ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1078×

11 examples

TechniqueUsed byProcedure example
T1078
Valid Accounts
CampaignRedPenguin

During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers.

T1078
Valid Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks.

T1078
Valid Accounts
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network.

T1078
Valid Accounts
Campaign3CX Supply Chain Attack

During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials.

T1078
Valid Accounts
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks.

T1078
Valid Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts.

T1078
Valid Accounts
CampaignC0032

During the C0032 campaign, TEMP.Veles used compromised VPN accounts.

T1078
Valid Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally.

T1078
Valid Accounts
CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1078
Valid Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used valid VPN credentials to gain initial access.

T1078
Valid Accounts
CampaignLeviathan Australian Intrusions

Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.