Activity timeline
T1608.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 38 reports, and 142 of the 142 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1608.001 Upload Malware is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1608 Stage Capabilities. Threadlinqs maps 142 of 2623 tracked threats (5.4%) to it; by severity that is 18 critical, 105 high, 19 medium.
Threats that use T1608.001 most often also use T1071.001 Web Protocols (96 threats), T1036.005 Match Legitimate Resource Name or Location (88 threats), T1204.002 Malicious File (85 threats), T1027 Obfuscated Files or Information (78 threats), T1583.001 Domains (69 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
41 tracked threat actors appear in the threats that use T1608.001; the most frequent are APT38 (11), Sapphire Sleet (9), Stardust Chollima (9), Lazarus Group (5), UNC1069 (5).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1608.001.
Data sources
Telemetry that can reveal T1608.001, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
The 30 most recent of 142 tracked threats that use T1608.001.
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Usersmedium
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…high
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentialsmedium
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)critical
- BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustionmedium
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcphigh
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…high
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…high
- indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()high
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Linkcritical
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2high
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Softwarehigh
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2high
- PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Huntinghigh
- Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)high
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affectedcritical
- ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Luremedium
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…high
- GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…high
- OpenAI Agent Swarm ("GemStuffer") Flooded RubyGems With 2,000+ Malicious Packages, Achieved RCE on…high
- GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…high
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacksmedium
- Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent…high
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
Detection coverage
Threadlinqs maintains 153 detection rules mapped to T1608.001 (SPL 42, KQL 46, Sigma 65). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1608 Stage Capabilities — 250 tracked threats at the technique level.