Skip to content
← LibraryTechnique entry
NET-BGP-HIJACKLateral Movement

BGP Route Hijack

Announce a more-specific or origin-spoofed prefix from a compliant AS — global traffic for that prefix routes through attacker for inspection / drop.

§ Where this technique fits

NET-BGP-HIJACK is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 2.5 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Network Sniffing
    T1040 · Credential Access
    seen 1×
  2. 02
    TLS Downgrade (POODLE / FREAK / LOGJAM)
    CR-TLS-DOWNGRADE · Credential Access
    seen 1×