Techniques › T1588 › T1588.001
T1588.001 Malware
resource development — PRE · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
1
Sigma rules tagged attack.t1588.001
2
KEV CVEs mapped here
<p>Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.</p><p>In addition to downloading free malware from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware development, criminal marketplaces (including Malware-as-a-Service, or MaaS), or from individuals. In addition to purchasing malware, adversaries may steal and repurpose malware from third-party entities (including other adversaries).</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-0411 | 7-Zip 7-Zip | primary impact | Mapped | 2025-02-06 |
| CVE-2023-34048 | VMware vCenter Server | secondary impact | Mapped | 2024-01-22 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0845 Detection of Malware v1.0
AN1977 PREMonitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle. Consider analyzing malware for features that may be associated with malware providers, such as compiler used, debugging artifacts, code similarities, or even group identifiers associated with specific MaaS offerings. Malware repositories can also be used to identify additional samples associated with the developers and the adversary utilizing their services. Identifying overlaps in malware use by different adversaries may indicate malware was obtained by the adversary rather than developed by them. In some cases, identifying overlapping characteristics in malware used by different adversaries may point to a shared quartermaster.
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1588.001
Author: Florian Roth (Nextron Systems)
· 2017-03-01 · logsource: product=linux service=clamav · 36aa86ca-fd9d-4456-814e-d3b1b8e1e0bb
Detects relevant ClamAV messages
Rules tagged at the parent level (attack.t1588) 2
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2017-02-19 (modified 2024-12-25) · logsource: product=windows service=application · 78bc5783-81d9-4d73-ac97-59f6db4f72a8
Detects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2018-09-09 (modified 2026-06-29) · logsource: category=antivirus · c9a88268-0047-4824-ba6e-4d81ce0b907c
Detects an Antivirus alert in a highly relevant file path or with a relevant file name.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.