Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.003 Local Accounts |
GroupKimsuky | Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP. |
| T1078.003 Local Accounts |
GroupAPT32 | APT32 has used legitimate local admin account credentials. |
| T1078.003 Local Accounts |
GroupHAFNIUM | HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. |
| T1078.003 Local Accounts |
GroupFIN7 | FIN7 has used compromised credentials for access as SYSTEM on Exchange servers. |
| T1078.003 Local Accounts |
GroupTropic Trooper | Tropic Trooper has used known administrator account credentials to execute the backdoor directly. |
| T1078.003 Local Accounts |
GroupSea Turtle | Sea Turtle compromised cPanel accounts in victim environments. |
| T1078.003 Local Accounts |
GroupTurla | Turla has abused local accounts that have the same password across the victim’s network. |
| T1078.003 Local Accounts |
GroupAPT29 | APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence. |
| T1078.003 Local Accounts |
GroupVelvet Ant | Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges. |
| T1078.003 Local Accounts |
GroupPlay | Play has used valid local accounts to gain initial access. |
| T1078.003 Local Accounts |
GroupPROMETHIUM | PROMETHIUM has created admin accounts on a compromised host. |
| T1078.003 Local Accounts |
GroupFIN10 | FIN10 has moved laterally using the Local Administrator account. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.