Umbra Wiki technique technique/T1496
Back to wiki

T1496 — Resource Hijacking

provenance: imported · ATT&CK: T1496

T1496: Resource Hijacking

MITRE ATT&CK® Enterprise technique

Tactics Impact
Platforms Windows, IaaS, Linux, macOS, Containers, SaaS
Permissions required
Version 2.0

Description

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Resource hijacking may take a number of different forms. For example, adversaries may:

  • Leverage compute resources in order to mine cryptocurrency
  • Sell network bandwidth to proxy networks
  • Generate SMS traffic for profit
  • Abuse cloud-based messaging services to send large quantities of spam messages

In some cases, adversaries may leverage multiple types of Resource Hijacking at once.(Citation: Sysdig Cryptojacking Proxyjacking 2023)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1496
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/