1200KM / simulation
T1608.001 Upload Malware — Attack Simulation
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web…
Technique description
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web…
No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Threat Group-3390 · G0027
- Sandworm Team · G0034
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- APT-C-36 · G0099
- Mustang Panda · G0129
- TeamTNT · G0139
- LazyScripter · G0140
- HEXANE · G1001
- BITTER · G1002
- Earth Lusca · G1006
- SideCopy · G1008
- EXOTIC LILY · G1011
- LuminousMoth · G1014
- TA2541 · G1018
- Mustard Tempest · G1020
- Saint Bear · G1031
- Star Blizzard · G1033
- Moonstone Sleet · G1036
- BlackByte · G1043
- APT42 · G1044
- Contagious Interview · G1052
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.