FORENSIA

ATT&CK · T1608

Stage Capabilities

Tactics: resource-development

About

Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take capabilities they developed (Develop Capabilities) or obtained (Obtain Capabilities) and stage them on infrastructure under their control. These capabilities may be staged on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Capabilities may also be staged on web services, such as GitHub or Pastebin, or on Platform-as-a-Service (PaaS) offerings that enable users to easily provision applications. Staging of capabilities can aid the adversary in a number of initial access and post-compromise behaviors, including (but not limited to): * Staging web resources necessary to conduct Drive-by Compromise when a user browses to a site. * Staging web resources for a link target to be used with spearphishing. * Uploading malware or tools to a location accessible to a victim network to enable Ingress Tool Transfer. * Installing a previously acquired SSL/TLS certificate to use to encrypt command and control traffic (ex: Asymmetric Cryptography with Web Protocols).

Platforms: PREMITRE ATT&CK ↗

Used by actors

1 known groups

Software

0 malware/tools implement this

None mapped.

Corpus indicators tagged with this technique

216 indicators in the corpus carry T1608.

IndicatorTypeFamilySevSrc
cve-2022-47945cve851
1e99972b1d84b131eb55a6b49f64871c5c0c6a1bb2a099a84313001b69dc53e8sha256802
e0fc365c042e708c8d04b5431238958586194cc4a8cbe069411a26dcfcc4e9b6sha256801
18dedc0009f0927cba6425c84cce9883hashcryptojacking804
95856f2ce428c728d9781d3296558068hashcryptojacking804
59868381885b33f6c8809cd3d945da7d167439a3hashcryptojacking804
74414ed4b63aadec039b603c32762b80hashcryptojacking804
206fdbe992b44ebd6720c49c79a5da3bdcb48d0d799a0ff3458323caac3cc490sha256801
4b9a95ebf5e471d11443fa2f19b75595fc1fcf6be234024cc1d4a2255068c19bsha256801
b371fbdce6935039218d4b4272db3521881c9cec48ef82dec1e9e0188a32d3adhash801
87480b151e465b73151220533c965f3a77046138f079ca3ceb961a7d5fee9a33hash801
8c2cc585ad8a13a72a704c0fda0c9854hashcryptojacking804
c133c3dd9f7d6934598025047df41abfhashcryptojacking804
ded08ae5df7f1b12e5fdb767dbbed0b1hashcryptojacking804
fc586cad94e5a10dd5be6a6ae6096bd02dfbfd094365bec87e788ed0798d6f67hashcryptojacking804
d8824f643127c1d8f73028be01363fd77b2ecb050ebe8c17793633b9879d20ebhash801
fb43c4191c40f159167a98a4ac20bf23ae66a8ec27a919f703e953933e22a266sha256801
146c62f408b6d7db4c832a6b5f7bdacb1cff2c69121b9b2f7e80646c37910abdsha256801
c85eedd51dced48b3764c2d5bdb8febefe4210a2d9611e0fb14ffc937b80e302hash801
efc81267da3ad48cc779e9aed8f9232504ed7c85abf3958a87ba2ae68056ae23sha256801
13907caae48ea741942bce60fa32087328475bd14f5a81a6d04d82286bd28b4dhash801
119b0994bcf9c9494ce44f896b7ff4a489b62f31706be2cb6e4a9338b63cdfdbhash801
22e2d84c2a9525e8c6a825fb53f2f30621c5e6c68b1051432b1c5c625ae46f8chash801
4fe8bec780537aa223406965415c1f85e83eec1f4e2181cf82e2a7b7516026e6hashphishing801
65142c8f490839a60f4907ab8f28dd9db4258e1cfab2d48e89437ef2188a6e94hash801
6f1f3415c3e52dcdbb012f412aef7b9744786b2d4a1b850f1f4561048716c750hash801
8e5546c83d764e1287b55cbe868a45344a6f0afa9782d798d03b2b7cfc53ec38hashphishing801
bd710ee53ef3ad872f3f0678117050608a8e073c87045a06a86fb4a7f0e4eff0hash801
c9f58d96ec809a75679ec3c7a61eaaf3adbbeb6613d667257517bdc41ecca9aehash801
5620f01284329f561b1839a36be55355hashcryptojacking804

Showing the top 30 by severity of 216.