Web Services

T1583.006

Sub-technique of T1583 Acquire Infrastructure.View on attack.mitre.org

About this technique

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Detection rules1

Rules on DetectionCode tagged with T1583.006.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Cisco Secure Firewall - Rare Snort Rule TriggeredHuntingNULLCisco Secure Firewall Threat Defense Intrusion Event

Groups27

Show 3 more

Software0

None recorded.

Campaigns4

Procedure examples31

Groups27

Used byProcedure example
GroupAPT-C-36

APT-C-36 campaign architecture has included image hosting sites, Pastebin, Discord, GitHub, Google Drive, BitBucket, and Dropbox.

GroupAPT17

APT17 has created profile pages in Microsoft TechNet that were used as C2 infrastructure.

GroupAPT28

APT28 has used newly-created Blogspot pages for credential harvesting operations.

GroupAPT29

APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations.

GroupAPT32

APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads.

GroupConfucius

Confucius has obtained cloud storage service accounts to host stolen data.

GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

GroupEarth Lusca

Earth Lusca has established GitHub accounts to host their malware.

View all 27 groups examples

Campaigns4

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries configured the FortiGate devices to send notifications to an attacker-controlled Slack channel. During the 2025 Poland Wiper Attacks, the adversaries had also staged tools and files on services such as Dropbox and Pastebin.

CampaignArcaneDoor

ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive.

CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used Dropbox to host lure documents and their first-stage downloader.

References2

  1. FireEye APT29 Open source
    FireEye Labs. (2015, July). HAMMERTOSS: Stealthy Tactics Define a Russian Cyber Threat Group. Retrieved November 17, 2024.
  2. Hacker News GitHub Abuse 2024 Open source
    Dvir Sasson. (2024, May 13). GitHub Abuse Flaw Shows Why We Can't Shrug Off Abuse Vulnerabilities in Security. Retrieved March 31, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.