28
Groups Using This
1
Tactics
1
Platforms
43
Prevalence Rank
Description

Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server. Malware may be placed on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Malware can also be staged on web services, such as GitHub or Pastebin; hosted on the InterPlanetary File System (IPFS), where decentralized content storage makes the removal of malicious files difficult; or saved on the blockchain as smart contracts, which are resilient against takedowns that would affect traditional infrastructure. Adversaries may upload backdoored files, such as software packages, application binaries, virtual machine images, or container images, to third-party software stores, package libraries, extension marketplaces, or repositories (ex: GitHub, CNET, AWS Community AMIs, Docker Hub, PyPi, NPM). By chance encounter, victims may directly download/install these backdoored files via User Execution. Masquerading, including typosquatting legitimate software, may increase the chance of users mistakenly executing these files.

View MITRE record โ†—

Platforms
PRE
Groups Using T1608.001 (28)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0047
Gamaredon Group
๐Ÿ‡ท๐Ÿ‡บ Russia70 techniques6 software
G0046
FIN7
67 techniques19 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G0139
TeamTNT
56 techniques4 software
G1052
Contagious Interview
๐Ÿ‡ฐ๐Ÿ‡ต North Korea54 techniques4 software
G1043
BlackByte
48 techniques8 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0099
APT-C-36
38 techniques9 software
G1056
TeamPCP
36 techniques3 software
G1001
HEXANE
36 techniques12 software
G0092
TA505
34 techniques16 software
G1044
APT42
๐Ÿ‡ฎ๐Ÿ‡ท Iran32 techniques2 software
G1036
Moonstone Sleet
๐Ÿ‡ฐ๐Ÿ‡ต North Korea30 techniques1 software
G1014
LuminousMoth
๐Ÿ‡จ๐Ÿ‡ณ China28 techniques2 software
G1018
TA2541
28 techniques9 software
G0090
WIRTE
26 techniques8 software
G1033
Star Blizzard
๐Ÿ‡ท๐Ÿ‡บ Russia20 techniques1 software
G0140
LazyScripter
20 techniques7 software
G1031
Saint Bear
๐Ÿ‡ท๐Ÿ‡บ Russia18 techniques2 software
G1002
BITTER
๐Ÿ‡จ๐Ÿ‡ณ China16 techniques1 software
G1008
SideCopy
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan16 techniques2 software
G1011
EXOTIC LILY
15 techniques2 software
G1020
Mustard Tempest
12 techniques2 software
โ†‘