Umbra Wiki technique technique/T1496.002
Back to wiki

T1496.002 — Bandwidth Hijacking

provenance: imported · ATT&CK: T1496.002

T1496.002: Bandwidth Hijacking

MITRE ATT&CK® Enterprise technique

Tactics Impact
Platforms Linux, Windows, macOS, IaaS, Containers
Permissions required
Version 1.0
Parent technique T1496

Description

Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Adversaries may also use malware that leverages a system's network bandwidth as part of a botnet in order to facilitate Network Denial of Service campaigns and/or to seed malicious torrents.(Citation: GoBotKR) Alternatively, they may engage in proxyjacking by selling use of the victims' network bandwidth and IP address to proxyware services.(Citation: Sysdig Proxyjacking) Finally, they may engage in internet-wide scanning in order to identify additional targets for compromise.(Citation: Unit 42 Leaked Environment Variables 2024)

In addition to incurring potential financial costs or availability disruptions, this technique may cause reputational damage if a victim’s bandwidth is used for illegal activities.(Citation: Sysdig Proxyjacking)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1496/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/