Threadlinqs IntelligenceStart free

ATT&CK techniqueResource Development

T1587 Develop Capabilities

Resource DevelopmentEnterprise

As of 2026-10-05, T1587 (Develop Capabilities) appears in 402 tracked threats, first reported 2026-01-19 and most recently 2026-09-27, with linked actors including APT38, APT28, Lazarus Group; it most often appears alongside T1059 (Command and Scripting Interpreter).

Tracked threats
402140 critical, 222 high, 33 medium, 1 low
First seen
2026-01-19
Last seen
2026-09-27
Threat actors
112In the threats using it
Detection rules
21Blue tier and above

Data as of:

Activity timeline

T1587 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 154 reports, and 402 of the 402 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1587 Develop Capabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 402 of 2623 tracked threats (15.3%) to it; by severity that is 140 critical, 222 high, 33 medium, 1 low.

Threats that use T1587 most often also use T1059 Command and Scripting Interpreter (288 threats), T1071 Application Layer Protocol (274 threats), T1005 Data from Local System (256 threats), T1027 Obfuscated Files or Information (239 threats), T1036 Masquerading (232 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

112 tracked threat actors appear in the threats that use T1587; the most frequent are APT38 (10), APT28 (8), Lazarus Group (8), Stardust Chollima (8), TeamPCP (8).

Mitigations

MITRE ATT&CK lists 1 mitigation for T1587.

Data sources

Telemetry that can reveal T1587, per MITRE ATT&CK.

  • Internet Scan — Response Content
  • Malware Repository — Malware Content, Malware Metadata

Threat actors using it

Tracked threats

The 30 most recent of 402 tracked threats that use T1587.

Detection coverage

Threadlinqs maintains 21 detection rules mapped to T1587 (SPL 6, KQL 5, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

21 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1587.001 Malware — 210 tracked threats
  • T1587.002 Code Signing Certificates — 1 tracked threat
  • T1587.003 Digital Certificates — 7 tracked threats
  • T1587.004 Exploits — 122 tracked threats