ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1136.001×

15 examples

TechniqueUsed byProcedure example
T1136.001
Local Account
MalwareHildegard

Hildegard has created a user named “monerodaemon”.

T1136.001
Local Account
MalwareS-Type

S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`.

T1136.001
Local Account
MalwareDarkGate

DarkGate creates a local user account, SafeMode, via net user commands.

T1136.001
Local Account
MalwareCarbanak

Carbanak can create a Windows account.

T1136.001
Local Account
MalwareSMOKEDHAM

SMOKEDHAM has created user accounts.

T1136.001
Local Account
MalwareServHelper

ServHelper has created a new user named "supportaccount".

T1136.001
Local Account
MalwareCalisto

Calisto has the capability to add its own account to the victim's machine.

T1136.001
Local Account
MalwareGoldenSpy

GoldenSpy can create new users on an infected system.

T1136.001
Local Account
MalwareZxShell

ZxShell has a feature to create local user accounts.

T1136.001
Local Account
MalwareMis-Type

Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`.

T1136.001
Local Account
MalwareHiddenWasp

HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine.

T1136.001
Local Account
ToolNet

The net user username \password commands in Net can be used to create a local account.

T1136.001
Local Account
ToolEmpire

Empire has a module for creating a local user if permissions allow.

T1136.001
Local Account
ToolPupy

Pupy can user PowerView to execute “net user” commands and create local system accounts.

T1136.001
Local Account
MalwareFlame

Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.