MITRE ATT&CK Technique
T1496Resource Hijacking
- First Reported
- Jul 24, 2025
- Latest Reported
- Sep 30, 2026
Official Description
Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
Resource hijacking may take a number of different forms. For example, adversaries may:
* Leverage compute resources in order to mine cryptocurrency
* Sell network bandwidth to proxy networks
* Generate SMS traffic for profit
* Abuse cloud-based messaging services to send large quantities of spam messages
In some cases, adversaries may leverage multiple types of Resource Hijacking at once.(Citation: Sysdig Cryptojacking Proxyjacking 2023)
Resource hijacking may take a number of different forms. For example, adversaries may:
* Leverage compute resources in order to mine cryptocurrency
* Sell network bandwidth to proxy networks
* Generate SMS traffic for profit
* Abuse cloud-based messaging services to send large quantities of spam messages
In some cases, adversaries may leverage multiple types of Resource Hijacking at once.(Citation: Sysdig Cryptojacking Proxyjacking 2023)
- Tactics
- Impact
- Platforms
- Windows, IaaS, Linux, macOS, Containers, SaaS
- MITRE Version
- 2.0
- Last Modified
- Oct 24, 2025
Sub-techniques (4)
Reported Context (4)
- XMRig was deployed and executed to mine cryptocurrency using the affected system. KMS Auto Abuse Led to Mining, Remote Access Tools and Ransomware-Themed Scareware; APT36 Link Unconfirmed
- The attacker ran XMRig to mine Monero using the affected workload's resources. Aqua Details Fileless Cryptomining Campaign Targeting Containerized Apps
- The article reports cryptominer deployment among observed post-exploitation activity. React Server Components Flaw CVE-2025-55182 Actively Exploited
- Koske deploys cryptominers and switches between coins or mining pools when one fails. Koske Linux Malware Hides in Panda Images and Shows Signs of AI-Assisted Development
CVE (1)
Malware (2)
Threat Actors (5)
MITRE ATT&CK (21)
Vendors (1)
Products (10)
Tools (4)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.