ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1136.001×

14 examples

TechniqueUsed byProcedure example
T1136.001
Local Account
GroupIndrik Spider

Indrik Spider has created local system accounts and has added the accounts to privileged groups.

T1136.001
Local Account
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1136.001
Local Account
GroupKimsuky

Kimsuky has created accounts with net user.

T1136.001
Local Account
GroupAPT41

APT41 has created user accounts.

T1136.001
Local Account
GroupDragonfly

Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target.

T1136.001
Local Account
GroupLeafminer

Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine.

T1136.001
Local Account
GroupTeamTNT

TeamTNT has created local privileged users on victim machines.

T1136.001
Local Account
GroupAPT39

APT39 has created accounts on multiple compromised hosts to perform actions within the network.

T1136.001
Local Account
GroupAPT5

APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation.

T1136.001
Local Account
GroupFox Kitten

Fox Kitten has created a local user account with administrator privileges.

T1136.001
Local Account
GroupWizard Spider

Wizard Spider has created local administrator accounts to maintain persistence in compromised networks.

T1136.001
Local Account
GroupDaggerfly

Daggerfly created a local account on victim machines to maintain access.

T1136.001
Local Account
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1136.001
Local Account
GroupFIN13

FIN13 has created MS-SQL local accounts in a compromised network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.