Domains

T1583.001

Sub-technique of T1583 Acquire Infrastructure.View on attack.mitre.org

About this technique

Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.

Adversaries may use acquired domains for a variety of purposes, including for Phishing, Drive-by Compromise, and Command and Control. Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD). Typosquatting may be used to aid in delivery of payloads via Drive-by Compromise. Adversaries may also use internationalized domain names (IDNs) and different character sets (e.g. Cyrillic, Greek, etc.) to execute "IDN homograph attacks," creating visually similar lookalike domains used to deliver malware to victim machines.

Different URIs/URLs may also be dynamically generated to uniquely serve malicious content to victims (including one-time, single use domain names).

Adversaries may also acquire and repurpose expired domains, which may be potentially already allowlisted/trusted by defenders based on an existing reputation/history.

Domain registrars each maintain a publicly viewable database that displays contact information for every registered domain. Private WHOIS services display alternative information, such as their own company data, rather than the owner of the domain. Adversaries may use such private WHOIS services to obscure information about who owns a purchased domain. Adversaries may further interrupt efforts to track their infrastructure by using varied registration information and purchasing domains with different domain registrars.

In addition to legitimately purchasing a domain, an adversary may register a new domain in a compromised environment. For example, in AWS environments, adversaries may leverage the Route53 domain service to register a domain and create hosted zones pointing to resources of the threat actor’s choosing.

Detection rules0

Rules on DetectionCode tagged with T1583.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups46

Show 22 more

Software3

Campaigns15

Procedure examples64

Groups46

Used byProcedure example
GroupAPT-C-36

APT-C-36 has acquired domains to host malicious payloads.

GroupAPT1

APT1 has registered hundreds of domains for use in operations.

GroupAPT28

APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations.

GroupAPT32

APT32 has set up and operated websites to gather information and deliver malware.

GroupAPT38

APT38 has created fake domains to imitate legitimate venture capital or bank domains.

GroupAPT42

APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations.

GroupBITTER

BITTER has registered a variety of domains to host malicious payloads and for C2.

GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

View all 46 groups examples

Software3

Used byProcedure example
MalwareDarkGate

DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services.

MalwareRaspberry Robin

Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as "v0[.]cx".

MalwareXLoader

XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap.

Campaigns15

Used byProcedure example
CampaignC0010

For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.

CampaignC0011

For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India.

CampaignC0021

For C0021, the threat actors registered domains for use in C2.

CampaignC0026

For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.

CampaignCostaRicto

For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains.

CampaignFunnyDream

For FunnyDream, the threat actors registered a variety of domains.

CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort.

View all 15 campaigns examples

References18

  1. CISA IDN ST05-016 Open source
    CISA. (2019, September 27). Security Tip (ST05-016): Understanding Internationalized Domain Names. Retrieved October 20, 2020.
  2. CISA MSS Sep 2020 Open source
    CISA. (2020, September 14). Alert (AA20-258A): Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity. Retrieved October 1, 2020.
  3. Categorisation_not_boundary Open source
    MDSec Research. (2017, July). Categorisation is not a Security Boundary. Retrieved September 20, 2019.
  4. Domain_Steal_CC Open source
    Krebs, B. (2018, November 13). That Domain You Forgot to Renew? Yeah, it’s Now Stealing Credit Cards. Retrieved September 20, 2019.
  5. FireEye APT28 Open source
    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
  6. Invictus IR DangerDev 2024 Open source
    Invictus Incident Response. (2024, January 31). The curious case of DangerDev@protonmail.me. Retrieved March 19, 2024.
  7. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  8. PaypalScam Open source
    Bob Sullivan. (2000, July 24). PayPal alert! Beware the 'PaypaI' scam. Retrieved March 2, 2017.
  9. Redirectors_Domain_Fronting Open source
    Mudge, R. (2017, February 6). High-reputation Redirectors and Domain Fronting. Retrieved July 11, 2022.
  10. URI Open source
    Michael Cobb. (2007, October 11). Preparing for uniform resource identifier (URI) exploits. Retrieved February 9, 2024.
  11. URI Unique Open source
    Australian Cyber Security Centre. National Security Agency. (2020, April 21). Detect and Prevent Web Shell Malware. Retrieved February 9, 2024.
  12. URI Use Open source
    Nathan McFeters. Billy Kim Rios. Rob Carter.. (2008). URI Use and Abuse. Retrieved February 9, 2024.
  13. bypass_webproxy_filtering Open source
    Fehrman, B. (2017, April 13). How to Bypass Web-Proxy Filtering. Retrieved September 20, 2019.
  14. httrack_unhcr Open source
    RISKIQ. (2022, March 15). RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure. Retrieved July 29, 2022.
  15. iOS URL Scheme Open source
    Ostorlab. (n.d.). iOS URL Scheme Hijacking. Retrieved February 9, 2024.
  16. lazgroup_idn_phishing Open source
    RISKIQ. (2017, December 20). Mining Insights: Infrastructure Analysis of Lazarus Group Cyber Attacks on the Cryptocurrency Industry. Retrieved July 29, 2022.
  17. tt_httrack_fake_domains Open source
    Malhotra, A., Thattil, J. et al. (2022, March 29). Transparent Tribe campaign uses new bespoke malware to target Indian government officials . Retrieved September 6, 2022.
  18. tt_obliqueRAT Open source
    Malhotra, A., McKay, K. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal . Retrieved July 29, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.