Has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files.1
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.3
- Created
- 01 October 2020
- Last modified
- 12 May 2026
- Contributor
- Dor Edry, Microsoft
Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, such as watering hole operations in Drive-by Compromise, enabling Phishing operations, or facilitating Command and Control. Instead of compromising a third-party Server or renting a Virtual Private Server, adversaries may opt to configure and run their own servers in support of operations. Free trial periods of cloud servers may also be abused.[1][2]
Server MITRE reference T1583.004
9 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has leased infrastructure specifically for offensive operations including Google assets in AS396982.12
Has leveraged backend servers within Iran.1
Has acquired servers to host second-stage payloads that remain active for a period of either days, weeks, or months.1
Has created dedicated servers for command and control and exfiltration purposes.1
Has acquired multiple servers for some of their operations, using each server for a different role.1
All 9 groups for this technique · 6 newest in this preview
4 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools.1
For Operation Wocao, the threat actors purchased servers with Bitcoin to use during the operation.1
For Operation Honeybee, at least one identified persona was used to register for a free account for a control server.1
During Night Dragon, threat actors purchased hosted services to use for C2.1
All 4 campaigns for this technique
Offense vs defense T1583.004
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Server detection strategy DET0871
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Server
AN2003 · PRE
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Once adversaries have provisioned a server (ex: for use as a command and control server), internet scans may reveal servers that adversaries have acquired. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.
Log sources
The data this analytic draws on. You do not need every component — each one you already collect covers part of it. Each links to its ATT&CK record.
| Data component | Name | Channel |
|---|---|---|
| Response ContentDC0104 | Internet Scan | None |
| Response MetadataDC0106 | Internet Scan | None |
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.