Upload Malware

T1608.001

Sub-technique of T1608 Stage Capabilities.View on attack.mitre.org

About this technique

Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server.

Malware may be placed on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Malware can also be staged on web services, such as GitHub or Pastebin; hosted on the InterPlanetary File System (IPFS), where decentralized content storage makes the removal of malicious files difficult; or saved on the blockchain as smart contracts, which are resilient against takedowns that would affect traditional infrastructure.

Adversaries may upload backdoored files, such as software packages, application binaries, virtual machine images, or container images, to third-party software stores, package libraries, extension marketplaces, or repositories (ex: GitHub, CNET, AWS Community AMIs, Docker Hub, PyPi, NPM). By chance encounter, victims may directly download/install these backdoored files via User Execution. Masquerading, including typosquatting legitimate software, may increase the chance of users mistakenly executing these files.

Detection rules1

Rules on DetectionCode tagged with T1608.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Windows Unusual File Creation in Confluence DirectoryAnomalyNULLSysmon EventID 11

Groups28

Show 4 more

Software1

Campaigns8

Procedure examples37

Groups28

Used byProcedure example
GroupAPT-C-36

APT-C-36 has staged malware implants on group-owned repositories and sites.

GroupAPT32

APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting.

GroupAPT42

APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.

GroupBITTER

BITTER has registered domains to stage payloads.

GroupBlackByte

BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.

GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

GroupEarth Lusca

Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive.

GroupEXOTIC LILY

EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive.

View all 28 groups examples

Software1

Used byProcedure example
MalwareShai-Hulud

Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts.

Campaigns8

Used byProcedure example
CampaignC0010

For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system.

CampaignC0011

For C0011, Transparent Tribe hosted malicious documents on domains registered by the group.

CampaignC0021

For C0021, the threat actors uploaded malware to websites under their control.

CampaignNight Dragon

During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers.

CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used compromised servers to host malware.

CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors staged malicious files on Dropbox and other websites.

CampaignOperation Spalax

For Operation Spalax, the threat actors staged malware and malicious files in legitimate hosting services such as OneDrive or MediaFire.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda staged malware on adversary-controlled domains and cloud storage instances during RedDelta Modified PlugX Infection Chain Operations.

References5

  1. Bleeping Computer Binance Smart Chain 2023 Open source
    Bill Toulas. (2023, October 13). Hackers use Binance Smart Chain contracts to store malicious scripts. Retrieved May 22, 2025.
  2. Datadog Security Labs Malicious PyPi Packages 2024 Open source
    Sebastian Obregoso and Christophe Tafani-Dereeper. (2024, May 23). Malicious PyPI packages targeting highly specific MacOS machines. Retrieved May 22, 2025.
  3. Guardio Etherhiding 2023 Open source
    Nati Tal and Oleg Zaytsev. (2023, October 13). “EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts. Retrieved May 22, 2025.
  4. Talos IPFS 2022 Open source
    Edmund Brumaghin. (2022, November 9). Threat Spotlight: Cyber Criminal Adoption of IPFS for Phishing, Malware Campaigns. Retrieved March 8, 2023.
  5. Volexity Ocean Lotus November 2020 Open source
    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.