Sub-technique of T1583 Acquire Infrastructure.View on attack.mitre.org
Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.
Rules on DetectionCode tagged with T1583.006.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco Secure Firewall - Rare Snort Rule Triggered | Hunting | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox. |
| GroupAPT17 | APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure. |
| GroupAPT28 | APT28 has used newly-created Blogspot pages for credential harvesting operations. |
| GroupAPT29 | APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations. |
| GroupAPT32 | APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| GroupConfucius | Confucius has obtained cloud storage service accounts to host stolen data. |
| GroupContagious Interview | Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities. Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| GroupEarth Lusca | Earth Lusca has established GitHub accounts to host their malware. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries configured the FortiGate devices to send notifications to an attacker-controlled Slack channel. During the 2025 Poland Wiper Attacks, the adversaries had also staged tools and files on services such as Dropbox and Pastebin. |
| CampaignArcaneDoor | ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive. |
| CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.