{"id":"T1496.001","name":"Compute Hijacking","url":"https://attack.mitre.org/techniques/T1496/001","tactics":["impact"],"platforms":["Windows","IaaS","Linux","macOS","Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0540","stix_id":"x-mitre-detection-strategy--be288974-9b74-41c1-8c43-66aef169255a","name":"Multi-Platform Behavioral Detection for Compute Hijacking","url":"https://attack.mitre.org/detectionstrategies/DET0540","analytics":[{"id":"AN1489","stix_id":"x-mitre-analytic--92157361-c2f8-45e6-9624-38a3cdb44598","name":"Analytic 1489","description":"Sustained execution of resource-intensive processes (e.g., cryptocurrency miners), often launched via scheduled tasks, WMI, or PowerShell. These processes frequently establish persistent external connections and attempt to evade detection using masqueraded or renamed binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0540#AN1489","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4698","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"Image","description":"The executable name of the miner or wrapper—can vary across campaigns."},{"field":"DestinationIP","description":"May differ depending on the mining pool or proxy server."},{"field":"ParentProcessName","description":"Useful for filtering known-good automation vs malicious task runners."}],"live":true,"detection_strategies":["DET0540"],"techniques":["T1496.001"]},{"id":"AN1490","stix_id":"x-mitre-analytic--45a34d76-16aa-45ac-9419-ffbc5d2e090d","name":"Analytic 1490","description":"Unusual long-running processes consuming high CPU cycles (e.g., via 'top' or 'ps') initiated via cron, shell scripts, or Docker. Connections to known mining pools or DNS over HTTPS usage as evasion.","url":"https://attack.mitre.org/detectionstrategies/DET0540#AN1490","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Outbound connection to mining pool port (3333, 4444, 5555)","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"linux:cron","channel":"Scheduled execution of unknown or unusual script/binary","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"linux-cron"}],"mutable_elements":[{"field":"CommandLine","description":"The miner's execution path and options may vary by campaign."},{"field":"CPUThreshold","description":"Environment-specific definition of anomalous CPU usage."}],"live":true,"detection_strategies":["DET0540"],"techniques":["T1496.001"]},{"id":"AN1491","stix_id":"x-mitre-analytic--57595eb2-4d20-4d99-86b3-82064b3566cf","name":"Analytic 1491","description":"Persistent or background daemons (e.g., plist or launchd jobs) spawning high-CPU processes like xmrig or cpuminer. Outbound encrypted traffic to IPs/domains commonly used by mining proxies.","url":"https://attack.mitre.org/detectionstrategies/DET0540#AN1491","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"launchd or cron spawning mining binaries","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Persistent outbound connections with consistent periodicity","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"launchd.plist_label","description":"May be disguised with benign-looking names."},{"field":"DestinationDomain","description":"Varying mining pool or obfuscated destination."}],"live":true,"detection_strategies":["DET0540"],"techniques":["T1496.001"]},{"id":"AN1492","stix_id":"x-mitre-analytic--7ac026eb-9a3b-49fe-b7ec-7261cb6d6191","name":"Analytic 1492","description":"Ephemeral or unauthorized container instantiation using public images (e.g., from DockerHub) that initiate high CPU usage shortly after startup. Often scheduled via Kubernetes or Docker socket abuse.","url":"https://attack.mitre.org/detectionstrategies/DET0540#AN1492","platforms":["Containers"],"log_source_references":[{"name":"containerd:events","channel":"create","data_component":"DC0072","data_component_name":"Container Creation","log_source_slug":"containerd-events"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Outbound traffic to mining pool upon container launch","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ImageSource","description":"May vary depending on where the image is pulled from (registry or custom URL)."},{"field":"Namespace","description":"Helps differentiate attacker-created namespaces."}],"live":true,"detection_strategies":["DET0540"],"techniques":["T1496.001"]},{"id":"AN1493","stix_id":"x-mitre-analytic--7a5e5aff-8395-4b4e-9072-dd765dae7d19","name":"Analytic 1493","description":"Unauthorized instance creation in unmonitored or unused regions. Burst of compute-intensive jobs in spot instances or sudden spike in resource usage in legitimate VMs.","url":"https://attack.mitre.org/detectionstrategies/DET0540#AN1493","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"RunInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudWatch","channel":"Unusual CPU burst or metric anomalies","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"aws-cloudwatch"}],"mutable_elements":[{"field":"Region","description":"Adversaries may deploy resources in rarely used or misconfigured regions."},{"field":"TagKey","description":"Used to evade detection with benign-looking tags or names."}],"live":true,"detection_strategies":["DET0540"],"techniques":["T1496.001"]}],"live":true,"version":"1.0","techniques":["T1496.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}