Sub-technique of T1584 Compromise Infrastructure.View on attack.mitre.org
Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.
Once an adversary has control, compromised network devices can be used to launch additional operations, such as hosting payloads for Phishing campaigns (i.e., Link Target) or enabling the required access to execute Content Injection operations. Adversaries may also be able to harvest reusable credentials (i.e., Valid Accounts) from compromised network devices.
Adversaries often target Internet-facing edge devices and related network appliances that specifically do not support robust host-based defenses.
Compromised network devices may be used to support subsequent Command and Control activity, such as Hide Infrastructure through an established Proxy and/or Botnet network.
Rules on DetectionCode tagged with T1584.008.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages. |
| GroupLeviathan | Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure. |
| GroupVolt Typhoon | Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic. |
| GroupZIRCONIUM | ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used compromised Cisco routers for network communications. |
| CampaignCutting Edge | During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2. |
| CampaignFLORAHOX Activity | FLORAHOX Activity has compromised network routers and IoT devices for the ORB network. |
| CampaignKV Botnet Activity | KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet. |
| CampaignQuad7 Activity | Quad7 Activity has compromised network devices, such as IP cameras, Network Attached Storage (NAS) devices, and SOHO routers, to leverage for follow-on activity. |
| CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.