Has utilized VPS solutions for C2.1
Virtual Private Server T1583.003
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.1
- Created
- 01 October 2020
- Last modified
- 12 May 2026
Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. By utilizing a VPS, adversaries can make it difficult to physically tie back operations to them. The use of cloud infrastructure can also make it easier for adversaries to rapidly provision, modify, and shut down their infrastructure.
Virtual Private Server MITRE reference T1583.003
16 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting.12 Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud.3
Has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment.12
Staged encryption keys on virtual private servers operated by the adversary.1
Created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture.1
Registered virtual private servers to host payloads for download.1
All 16 groups for this technique · 6 newest in this preview
6 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
Included the use of dedicated, adversary-controlled virtual private servers for command and control.1
During the J-magic Campaign, threat actors acquired VPS for use in C2.1
Used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware.1
Has used acquired Virtual Private Servers as control systems for the ORB network.1
Has used acquired Virtual Private Servers as control systems for devices within the ORB network.1
During the C0032 campaign, TEMP.Veles used Virtual Private Server (VPS) infrastructure.1
All 6 campaigns for this technique
Offense vs defense T1583.003
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Virtual Private Server detection strategy DET0838
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Virtual Private Server
AN1970 · PRE
Once adversaries have provisioned a VPS (ex: for use as a command and control server), internet scans may reveal servers that adversaries have acquired. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Log sources
The data this analytic draws on. You do not need every component — each one you already collect covers part of it. Each links to its ATT&CK record.
| Data component | Name | Channel |
|---|---|---|
| Response ContentDC0104 | Internet Scan | None |
| Response MetadataDC0106 | Internet Scan | None |
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.