Compromise Infrastructure

T1584

Technique with 8 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party web and DNS services. Instead of buying, leasing, or renting infrastructure an adversary may compromise infrastructure and use it during other phases of the adversary lifecycle. Additionally, adversaries may compromise numerous machines to form a botnet they can leverage.

Use of compromised infrastructure allows adversaries to stage, launch, and execute operations. Compromised infrastructure can help adversary operations blend in with traffic that is seen as normal, such as contact with high reputation or trusted sites. For example, adversaries may leverage compromised infrastructure (potentially also in conjunction with Digital Certificates) to further blend in and support staged information gathering and/or Phishing campaigns. Adversaries may also compromise numerous machines to support Proxy and/or proxyware services or to form a botnet. Additionally, adversaries may compromise infrastructure residing in close proximity to a target in order to gain Initial Access via Wi-Fi Networks.

By using compromised infrastructure, adversaries may enable follow-on malicious operations. Prior to targeting, adversaries may also compromise the infrastructure of other adversaries.

Detection rules3

Rules on DetectionCode tagged with T1584 or one of its sub-techniques.

Sigma3

RuleLevelLog sourceTechnique
Suspicious External WebDAV ExecutionhighNULL / proxyT1584
Program Executions in Suspicious Foldersmediumlinux / NULLT1584
Windows Update Errorinformationalwindows / NULLT1584

Splunk0

No Splunk rules are mapped to this technique yet.

Sub-techniques8

IDNameExamples
T1584.001Domains12
T1584.002DNS Server2
T1584.003Virtual Private Server4
T1584.004Server16
T1584.005Botnet6
T1584.006Web Services6
T1584.007Serverless0
T1584.008Network Devices10

Groups0

None recorded.

Software0

None recorded.

Campaigns2

Procedure examples2

Campaigns2

Used byProcedure example
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 compromised third-party infrastructure in physical proximity to targets of interest for follow-on activities.

CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity.

References9

  1. FireEye DNS Hijack 2019 Open source
    Hirani, M., Jones, S., Read, B. (2019, January 10). Global DNS Hijacking Campaign: DNS Record Manipulation at Scale. Retrieved October 9, 2020.
  2. FireEye EPS Awakens Part 2 Open source
    Winters, R. (2015, December 20). The EPS Awakens - Part 2. Retrieved January 22, 2016.
  3. ICANNDomainNameHijacking Open source
    ICANN Security and Stability Advisory Committee. (2005, July 12). Domain Name Hijacking: Incidents, Threats, Risks and Remediation. Retrieved November 17, 2024.
  4. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  5. NSA NCSC Turla OilRig Open source
    NSA/NCSC. (2019, October 21). Cybersecurity Advisory: Turla Group Exploits Iranian APT To Expand Coverage Of Victims. Retrieved October 16, 2020.
  6. Nearest Neighbor Volexity Open source
    Koessel, Sean. Adair, Steven. Lancaster, Tom. (2024, November 22). The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access. Retrieved February 25, 2025.
  7. Sysdig Proxyjacking Open source
    Crystal Morin. (2023, April 4). Proxyjacking has Entered the Chat. Retrieved July 6, 2023.
  8. Talos DNSpionage Nov 2018 Open source
    Mercer, W., Rascagneres, P. (2018, November 27). DNSpionage Campaign Targets Middle East. Retrieved October 9, 2020.
  9. amnesty_nso_pegasus Open source
    Amnesty International Security Lab. (2021, July 18). Forensic Methodology Report: How to catch NSO Group’s Pegasus. Retrieved February 22, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.