ATT&CK-CN V1.01 Last Update: 2019-11

译者: 林妙倩、戴亦仑 原创翻译作品,如果需要转载请取得翻译作者同意。

数据来源:ATT&CK Matrices


术语表: /attack/glossary




Adversaries may leverage the resources of co-opted systems in order to solve resource intensive problems which may impact system and/or hosted service availability.

One common purpose for Resource Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency. Adversaries may consume enough system resources to negatively impact and/or cause affected machines to become unresponsive. Servers and cloud-based systems are common targets because of the high potential for available resources, but user endpoint systems may also be compromised and used for Resource Hijacking and cryptocurrency mining.


ID编号: T1496

策略: 影响

平台: Linux,macOS,Windows,AWS,GCP,Azure

所需权限: 用户,管理员

数据源: Azure活动日志,Stackdriver日志,AWS CloudTrail日志,网络的流程使用,流程监控,网络协议分析,网络设备日志

影响类型: 可用性


Name Description
APT41 APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.
Lazarus Group Lazarus Grouphas subset groups like Bluenoroff who have used cryptocurrency mining software on victim machines.



This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.



Consider monitoring process resource usage to determine anomalous activity associated with malicious hijacking of computer resources such as CPU, memory, and graphics processing resources. Monitor for suspicious use of network resources associated with cryptocurrency mining software. Monitor for common cryptomining software process names and files on local systems that may indicate compromise and resource usage.