Network Devices

T1584.008

Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org

About this technique

Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.

Once an adversary has control, compromised network devices can be used to launch additional operations, such as hosting payloads for Phishing campaigns (i.e., Link Target) or enabling the required access to execute Content Injection operations. Adversaries may also be able to harvest reusable credentials (i.e., Valid Accounts) from compromised network devices.

Adversaries often target Internet-facing edge devices and related network appliances that specifically do not support robust host-based defenses.

Compromised network devices may be used to support subsequent Command and Control activity, such as Hide Infrastructure through an established Proxy and/or Botnet network.

Detection rules0

Rules on DetectionCode tagged with T1584.008.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software0

None recorded.

Campaigns6

Procedure examples10

Groups4

Used byProcedure example
GroupAPT28

APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages.

GroupLeviathan

Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure.

GroupVolt Typhoon

Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.

GroupZIRCONIUM

ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks.

Campaigns6

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used compromised Cisco routers for network communications.

CampaignCutting Edge

During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2.

CampaignFLORAHOX Activity

FLORAHOX Activity has compromised network routers and IoT devices for the ORB network.

CampaignKV Botnet Activity

KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet.

CampaignQuad7 Activity

Quad7 Activity has compromised network devices, such as IP cameras, Network Attached Storage (NAS) devices, and SOHO routers, to leverage for follow-on activity.

CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers.

References3

  1. Justice GRU 2024 Open source
    Office of Public Affairs. (2024, February 15). Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the General Staff (GRU). Retrieved March 28, 2024.
  2. Mandiant Fortinet Zero Day Open source
    Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.
  3. Wired Russia Cyberwar Open source
    Greenberg, A. (2022, November 10). Russia’s New Cyberwarfare in Ukraine Is Fast, Dirty, and Relentless. Retrieved March 22, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.