ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1078.004×

12 examples

TechniqueUsed byProcedure example
T1078.004
Cloud Accounts
GroupHAFNIUM

HAFNIUM has abused service principals in compromised environments to enable data exfiltration.

T1078.004
Cloud Accounts
GroupScattered Spider

Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments.

T1078.004
Cloud Accounts
GroupKe3chang

Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts.

T1078.004
Cloud Accounts
GroupStorm-0501

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment.

T1078.004
Cloud Accounts
GroupAPT29

APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange.

T1078.004
Cloud Accounts
GroupAPT28

APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes.

T1078.004
Cloud Accounts
GroupAPT5

APT5 has accessed Microsoft M365 cloud environments using stolen credentials.

T1078.004
Cloud Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials to access cloud assets within a target organization.

T1078.004
Cloud Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment.

T1078.004
Cloud Accounts
GroupAPT33

APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.

T1078.004
Cloud Accounts
GroupTeamPCP

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.

T1078.004
Cloud Accounts
GroupShinyHunters

ShinyHunters has used valid cloud accounts to gain initial access or to escalate privileges within cloud environments. Additionally, ShinyHunters has also used valid credentials from public repositories to include access keys to gain access to the victim organization’s AWS environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.