Umbra Wiki technique technique/T1588.001
Back to wiki

T1588.001 — Malware

provenance: imported · ATT&CK: T1588.001

T1588.001: Malware

MITRE ATT&CK® Enterprise technique

Tactics Resource Development
Platforms PRE
Permissions required
Version 1.1
Parent technique T1588

Description

Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.

In addition to downloading free malware from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware development, criminal marketplaces (including Malware-as-a-Service, or MaaS), or from individuals. In addition to purchasing malware, adversaries may steal and repurpose malware from third-party entities (including other adversaries).

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1588/001
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/