ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1078.002×

20 examples

TechniqueUsed byProcedure example
T1078.002
Domain Accounts
GroupIndrik Spider

Indrik Spider has collected credentials from infected systems, including domain accounts.

T1078.002
Domain Accounts
GroupBlackByte

BlackByte captured credentials for or impersonated domain administration users.

T1078.002
Domain Accounts
GroupAPT3

APT3 leverages valid accounts after gaining credentials for use within the victim domain.

T1078.002
Domain Accounts
GroupVolt Typhoon

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.

T1078.002
Domain Accounts
GroupNaikon

Naikon has used administrator credentials for lateral movement in compromised networks.

T1078.002
Domain Accounts
GroupSandworm Team

Sandworm Team has used stolen credentials to access administrative accounts within the domain.

T1078.002
Domain Accounts
GroupOilRig

OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials.

T1078.002
Domain Accounts
GroupAquatic Panda

Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.

T1078.002
Domain Accounts
GroupTA505

TA505 has used stolen domain admin accounts to compromise additional hosts.

T1078.002
Domain Accounts
GroupCinnamon Tempest

Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.

T1078.002
Domain Accounts
GroupChimera

Chimera has used compromised domain accounts to gain access to the target environment.

T1078.002
Domain Accounts
GroupToddyCat

ToddyCat has used compromised domain admin credentials to mount local network shares.

T1078.002
Domain Accounts
GroupAgrius

Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement.

T1078.002
Domain Accounts
GroupAPT5

APT5 has used legitimate account credentials to move laterally through compromised environments.

T1078.002
Domain Accounts
GroupThreat Group-1314

Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally.

T1078.002
Domain Accounts
GroupWizard Spider

Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network.

T1078.002
Domain Accounts
GroupVOID MANTICORE

VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access.

T1078.002
Domain Accounts
GroupPlay

Play has used valid domain accounts for access.

T1078.002
Domain Accounts
GroupMagic Hound

Magic Hound has used domain administrator accounts after dumping LSASS process memory.

T1078.002
Domain Accounts
GroupShinyHunters

ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.