Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.001 Default Accounts |
GroupUNC3886 | UNC3886 has harvested and used vCenter Server service accounts. |
| T1078.001 Default Accounts |
GroupEmber Bear | Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access. |
| T1078.001 Default Accounts |
GroupMagic Hound | Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP. |
| T1078.001 Default Accounts |
GroupFIN13 | FIN13 has leveraged default credentials for authenticating myWebMethods (WMS) and QLogic web management interface to gain initial access. |
| T1078.002 Domain Accounts |
GroupIndrik Spider | Indrik Spider has collected credentials from infected systems, including domain accounts. |
| T1078.002 Domain Accounts |
GroupBlackByte | BlackByte captured credentials for or impersonated domain administration users. |
| T1078.002 Domain Accounts |
GroupAPT3 | APT3 leverages valid accounts after gaining credentials for use within the victim domain. |
| T1078.002 Domain Accounts |
GroupVolt Typhoon | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks. |
| T1078.002 Domain Accounts |
GroupNaikon | Naikon has used administrator credentials for lateral movement in compromised networks. |
| T1078.002 Domain Accounts |
GroupSandworm Team | Sandworm Team has used stolen credentials to access administrative accounts within the domain. |
| T1078.002 Domain Accounts |
GroupOilRig | OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials. |
| T1078.002 Domain Accounts |
GroupAquatic Panda | Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments. |
| T1078.002 Domain Accounts |
GroupTA505 | TA505 has used stolen domain admin accounts to compromise additional hosts. |
| T1078.002 Domain Accounts |
GroupCinnamon Tempest | Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware. |
| T1078.002 Domain Accounts |
GroupChimera | Chimera has used compromised domain accounts to gain access to the target environment. |
| T1078.002 Domain Accounts |
GroupToddyCat | ToddyCat has used compromised domain admin credentials to mount local network shares. |
| T1078.002 Domain Accounts |
GroupAgrius | Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement. |
| T1078.002 Domain Accounts |
GroupAPT5 | APT5 has used legitimate account credentials to move laterally through compromised environments. |
| T1078.002 Domain Accounts |
GroupThreat Group-1314 | Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally. |
| T1078.002 Domain Accounts |
GroupWizard Spider | Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network. |
| T1078.002 Domain Accounts |
GroupVOID MANTICORE | VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access. |
| T1078.002 Domain Accounts |
GroupPlay | Play has used valid domain accounts for access. |
| T1078.002 Domain Accounts |
GroupMagic Hound | Magic Hound has used domain administrator accounts after dumping LSASS process memory. |
| T1078.002 Domain Accounts |
GroupShinyHunters | ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments. |
| T1078.003 Local Accounts |
GroupKimsuky | Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP. |
| T1078.003 Local Accounts |
GroupAPT32 | APT32 has used legitimate local admin account credentials. |
| T1078.003 Local Accounts |
GroupHAFNIUM | HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. |
| T1078.003 Local Accounts |
GroupFIN7 | FIN7 has used compromised credentials for access as SYSTEM on Exchange servers. |
| T1078.003 Local Accounts |
GroupTropic Trooper | Tropic Trooper has used known administrator account credentials to execute the backdoor directly. |
| T1078.003 Local Accounts |
GroupSea Turtle | Sea Turtle compromised cPanel accounts in victim environments. |
| T1078.003 Local Accounts |
GroupTurla | Turla has abused local accounts that have the same password across the victim’s network. |
| T1078.003 Local Accounts |
GroupAPT29 | APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence. |
| T1078.003 Local Accounts |
GroupVelvet Ant | Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges. |
| T1078.003 Local Accounts |
GroupPlay | Play has used valid local accounts to gain initial access. |
| T1078.003 Local Accounts |
GroupPROMETHIUM | PROMETHIUM has created admin accounts on a compromised host. |
| T1078.003 Local Accounts |
GroupFIN10 | FIN10 has moved laterally using the Local Administrator account. |
| T1078.004 Cloud Accounts |
GroupHAFNIUM | HAFNIUM has abused service principals in compromised environments to enable data exfiltration. |
| T1078.004 Cloud Accounts |
GroupScattered Spider | Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments. |
| T1078.004 Cloud Accounts |
GroupKe3chang | Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts. |
| T1078.004 Cloud Accounts |
GroupStorm-0501 | Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment. |
| T1078.004 Cloud Accounts |
GroupAPT29 | APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange. |
| T1078.004 Cloud Accounts |
GroupAPT28 | APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes. |
| T1078.004 Cloud Accounts |
GroupAPT5 | APT5 has accessed Microsoft M365 cloud environments using stolen credentials. |
| T1078.004 Cloud Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials to access cloud assets within a target organization. |
| T1078.004 Cloud Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment. |
| T1078.004 Cloud Accounts |
GroupAPT33 | APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints. |
| T1078.004 Cloud Accounts |
GroupTeamPCP | TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines. |
| T1078.004 Cloud Accounts |
GroupShinyHunters | ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
| T1080 Taint Shared Content |
GroupGamaredon Group | Gamaredon Group has injected malicious macros into all Word and Excel documents on mapped network drives. |
| T1080 Taint Shared Content |
GroupRedCurl | RedCurl has placed modified LNK files on network drives for lateral movement. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.