Domains

T1584.001

Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org

About this technique

Adversaries may hijack domains and/or subdomains that can be used during targeting. Domain registration hijacking is the act of changing the registration of a domain name without the permission of the original registrant. Adversaries may gain access to an email account for the person listed as the owner of the domain. The adversary can then claim that they forgot their password in order to make changes to the domain registration. Other possibilities include social engineering a domain registration help desk to gain access to an account, taking advantage of renewal process gaps, or compromising a cloud service that enables managing domains (e.g., AWS Route53).

Subdomain hijacking can occur when organizations have DNS entries that point to non-existent or deprovisioned resources. In such cases, an adversary may take control of a subdomain to conduct operations with the benefit of the trust associated with that domain.

Adversaries who compromise a domain may also engage in domain shadowing by creating malicious subdomains under their control while keeping any existing DNS records. As service will not be disrupted, the malicious subdomains may go unnoticed for long periods of time.

Detection rules0

Rules on DetectionCode tagged with T1584.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups6

Software1

Campaigns5

Procedure examples12

Groups6

Used byProcedure example
GroupAPT1

APT1 hijacked FQDNs associated with legitimate websites hosted by hop points.

GroupKimsuky

Kimsuky has compromised legitimate sites and used them to distribute malware.

GroupMagic Hound

Magic Hound has used compromised domains to host links targeted to specific phishing victims.

GroupMustard Tempest

Mustard Tempest operates a global network of compromised websites that redirect into a traffic distribution system (TDS) to select victims for a fake browser update page.

GroupSideCopy

SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware.

GroupTransparent Tribe

Transparent Tribe has compromised domains for use in targeted malicious campaigns.

Software1

Used byProcedure example
MalwareGootloader

Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads.

Campaigns5

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compromised infrastructure to use for C2.

CampaignC0010

During C0010, UNC3890 actors likely compromised the domain of a legitimate Israeli shipping company.

CampaignC0021

For C0021, the threat actors used legitimate but compromised domains to host malicious payloads.

CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure.

CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 compromised domains to use for C2.

References4

  1. ICANNDomainNameHijacking Open source
    ICANN Security and Stability Advisory Committee. (2005, July 12). Domain Name Hijacking: Incidents, Threats, Risks and Remediation. Retrieved November 17, 2024.
  2. Krebs DNS Hijack 2019 Open source
    Brian Krebs. (2019, February 18). A Deep Dive on the Recent Widespread DNS Hijacking Attacks. Retrieved February 14, 2022.
  3. Microsoft Sub Takeover 2020 Open source
    Microsoft. (2020, September 29). Prevent dangling DNS entries and avoid subdomain takeover. Retrieved October 12, 2020.
  4. Palo Alto Unit 42 Domain Shadowing 2022 Open source
    Janos Szurdi, Rebekah Houser and Daiping Liu. (2022, September 21). Domain Shadowing: A Stealthy Use of DNS Compromise for Cybercrime. Retrieved March 7, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.