| name | T1587.001_malware |
| description | Adversaries may develop malware and malware components that can be used during targeting. |
| category | information-gathering |
| version | 18.1 |
| author | cyberstrike-official |
| tags | ["mitre-attack","enterprise","t1587.001","resource-development","pre","sub-technique"] |
| technique_id | T1587.001 |
| tactic | resource-development |
| all_tactics | ["resource-development"] |
| platforms | ["PRE"] |
| mitre_url | https://attack.mitre.org/techniques/T1587/001 |
| tech_stack | ["pre"] |
| cwe_ids | [] |
| chains_with | ["T1587","T1587.002","T1587.003","T1587.004"] |
| prerequisites | ["T1587"] |
| severity_boost | {"T1587":"Chain with T1587 for deeper attack path","T1587.002":"Chain with T1587.002 for deeper attack path","T1587.003":"Chain with T1587.003 for deeper attack path"} |
T1587.001 Malware
Sub-technique of: T1587
High-Level Description
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
During malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders.
As with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware.
Some aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of Web Services.
Kill Chain Phase
- Resource Development (TA0042)
Platforms: PRE
What to Check
How to Test
Manual Testing
-
Identify Attack Surface: Determine if the target environment is susceptible to Malware by examining the target platforms (PRE).
-
Assess Existing Defenses: Review whether mitigations for T1587.001 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
-
Execute Test: Use tools and methods described in the MITRE ATT&CK page and external references below.
Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.