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware. Retrieved January 14, 2022.
  3. FireEye APT29 Open source
    FireEye Labs. (2015, July). HAMMERTOSS: Stealthy Tactics Define a Russian Cyber Threat Group. Retrieved November 17, 2024.
  4. GamaCopy organization Open source
    Knownsec 404 Advanced Threat Intelligence team. (2025, January 21). Love and hate under war: The GamaCopy organization, which imitates the Russian Gamaredon, uses military — related bait to launch attacks on Russia. Retrieved June 14, 2025.
  5. Kaspersky Sofacy Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.
  6. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  7. Olympic Destroyer Open source
    Paul Rascagneres, Martin Lee. (2018, February 26). Who Wasn’t Responsible for Olympic Destroyer?. Retrieved June 14, 2025.
  8. Risky Bulletin Threat actor impersonates FSB APT Open source
    Catalin Cimpanu. (2025, January 22). Risky Bulletin: Threat actor impersonates FSB APT for months to target Russian orgs. Retrieved June 14, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.