UK National Cyber Security Center et al. (2024, February). SVR cyber actors adapt tactics for initial cloud access. Retrieved March 1, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078.003 Local Accounts |
GroupAPT29 | APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence. |
| T1090.002 External Proxy |
GroupAPT29 | APT29 uses compromised residential endpoints as proxies for defense evasion and network access. |
| T1098.005 Device Registration |
GroupAPT29 | APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account. |
| T1110.003 Password Spraying |
GroupAPT29 | APT29 has conducted brute force password spray attacks. |
| T1528 Steal Application Access Token |
GroupAPT29 | APT29 uses stolen tokens to access victim accounts, without needing a password. |
| T1621 Multi-Factor Authentication Request Generation |
GroupAPT29 | APT29 has used repeated MFA requests to gain access to victim accounts. |
| T1665 Hide Infrastructure |
GroupAPT29 | APT29 uses compromised residential endpoints, typically within the same ISP IP address range, as proxies to hide the true source of C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.