Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Impact/ T1496

T1496Resource Hijacking

T1496 — Resource Hijacking is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 9 detection use cases covering it and 6 threat-intel articles citing it.

Impact
View on the matrix → Filter Detection Library MITRE official spec ↗
9Use cases
6Articles
4Sub-techniques
1Tactic

Sub-techniques (4)

Use cases covering this technique (9)

Excessive resource consumption of third-party API Internal actions · hunting DD [LLM] LightRAG destructive document ops post-bypass (DELETE /documents, clear_cache, unauth upload) Bespoke actions · alerting SΣP [LLM] XMRig Monero mining to pool.supportxmr.com / 136.243.203.109 Bespoke actions · alerting DSΣPDDCS [LLM] Dormant crypto-miner on servers: sustained stratum egress to mining pools Bespoke actions · hunting DSPDDCS [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDD [LLM] Ultralytics PyPI supply-chain XMRig coinminer execution from /tmp/ultralytics_runner Bespoke actions · alerting DSΣPDDCS [LLM] Ultralytics coinminer C2 — Stratum to connect.consrensys.com:8080 mining pool Bespoke c2 · alerting DSΣPCS [LLM] IndonesianFoods auto-publish artifact (auto.js / publishScript.js) dropped in node_modules Bespoke install · alerting DSΣPDDCS [LLM] TEA Protocol (tea.xyz) DNS resolution from developer or build endpoint Bespoke c2 · hunting DSΣPDDCS

Articles citing this technique (6)