TACTIC: RESOURCE DEVELOPMENT
Compromise Infrastructure (T1584): real cases
MITRE Definition ↗ Adversaries hijack third-party domains, servers, and routers to use as attack relay infrastructure.
Key Facts
Technique ID
T1584
Resource Development
Mapped Cases
3
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1584.
- Tactical Phase: Resource Development.
- Substantiated in 3 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
Volt Typhoon Critical Infrastructure Pre-Positioning
alleged 2023-05-24
Primary Source Evidence Excerpt: DOJ Press Release 24-118
"Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States."
Federal Law Enforcement Action / FISA Court Authorized Operations
View full case dossier →
U.S. v. Peter Levashov (Kelihos Botnet)
pleaded 2017-04-07
Primary Source Evidence Excerpt: Indictment ¶ 11, Page 5
"Levashov leased out compromised zombie computers as an automated bulletproof proxy network to shield criminal infrastructure."
U.S. District Court for the District of Connecticut
View full case dossier →
U.S. v. Elena Alekseevna Khusyaynova (Project Lakhta)
fugitive 2018-09-28
Primary Source Evidence Excerpt: Criminal Complaint ¶ 24, Page 12
"Operatives purchased thousands of virtual private servers and compromised proxy networks in the United States to disguise Russian origins."
U.S. District Court for the Eastern District of Virginia
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.