Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupLeviathan | Leviathan has obtained valid accounts to gain initial access. |
| T1078 Valid Accounts |
GroupFIN5 | FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment. |
| T1078 Valid Accounts |
GroupAPT29 | APT29 has used a compromised account to access an organization's VPN infrastructure. |
| T1078 Valid Accounts |
GroupCinnamon Tempest | Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services. |
| T1078 Valid Accounts |
GroupChimera | Chimera has used a valid account to maintain persistence via scheduled task. |
| T1078 Valid Accounts |
GroupSilent Librarian | Silent Librarian has used compromised credentials to obtain unauthorized access to online accounts. |
| T1078 Valid Accounts |
GroupMedusa Group | Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec. |
| T1078 Valid Accounts |
GroupStar Blizzard | Star Blizzard has used stolen credentials to sign into victim email accounts. |
| T1078 Valid Accounts |
GroupAxiom | Axiom has used previously compromised administrative accounts to escalate privileges. |
| T1078 Valid Accounts |
GroupAPT28 | APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder. |
| T1078 Valid Accounts |
GroupFox Kitten | Fox Kitten has used valid credentials with various services during lateral movement. |
| T1078 Valid Accounts |
GroupLazarus Group | Lazarus Group has used administrator credentials to gain access to restricted network segments. |
| T1078 Valid Accounts |
GroupINC Ransom | INC Ransom has used compromised valid accounts for access to victim environments. |
| T1078 Valid Accounts |
GroupFIN4 | FIN4 has used legitimate credentials to hijack email communications. |
| T1078 Valid Accounts |
GroupSilence | Silence has used compromised credentials to log on to other systems and escalate privileges. |
| T1078 Valid Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs. |
| T1078 Valid Accounts |
GroupWizard Spider | Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers. |
| T1078 Valid Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions. |
| T1078 Valid Accounts |
GroupPlay | Play has used valid VPN accounts to achieve initial access. |
| T1078 Valid Accounts |
GroupThreat Group-3390 | Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks. |
| T1078 Valid Accounts |
GroupAPT33 | APT33 has used valid accounts for initial access and privilege escalation. |
| T1078 Valid Accounts |
GroupFIN10 | FIN10 has used stolen credentials to connect remotely to victim networks using VPNs protected with only a single factor. |
| T1078 Valid Accounts |
GroupFIN8 | FIN8 has used valid accounts for persistence and lateral movement. |
| T1078 Valid Accounts |
GroupPittyTiger | PittyTiger attempts to obtain legitimate credentials during operations. |
| T1078 Valid Accounts |
MalwareLinux Rabbit | Linux Rabbit acquires valid SSH accounts through brute force. |
| T1078 Valid Accounts |
MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1078 Valid Accounts |
MalwareLP-Notes | LP-Notes has used stolen Windows credentials to log in as the users. |
| T1078 Valid Accounts |
MalwareKinsing | Kinsing has used valid SSH credentials to access remote hosts. |
| T1078 Valid Accounts |
MalwareIndustroyer | Industroyer can use supplied user credentials to execute processes and stop services. |
| T1078 Valid Accounts |
MalwareDtrack | Dtrack used hard-coded credentials to gain access to a network share. |
| T1078 Valid Accounts |
GroupTeamPCP | TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to. |
| T1078 Valid Accounts |
GroupShinyHunters | ShinyHunters has used valid high-privileged SSO users as leverage during negotiations. |
| T1078 Valid Accounts |
MalwareDuqu | Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1078.001 Default Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket. |
| T1078.001 Default Accounts |
GroupUNC3886 | UNC3886 has harvested and used vCenter Server service accounts. |
| T1078.001 Default Accounts |
GroupEmber Bear | Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access. |
| T1078.001 Default Accounts |
GroupMagic Hound | Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP. |
| T1078.001 Default Accounts |
GroupFIN13 | FIN13 has leveraged default credentials for authenticating myWebMethods (WMS) and QLogic web management interface to gain initial access. |
| T1078.001 Default Accounts |
MalwareStuxnet | Stuxnet infected WinCC machines via a hardcoded database server password. |
| T1078.001 Default Accounts |
MalwareHyperStack | HyperStack can use default credentials to connect to IPC$ shares on remote machines. |
| T1078.002 Domain Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally. |
| T1078.002 Domain Accounts |
CampaignCutting Edge | During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks. |
| T1078.002 Domain Accounts |
CampaignOperation Ghost | For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks. |
| T1078.002 Domain Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks. |
| T1078.002 Domain Accounts |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement. |
| T1078.002 Domain Accounts |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used compromised credentials for lateral movement. |
| T1078.002 Domain Accounts |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets. |
| T1078.002 Domain Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used domain accounts to gain further access to victim systems. |
| T1078.002 Domain Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation. |
| T1078.002 Domain Accounts |
CampaignLeviathan Australian Intrusions | Leviathan compromised domain credentials during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.