T1583.003: T1583.003
Essential information
- MITRE technique ID
T1583.003- Confidence
- 100/100
- Revoked
- No
- Published
- 01/10/2020 02:44
- Modified
- 13/04/2026 17:48
- Author / Source
- The MITRE Corporation
Aliases
Virtual Private Server
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (46)
-
The MITRE Corporation Confidence 100
[Moonstone Sleet](https://attack.mitre.org/groups/G1036) is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, [Lazarus Group](https://attack.mitre.org/groups/G0032),…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Intellexa alliance usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TAG-124 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DPRK usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Squeamish Libra usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RedGolf usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Contagious Interview](https://attack.mitre.org/groups/G1052) is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials.…
First seen 01/01/1970 · Last seen 16/11/5138 · -
SolarMarker usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Red Menshen usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TGR-STA-1030 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT-C-36](https://attack.mitre.org/groups/G0099) is a suspected South America espionage group that has been active since at least 2018. The group mainly targets Colombian government institutions as well as important corporations…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (60)
-
KEYPLUG uses
-
SocGholish usesFamily
-
Shahmaran usesFamily
-
Pinar usesFamily
-
Korplug usesThe MITRE Corporation Confidence 100
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 · -
TSPY_TRICKLOAD usesFamily
-
WhisperGate - S0689 usesFamily
-
InvisibleFerret usesFamily
-
QakBot - S0650 usesFamily
-
Pantegana usesFamily
-
SolarMarker usesFamily
-
Pikabot usesFamily
Reports (29)
-
AlienVault Confidence 100 18 MITREs 17 Malwares 12 IOCs 12 Observables 1 APT
-
2 CVEs 11 MITREs 1 Malware 7 Observables 1 APT
-
1 CVE 12 MITREs 2 Malwares 2 Observables 1 APT
-
Threat landscape — Belgium relatedConfidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 Tools
-
10 MITREs
-
AlienVault Confidence 100 15 MITREs 9 IOCs 9 Observables
-
AlienVault Confidence 100 16 MITREs 3 IOCs 3 Observables 1 APT
-
20 MITREs 2 Malwares 12 Observables 1 APT
-
AlienVault Confidence 100 2 CVEs 8 MITREs 1 Malware 23 IOCs 23 Observables
-
1 CVE 20 MITREs 6 Malwares 20 Observables 1 APT
-
Global Corporate Web related5 MITREs 1 Malware 1 Observable 1 APT
-
18 MITREs 2 Malwares 38 Observables 1 APT
Vulnerabilities (CVE) (23)
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 04/03/2024
- Modified
- 22/04/2026
Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in …
- Published
- 03/11/2021
- Modified
- 21/12/2025
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
- Attack vector
- Network
- Complexity
- LOW
- Published
- 10/10/2023
- Modified
- 15/05/2026
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a …
- Attack vector
- Network
- Published
- 12/11/2024
- Modified
- 27/05/2026
The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.
- Published
- 27/06/2022
- Modified
- 20/12/2025
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries …
- Attack vector
- Network
- Published
- 29/04/2025
- Modified
- 21/12/2025
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
- Attack vector
- Network
- Published
- 07/03/2024
- Modified
- 21/12/2025
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
- Attack vector
- Network
- Published
- 10/12/2021
- Modified
- 27/05/2026
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. …
- Attack vector
- NETWORK
- Published
- 12/10/2024
- Modified
- 21/12/2025
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse …
- Published
- 03/11/2021
- Modified
- 20/12/2025
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
- Published
- 28/01/2022
- Modified
- 20/12/2025
Campaign (4)
-
KV Botnet Activity uses
-
SPACEHOP Activity uses
-
ArcaneDoor uses
-
J-magic Campaign uses
Course Of Action (1)
-
Pre-compromise mitigates