# T1587.001 Malware

> As of 2026-10-05, T1587.001 (Malware) appears in 210 tracked threats, first reported 2026-02-21 and most recently 2026-10-01, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 210 (36 critical, 149 high, 22 medium)
- **First seen:** 2026-02-21
- **Last seen:** 2026-10-01
- **Threat actors:** 73
- **Detection rules:** 79 (counts only; Blue tier and above)

## Key facts

- **ID:** T1587.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1587
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1587/001/

## Activity timeline

T1587.001 first appeared in tracked threats on 2026-02-21 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 104 reports, and 210 of the 210 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1587.001 Malware is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1587 Develop Capabilities](https://intel.threadlinqs.com/technique/T1587). Threadlinqs maps 210 of 2623 tracked threats (8%) to it; by severity that is 36 critical, 149 high, 22 medium.

Threats that use T1587.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (135 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (116 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (114 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (108 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (107 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

73 tracked threat actors appear in the threats that use T1587.001; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (11), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (7), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (7), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (5), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (5).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1587.001.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1587.001, per MITRE ATT&CK.

- Malware Repository — Malware Content, Malware Metadata

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 11
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 7
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 7
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 5
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 5
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 3
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 3
- [PolinRider](https://intel.threadlinqs.com/actor/PolinRider) — 3

## Tracked threats

The 30 most recent of 210 tracked threats that use T1587.001.

- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA](https://intel.threadlinqs.com/threat/TL-2026-2834) — high — 2026-10-01
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustion](https://intel.threadlinqs.com/threat/TL-2026-2618) — medium — 2026-09-22
- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — high — 2026-09-21
- [GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaign](https://intel.threadlinqs.com/threat/TL-2026-2588) — high — 2026-09-20
- [Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected](https://intel.threadlinqs.com/threat/TL-2026-2524) — critical — 2026-09-15
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…](https://intel.threadlinqs.com/threat/TL-2026-2462) — high — 2026-09-12
- [GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…](https://intel.threadlinqs.com/threat/TL-2026-2458) — high — 2026-09-12
- [Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…](https://intel.threadlinqs.com/threat/TL-2026-2373) — critical — 2026-09-07
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…](https://intel.threadlinqs.com/threat/TL-2026-2214) — high — 2026-08-29
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Critical WatchGuard Agent for Windows Flaws (CVE-2026-57910, CVE-2026-57909) Enable Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-2162) — critical — 2026-08-27
- [Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…](https://intel.threadlinqs.com/threat/TL-2026-2143) — critical — 2026-08-25
- [Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card Purchases](https://intel.threadlinqs.com/threat/TL-2026-2102) — high — 2026-08-21
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-2083) — critical — 2026-08-20
- [SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2200) — high — 2026-08-19
- [AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…](https://intel.threadlinqs.com/threat/TL-2026-2070) — critical — 2026-08-19
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generation](https://intel.threadlinqs.com/threat/TL-2026-2036) — high — 2026-08-16
- [Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar…](https://intel.threadlinqs.com/threat/TL-2026-2033) — medium — 2026-08-16
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug…](https://intel.threadlinqs.com/threat/TL-2026-2011) — medium — 2026-08-13
- [Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat Actors](https://intel.threadlinqs.com/threat/TL-2026-2008) — high — 2026-08-13
- [PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian…](https://intel.threadlinqs.com/threat/TL-2026-2006) — high — 2026-08-13

## Related CVEs

CVEs referenced by the tracked threats that use T1587.001, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48939](https://intel.threadlinqs.com/cve/CVE-2026-48939)
- [CVE-2026-56291](https://intel.threadlinqs.com/cve/CVE-2026-56291)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2019-7192](https://intel.threadlinqs.com/cve/CVE-2019-7192)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-49105](https://intel.threadlinqs.com/cve/CVE-2023-49105)
- [CVE-2024-28000](https://intel.threadlinqs.com/cve/CVE-2024-28000)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)

## Detection coverage

Threadlinqs maintains 79 detection rules mapped to T1587.001 (SPL 18, KQL 18, Sigma 43). Rule content is available to Blue tier accounts and above; this page shows counts only.

79 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1587 Develop Capabilities](https://intel.threadlinqs.com/technique/T1587) — 402 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1587.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
