Skip to content
Every technique
T1496Detection written

Resource Hijacking

ImpactWindows, IaaS, Linux, macOS, Containers, SaaS

Where this stands

One published detection covers this technique. Every one is unverified — no rule on Siemphony has been executed against real telemetry.

What the technique is

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. Resource hijacking may take a number of different forms. For example, adversaries may: Leverage compute resources in order to mine cryptocurrency Sell network bandwidth to proxy networks Generate SMS traffic for profit Abuse cloud-based messaging services to send large quantities of spam messages In some cases, adversaries may leverage multiple types of Resource Hijacking at once.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN0741

    Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.

  • AN0742

    Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.

  • AN0743

    Background launch agents/daemons with high CPU use and network access to external mining services.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.