Botnet

T1584.005

Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org

About this technique

Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems. Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).

Detection rules0

Rules on DetectionCode tagged with T1584.005.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups5

Software0

None recorded.

Campaigns1

Procedure examples6

Groups5

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used a botnet management interface to control large numbers of compromised hosts.

GroupAxiom

Axiom has used large groups of compromised machines for use as proxy nodes.

GroupHAFNIUM

HAFNIUM has used compromised devices in covert networks to obfuscate communications.

GroupSandworm Team

Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices.

GroupVolt Typhoon

Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.

Campaigns1

Used byProcedure example
CampaignQuad7 Activity

Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity.

References3

  1. Dell Dridex Oct 2015 Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.
  2. Imperva DDoS for Hire Open source
    Imperva. (n.d.). Booters, Stressers and DDoSers. Retrieved October 4, 2020.
  3. Norton Botnet Open source
    Norton. (n.d.). What is a botnet?. Retrieved October 4, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.