Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1496 — Resource Hijacking
T1496

Resource Hijacking

Impact
TLP:CLEAR

Description

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. Resource hijacking may take a number of different forms. For example, adversaries may: * Leverage compute resources in order to mine cryptocurrency * Sell network bandwidth to proxy networks * Generate SMS traffic for profit * Abuse cloud-based messaging services to send large quantities of spam messages In some cases, adversaries may leverage multiple types of Resource Hijacking at once.(Citation: Sysdig Cryptojacking Proxyjacking 2023)

MITRE ATT&CK Detection Strategies
1

DET0267 Resource Hijacking Detection Strategy
AN0746 SaaS

Abuse of cloud messaging platforms to send mass spam or consume quota-based resources.

m365:unified saas:application
AN0745 Containers

High CPU usage by unauthorized containers running mining binaries or public proxy tools.

containerd:events prometheus:metrics container:cni
AN0742 Linux

Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.

auditd:SYSCALL linux:procfs NSM:Flow
+3 more analytics

Details

Platforms
Windows
Iaas
Linux
Macos
Containers
Saas
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.