Botnet

T1583.005

Sub-technique of T1583 Acquire Infrastructure.View on attack.mitre.org

About this technique

Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Adversaries may purchase a subscription to use an existing botnet from a booter/stresser service.

Internet-facing edge devices and related network appliances that are end-of-life (EOL) and unsupported by their manufacturers are commonly acquired for botnet activities. Adversaries may lease operational relay box (ORB) networks – consisting of virtual private servers (VPS), small office/home office (SOHO) routers, or Internet of Things (IoT) devices – to serve as a botnet.

With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS). Acquired botnets may also be used to support Command and Control activity, such as Hide Infrastructure through an established Proxy network.

Detection rules0

Rules on DetectionCode tagged with T1583.005.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

Groups3

Used byProcedure example
GroupAPT5

APT5 has acquired a network of compromised systems – specifically an ORB (operational relay box) network – for follow on activities.

GroupHAFNIUM

HAFNIUM has incorporated leased devices into covert networks to obfuscate communications.

GroupKe3chang

Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation.

References6

  1. Imperva DDoS for Hire Open source
    Imperva. (n.d.). Booters, Stressers and DDoSers. Retrieved October 4, 2020.
  2. Krebs-Anna Open source
    Brian Krebs. (2017, January 18). Who is Anna-Senpai, the Mirai Worm Author?. Retrieved May 15, 2017.
  3. Krebs-Bazaar Open source
    Brian Krebs. (2016, October 31). Hackforums Shutters Booter Service Bazaar. Retrieved May 15, 2017.
  4. Krebs-Booter Open source
    Brian Krebs. (2016, October 27). Are the Days of “Booter” Services Numbered?. Retrieved May 15, 2017.
  5. Norton Botnet Open source
    Norton. (n.d.). What is a botnet?. Retrieved October 4, 2020.
  6. ORB Mandiant Open source
    Raggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.