Malware

T1588.001

Sub-technique of T1588 Obtain Capabilities.View on attack.mitre.org

About this technique

Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.

In addition to downloading free malware from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware development, criminal marketplaces (including Malware-as-a-Service, or MaaS), or from individuals. In addition to purchasing malware, adversaries may steal and repurpose malware from third-party entities (including other adversaries).

Detection rules1

Rules on DetectionCode tagged with T1588.001.

Sigma1

RuleLevelLog source
Relevant ClamAV Messagehighlinux / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups18

Software0

None recorded.

Campaigns5

Procedure examples23

Groups18

Used byProcedure example
GroupAndariel

Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations.

GroupAPT-C-36

APT-C-36 has utilized well known malware including the Packer-as-a-Service HeartCrypt, PureCrypter, and open-source RATs such as Remcos.

GroupAPT1

APT1 used publicly available malware for privilege escalation.

GroupAquatic Panda

Aquatic Panda has acquired and used njRAT in its operations.

GroupBackdoorDiplomacy

BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.

GroupEarth Lusca

Earth Lusca has acquired and used a variety of malware, including Cobalt Strike.

GroupEmber Bear

Ember Bear has acquired malware and related tools from dark web forums.

GroupLAPSUS$

LAPSUS$ acquired and used the Redline password stealer in their operations.

View all 18 groups examples

Campaigns5

Used byProcedure example
CampaignC0015

For C0015, the threat actors used Cobalt Strike and Conti ransomware.

CampaignFunnyDream

For FunnyDream, the threat actors used a new backdoor named FunnyDream.

CampaignJ-magic Campaign

During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor.

CampaignNight Dragon

During Night Dragon, threat actors used Trojans from underground hacker websites.

CampaignOperation Spalax

For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.