Compromised web servers hosting updates for software as part of a supply chain intrusion.1
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.2
- Created
- 01 October 2020
- Last modified
- 12 May 2026
- Contributor
- Dor Edry, Microsoft
Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control.[1] Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.
Server MITRE reference T1584.004
10 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.12
Has used compromised web servers as part of their operational infrastructure.1
Has served fake updates via legitimate websites that have been compromised.1
Has used compromised legitimate websites as command and control nodes for operations.1
Has compromised legitimate websites to host C2 and malware modules.1
All 10 groups for this technique · 6 newest in this preview
6 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
During the Anthropic AI-orchestrated Campaign, the adversary operated dedicated penetration testing servers accessible via MCP to support remote command execution, simultaneous tool coordination, and persistent operational state maintenance across campaign sessions.1
During Juicy Mix, OilRig compromised an Israeli job portal to use for a C2 server.1
During Outer Space, OilRig compromised an Israeli human resources site to use as a C2 server.1
For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.123
For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure.1
During Night Dragon, threat actors compromised web servers to use for C2.1
All 6 campaigns for this technique
Offense vs defense T1584.004
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Server detection strategy DET0874
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Server
AN2006 · PRE
Once adversaries have provisioned software on a compromised server (ex: for use as a command and control server), internet scans may reveal servers that adversaries have compromised. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
Log sources
The data this analytic draws on. You do not need every component — each one you already collect covers part of it. Each links to its ATT&CK record.
| Data component | Name | Channel |
|---|---|---|
| Response ContentDC0104 | Internet Scan | None |
| Response MetadataDC0106 | Internet Scan | None |
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.