Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.002 Domain Accounts |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally. |
| T1078.002 Domain Accounts |
CampaignCutting Edge | During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks. |
| T1078.002 Domain Accounts |
CampaignOperation Ghost | For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks. |
| T1078.002 Domain Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks. |
| T1078.002 Domain Accounts |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement. |
| T1078.002 Domain Accounts |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used compromised credentials for lateral movement. |
| T1078.002 Domain Accounts |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets. |
| T1078.002 Domain Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used domain accounts to gain further access to victim systems. |
| T1078.002 Domain Accounts |
CampaignOperation Wocao | During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation. |
| T1078.002 Domain Accounts |
CampaignLeviathan Australian Intrusions | Leviathan compromised domain credentials during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.