Resource Hijacking

T1496

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Resource hijacking may take a number of different forms. For example, adversaries may:

* Leverage compute resources in order to mine cryptocurrency
* Sell network bandwidth to proxy networks
* Generate SMS traffic for profit
* Abuse cloud-based messaging services to send large quantities of spam messages

In some cases, adversaries may leverage multiple types of Resource Hijacking at once.

Detection rules13

Rules on DetectionCode tagged with T1496 or one of its sub-techniques.

Sigma13

Splunk0

No Splunk rules are mapped to this technique yet.

Sub-techniques4

IDNameExamples
T1496.001Compute Hijacking14
T1496.002Bandwidth Hijacking0
T1496.003SMS Pumping0
T1496.004Cloud Service Hijacking0

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References1

  1. Sysdig Cryptojacking Proxyjacking 2023 Open source
    Miguel Hernandez. (2023, August 17). LABRAT: Stealthy Cryptojacking and Proxyjacking Campaign Targeting GitLab . Retrieved September 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.