Techniques › T1496
T1496 Resource Hijacking
impact — Windows, IaaS, Linux, macOS, Containers, SaaS · attack.mitre.org · JSON
1
MITRE detection strategy
6
analytics
13
Sigma rules tagged attack.t1496
19
KEV CVEs mapped here
<p>Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.</p><p>Resource hijacking may take a number of different forms. For example, adversaries may:</p>
- <li>Leverage compute resources in order to mine cryptocurrency</li><li>Sell network bandwidth to proxy networks</li><li>Generate SMS traffic for profit</li><li>Abuse cloud-based messaging services to send large quantities of spam messages</li>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-4632 | Samsung MagicINFO 9 Server | secondary impact | Mapped | 2025-05-22 |
| CVE-2024-23692 | Rejetto HTTP File Server | secondary impact | Mapped | 2024-07-09 |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | primary impact | Mapped | 2024-01-24 |
| CVE-2023-49897 | FXC AE1021, AE1021PE | primary impact | Mapped | 2023-12-21 |
| CVE-2023-47565 | QNAP VioStor NVR | primary impact | Mapped | 2023-12-21 |
| CVE-2023-32315 | Ignite Realtime Openfire | secondary impact | Mapped | 2023-08-24 |
| CVE-2023-38035 | Ivanti Sentry | secondary impact | Mapped | 2023-08-22 |
| CVE-2022-29303 | SolarView Compact | secondary impact | Mapped | 2023-07-13 |
| CVE-2023-1389 | TP-Link Archer AX21 | primary impact | Mapped | 2023-05-01 |
| CVE-2022-29464 | WSO2 Multiple Products | secondary impact | Mapped | 2022-04-25 |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | secondary impact | Mapped | 2021-12-10 |
| CVE-2021-44228 | Apache Log4j2 | secondary impact | Mapped | 2021-12-10 |
| CVE-2018-11776 | Apache Struts | secondary impact | Mapped | 2021-11-03 |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | secondary impact | Mapped | 2021-11-03 |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | secondary impact | Mapped | 2021-11-03 |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | secondary impact | Mapped | 2021-11-03 |
| CVE-2018-7600 | Drupal Drupal Core | secondary impact | Mapped | 2021-11-03 |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | secondary impact | Mapped | 2021-11-03 |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | primary impact | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0267 Resource Hijacking Detection Strategy v1.0
AN0741 WindowsPersistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.Tunable:
TimeWindowDestinationIPListExecutableNamePatternsAN0742 LinuxAbnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.Tunable:ProcessPathCPUThresholdKnownMiningDomainsAN0743 macOSBackground launch agents/daemons with high CPU use and network access to external mining services.Tunable:launchdLabelTrafficVolumeThresholdAN0744 IaaSSudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation.Tunable:CPUUtilizationThresholdUnusualRegionListAN0745 ContainersHigh CPU usage by unauthorized containers running mining binaries or public proxy tools.containerd:eventsNew container with suspicious image name or high resource usage→ DC0032 Process CreationTunable:ImageNameCPUQuotaThresholdAN0746 SaaSAbuse of cloud messaging platforms to send mass spam or consume quota-based resources.saas:applicationHigh-volume API calls or traffic via messaging or webhook service→ DC0038 Application Log ContentTunable:MessageRateThresholdAPIKeyList
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1496
Author: Austin Songer @austinsonger
· 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 08d6ac24-c927-4469-b3b7-2e422d6e3c43
Identifies when a Azure Kubernetes network policy is modified or deleted.
Author: Austin Songer @austinsonger
· 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 12d027c3-b48c-4d9d-8bb6-a732200034b2
Identifies when a service account is modified or deleted.
Author: Austin Songer @austinsonger
· 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 25cb259b-bbdc-4b87-98b7-90d7c72f8743
Detects the creation or patching of potential malicious RoleBinding/ClusterRoleBinding.
Author: Florian Roth (Nextron Systems)
· 2021-10-26 (modified 2023-02-13) · logsource: product=windows category=process_creation · 66c3b204-9f88-4d0a-a7f7-8a57d521ca55
Detects command line parameters or strings often used by crypto miners
Author: Austin Songer @austinsonger
· 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 7ee0b4aa-d8d4-4088-b661-20efdf41a04c
Identifies when a Kubernetes account access a sensitive objects such as configmaps or secrets.
Author: Austin Songer @austinsonger
· 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 818fee0c-e0ec-4e45-824e-83e4817b0887
Identifies when ClusterRoles/Roles are being modified or deleted.
Author: Florian Roth (Nextron Systems)
· 2021-10-26 (modified 2022-12-25) · logsource: product=linux category=process_creation · 9069ea3c-b213-4c52-be13-86506a227ab1
Detects command line parameters or strings often used by crypto miners
Author: Austin Songer @austinsonger
· 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 93e0ef48-37c8-49ed-a02c-038aab23628e
Detects when a Container Registry is created or deleted.
Author: Austin Songer @austinsonger
· 2021-08-07 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 9541f321-7cba-4b43-80fc-fbd1fb922808
Detects when a Azure Kubernetes Cluster is created or deleted.
Author: Florian Roth (Nextron Systems)
· 2021-10-26 · logsource: product=linux category=network_connection · a46c93b7-55ed-4d27-a41b-c259456c4746
Detects process connections to a Monero crypto mining pool
Author: Florian Roth (Nextron Systems)
· 2021-10-24 · logsource: category=dns · b593fd50-7335-4682-a36c-4edcb68e4641
Detects suspicious DNS queries to Monero mining pools
Author: Saw Winn Naung, Azure-Sentinel, @neu5ron
· 2021-08-19 (modified 2022-07-07) · logsource: product=zeek service=dns · bf74135c-18e8-4a72-a926-0e4f47888c19
Identifies clients that may be performing DNS lookups associated with common currency mining pools.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2021-10-26 (modified 2026-07-24) · logsource: product=windows category=network_connection · fa5b1358-b040-4403-9868-15f7d9ab6329
Detects initiated network connections to crypto mining pools.
It indicates that the system is likely infected with a crypto miner malware or is being used for crypto mining.