Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org
Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.
Adversaries may also compromise web servers to support watering hole operations, as in Drive-by Compromise, or email servers to support Phishing operations.
Rules on DetectionCode tagged with T1584.004.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT16 | APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads. |
| GroupDaggerfly | Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion. |
| GroupDragonfly | Dragonfly has compromised legitimate websites to host C2 and malware modules. |
| GroupEarth Lusca | Earth Lusca has used compromised web servers as part of their operational infrastructure. |
| GroupIndrik Spider | Indrik Spider has served fake updates via legitimate websites that have been compromised. |
| GroupLazarus Group | Lazarus Group has compromised servers to stage malicious tools. |
| GroupLeviathan | Leviathan has used compromised legitimate websites as command and control nodes for operations. |
| GroupSandworm Team | Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary operated dedicated penetration testing servers accessible via MCP to support remote command execution, simultaneous tool coordination, and persistent operational state maintenance across campaign sessions. |
| CampaignJuicy Mix | During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server. |
| CampaignNight Dragon | During Night Dragon, threat actors compromised web servers to use for C2. |
| CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools. |
| CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure. |
| CampaignOuter Space | During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.