Cloud Services

T1021.007

Sub-technique of T1021 Remote Services.View on attack.mitre.org

About this technique

Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities. The adversary may then perform management actions or access cloud-hosted resources as the logged-on user.

Many enterprises federate centrally managed user identities to cloud services, allowing users to login with their domain credentials in order to access the cloud control plane. Similarly, adversaries may connect to available cloud services through the web console or through the cloud command line interface (CLI) (e.g., Cloud API), using commands such as Connect-AZAccount for Azure PowerShell, Connect-MgGraph for Microsoft Graph PowerShell, and gcloud auth login for the Google Cloud CLI.

In some cases, adversaries may be able to authenticate to these services via Application Access Token instead of a username and password.

Detection rules6

Rules on DetectionCode tagged with T1021.007.

Sigma1

RuleLevelLog source
AWS Console GetSigninToken Potential Abusemediumaws / NULL

Splunk5

RuleTypeRiskData source
Microsoft Intune Device Health ScriptsHuntingNULLAzure Monitor Activity
Microsoft Intune DeviceManagementConfigurationPoliciesHuntingNULLAzure Monitor Activity
Microsoft Intune Manual Device ManagementHuntingNULLAzure Monitor Activity
Microsoft Intune Mobile AppsHuntingNULLAzure Monitor Activity
Windows Azure PowerShell Module Installation Via PowerShell ScriptAnomalyNULLPowershell Script Block Logging 4104

Groups3

Software1

Campaigns1

Procedure examples5

Groups3

Used byProcedure example
GroupAPT29

APT29 has leveraged compromised high-privileged on-premises accounts synced to Office 365 to move laterally into a cloud environment, including through the use of Azure AD PowerShell.

GroupScattered Spider

Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes.

GroupStorm-0501

Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment.

Software1

Used byProcedure example
MalwareMini Shai-Hulud

Mini Shai-Hulud has accessed and propagated to AWS EC2 instances via SSM Send-Command.

Campaigns1

Used byProcedure example
CampaignC0027

During C0027, Scattered Spider used compromised Azure credentials for credential theft activity and lateral movement to on-premises systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.