kevmap

Techniques › T1496

T1496 Resource Hijacking

impact — Windows, IaaS, Linux, macOS, Containers, SaaS · attack.mitre.org · JSON

1
MITRE detection strategy
6
analytics
13
Sigma rules tagged attack.t1496
19
KEV CVEs mapped here
<p>Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.</p><p>Resource hijacking may take a number of different forms. For example, adversaries may:</p>
    <li>Leverage compute resources in order to mine cryptocurrency</li><li>Sell network bandwidth to proxy networks</li><li>Generate SMS traffic for profit</li><li>Abuse cloud-based messaging services to send large quantities of spam messages</li>
<p>In some cases, adversaries may leverage multiple types of Resource Hijacking at once.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-4632Samsung MagicINFO 9 Server secondary impact Mapped2025-05-22
CVE-2024-23692Rejetto HTTP File Server secondary impact Mapped2024-07-09
CVE-2023-22527Atlassian Confluence Data Center and Server primary impact Mapped2024-01-24
CVE-2023-49897FXC AE1021, AE1021PE primary impact Mapped2023-12-21
CVE-2023-47565QNAP VioStor NVR primary impact Mapped2023-12-21
CVE-2023-32315Ignite Realtime Openfire secondary impact Mapped2023-08-24
CVE-2023-38035Ivanti Sentry secondary impact Mapped2023-08-22
CVE-2022-29303SolarView Compact secondary impact Mapped2023-07-13
CVE-2023-1389TP-Link Archer AX21 primary impact Mapped2023-05-01
CVE-2022-29464WSO2 Multiple Products secondary impact Mapped2022-04-25
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) secondary impact Mapped2021-12-10
CVE-2021-44228Apache Log4j2 secondary impact Mapped2021-12-10
CVE-2018-11776Apache Struts secondary impact Mapped2021-11-03
CVE-2021-26084Atlassian Confluence Server and Data Center secondary impact Mapped2021-11-03
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) secondary impact Mapped2021-11-03
CVE-2020-8515DrayTek Multiple Vigor Routers secondary impact Mapped2021-11-03
CVE-2018-7600Drupal Drupal Core secondary impact Mapped2021-11-03
CVE-2021-22205GitLab Community and Enterprise Editions secondary impact Mapped2021-11-03
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX primary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1496

Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 08d6ac24-c927-4469-b3b7-2e422d6e3c43
Identifies when a Azure Kubernetes network policy is modified or deleted.
Techniques: T1485T1496T1489
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 12d027c3-b48c-4d9d-8bb6-a732200034b2
Identifies when a service account is modified or deleted.
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 25cb259b-bbdc-4b87-98b7-90d7c72f8743
Detects the creation or patching of potential malicious RoleBinding/ClusterRoleBinding.
Techniques: T1485T1496T1489
Author: Florian Roth (Nextron Systems) · 2021-10-26 (modified 2023-02-13) · logsource: product=windows category=process_creation · 66c3b204-9f88-4d0a-a7f7-8a57d521ca55
Detects command line parameters or strings often used by crypto miners
Techniques: T1496
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 7ee0b4aa-d8d4-4088-b661-20efdf41a04c
Identifies when a Kubernetes account access a sensitive objects such as configmaps or secrets.
Techniques: T1485T1496T1489
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 818fee0c-e0ec-4e45-824e-83e4817b0887
Identifies when ClusterRoles/Roles are being modified or deleted.
Techniques: T1485T1496T1489
Author: Florian Roth (Nextron Systems) · 2021-10-26 (modified 2022-12-25) · logsource: product=linux category=process_creation · 9069ea3c-b213-4c52-be13-86506a227ab1
Detects command line parameters or strings often used by crypto miners
Techniques: T1496
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 93e0ef48-37c8-49ed-a02c-038aab23628e
Detects when a Container Registry is created or deleted.
Techniques: T1485T1496T1489
Author: Austin Songer @austinsonger · 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 9541f321-7cba-4b43-80fc-fbd1fb922808
Detects when a Azure Kubernetes Cluster is created or deleted.
Techniques: T1485T1496T1489
Author: Florian Roth (Nextron Systems) · 2021-10-26 · logsource: product=linux category=network_connection · a46c93b7-55ed-4d27-a41b-c259456c4746
Detects process connections to a Monero crypto mining pool
Techniques: T1496
Author: Florian Roth (Nextron Systems) · 2021-10-24 · logsource: category=dns · b593fd50-7335-4682-a36c-4edcb68e4641
Detects suspicious DNS queries to Monero mining pools
Techniques: T1496T1567
Author: Saw Winn Naung, Azure-Sentinel, @neu5ron · 2021-08-19 (modified 2022-07-07) · logsource: product=zeek service=dns · bf74135c-18e8-4a72-a926-0e4f47888c19
Identifies clients that may be performing DNS lookups associated with common currency mining pools.
Techniques: T1569.002T1496
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2021-10-26 (modified 2026-07-24) · logsource: product=windows category=network_connection · fa5b1358-b040-4403-9868-15f7d9ab6329
Detects initiated network connections to crypto mining pools. It indicates that the system is likely infected with a crypto miner malware or is being used for crypto mining.
Techniques: T1496

Sub-techniques

IDNameSigma rulesKEV CVEs
T1496.001Compute Hijacking00
T1496.002Bandwidth Hijacking00
T1496.003SMS Pumping00
T1496.004Cloud Service Hijacking00