T1583.001Domains
T1583.001 — Domains is a MITRE ATT&CK technique in the Resource Development tactic. Clankerusecase tracks 11 detection use cases covering it and 11 threat-intel articles citing it.
Resource Development
11Use cases
11Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1583 · Acquire Infrastructure
Use cases covering this technique (11)
Click on URL whose host doesn't match the sender domain [LLM] Endpoint callback to Sable Squirrel dropcatch C2 domains (Quasar RAT via cel-robox[.]com) [LLM] Armored Likho Still Toolkit C2 infrastructure IOC match (domains + IPs) [LLM] BTMOB C2/phishing domain contact — arbsniper.com [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirectArticles citing this technique (11)
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40