# T1588.001 Malware

> As of 2026-10-05, T1588.001 (Malware) appears in 38 tracked threats, first reported 2026-02-06 and most recently 2026-09-27, with linked actors including 1VPNS, APT10, APT28; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 38 (9 critical, 21 high, 7 medium)
- **First seen:** 2026-02-06
- **Last seen:** 2026-09-27
- **Threat actors:** 32
- **Detection rules:** 16 (counts only; Blue tier and above)

## Key facts

- **ID:** T1588.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1588
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1588/001/

## Activity timeline

T1588.001 first appeared in tracked threats on 2026-02-06 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 18 reports, and 38 of the 38 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1588.001 Malware is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588). Threadlinqs maps 38 of 2623 tracked threats (1.4%) to it; by severity that is 9 critical, 21 high, 7 medium.

Threats that use T1588.001 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (23 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (22 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (22 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (21 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

32 tracked threat actors appear in the threats that use T1588.001; the most frequent are [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) (2), [APT10](https://intel.threadlinqs.com/actor/APT10) (1), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [APT32](https://intel.threadlinqs.com/actor/APT32) (1), [APT37](https://intel.threadlinqs.com/actor/APT37) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1588.001.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1588.001, per MITRE ATT&CK.

- Malware Repository — Malware Content, Malware Metadata

## Threat actors using it

- [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) — 2
- [APT10](https://intel.threadlinqs.com/actor/APT10) — 1
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT32](https://intel.threadlinqs.com/actor/APT32) — 1
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 1
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 1
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 1
- [DevMan](https://intel.threadlinqs.com/actor/DevMan) — 1
- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 1

## Tracked threats

The 30 most recent of 38 tracked threats that use T1588.001.

- [Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…](https://intel.threadlinqs.com/threat/TL-2026-2685) — high — 2026-09-27
- [China-Nexus and India-Nexus Espionage Groups Converge on Pakistani Law Enforcement Digitalization Platforms…](https://intel.threadlinqs.com/threat/TL-2026-2343) — high — 2026-09-05
- [Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…](https://intel.threadlinqs.com/threat/TL-2026-2279) — high — 2026-09-01
- [Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts](https://intel.threadlinqs.com/threat/TL-2026-2167) — high — 2026-08-27
- [Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…](https://intel.threadlinqs.com/threat/TL-2026-2079) — critical — 2026-08-20
- [CVE-2026-70329: Microsoft Outlook Remote Code Execution via Integer Overflow](https://intel.threadlinqs.com/threat/TL-2026-1991) — high — 2026-08-11
- [Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1914) — high — 2026-08-06
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of…](https://intel.threadlinqs.com/threat/TL-2026-1831) — high — 2026-08-03
- [Joyfill npm Packages Compromised with Blockchain C2 Loader](https://intel.threadlinqs.com/threat/TL-2026-1771) — medium — 2026-07-30
- [Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004)](https://intel.threadlinqs.com/threat/TL-2026-1767) — critical — 2026-07-29
- [ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales…](https://intel.threadlinqs.com/threat/TL-2026-1597) — medium — 2026-07-21
- [OTTERCOOKIE Malware Hidden in SVG Flag Images Backdoors Developers via Fake Coding Tests (Contagious…](https://intel.threadlinqs.com/threat/TL-2026-1581) — high — 2026-07-20
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1441) — high — 2026-07-17
- [Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Production](https://intel.threadlinqs.com/threat/TL-2026-1427) — high — 2026-07-16
- [PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…](https://intel.threadlinqs.com/threat/TL-2026-1416) — high — 2026-07-16
- [AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework](https://intel.threadlinqs.com/threat/TL-2026-1360) — critical — 2026-07-15
- [Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS Botnet](https://intel.threadlinqs.com/threat/TL-2026-1328) — critical — 2026-07-14
- [Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…](https://intel.threadlinqs.com/threat/TL-2026-1313) — high — 2026-07-14
- [US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1295) — medium — 2026-07-14
- [OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy…](https://intel.threadlinqs.com/threat/TL-2026-1291) — medium — 2026-07-14
- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-1287) — medium — 2026-07-14
- [Zhipu AI's GLM-5.2 Matches Export-Controlled Claude Mythos on IDOR Vulnerability Detection](https://intel.threadlinqs.com/threat/TL-2026-1228) — 2026-07-11
- [Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)](https://intel.threadlinqs.com/threat/TL-2026-1183) — medium — 2026-07-10
- [Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abuse](https://intel.threadlinqs.com/threat/TL-2026-1108) — high — 2026-07-03
- [Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader…](https://intel.threadlinqs.com/threat/TL-2026-1077) — critical — 2026-07-02
- [StealC Infostealer and Amadey Loader Malware-as-a-Service Cybercrime Ecosystem (Operation Endgame Disruption)](https://intel.threadlinqs.com/threat/TL-2026-0941) — high — 2026-06-25
- [Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service…](https://intel.threadlinqs.com/threat/TL-2026-0919) — high — 2026-06-23
- [CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day Exploited In-the-Wild Against Ukrainian Entities…](https://intel.threadlinqs.com/threat/TL-2026-0761) — high — 2026-06-10

## Related CVEs

CVEs referenced by the tracked threats that use T1588.001, most frequent first.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-43451](https://intel.threadlinqs.com/cve/CVE-2024-43451)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-70329](https://intel.threadlinqs.com/cve/CVE-2026-70329)

## Detection coverage

Threadlinqs maintains 16 detection rules mapped to T1588.001 (SPL 1, KQL 6, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.

16 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588) — 363 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1588.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
