Server

T1583.004

Sub-technique of T1583 Acquire Infrastructure.View on attack.mitre.org

About this technique

Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, such as watering hole operations in Drive-by Compromise, enabling Phishing operations, or facilitating Command and Control. Instead of compromising a third-party Server or renting a Virtual Private Server, adversaries may opt to configure and run their own servers in support of operations. Free trial periods of cloud servers may also be abused.

Adversaries may only need a lightweight setup if most of their activities will take place using online infrastructure. Or, they may need to build extensive infrastructure if they want to test, communicate, and control other aspects of their activities on their own systems.

Detection rules0

Rules on DetectionCode tagged with T1583.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups9

Software0

None recorded.

Campaigns4

Procedure examples13

Groups9

Used byProcedure example
GroupCURIUM

CURIUM has created dedicated servers for command and control and exfiltration purposes.

GroupEarth Lusca

Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role.

GroupGALLIUM

GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM.

GroupKimsuky

Kimsuky has purchased hosting servers with virtual currency and prepaid cards.

GroupMustard Tempest

Mustard Tempest has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months.

GroupSandworm Team

Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations.

GroupShinyHunters

ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.

GroupTeamPCP

TeamPCP has leased infrastructure specifically for offensive operations including Google assets in AS396982.

View all 9 groups examples

Campaigns4

Used byProcedure example
CampaignNight Dragon

During Night Dragon, threat actors purchased hosted services to use for C2.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools.

CampaignOperation Honeybee

For Operation Honeybee, at least one identified persona was used to register for a free account for a control server.

CampaignOperation Wocao

For Operation Wocao, the threat actors purchased servers with Bitcoin to use during the operation.

References3

  1. Free Trial PurpleUrchin Open source
    Gamazo, William. Quist, Nathaniel.. (2023, January 5). PurpleUrchin Bypasses CAPTCHA and Steals Cloud Platform Resources. Retrieved February 28, 2024.
  2. Freejacked Open source
    Clark, Michael. (2023, August 14). Google’s Vertex AI Platform Gets Freejacked. Retrieved February 28, 2024.
  3. NYTStuxnet Open source
    William J. Broad, John Markoff, and David E. Sanger. (2011, January 15). Israeli Test on Worm Called Crucial in Iran Nuclear Delay. Retrieved March 1, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.