# T1608.001 Upload Malware

> As of 2026-10-05, T1608.001 (Upload Malware) appears in 142 tracked threats, first reported 2026-01-14 and most recently 2026-10-02, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 142 (18 critical, 105 high, 19 medium)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-02
- **Threat actors:** 41
- **Detection rules:** 153 (counts only; Blue tier and above)

## Key facts

- **ID:** T1608.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1608
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1608/001/

## Activity timeline

T1608.001 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 38 reports, and 142 of the 142 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1608.001 Upload Malware is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608). Threadlinqs maps 142 of 2623 tracked threats (5.4%) to it; by severity that is 18 critical, 105 high, 19 medium.

Threats that use T1608.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (96 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (88 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (85 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (78 threats), [T1583.001 Domains](https://intel.threadlinqs.com/technique/T1583.001) (69 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

41 tracked threat actors appear in the threats that use T1608.001; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (11), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (9), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (9), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (5), [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) (5).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1608.001.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1608.001, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 11
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 9
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 9
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 5
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 5
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 2
- [Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel) — 2
- [UNC5342](https://intel.threadlinqs.com/actor/UNC5342) — 2

## Tracked threats

The 30 most recent of 142 tracked threats that use T1608.001.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…](https://intel.threadlinqs.com/threat/TL-2026-2631) — high — 2026-09-23
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2627) — medium — 2026-09-23
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustion](https://intel.threadlinqs.com/threat/TL-2026-2618) — medium — 2026-09-22
- [GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp](https://intel.threadlinqs.com/threat/TL-2026-2605) — high — 2026-09-21
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…](https://intel.threadlinqs.com/threat/TL-2026-2604) — high — 2026-09-21
- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — high — 2026-09-21
- [Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator…](https://intel.threadlinqs.com/threat/TL-2026-2602) — high — 2026-09-21
- [indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()](https://intel.threadlinqs.com/threat/TL-2026-2590) — high — 2026-09-20
- [Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link](https://intel.threadlinqs.com/threat/TL-2026-2587) — critical — 2026-09-19
- [MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2](https://intel.threadlinqs.com/threat/TL-2026-2560) — high — 2026-09-18
- [KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software](https://intel.threadlinqs.com/threat/TL-2026-2555) — high — 2026-09-17
- [EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2](https://intel.threadlinqs.com/threat/TL-2026-2547) — high — 2026-09-17
- [PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Hunting](https://intel.threadlinqs.com/threat/TL-2026-2531) — high — 2026-09-16
- [Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)](https://intel.threadlinqs.com/threat/TL-2026-2529) — high — 2026-09-15
- [Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected](https://intel.threadlinqs.com/threat/TL-2026-2524) — critical — 2026-09-15
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — medium — 2026-09-14
- [VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…](https://intel.threadlinqs.com/threat/TL-2026-2464) — high — 2026-09-12
- [GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…](https://intel.threadlinqs.com/threat/TL-2026-2462) — high — 2026-09-12
- [OpenAI Agent Swarm ("GemStuffer") Flooded RubyGems With 2,000+ Malicious Packages, Achieved RCE on…](https://intel.threadlinqs.com/threat/TL-2026-2459) — high — 2026-09-12
- [GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…](https://intel.threadlinqs.com/threat/TL-2026-2458) — high — 2026-09-12
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-2299) — medium — 2026-09-02
- [Infostealer Malware Hijacks Claude Login Sessions to Bypass MFA and Drain Usage; Related FakeAgent…](https://intel.threadlinqs.com/threat/TL-2026-2249) — high — 2026-08-30
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30

## Related CVEs

CVEs referenced by the tracked threats that use T1608.001, most frequent first.

- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-7028](https://intel.threadlinqs.com/cve/CVE-2023-7028)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-22679](https://intel.threadlinqs.com/cve/CVE-2026-22679)
- [CVE-2026-3102](https://intel.threadlinqs.com/cve/CVE-2026-3102)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-56711](https://intel.threadlinqs.com/cve/CVE-2026-56711)
- [CVE-2026-73324](https://intel.threadlinqs.com/cve/CVE-2026-73324)
- [CVE-2026-87902](https://intel.threadlinqs.com/cve/CVE-2026-87902)

## Detection coverage

Threadlinqs maintains 153 detection rules mapped to T1608.001 (SPL 42, KQL 46, Sigma 65). Rule content is available to Blue tier accounts and above; this page shows counts only.

153 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1608 Stage Capabilities](https://intel.threadlinqs.com/technique/T1608) — 250 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1608.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
