Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1136.001 Local Account |
GroupTeamTNT | TeamTNT has created local privileged users on victim machines. |
| T1136.001 Local Account |
GroupAPT39 | APT39 has created accounts on multiple compromised hosts to perform actions within the network. |
| T1136.001 Local Account |
GroupAPT5 | APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation. |
| T1136.001 Local Account |
GroupFox Kitten | Fox Kitten has created a local user account with administrator privileges. |
| T1136.001 Local Account |
GroupWizard Spider | Wizard Spider has created local administrator accounts to maintain persistence in compromised networks. |
| T1136.001 Local Account |
GroupDaggerfly | Daggerfly created a local account on victim machines to maintain access. |
| T1136.001 Local Account |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1136.001 Local Account |
GroupFIN13 | FIN13 has created MS-SQL local accounts in a compromised network. |
| T1136.001 Local Account |
MalwareHildegard | Hildegard has created a user named “monerodaemon”. |
| T1136.001 Local Account |
MalwareS-Type | S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`. |
| T1136.001 Local Account |
MalwareDarkGate | DarkGate creates a local user account, |
| T1136.001 Local Account |
MalwareCarbanak | Carbanak can create a Windows account. |
| T1136.001 Local Account |
MalwareSMOKEDHAM | SMOKEDHAM has created user accounts. |
| T1136.001 Local Account |
MalwareServHelper | ServHelper has created a new user named "supportaccount". |
| T1136.001 Local Account |
MalwareCalisto | Calisto has the capability to add its own account to the victim's machine. |
| T1136.001 Local Account |
MalwareGoldenSpy | GoldenSpy can create new users on an infected system. |
| T1136.001 Local Account |
MalwareZxShell | ZxShell has a feature to create local user accounts. |
| T1136.001 Local Account |
MalwareMis-Type | Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`. |
| T1136.001 Local Account |
MalwareHiddenWasp | HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine. |
| T1136.001 Local Account |
ToolNet | The |
| T1136.001 Local Account |
ToolEmpire | Empire has a module for creating a local user if permissions allow. |
| T1136.001 Local Account |
ToolPupy | Pupy can user PowerView to execute “net user” commands and create local system accounts. |
| T1136.001 Local Account |
MalwareFlame | Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available. |
| T1136.002 Domain Account |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team created privileged domain accounts to be used for further exploitation and lateral movement. |
| T1136.002 Domain Account |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). The accounts were then assigned to a domain matching local operation and were delegated new privileges. |
| T1136.002 Domain Account |
GroupBlackByte | BlackByte created privileged domain accounts during intrusions. |
| T1136.002 Domain Account |
GroupGALLIUM | GALLIUM created high-privileged domain user accounts to maintain access to victim networks. |
| T1136.002 Domain Account |
GroupHAFNIUM | HAFNIUM has created domain accounts. |
| T1136.002 Domain Account |
GroupMedusa Group | Medusa Group has created a domain account within the victim environment. |
| T1136.002 Domain Account |
GroupWizard Spider | Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence. |
| T1136.002 Domain Account |
ToolNet | The |
| T1136.002 Domain Account |
ToolEmpire | Empire has a module for creating a new domain user if permissions allow. |
| T1136.002 Domain Account |
ToolPupy | Pupy can user PowerView to execute “net user” commands and create domain accounts. |
| T1136.002 Domain Account |
ToolPsExec | PsExec has the ability to remotely create accounts on target systems. |
| T1136.003 Cloud Account |
GroupAPT29 | APT29 can create new users through Azure AD. |
| T1136.003 Cloud Account |
GroupLAPSUS$ | LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence. |
| T1136.003 Cloud Account |
ToolAADInternals | AADInternals can create new Azure AD users. |
| T1137 Office Application Startup |
GroupAPT32 | APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence. |
| T1137 Office Application Startup |
GroupGamaredon Group | Gamaredon Group has inserted malicious macros into existing documents, providing persistence when they are reopened. Gamaredon Group has loaded the group's previously delivered VBA project by relaunching Microsoft Outlook with the |
| T1137.001 Office Template Macros |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT. |
| T1137.001 Office Template Macros |
GroupMuddyWater | MuddyWater has used a Word Template, Normal.dotm, for persistence. |
| T1137.001 Office Template Macros |
MalwareROAMINGHOUSE | ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro. |
| T1137.001 Office Template Macros |
MalwareCobalt Strike | Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission. |
| T1137.001 Office Template Macros |
MalwareBackConfig | BackConfig has the ability to use hidden columns in Excel spreadsheets to store executable files or commands for VBA macros. |
| T1137.002 Office Test |
GroupAPT28 | APT28 has used the Office Test persistence mechanism within Microsoft Office by adding the Registry key |
| T1137.003 Outlook Forms |
ToolRuler | Ruler can be used to automate the abuse of Outlook Forms to establish persistence. |
| T1137.004 Outlook Home Page |
GroupOilRig | OilRig has abused the Outlook Home Page feature for persistence. OilRig has also used CVE-2017-11774 to roll back the initial patch designed to protect against Home Page abuse. |
| T1137.004 Outlook Home Page |
ToolRuler | Ruler can be used to automate the abuse of Outlook Home Pages to establish persistence. |
| T1137.005 Outlook Rules |
ToolRuler | Ruler can be used to automate the abuse of Outlook Rules to establish persistence. |
| T1137.006 Add-ins |
GroupNaikon | Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.