Virtual Private Server

T1584.003

Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org

About this technique

Adversaries may compromise third-party Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. Adversaries may compromise VPSs purchased by third-party entities. By compromising a VPS to use as infrastructure, adversaries can make it difficult to physically tie back operations to themselves.

Compromising a VPS for use in later stages of the adversary lifecycle, such as Command and Control, can allow adversaries to benefit from the ubiquity and trust associated with higher reputation cloud service providers as well as that added by the compromised third-party.

Detection rules0

Rules on DetectionCode tagged with T1584.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software0

None recorded.

Campaigns2

Procedure examples4

Groups2

Used byProcedure example
GroupTurla

Turla has used the VPS infrastructure of compromised Iranian threat actors.

GroupVolt Typhoon

Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic.

Campaigns2

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used compromised VPS servers for C2.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files.

References1

  1. NSA NCSC Turla OilRig Open source
    NSA/NCSC. (2019, October 21). Cybersecurity Advisory: Turla Group Exploits Iranian APT To Expand Coverage Of Victims. Retrieved October 16, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.