T1584.001sub-technique of T1584 Compromise Infrastructure
Domains
PRE1 piece on this siteT1584.001 on attack.mitre.org
Adversaries may hijack domains and/or subdomains that can be used during targeting. Domain registration hijacking is the act of changing the registration of a domain name without the permission of the original registrant. Adversaries may gain access to an email account for the person listed as the owner of the domain. The adversary can then claim that they forgot their password in order to make changes to the domain registration.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Your DNS records changed and nobody here did it
Mail stops arriving, a site resolves somewhere unexpected, a certificate appears that nobody requested, or the registrar emails about a change nobody made.
how MITRE says to see it
Detection of Domains
- Monitor for logged domain name system (DNS) registry data that may hijack domains and/or subdomains that can be used during targeting. In some cases, abnormal subdomain IP addresses (such as those originating in a different country from the root domain) may indicate a malicious subdomain.
what reduces it
- M1056 Pre-compromise. This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.