Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.002 Domain Accounts |
GroupIndrik Spider | Indrik Spider has collected credentials from infected systems, including domain accounts. |
| T1078.002 Domain Accounts |
GroupBlackByte | BlackByte captured credentials for or impersonated domain administration users. |
| T1078.002 Domain Accounts |
GroupAPT3 | APT3 leverages valid accounts after gaining credentials for use within the victim domain. |
| T1078.002 Domain Accounts |
GroupVolt Typhoon | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks. |
| T1078.002 Domain Accounts |
GroupNaikon | Naikon has used administrator credentials for lateral movement in compromised networks. |
| T1078.002 Domain Accounts |
GroupSandworm Team | Sandworm Team has used stolen credentials to access administrative accounts within the domain. |
| T1078.002 Domain Accounts |
GroupOilRig | OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials. |
| T1078.002 Domain Accounts |
GroupAquatic Panda | Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments. |
| T1078.002 Domain Accounts |
GroupTA505 | TA505 has used stolen domain admin accounts to compromise additional hosts. |
| T1078.002 Domain Accounts |
GroupCinnamon Tempest | Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware. |
| T1078.002 Domain Accounts |
GroupChimera | Chimera has used compromised domain accounts to gain access to the target environment. |
| T1078.002 Domain Accounts |
GroupToddyCat | ToddyCat has used compromised domain admin credentials to mount local network shares. |
| T1078.002 Domain Accounts |
GroupAgrius | Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement. |
| T1078.002 Domain Accounts |
GroupAPT5 | APT5 has used legitimate account credentials to move laterally through compromised environments. |
| T1078.002 Domain Accounts |
GroupThreat Group-1314 | Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally. |
| T1078.002 Domain Accounts |
GroupWizard Spider | Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network. |
| T1078.002 Domain Accounts |
GroupVOID MANTICORE | VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access. |
| T1078.002 Domain Accounts |
GroupPlay | Play has used valid domain accounts for access. |
| T1078.002 Domain Accounts |
GroupMagic Hound | Magic Hound has used domain administrator accounts after dumping LSASS process memory. |
| T1078.002 Domain Accounts |
MalwareStuxnet | Stuxnet attempts to access network resources with a domain account’s credentials. |
| T1078.002 Domain Accounts |
MalwareShamoon | If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion. |
| T1078.002 Domain Accounts |
MalwareRyuk | Ryuk can use stolen domain admin accounts to move laterally within a victim domain. |
| T1078.002 Domain Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account. |
| T1078.002 Domain Accounts |
MalwareCreepySnail | CreepySnail can use stolen credentials to authenticate on target networks. |
| T1078.002 Domain Accounts |
GroupShinyHunters | ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments. |
| T1078.003 Local Accounts |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to test credentials harvested against discovered devices. |
| T1078.003 Local Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks. |
| T1078.003 Local Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation. |
| T1078.003 Local Accounts |
CampaignLeviathan Australian Intrusions | Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions. |
| T1078.003 Local Accounts |
GroupKimsuky | Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP. |
| T1078.003 Local Accounts |
GroupAPT32 | APT32 has used legitimate local admin account credentials. |
| T1078.003 Local Accounts |
GroupHAFNIUM | HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. |
| T1078.003 Local Accounts |
GroupFIN7 | FIN7 has used compromised credentials for access as SYSTEM on Exchange servers. |
| T1078.003 Local Accounts |
GroupTropic Trooper | Tropic Trooper has used known administrator account credentials to execute the backdoor directly. |
| T1078.003 Local Accounts |
GroupSea Turtle | Sea Turtle compromised cPanel accounts in victim environments. |
| T1078.003 Local Accounts |
GroupTurla | Turla has abused local accounts that have the same password across the victim’s network. |
| T1078.003 Local Accounts |
GroupAPT29 | APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence. |
| T1078.003 Local Accounts |
GroupVelvet Ant | Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges. |
| T1078.003 Local Accounts |
GroupPlay | Play has used valid local accounts to gain initial access. |
| T1078.003 Local Accounts |
GroupPROMETHIUM | PROMETHIUM has created admin accounts on a compromised host. |
| T1078.003 Local Accounts |
GroupFIN10 | FIN10 has moved laterally using the Local Administrator account. |
| T1078.003 Local Accounts |
MalwareEmotet | Emotet can brute force a local admin password, then use it to facilitate lateral movement. |
| T1078.003 Local Accounts |
MalwareUmbreon | Umbreon creates valid local users to provide access to the system. |
| T1078.003 Local Accounts |
MalwareNotPetya | NotPetya can use valid credentials with PsExec or |
| T1078.003 Local Accounts |
MalwareLockBit 3.0 | LockBit 3.0 can use a compromised local account for lateral movement. |
| T1078.003 Local Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a local user account. |
| T1078.004 Cloud Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal. |
| T1078.004 Cloud Accounts |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services. |
| T1078.004 Cloud Accounts |
CampaignC0027 | During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants. |
| T1078.004 Cloud Accounts |
GroupHAFNIUM | HAFNIUM has abused service principals in compromised environments to enable data exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.