Server

T1584.004

Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org

About this technique

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.

Adversaries may also compromise web servers to support watering hole operations, as in Drive-by Compromise, or email servers to support Phishing operations.

Detection rules0

Rules on DetectionCode tagged with T1584.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups10

Software0

None recorded.

Campaigns6

Procedure examples16

Groups10

Used byProcedure example
GroupAPT16

APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads.

GroupDaggerfly

Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion.

GroupDragonfly

Dragonfly has compromised legitimate websites to host C2 and malware modules.

GroupEarth Lusca

Earth Lusca has used compromised web servers as part of their operational infrastructure.

GroupIndrik Spider

Indrik Spider has served fake updates via legitimate websites that have been compromised.

GroupLazarus Group

Lazarus Group has compromised servers to stage malicious tools.

GroupLeviathan

Leviathan has used compromised legitimate websites as command and control nodes for operations.

GroupSandworm Team

Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns.

View all 10 groups examples

Campaigns6

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary operated dedicated penetration testing servers accessible via MCP to support remote command execution, simultaneous tool coordination, and persistent operational state maintenance across campaign sessions.

CampaignJuicy Mix

During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server.

CampaignNight Dragon

During Night Dragon, threat actors compromised web servers to use for C2.

CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.

CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure.

CampaignOuter Space

During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server.

References1

  1. TrendMicro EarthLusca 2022 Open source
    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.