Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
MalwareSLOWPULSE | SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`. |
| T1074.001 Local Data Staging |
MalwareADVSTORESHELL | ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory. |
| T1074.001 Local Data Staging |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data. |
| T1074.001 Local Data Staging |
MalwareDuqu | Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
| T1074.002 Remote Data Staging |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server. |
| T1074.002 Remote Data Staging |
CampaignNight Dragon | During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them. |
| T1074.002 Remote Data Staging |
GroupmenuPass | menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupFIN6 | FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration. |
| T1074.002 Remote Data Staging |
GroupSea Turtle | Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet. |
| T1074.002 Remote Data Staging |
GroupLeviathan | Leviathan has staged data remotely prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share. |
| T1074.002 Remote Data Staging |
GroupChimera | Chimera has staged stolen data on designated servers in the target environment. |
| T1074.002 Remote Data Staging |
GroupMirrorFace | MirrorFace has gathered data and files of interest on a single victim machine. |
| T1074.002 Remote Data Staging |
GroupToddyCat | ToddyCat manually transferred collected files to an exfiltration host using xcopy. |
| T1074.002 Remote Data Staging |
GroupAPT28 | APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server. |
| T1074.002 Remote Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration. |
| T1074.002 Remote Data Staging |
GroupFIN8 | FIN8 aggregates staged data from a network into a single location. |
| T1074.002 Remote Data Staging |
Malwareccf32 | ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor. |
| T1078 Valid Accounts |
CampaignRedPenguin | During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers. |
| T1078 Valid Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks. |
| T1078 Valid Accounts |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network. |
| T1078 Valid Accounts |
Campaign3CX Supply Chain Attack | During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials. |
| T1078 Valid Accounts |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks. |
| T1078 Valid Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts. |
| T1078 Valid Accounts |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used compromised VPN accounts. |
| T1078 Valid Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally. |
| T1078 Valid Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1078 Valid Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used valid VPN credentials to gain initial access. |
| T1078 Valid Accounts |
CampaignLeviathan Australian Intrusions | Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions. |
| T1078 Valid Accounts |
GroupIndrik Spider | Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure. |
| T1078 Valid Accounts |
GroupBlackByte | BlackByte has gained access to victim environments through legitimate VPN credentials. |
| T1078 Valid Accounts |
GroupGALLIUM | GALLIUM leveraged valid accounts to maintain access to a victim network. |
| T1078 Valid Accounts |
GroupVolt Typhoon | Volt Typhoon relies primarily on valid credentials for persistence. |
| T1078 Valid Accounts |
GroupAPT41 | APT41 used compromised credentials to log on to other systems. |
| T1078 Valid Accounts |
GroupDragonfly | Dragonfly has compromised user credentials and used valid accounts for operations. |
| T1078 Valid Accounts |
GroupmenuPass | menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments. |
| T1078 Valid Accounts |
GroupFIN6 | To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes. |
| T1078 Valid Accounts |
GroupFIN7 | FIN7 has harvested valid administrative credentials for lateral movement. |
| T1078 Valid Accounts |
GroupSandworm Team | Sandworm Team have used previously acquired legitimate credentials prior to attacks. |
| T1078 Valid Accounts |
GroupAPT18 | APT18 actors leverage legitimate credentials to log into external remote services. |
| T1078 Valid Accounts |
GroupScattered Spider | Scattered Spider has used compromised credentials for initial access. |
| T1078 Valid Accounts |
GroupAPT39 | APT39 has used stolen credentials to compromise Outlook Web Access (OWA). |
| T1078 Valid Accounts |
GroupUNC3886 | UNC3886 has used tools to hijack valid SSH accounts. |
| T1078 Valid Accounts |
GroupAkira | Akira uses valid account information to remotely access victim networks, such as VPN credentials. |
| T1078 Valid Accounts |
GroupOilRig | OilRig has used compromised credentials to access other systems on a victim network. |
| T1078 Valid Accounts |
GroupCarbanak | Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars. |
| T1078 Valid Accounts |
GroupSea Turtle | Sea Turtle used compromised credentials to maintain long-term access to victim environments. |
| T1078 Valid Accounts |
GroupSuckfly | Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner. |
| T1078 Valid Accounts |
GroupPOLONIUM | POLONIUM has used valid compromised credentials to gain access to victim environments. |
| T1078 Valid Accounts |
GroupKe3chang | Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.