Has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data.12 Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com.34
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.4
- Created
- 30 September 2020
- Last modified
- 12 May 2026
- Contributors
- Wes Hurd; Vinayak Wadhwa, Lucideus; Deloitte Threat Library Team; Oleg Kolesnikov, Securonix; Menachem Goldstein; Nikola Kovac
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.
Domains MITRE reference T1583.001
46 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints.12345678 TeamPCP has also set up a dark web leak site to post stolen data.910
Has registered domains for messaging purposes.1 VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion.23 VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex.2 VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations.4
Has registered domains to leverage in their social engineering campaigns.123 Contagious Interview has also registered domains to utilize for C2.456789
Has created domains for use with RMM tools.1
Has registered domains, several of which masqueraded as news outlets and login services, for use in operations.12
All 46 groups for this technique · 6 newest in this preview
15 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains.12
Mustang Panda registered adversary-controlled domains during RedDelta Modified PlugX Infection Chain Operations that were re-registrations of expired domains.1
For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.1
For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India.1
During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities.1
For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.1
All 15 campaigns for this technique · 6 newest in this preview
3 software entries are documented implementing this technique. MITRE files each as a tool or as malware; newest first, then by how many groups carry them.
Can utilize hardcoded command and control domain configurations created by the XLoader authors. These are designed to mimic domain registrars and hosting service providers such as Hostinger and Namecheap.1
Uses newly-registered domains containing only a few characters for command and controll purposes, such as "v0[.]cx".1
Command and control includes hard-coded domains in the malware chosen to masquerade as legitimate services such as Akamai CDN or Amazon Web Services.1
All 3 software entries for this technique
Offense vs defense T1583.001
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Domains detection strategy DET0892
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Domains
AN2024 · PRE
Monitor logged domain name system (DNS) data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. Domain registration information is, by design, captured in public registration logs. Consider use of services that may aid in tracking of newly acquired domains, such as WHOIS databases and/or passive DNS. In some cases it may be possible to pivot on known pieces of domain registration information to uncover other infrastructure purchased by the adversary. Consider monitoring for domains created with a similar structure to your own, including under a different TLD. Though various tools and services exist to track, query, and monitor domain name registration information, tracking across multiple DNS infrastructures can require multiple tools/services or more advanced analytics. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. Monitor queried domain name system (DNS) registry data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control.
Log sources
The data this analytic draws on. You do not need every component — each one you already collect covers part of it. Each links to its ATT&CK record.
| Data component | Name | Channel |
|---|---|---|
| Passive DNSDC0096 | Domain Name | None |
| Domain RegistrationDC0101 | Domain Name | None |
| Active DNSDC0103 | Domain Name | None |
Organizations may intentionally register similar domains to their own to deter adversaries from creating typosquatting domains. Other facets of this technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.