Sub-technique of T1588 Obtain Capabilities.View on attack.mitre.org
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
In addition to downloading free malware from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware development, criminal marketplaces (including Malware-as-a-Service, or MaaS), or from individuals. In addition to purchasing malware, adversaries may steal and repurpose malware from third-party entities (including other adversaries).
Rules on DetectionCode tagged with T1588.001.
| Rule | Level | Log source |
|---|---|---|
| Relevant ClamAV Message | high | linux / NULL |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAndariel | Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations. |
| GroupAPT-C-36 | APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos. |
| GroupAPT1 | APT1 used publicly available malware for privilege escalation. |
| GroupAquatic Panda | Aquatic Panda has acquired and used njRAT in its operations. |
| GroupBackdoorDiplomacy | BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations. |
| GroupEarth Lusca | Earth Lusca has acquired and used a variety of malware, including Cobalt Strike. |
| GroupEmber Bear | Ember Bear has acquired malware and related tools from dark web forums. |
| GroupLAPSUS$ | LAPSUS$ acquired and used the Redline password stealer in their operations. |
| Used by | Procedure example |
|---|---|
| CampaignC0015 | For C0015, the threat actors used Cobalt Strike and Conti ransomware. |
| CampaignFunnyDream | For FunnyDream, the threat actors used a new backdoor named FunnyDream. |
| CampaignJ-magic Campaign | During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor. |
| CampaignNight Dragon | During Night Dragon, threat actors used Trojans from underground hacker websites. |
| CampaignOperation Spalax | For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.