Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1498.001 ↗inferred | Network Denial of Service: Direct Network Flood | Impact | Microsoft observed KillNet healthcare DDoS as 53% UDP floods and 44% TCP floods at 250K-5M pps from ~22,000 bot sources, with large-scale source-IP spoofing and vector switching to evade mitigation |
| T1498.002 ↗inferred | Network Denial of Service: Reflection Amplification | Impact | Microsoft reported 29% of KillNet-attributed attacks were DNS amplification, alongside UDP spoof floods |
| T1499.002 ↗inferred | Endpoint Denial of Service: Service Exhaustion Flood | Impact | Microsoft observed layer-7 HTTP request floods against victim websites; Cyfirma documents affiliate Phoenix using simple HTTP GET floods at millions of requests/sec |
| T1499.001 ↗inferred | Endpoint Denial of Service: OS Exhaustion Flood | Impact | Microsoft observed TCP SYN and ACK floods and layer-7 attacks that hold many TCP connections open to deplete memory/state resources |
| T1591 ↗inferred | Gather Victim Org Information | Reconnaissance | Flashpoint assesses KillNet selects targets opportunistically off the news cycle (Eurovision/Italy May 2022, Lithuania June 2022) rather than strategically; Microsoft describes recruitment of OSINT specialists for targeting |
| T1584.005 ↗inferred | Compromise Infrastructure: Botnet | Resource Development | Cyfirma reports KillNet developed its own botnets (Tesla-Botnet, Mirai variants) and Sysdig reports KillNet acknowledged using Mirai-infected devices for its 2022 Italy/NATO attacks |
| T1588.002 ↗inferred | Obtain Capabilities: Tool | Resource Development | Cyfirma documents KillNet initially relying on open-source GitHub DDoS tools (CC-Attack, KARMA-DDoS, Aura-DDoS, mhddos_p) before developing in-house tooling |
| T1583.006 ↗inferred | Acquire Infrastructure: Web Services | Resource Development | Sysdig and Cyfirma document KillNet running Telegram channels (killnet_channel, legion_russia) to publish target lists before attacks, recruit members, and coordinate sub-groups (Legion, Zarya, Anonymous Russia, Phoenix) |
| T1583.005 ↗inferred | Acquire Infrastructure: Botnet | Resource Development | Microsoft notes KillNet recruits botnets and uses stressors; Cyfirma documents subscription DDoS-as-a-service platforms (Passion DDoS, ~27 GB/s demos) closely tied to KillNet |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Killnet's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Defensive techniques that counter Killnet's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.