T1496
Resource Hijacking
Windows · IaaS · Linux · macOS · Containers · SaaS1 piece on this siteT1496 on attack.mitre.org
Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. Resource hijacking may take a number of different forms. For example, adversaries may: * Leverage compute resources in order to mine cryptocurrency * Sell network bandwidth to proxy networks * Generate SMS traffic for profit * Abuse cloud-based messaging services to send large quantities of spam...
If this is happening now
Checklists and playbooks to open while the alert is still live.
First-hour playbookMembers
Unexplained compute in a cloud account
A billing alert, instances nobody created, or a provider notification about mining.
T1496.001
how MITRE says to see it
Resource Hijacking Detection Strategy
- Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.
- Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.
- Background launch agents/daemons with high CPU use and network access to external mining services.
- Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation.