Acquire Infrastructure

T1583

Technique with 8 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure solutions include physical or cloud servers, domains, and third-party web services. Some infrastructure providers offer free trial periods, enabling infrastructure acquisition at limited to no cost. Additionally, botnets are available for rent or purchase.

Use of these infrastructure solutions allows adversaries to stage, launch, and execute operations. Solutions may help adversary operations blend in with traffic that is seen as normal, such as contacting third-party web services or acquiring infrastructure to support Proxy, including from residential proxy services. Depending on the implementation, adversaries may use infrastructure that makes it difficult to physically tie back to them as well as utilize infrastructure that can be rapidly provisioned, modified, and shut down.

Detection rules1

Rules on DetectionCode tagged with T1583 or one of its sub-techniques.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData sourceTechnique
Cisco Secure Firewall - Rare Snort Rule TriggeredHuntingNULLCisco Secure Firewall Threat Defense Intrusion EventT1583.006

Sub-techniques8

IDNameExamples
T1583.001Domains64
T1583.002DNS Server3
T1583.003Virtual Private Server22
T1583.004Server13
T1583.005Botnet3
T1583.006Web Services31
T1583.007Serverless1
T1583.008Malvertising2

Groups9

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

Groups9

Used byProcedure example
GroupAgrius

Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN.

GroupContagious Interview

Contagious Interview has used services such as Astrill VPN.

GroupEmber Bear

Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations.

GroupIndrik Spider

Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments.

GroupKimsuky

Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure.

GroupSandworm Team

Sandworm Team used various third-party email campaign management services to deliver phishing emails.

GroupSea Turtle

Sea Turtle accessed victim networks from VPN service provider networks.

GroupStar Blizzard

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.

View all 9 groups examples

References5

  1. FBI Proxies Credential Stuffing Open source
    FBI. (2022, August 18). Proxies and Configurations Used for Credential Stuffing Attacks on Online Customer Accounts . Retrieved July 6, 2023.
  2. Free Trial PurpleUrchin Open source
    Gamazo, William. Quist, Nathaniel.. (2023, January 5). PurpleUrchin Bypasses CAPTCHA and Steals Cloud Platform Resources. Retrieved February 28, 2024.
  3. Mandiant APT29 Microsoft 365 2022 Open source
    Douglas Bienstock. (2022, August 18). You Can’t Audit Me: APT29 Continues Targeting Microsoft 365. Retrieved February 23, 2023.
  4. TrendmicroHideoutsLease Open source
    Max Goncharov. (2015, July 15). Criminal Hideouts for Lease: Bulletproof Hosting Services. Retrieved March 6, 2017.
  5. amnesty_nso_pegasus Open source
    Amnesty International Security Lab. (2021, July 18). Forensic Methodology Report: How to catch NSO Group’s Pegasus. Retrieved February 22, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.