T1584.005 — Botnet
T1584.005: Botnet
MITRE ATT&CK® Enterprise technique
| Tactics | Resource Development |
| Platforms | PRE |
| Permissions required | — |
| Version | 1.0 |
| Parent technique | T1584 |
Description
Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks.(Citation: Norton Botnet) Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems.(Citation: Imperva DDoS for Hire) Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers.(Citation: Dell Dridex Oct 2015) With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1584/005
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/