Malware copy paste: Software developers do it all the time, and malware devs are no exception. While we often think of different malware as separate entities, in reality most new malware uses large chunks of existing malware source code with some changes and additions.
This approach seems to make sense. Why reinvent the wheel when another developer has already created a solution that works? 
It should be mentioned that there are many reasons why attackers reuse code when developing malware.
First of all, they save time. By copying code where possible, malware authors have more time to focus on other areas, such as avoiding detection and improving performance. In some cases, there may be only one way to successfully perform a task, such as exploiting a vulnerability. In these cases, code reuse is essential.
A malicious dev also tends to reuse effective tactics such as social engineering, malicious macros, and spear phishing whenever possible because they have a high success rate.
Examples of creating malware from older code
Reaper (or the Troop IoT botnet), first discovered in October by Check Point researchers, is a prime example of malware developers repurposing and improving existing malware.
It uses the core code from the incredibly effective Mirai botnet. Reaper's author appears to have used Mirai as a platform on which to build much more efficient methods for exploitation and distribution. Reaper's additions to Mirai's source code include active exploitation of known IoT vulnerabilities and the use of the LUA programming language, allowing for more sophisticated attacks than a simple DDoS.
Another example.
Earlier this year, the Shadow Brokers group publicly released the source code of NSA tools. The source code contained several 0Day vulnerabilities targeting the Windows SMB file sharing service. Within a month, attackers used the source code to turn their ransomware into ransomworms for the WannaCry and NotPetya attack campaigns. These new ransomware variants showed us how attackers can quickly recycle new attack methods and exploit them with devastating results.
Reuse of generic attack methods
Malware code isn't the only place where malicious developers reuse source code. They also reuse generic attack methods wherever possible. Novice hackers, or 'script kiddies', use pre-built tools and attack methods to compensate for their lack of knowledge.
Tools like Rapid7 's Metasploit framework are ideal for legitimate security researchers conducting penetration tests for clients, but also for novice hackers who don't have the knowledge. Rapid7 is not the only vendor to address this issue. The entire penetration testing industry relies on tools developed for professionals, but used by criminals as well.
Attack methods are also reused when the method is particularly effective.
Malicious Office document macros are still in use, despite Microsoft's efforts to make them less effective. Attackers continue to use malicious macros as a method of delivering malware, mainly because it is very easy to convince a victim to run the macros.
Code reuse is a trend that is not going to stop.
Malicious code writers cite many reasons for opening up their work. The developer of EDA2 ransomware claims to have released his code to teach how ransomware works, while the author of the Mirai botnet released his code as a “last act” as he left the botnet when his attacks gained too much notoriety.
Attackers will continue to build on previous successful malware to create more effective and destructive attacks. What we saw with WannaCry and the NSA's Eternal Blue will be repeated..
