ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupLeviathan

Leviathan has obtained valid accounts to gain initial access.

T1078
Valid Accounts
GroupFIN5

FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment.

T1078
Valid Accounts
GroupAPT29

APT29 has used a compromised account to access an organization's VPN infrastructure.

T1078
Valid Accounts
GroupCinnamon Tempest

Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services.

T1078
Valid Accounts
GroupChimera

Chimera has used a valid account to maintain persistence via scheduled task.

T1078
Valid Accounts
GroupSilent Librarian

Silent Librarian has used compromised credentials to obtain unauthorized access to online accounts.

T1078
Valid Accounts
GroupMedusa Group

Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.

T1078
Valid Accounts
GroupStar Blizzard

Star Blizzard has used stolen credentials to sign into victim email accounts.

T1078
Valid Accounts
GroupAxiom

Axiom has used previously compromised administrative accounts to escalate privileges.

T1078
Valid Accounts
GroupAPT28

APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder.

T1078
Valid Accounts
GroupFox Kitten

Fox Kitten has used valid credentials with various services during lateral movement.

T1078
Valid Accounts
GroupLazarus Group

Lazarus Group has used administrator credentials to gain access to restricted network segments.

T1078
Valid Accounts
GroupINC Ransom

INC Ransom has used compromised valid accounts for access to victim environments.

T1078
Valid Accounts
GroupFIN4

FIN4 has used legitimate credentials to hijack email communications.

T1078
Valid Accounts
GroupSilence

Silence has used compromised credentials to log on to other systems and escalate privileges.

T1078
Valid Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.

T1078
Valid Accounts
GroupWizard Spider

Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers.

T1078
Valid Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions.

T1078
Valid Accounts
GroupPlay

Play has used valid VPN accounts to achieve initial access.

T1078
Valid Accounts
GroupThreat Group-3390

Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks.

T1078
Valid Accounts
GroupAPT33

APT33 has used valid accounts for initial access and privilege escalation.

T1078
Valid Accounts
GroupFIN10

FIN10 has used stolen credentials to connect remotely to victim networks using VPNs protected with only a single factor.

T1078
Valid Accounts
GroupFIN8

FIN8 has used valid accounts for persistence and lateral movement.

T1078
Valid Accounts
GroupPittyTiger

PittyTiger attempts to obtain legitimate credentials during operations.

T1078
Valid Accounts
MalwareLinux Rabbit

Linux Rabbit acquires valid SSH accounts through brute force.

T1078
Valid Accounts
MalwareSeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

T1078
Valid Accounts
MalwareLP-Notes

LP-Notes has used stolen Windows credentials to log in as the users.

T1078
Valid Accounts
MalwareKinsing

Kinsing has used valid SSH credentials to access remote hosts.

T1078
Valid Accounts
MalwareIndustroyer

Industroyer can use supplied user credentials to execute processes and stop services.

T1078
Valid Accounts
MalwareDtrack

Dtrack used hard-coded credentials to gain access to a network share.

T1078
Valid Accounts
GroupTeamPCP

TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.

T1078
Valid Accounts
GroupShinyHunters

ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.

T1078
Valid Accounts
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1078.001
Default Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket.

T1078.001
Default Accounts
GroupUNC3886

UNC3886 has harvested and used vCenter Server service accounts.

T1078.001
Default Accounts
GroupEmber Bear

Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access.

T1078.001
Default Accounts
GroupMagic Hound

Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP.

T1078.001
Default Accounts
GroupFIN13

FIN13 has leveraged default credentials for authenticating myWebMethods (WMS) and QLogic web management interface to gain initial access.

T1078.001
Default Accounts
MalwareStuxnet

Stuxnet infected WinCC machines via a hardcoded database server password.

T1078.001
Default Accounts
MalwareHyperStack

HyperStack can use default credentials to connect to IPC$ shares on remote machines.

T1078.002
Domain Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally.

T1078.002
Domain Accounts
CampaignCutting Edge

During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks.

T1078.002
Domain Accounts
CampaignOperation Ghost

For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks.

T1078.002
Domain Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks.

T1078.002
Domain Accounts
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement.

T1078.002
Domain Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used compromised credentials for lateral movement.

T1078.002
Domain Accounts
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets.

T1078.002
Domain Accounts
CampaignNight Dragon

During Night Dragon, threat actors used domain accounts to gain further access to victim systems.

T1078.002
Domain Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation.

T1078.002
Domain Accounts
CampaignLeviathan Australian Intrusions

Leviathan compromised domain credentials during Leviathan Australian Intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.