Activity timeline
T1587 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 154 reports, and 402 of the 402 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1587 Develop Capabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 402 of 2623 tracked threats (15.3%) to it; by severity that is 140 critical, 222 high, 33 medium, 1 low.
Threats that use T1587 most often also use T1059 Command and Scripting Interpreter (288 threats), T1071 Application Layer Protocol (274 threats), T1005 Data from Local System (256 threats), T1027 Obfuscated Files or Information (239 threats), T1036 Masquerading (232 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
112 tracked threat actors appear in the threats that use T1587; the most frequent are APT38 (10), APT28 (8), Lazarus Group (8), Stardust Chollima (8), TeamPCP (8).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1587.
Data sources
Telemetry that can reveal T1587, per MITRE ATT&CK.
- Internet Scan — Response Content
- Malware Repository — Malware Content, Malware Metadata
Threat actors using it
Tracked threats
The 30 most recent of 402 tracked threats that use T1587.
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplacemedium
- Cloudflare Containers cross-tenant residual disk data exposure via device-mapper thin-provisioning…high
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devicescritical
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence…high
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…high
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp…high
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurecritical
- Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Accesscritical
- MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generationhigh
- AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…critical
- Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident…high
- QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Acceleratormedium
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)critical
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolencritical
- Coldcard Firmware RNG Flaw Enables Coordinated Bitcoin Wallet Theft ($70.2M Drained)critical
- COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theftcritical
- Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…high
- Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150…
- North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…high
- GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXihigh
- Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)critical
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…critical
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…critical
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…critical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…critical
- US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities…high
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT…critical
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojancritical
Detection coverage
Threadlinqs maintains 21 detection rules mapped to T1587 (SPL 6, KQL 5, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1587.001 Malware — 210 tracked threats
- T1587.002 Code Signing Certificates — 1 tracked threat
- T1587.003 Digital Certificates — 7 tracked threats
- T1587.004 Exploits — 122 tracked threats