ARP Cache Poisoning

T1557.002

Sub-technique of T1557 Adversary-in-the-Middle.View on attack.mitre.org

About this technique

Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices. This activity may be used to enable follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation.

The ARP protocol is used to resolve IPv4 addresses to link layer addresses, such as a media access control (MAC) address. Devices in a local network segment communicate with each other by using link layer addresses. If a networked device does not have the link layer address of a particular networked device, it may send out a broadcast ARP request to the local network to translate the IP address to a MAC address. The device with the associated IP address directly replies with its MAC address. The networked device that made the ARP request will then use as well as store that information in its ARP cache.

An adversary may passively wait for an ARP request to poison the ARP cache of the requesting device. The adversary may reply with their MAC address, thus deceiving the victim by making them believe that they are communicating with the intended networked device. For the adversary to poison the ARP cache, their reply must be faster than the one made by the legitimate IP address owner. Adversaries may also send a gratuitous ARP reply that maliciously announces the ownership of a particular IP address to all the devices in the local network segment.

The ARP protocol is stateless and does not require authentication. Therefore, devices may wrongly add or update the MAC address of the IP address in their ARP cache.

Adversaries may use ARP cache poisoning as a means to intercept network traffic. This activity may be used to collect and/or relay data such as credentials, especially those sent over an insecure, unencrypted protocol.

Detection rules3

Rules on DetectionCode tagged with T1557.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk3

RuleTypeRiskData source
Detect ARP PoisoningTTPNULLCisco IOS Logs
Detect IPv6 Network Infrastructure ThreatsTTPNULLCisco IOS Logs
Detect Port Security ViolationTTPNULLCisco IOS Logs

Groups2

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

Groups2

Used byProcedure example
GroupCleaver

Cleaver has used custom tools to facilitate ARP cache poisoning.

GroupLuminousMoth

LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website.

References3

  1. Cylance Cleaver Open source
    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.
  2. RFC826 ARP Open source
    Plummer, D. (1982, November). An Ethernet Address Resolution Protocol. Retrieved October 15, 2020.
  3. Sans ARP Spoofing Aug 2003 Open source
    Siles, R. (2003, August). Real World ARP Spoofing. Retrieved October 15, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.