Sub-technique of T1583 Acquire Infrastructure.View on attack.mitre.org
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.
Adversaries may use acquired domains for a variety of purposes, including for Phishing, Drive-by Compromise, and Command and Control. Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD). Typosquatting may be used to aid in delivery of payloads via Drive-by Compromise. Adversaries may also use internationalized domain names (IDNs) and different character sets (e.g. Cyrillic, Greek, etc.) to execute "IDN homograph attacks," creating visually similar lookalike domains used to deliver malware to victim machines.
Different URIs/URLs may also be dynamically generated to uniquely serve malicious content to victims (including one-time, single use domain names).
Adversaries may also acquire and repurpose expired domains, which may be potentially already allowlisted/trusted by defenders based on an existing reputation/history.
Domain registrars each maintain a publicly viewable database that displays contact information for every registered domain. Private WHOIS services display alternative information, such as their own company data, rather than the owner of the domain. Adversaries may use such private WHOIS services to obscure information about who owns a purchased domain. Adversaries may further interrupt efforts to track their infrastructure by using varied registration information and purchasing domains with different domain registrars.
In addition to legitimately purchasing a domain, an adversary may register a new domain in a compromised environment. For example, in AWS environments, adversaries may leverage the Route53 domain service to register a domain and create hosted zones pointing to resources of the threat actor’s choosing.
Rules on DetectionCode tagged with T1583.001.
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has acquired domains to host malicious payloads. |
| GroupAPT1 | APT1 has registered hundreds of domains for use in operations. |
| GroupAPT28 | APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations. |
| GroupAPT32 | APT32 has set up and operated websites to gather information and deliver malware. |
| GroupAPT38 | APT38 has created fake domains to imitate legitimate venture capital or bank domains. |
| GroupAPT42 | APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations. |
| GroupBITTER | BITTER has registered a variety of domains to host malicious payloads and for C2. |
| GroupContagious Interview | Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2. ESET Contagious Interview BeaverTail InvisibleFerret February 2025PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Sekoia ClickFake 2025Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| Used by | Procedure example |
|---|---|
| MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services. |
| MalwareRaspberry Robin | Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as " |
| MalwareXLoader | XLoader can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap. |
| Used by | Procedure example |
|---|---|
| CampaignC0010 | For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer. |
| CampaignC0011 | For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India. |
| CampaignC0021 | For C0021, the threat actors registered domains for use in C2. |
| CampaignC0026 | For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware. |
| CampaignCostaRicto | For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains. |
| CampaignFunnyDream | For FunnyDream, the threat actors registered a variety of domains. |
| CampaignIndian Critical Infrastructure Intrusions | During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.