ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1078.002×

10 examples

TechniqueUsed byProcedure example
T1078.002
Domain Accounts
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally.

T1078.002
Domain Accounts
CampaignCutting Edge

During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks.

T1078.002
Domain Accounts
CampaignOperation Ghost

For Operation Ghost, APT29 used stolen administrator credentials for lateral movement on compromised networks.

T1078.002
Domain Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks.

T1078.002
Domain Accounts
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used compromised domain administrator credentials as part of their lateral movement.

T1078.002
Domain Accounts
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used compromised credentials for lateral movement.

T1078.002
Domain Accounts
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets.

T1078.002
Domain Accounts
CampaignNight Dragon

During Night Dragon, threat actors used domain accounts to gain further access to victim systems.

T1078.002
Domain Accounts
CampaignOperation Wocao

During Operation Wocao, threat actors used domain credentials, including domain admin, for lateral movement and privilege escalation.

T1078.002
Domain Accounts
CampaignLeviathan Australian Intrusions

Leviathan compromised domain credentials during Leviathan Australian Intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.