# T1608 Stage Capabilities

> As of 2026-10-05, T1608 (Stage Capabilities) appears in 250 tracked threats, first reported 2026-01-14 and most recently 2026-09-27, with linked actors including TeamPCP, WageMole, APT28; it most often appears alongside T1583 (Acquire Infrastructure).

- **Tracked threats:** 250 (52 critical, 166 high, 30 medium, 1 low)
- **First seen:** 2026-01-14
- **Last seen:** 2026-09-27
- **Threat actors:** 93
- **Detection rules:** 57 (counts only; Blue tier and above)

## Key facts

- **ID:** T1608
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1608/

## Activity timeline

T1608 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-09-27. The busiest month was 2026-06 with 67 reports, and 250 of the 250 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1608 Stage Capabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix. Threadlinqs maps 250 of 2623 tracked threats (9.5%) to it; by severity that is 52 critical, 166 high, 30 medium, 1 low.

Threats that use T1608 most often also use [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (191 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (185 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (179 threats), [T1204 User Execution](https://intel.threadlinqs.com/technique/T1204) (178 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (175 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

93 tracked threat actors appear in the threats that use T1608; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (9), [WageMole](https://intel.threadlinqs.com/actor/WageMole) (7), [APT28](https://intel.threadlinqs.com/actor/APT28) (6), [APT38](https://intel.threadlinqs.com/actor/APT38) (6), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (6).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1608.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1608, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 9
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 7
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 6
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 6
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 6
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 5
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 5
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 4
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4

## Tracked threats

The 30 most recent of 250 tracked threats that use T1608.

- [Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2707) — medium — 2026-09-27
- [GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaign](https://intel.threadlinqs.com/threat/TL-2026-2588) — high — 2026-09-20
- [North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…](https://intel.threadlinqs.com/threat/TL-2026-2577) — high — 2026-09-19
- [Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…](https://intel.threadlinqs.com/threat/TL-2026-2573) — critical — 2026-09-18
- [Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data](https://intel.threadlinqs.com/threat/TL-2026-2550) — high — 2026-09-17
- [Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-2506) — high — 2026-09-14
- [Blob URL Phishing: Fake Login Pages Rendered Entirely Inside the Browser via Microsoft OAuth and Teams](https://intel.threadlinqs.com/threat/TL-2026-2430) — medium — 2026-09-10
- [Cybercriminals Build Fake School Websites and Phishing Domains as Education-Sector Attacks Hit Record High](https://intel.threadlinqs.com/threat/TL-2026-2236) — medium — 2026-08-30
- [Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2235) — high — 2026-08-30
- [Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofing](https://intel.threadlinqs.com/threat/TL-2026-2230) — high — 2026-08-30
- [24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login…](https://intel.threadlinqs.com/threat/TL-2026-2150) — medium — 2026-08-26
- [AnonyMousKIT: AI-Powered Phishing-as-a-Service Platform Stealing Apple IDs from Stolen iPhones](https://intel.threadlinqs.com/threat/TL-2026-2141) — high — 2026-08-24
- [BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Admins](https://intel.threadlinqs.com/threat/TL-2026-1978) — medium — 2026-08-10
- [TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bank](https://intel.threadlinqs.com/threat/TL-2026-1977) — high — 2026-08-10
- [Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts](https://intel.threadlinqs.com/threat/TL-2026-1953) — high — 2026-08-09
- [FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-1947) — critical — 2026-08-07
- [AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social…](https://intel.threadlinqs.com/threat/TL-2026-1900) — critical — 2026-08-04
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolen](https://intel.threadlinqs.com/threat/TL-2026-1848) — critical — 2026-08-03
- [ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Data](https://intel.threadlinqs.com/threat/TL-2026-1836) — medium — 2026-08-03
- [NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skills](https://intel.threadlinqs.com/threat/TL-2026-1828) — low — 2026-08-03
- [Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across…](https://intel.threadlinqs.com/threat/TL-2026-1816) — high — 2026-08-02
- [Anthropic AI Agent Publishes Live Credential-Stealing Malware as PyPI Package "anthropickit"](https://intel.threadlinqs.com/threat/TL-2026-1801) — high — 2026-07-31
- [SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD](https://intel.threadlinqs.com/threat/TL-2026-1787) — high — 2026-07-31
- [State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…](https://intel.threadlinqs.com/threat/TL-2026-1780) — critical — 2026-07-31
- [Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-1775) — high — 2026-07-30
- [Tax Season Phishing and Malware Campaign Targets Indian Taxpayers via Fake Income Tax Department Notices](https://intel.threadlinqs.com/threat/TL-2026-1769) — high — 2026-07-30
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft](https://intel.threadlinqs.com/threat/TL-2026-1811) — high — 2026-07-29
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29

## Related CVEs

CVEs referenced by the tracked threats that use T1608, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-46604](https://intel.threadlinqs.com/cve/CVE-2023-46604)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-11182](https://intel.threadlinqs.com/cve/CVE-2024-11182)
- [CVE-2024-21338](https://intel.threadlinqs.com/cve/CVE-2024-21338)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-27443](https://intel.threadlinqs.com/cve/CVE-2024-27443)

## Detection coverage

Threadlinqs maintains 57 detection rules mapped to T1608 (SPL 17, KQL 16, Sigma 24). Rule content is available to Blue tier accounts and above; this page shows counts only.

57 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1608.001 Upload Malware](https://intel.threadlinqs.com/technique/T1608.001) — 142 tracked threats
- [T1608.002 Upload Tool](https://intel.threadlinqs.com/technique/T1608.002) — 11 tracked threats
- T1608.003 Install Digital Certificate — 2 tracked threats
- [T1608.004 Drive-by Target](https://intel.threadlinqs.com/technique/T1608.004) — 18 tracked threats
- [T1608.005 Link Target](https://intel.threadlinqs.com/technique/T1608.005) — 39 tracked threats
- [T1608.006 SEO Poisoning](https://intel.threadlinqs.com/technique/T1608.006) — 25 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1608
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
