Stage Capabilities

T1608

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take capabilities they developed (Develop Capabilities) or obtained (Obtain Capabilities) and stage them on infrastructure under their control. These capabilities may be staged on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Capabilities may also be staged on web services, such as GitHub or Pastebin, or on Platform-as-a-Service (PaaS) offerings that enable users to easily provision applications.

Staging of capabilities can aid the adversary in a number of initial access and post-compromise behaviors, including (but not limited to):

* Staging web resources necessary to conduct Drive-by Compromise when a user browses to a site.
* Staging web resources for a link target to be used with spearphishing.
* Uploading malware or tools to a location accessible to a victim network to enable Ingress Tool Transfer.
* Installing a previously acquired SSL/TLS certificate to use to encrypt command and control traffic (ex: Asymmetric Cryptography with Web Protocols).

Detection rules8

Rules on DetectionCode tagged with T1608 or one of its sub-techniques.

Sigma3

RuleLevelLog sourceTechnique
AWS KMS Imported Key Material Usagehighaws / NULLT1608.003
HybridConnectionManager Service Installation - Registryhighwindows / registry_eventT1608
Suspicious Download from Office Domainhighwindows / process_creationT1608

Splunk5

RuleTypeRiskData sourceTechnique
Linux Suspicious GCC Invocation Building Init Shared ObjectTTPNULLSysmon for Linux EventID 1T1608
Windows Cobalt Strike PowerShell LoaderTTPNULLPowershell Script Block Logging 4104T1608
Windows Metasploit Confluence Plugin ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1608
Windows NorthStar C2 Agent ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1608
Windows Unusual File Creation in Confluence DirectoryAnomalyNULLSysmon EventID 11T1608.001 T1608.002

Sub-techniques6

IDNameExamples
T1608.001Upload Malware37
T1608.002Upload Tool5
T1608.003Install Digital Certificate1
T1608.004Drive-by Target9
T1608.005Link Target5
T1608.006SEO Poisoning1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

Groups1

Used byProcedure example
GroupMustang Panda

Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims.

References11

  1. ATT ScanBox Open source
    Blasco, J. (2014, August 28). Scanbox: A Reconnaissance Framework Used with Watering Hole Attacks. Retrieved October 19, 2020.
  2. DigiCert Install SSL Cert Open source
    DigiCert. (n.d.). How to Install an SSL Certificate. Retrieved April 19, 2021.
  3. Dragos Heroku Watering Hole Open source
    Kent Backman. (2021, May 18). When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar. Retrieved August 18, 2022.
  4. FireEye CFR Watering Hole 2012 Open source
    Kindlund, D. (2012, December 30). CFR Watering Hole Attack Details. Retrieved November 17, 2024.
  5. Gallagher 2015 Open source
    Gallagher, S.. (2015, August 5). Newly discovered Chinese hacking group hacked 100+ websites to use as “watering holes”. Retrieved January 25, 2016.
  6. Malwarebytes Heroku Skimmers Open source
    Jérôme Segura. (2019, December 4). There's an app for that: web skimmers found on PaaS Heroku. Retrieved August 18, 2022.
  7. Malwarebytes Silent Librarian October 2020 Open source
    Malwarebytes Threat Intelligence Team. (2020, October 14). Silent Librarian APT right on schedule for 20/21 academic year. Retrieved February 3, 2021.
  8. Netskope Cloud Phishing Open source
    Ashwin Vamshi. (2020, August 12). A Big Catch: Cloud Phishing from Google App Engine and Azure App Service. Retrieved August 18, 2022.
  9. Netskope GCP Redirection Open source
    Ashwin Vamshi. (2019, January 24). Targeted Attacks Abusing Google Cloud Platform Open Redirection. Retrieved August 18, 2022.
  10. Proofpoint TA407 September 2019 Open source
    Proofpoint Threat Insight Team. (2019, September 5). Threat Actor Profile: TA407, the Silent Librarian. Retrieved February 3, 2021.
  11. Volexity Ocean Lotus November 2020 Open source
    Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.