ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1078.001
Default Accounts
GroupUNC3886

UNC3886 has harvested and used vCenter Server service accounts.

T1078.001
Default Accounts
GroupEmber Bear

Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access.

T1078.001
Default Accounts
GroupMagic Hound

Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP.

T1078.001
Default Accounts
GroupFIN13

FIN13 has leveraged default credentials for authenticating myWebMethods (WMS) and QLogic web management interface to gain initial access.

T1078.002
Domain Accounts
GroupIndrik Spider

Indrik Spider has collected credentials from infected systems, including domain accounts.

T1078.002
Domain Accounts
GroupBlackByte

BlackByte captured credentials for or impersonated domain administration users.

T1078.002
Domain Accounts
GroupAPT3

APT3 leverages valid accounts after gaining credentials for use within the victim domain.

T1078.002
Domain Accounts
GroupVolt Typhoon

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.

T1078.002
Domain Accounts
GroupNaikon

Naikon has used administrator credentials for lateral movement in compromised networks.

T1078.002
Domain Accounts
GroupSandworm Team

Sandworm Team has used stolen credentials to access administrative accounts within the domain.

T1078.002
Domain Accounts
GroupOilRig

OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials.

T1078.002
Domain Accounts
GroupAquatic Panda

Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.

T1078.002
Domain Accounts
GroupTA505

TA505 has used stolen domain admin accounts to compromise additional hosts.

T1078.002
Domain Accounts
GroupCinnamon Tempest

Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.

T1078.002
Domain Accounts
GroupChimera

Chimera has used compromised domain accounts to gain access to the target environment.

T1078.002
Domain Accounts
GroupToddyCat

ToddyCat has used compromised domain admin credentials to mount local network shares.

T1078.002
Domain Accounts
GroupAgrius

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.

T1078.002
Domain Accounts
GroupAPT5

APT5 has used legitimate account credentials to move laterally through compromised environments.

T1078.002
Domain Accounts
GroupThreat Group-1314

Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally.

T1078.002
Domain Accounts
GroupWizard Spider

Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network.

T1078.002
Domain Accounts
GroupVOID MANTICORE

VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access.

T1078.002
Domain Accounts
GroupPlay

Play has used valid domain accounts for access.

T1078.002
Domain Accounts
GroupMagic Hound

Magic Hound has used domain administrator accounts after dumping LSASS process memory.

T1078.002
Domain Accounts
GroupShinyHunters

ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.

T1078.003
Local Accounts
GroupKimsuky

Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.

T1078.003
Local Accounts
GroupAPT32

APT32 has used legitimate local admin account credentials.

T1078.003
Local Accounts
GroupHAFNIUM

HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers.

T1078.003
Local Accounts
GroupFIN7

FIN7 has used compromised credentials for access as SYSTEM on Exchange servers.

T1078.003
Local Accounts
GroupTropic Trooper

Tropic Trooper has used known administrator account credentials to execute the backdoor directly.

T1078.003
Local Accounts
GroupSea Turtle

Sea Turtle compromised cPanel accounts in victim environments.

T1078.003
Local Accounts
GroupTurla

Turla has abused local accounts that have the same password across the victim’s network.

T1078.003
Local Accounts
GroupAPT29

APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence.

T1078.003
Local Accounts
GroupVelvet Ant

Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges.

T1078.003
Local Accounts
GroupPlay

Play has used valid local accounts to gain initial access.

T1078.003
Local Accounts
GroupPROMETHIUM

PROMETHIUM has created admin accounts on a compromised host.

T1078.003
Local Accounts
GroupFIN10

FIN10 has moved laterally using the Local Administrator account.

T1078.004
Cloud Accounts
GroupHAFNIUM

HAFNIUM has abused service principals in compromised environments to enable data exfiltration.

T1078.004
Cloud Accounts
GroupScattered Spider

Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments.

T1078.004
Cloud Accounts
GroupKe3chang

Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts.

T1078.004
Cloud Accounts
GroupStorm-0501

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment.

T1078.004
Cloud Accounts
GroupAPT29

APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange.

T1078.004
Cloud Accounts
GroupAPT28

APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes.

T1078.004
Cloud Accounts
GroupAPT5

APT5 has accessed Microsoft M365 cloud environments using stolen credentials.

T1078.004
Cloud Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials to access cloud assets within a target organization.

T1078.004
Cloud Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment.

T1078.004
Cloud Accounts
GroupAPT33

APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.

T1078.004
Cloud Accounts
GroupTeamPCP

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.

T1078.004
Cloud Accounts
GroupShinyHunters

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

T1080
Taint Shared Content
GroupGamaredon Group

Gamaredon Group has injected malicious macros into all Word and Excel documents on mapped network drives.

T1080
Taint Shared Content
GroupRedCurl

RedCurl has placed modified LNK files on network drives for lateral movement.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.