Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
CampaignRedPenguin | During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers. |
| T1078 Valid Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks. |
| T1078 Valid Accounts |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network. |
| T1078 Valid Accounts |
Campaign3CX Supply Chain Attack | During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials. |
| T1078 Valid Accounts |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks. |
| T1078 Valid Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts. |
| T1078 Valid Accounts |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used compromised VPN accounts. |
| T1078 Valid Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally. |
| T1078 Valid Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1078 Valid Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used valid VPN credentials to gain initial access. |
| T1078 Valid Accounts |
CampaignLeviathan Australian Intrusions | Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.