Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.004 Cloud Accounts |
GroupHAFNIUM | HAFNIUM has abused service principals in compromised environments to enable data exfiltration. |
| T1078.004 Cloud Accounts |
GroupScattered Spider | Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments. |
| T1078.004 Cloud Accounts |
GroupKe3chang | Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts. |
| T1078.004 Cloud Accounts |
GroupStorm-0501 | Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment. |
| T1078.004 Cloud Accounts |
GroupAPT29 | APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange. |
| T1078.004 Cloud Accounts |
GroupAPT28 | APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes. |
| T1078.004 Cloud Accounts |
GroupAPT5 | APT5 has accessed Microsoft M365 cloud environments using stolen credentials. |
| T1078.004 Cloud Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials to access cloud assets within a target organization. |
| T1078.004 Cloud Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment. |
| T1078.004 Cloud Accounts |
GroupAPT33 | APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints. |
| T1078.004 Cloud Accounts |
GroupTeamPCP | TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines. |
| T1078.004 Cloud Accounts |
GroupShinyHunters | ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.