Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org
Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems. Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).
Rules on DetectionCode tagged with T1584.005.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used a botnet management interface to control large numbers of compromised hosts. |
| GroupAxiom | Axiom has used large groups of compromised machines for use as proxy nodes. |
| GroupHAFNIUM | HAFNIUM has used compromised devices in covert networks to obfuscate communications. |
| GroupSandworm Team | Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices. |
| GroupVolt Typhoon | Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations. |
| Used by | Procedure example |
|---|---|
| CampaignQuad7 Activity | Quad7 Activity has compromised various branded SOHO routers to form a botnet that has been leveraged in password spraying activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.