ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1078.003×

12 examples

TechniqueUsed byProcedure example
T1078.003
Local Accounts
GroupKimsuky

Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.

T1078.003
Local Accounts
GroupAPT32

APT32 has used legitimate local admin account credentials.

T1078.003
Local Accounts
GroupHAFNIUM

HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers.

T1078.003
Local Accounts
GroupFIN7

FIN7 has used compromised credentials for access as SYSTEM on Exchange servers.

T1078.003
Local Accounts
GroupTropic Trooper

Tropic Trooper has used known administrator account credentials to execute the backdoor directly.

T1078.003
Local Accounts
GroupSea Turtle

Sea Turtle compromised cPanel accounts in victim environments.

T1078.003
Local Accounts
GroupTurla

Turla has abused local accounts that have the same password across the victim’s network.

T1078.003
Local Accounts
GroupAPT29

APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence.

T1078.003
Local Accounts
GroupVelvet Ant

Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges.

T1078.003
Local Accounts
GroupPlay

Play has used valid local accounts to gain initial access.

T1078.003
Local Accounts
GroupPROMETHIUM

PROMETHIUM has created admin accounts on a compromised host.

T1078.003
Local Accounts
GroupFIN10

FIN10 has moved laterally using the Local Administrator account.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.