Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.002 Domain Accounts |
GroupIndrik Spider | Indrik Spider has collected credentials from infected systems, including domain accounts. |
| T1078.002 Domain Accounts |
GroupBlackByte | BlackByte captured credentials for or impersonated domain administration users. |
| T1078.002 Domain Accounts |
GroupAPT3 | APT3 leverages valid accounts after gaining credentials for use within the victim domain. |
| T1078.002 Domain Accounts |
GroupVolt Typhoon | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks. |
| T1078.002 Domain Accounts |
GroupNaikon | Naikon has used administrator credentials for lateral movement in compromised networks. |
| T1078.002 Domain Accounts |
GroupSandworm Team | Sandworm Team has used stolen credentials to access administrative accounts within the domain. |
| T1078.002 Domain Accounts |
GroupOilRig | OilRig has used an exfiltration tool named STEALHOOK to retreive valid domain credentials. |
| T1078.002 Domain Accounts |
GroupAquatic Panda | Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments. |
| T1078.002 Domain Accounts |
GroupTA505 | TA505 has used stolen domain admin accounts to compromise additional hosts. |
| T1078.002 Domain Accounts |
GroupCinnamon Tempest | Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware. |
| T1078.002 Domain Accounts |
GroupChimera | Chimera has used compromised domain accounts to gain access to the target environment. |
| T1078.002 Domain Accounts |
GroupToddyCat | ToddyCat has used compromised domain admin credentials to mount local network shares. |
| T1078.002 Domain Accounts |
GroupAgrius | Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement. |
| T1078.002 Domain Accounts |
GroupAPT5 | APT5 has used legitimate account credentials to move laterally through compromised environments. |
| T1078.002 Domain Accounts |
GroupThreat Group-1314 | Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally. |
| T1078.002 Domain Accounts |
GroupWizard Spider | Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network. |
| T1078.002 Domain Accounts |
GroupVOID MANTICORE | VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access. |
| T1078.002 Domain Accounts |
GroupPlay | Play has used valid domain accounts for access. |
| T1078.002 Domain Accounts |
GroupMagic Hound | Magic Hound has used domain administrator accounts after dumping LSASS process memory. |
| T1078.002 Domain Accounts |
GroupShinyHunters | ShinyHunters has used valid domain accounts to gain initial access or to escalate privileges within environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.