Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupIndrik Spider | Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure. |
| T1078 Valid Accounts |
GroupBlackByte | BlackByte has gained access to victim environments through legitimate VPN credentials. |
| T1078 Valid Accounts |
GroupGALLIUM | GALLIUM leveraged valid accounts to maintain access to a victim network. |
| T1078 Valid Accounts |
GroupVolt Typhoon | Volt Typhoon relies primarily on valid credentials for persistence. |
| T1078 Valid Accounts |
GroupAPT41 | APT41 used compromised credentials to log on to other systems. |
| T1078 Valid Accounts |
GroupDragonfly | Dragonfly has compromised user credentials and used valid accounts for operations. |
| T1078 Valid Accounts |
GroupmenuPass | menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments. |
| T1078 Valid Accounts |
GroupFIN6 | To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes. |
| T1078 Valid Accounts |
GroupFIN7 | FIN7 has harvested valid administrative credentials for lateral movement. |
| T1078 Valid Accounts |
GroupSandworm Team | Sandworm Team have used previously acquired legitimate credentials prior to attacks. |
| T1078 Valid Accounts |
GroupAPT18 | APT18 actors leverage legitimate credentials to log into external remote services. |
| T1078 Valid Accounts |
GroupScattered Spider | Scattered Spider has used compromised credentials for initial access. |
| T1078 Valid Accounts |
GroupAPT39 | APT39 has used stolen credentials to compromise Outlook Web Access (OWA). |
| T1078 Valid Accounts |
GroupUNC3886 | UNC3886 has used tools to hijack valid SSH accounts. |
| T1078 Valid Accounts |
GroupAkira | Akira uses valid account information to remotely access victim networks, such as VPN credentials. |
| T1078 Valid Accounts |
GroupOilRig | OilRig has used compromised credentials to access other systems on a victim network. |
| T1078 Valid Accounts |
GroupCarbanak | Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars. |
| T1078 Valid Accounts |
GroupSea Turtle | Sea Turtle used compromised credentials to maintain long-term access to victim environments. |
| T1078 Valid Accounts |
GroupSuckfly | Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner. |
| T1078 Valid Accounts |
GroupPOLONIUM | POLONIUM has used valid compromised credentials to gain access to victim environments. |
| T1078 Valid Accounts |
GroupKe3chang | Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts. |
| T1078 Valid Accounts |
GroupLeviathan | Leviathan has obtained valid accounts to gain initial access. |
| T1078 Valid Accounts |
GroupFIN5 | FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment. |
| T1078 Valid Accounts |
GroupAPT29 | APT29 has used a compromised account to access an organization's VPN infrastructure. |
| T1078 Valid Accounts |
GroupCinnamon Tempest | Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services. |
| T1078 Valid Accounts |
GroupChimera | Chimera has used a valid account to maintain persistence via scheduled task. |
| T1078 Valid Accounts |
GroupSilent Librarian | Silent Librarian has used compromised credentials to obtain unauthorized access to online accounts. |
| T1078 Valid Accounts |
GroupMedusa Group | Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec. |
| T1078 Valid Accounts |
GroupStar Blizzard | Star Blizzard has used stolen credentials to sign into victim email accounts. |
| T1078 Valid Accounts |
GroupAxiom | Axiom has used previously compromised administrative accounts to escalate privileges. |
| T1078 Valid Accounts |
GroupAPT28 | APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder. |
| T1078 Valid Accounts |
GroupFox Kitten | Fox Kitten has used valid credentials with various services during lateral movement. |
| T1078 Valid Accounts |
GroupLazarus Group | Lazarus Group has used administrator credentials to gain access to restricted network segments. |
| T1078 Valid Accounts |
GroupINC Ransom | INC Ransom has used compromised valid accounts for access to victim environments. |
| T1078 Valid Accounts |
GroupFIN4 | FIN4 has used legitimate credentials to hijack email communications. |
| T1078 Valid Accounts |
GroupSilence | Silence has used compromised credentials to log on to other systems and escalate privileges. |
| T1078 Valid Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs. |
| T1078 Valid Accounts |
GroupWizard Spider | Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers. |
| T1078 Valid Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions. |
| T1078 Valid Accounts |
GroupPlay | Play has used valid VPN accounts to achieve initial access. |
| T1078 Valid Accounts |
GroupThreat Group-3390 | Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks. |
| T1078 Valid Accounts |
GroupAPT33 | APT33 has used valid accounts for initial access and privilege escalation. |
| T1078 Valid Accounts |
GroupFIN10 | FIN10 has used stolen credentials to connect remotely to victim networks using VPNs protected with only a single factor. |
| T1078 Valid Accounts |
GroupFIN8 | FIN8 has used valid accounts for persistence and lateral movement. |
| T1078 Valid Accounts |
GroupPittyTiger | PittyTiger attempts to obtain legitimate credentials during operations. |
| T1078 Valid Accounts |
GroupTeamPCP | TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to. |
| T1078 Valid Accounts |
GroupShinyHunters | ShinyHunters has used valid high-privileged SSO users as leverage during negotiations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.