Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1136.001 Local Account |
MalwareHildegard | Hildegard has created a user named “monerodaemon”. |
| T1136.001 Local Account |
MalwareS-Type | S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`. |
| T1136.001 Local Account |
MalwareDarkGate | DarkGate creates a local user account, |
| T1136.001 Local Account |
MalwareCarbanak | Carbanak can create a Windows account. |
| T1136.001 Local Account |
MalwareSMOKEDHAM | SMOKEDHAM has created user accounts. |
| T1136.001 Local Account |
MalwareServHelper | ServHelper has created a new user named "supportaccount". |
| T1136.001 Local Account |
MalwareCalisto | Calisto has the capability to add its own account to the victim's machine. |
| T1136.001 Local Account |
MalwareGoldenSpy | GoldenSpy can create new users on an infected system. |
| T1136.001 Local Account |
MalwareZxShell | ZxShell has a feature to create local user accounts. |
| T1136.001 Local Account |
MalwareMis-Type | Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`. |
| T1136.001 Local Account |
MalwareHiddenWasp | HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine. |
| T1136.001 Local Account |
ToolNet | The |
| T1136.001 Local Account |
ToolEmpire | Empire has a module for creating a local user if permissions allow. |
| T1136.001 Local Account |
ToolPupy | Pupy can user PowerView to execute “net user” commands and create local system accounts. |
| T1136.001 Local Account |
MalwareFlame | Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.