Activity timeline
T1587.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 104 reports, and 210 of the 210 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1587.001 Malware is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1587 Develop Capabilities. Threadlinqs maps 210 of 2623 tracked threats (8%) to it; by severity that is 36 critical, 149 high, 22 medium.
Threats that use T1587.001 most often also use T1071.001 Web Protocols (135 threats), T1027 Obfuscated Files or Information (116 threats), T1005 Data from Local System (114 threats), T1082 System Information Discovery (108 threats), T1041 Exfiltration Over C2 Channel (107 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
73 tracked threat actors appear in the threats that use T1587.001; the most frequent are APT38 (11), Sapphire Sleet (7), Stardust Chollima (7), Andariel (5), Lazarus Group (5).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1587.001.
Data sources
Telemetry that can reveal T1587.001, per MITRE ATT&CK.
- Malware Repository — Malware Content, Malware Metadata
Threat actors using it
Tracked threats
The 30 most recent of 210 tracked threats that use T1587.001.
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFAhigh
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Usersmedium
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustionmedium
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
- GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaignhigh
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affectedcritical
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injectionmedium
- GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…high
- GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…high
- Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…critical
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…high
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…critical
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…critical
- Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card Purchaseshigh
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnethigh
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…critical
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attackcritical
- SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governmentshigh
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…critical
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimihigh
- MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generationhigh
- Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar…medium
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targetshigh
- Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug…medium
- Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actorshigh
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…high
Detection coverage
Threadlinqs maintains 79 detection rules mapped to T1587.001 (SPL 18, KQL 18, Sigma 43). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1587 Develop Capabilities — 402 tracked threats at the technique level.