Has pushed GitHub commits that modified the actions/checkout to reference an imposter commit that downloaded malicious files from attacker-controlled C2 domains.1
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.3
- Created
- 17 March 2021
- Last modified
- 12 May 2026
- Contributors
- Kobi Haimovich, CardinalOps; Menachem Goldstein; Adam Hunt; Ray Jasinski
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server.
Upload Malware MITRE reference T1608.001
28 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has hosted malicious payloads on code repositories used as lures for victims to download.123456789101112
Has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.1
Has staged tools such as Cobalt Strike at public file sharing and hosting sites.1
Staged malicious capabilities online for follow-on download by victims or malware.1
Has uploaded malicious payloads to cloud storage sites.1
All 28 groups for this technique · 6 newest in this preview
8 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
Mustang Panda staged malware on adversary-controlled domains and cloud storage instances during RedDelta Modified PlugX Infection Chain Operations.1
For C0011, Transparent Tribe hosted malicious documents on domains registered by the group.1
For C0010, UNC3890 actors staged malware on their infrastructure for direct download onto a compromised system.1
For Operation Spalax, the threat actors staged malware and malicious files in legitimate hosting services such as OneDrive or MediaFire.1
For Operation Dream Job, Lazarus Group used compromised servers to host malware.1234
For C0021, the threat actors uploaded malware to websites under their control.12
All 8 campaigns for this technique · 6 newest in this preview
1 software entry is documented implementing this technique. MITRE files each as a tool or as malware; newest first, then by how many groups carry them.
Has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts.12 Shai-Hulud has also modified packages within compromised accounts.34
All 1 software entries for this technique
Offense vs defense T1608.001
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
How it got here
Adversary activity (campaign spans) over cumulative rule output. Each source is plotted independently from zero, so neither line includes the other. Campaign dates are year-granularity.
Upload Malware detection strategy DET0824
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Upload Malware
AN1956 · PRE
If infrastructure or patterns in malware have been previously identified, internet scanning may uncover when an adversary has staged malware to make it accessible for targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle, such as User Execution or Ingress Tool Transfer .
Log sources
The data this analytic draws on. You do not need every component — each one you already collect covers part of it. Each links to its ATT&CK record.
| Data component | Name | Channel |
|---|---|---|
| Response ContentDC0104 | Internet Scan | None |
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.