T1496Resource Hijacking
T1496 — Resource Hijacking is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 14 detection use cases covering it and 11 threat-intel articles citing it.
Impact
14Use cases
11Articles
4Sub-techniques
1Tactic
Sub-techniques (4)
Use cases covering this technique (14)
Excessive resource consumption of third-party API [LLM] Talos weekly prevalent malware hash execution (Coinminer/Injector/Dropper.Miner) [LLM] nebula-mesh CVE-2026-47724 — operator sabotage (disable/enable/key revocation) by non-admin actor [LLM] Smart-TV / mobile device acting as residential proxy exit node (high-fan-out HTTPS to unrelated public destinations) [LLM] Talos weekly prevalent malware SHA256 IOC sweep (Coinminer / Procpatcher / KMS activator) [LLM] Container egress to cryptominer pool / Kinsing C2 [LLM] powercfg sleep/hibernate disable burst (4-command sequence) [LLM] Talos weekly prevalent-malware hash hit (Coinminer worm / TunMirror / SECOH-QAD / KMS-Loader) [LLM] BadIIS traffic-hijacking: IIS 503 surge + anomalous external redirect ratio per site/hour [LLM] Talos weekly top-prevalent malware hash watch (Coinminer / Injector / W32.Variant) [LLM] UAT-8616 post-compromise on SD-WAN: SSH key add, NETCONF edit, su root, XMRig miner.sh [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding [LLM] IndonesianFoods auto-publish artifact (auto.js / publishScript.js) dropped in node_modules [LLM] TEA Protocol (tea.xyz) DNS resolution from developer or build endpointArticles citing this technique (11)
high A tale of two eras art-40