Sub-technique of T1056 Input Capture.View on attack.mitre.org
Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.
This variation on input capture may be conducted post-compromise using legitimate administrative access as a backup measure to maintain network access through External Remote Services and Valid Accounts or as part of the initial compromise by exploitation of the externally facing web service.
Rules on DetectionCode tagged with T1056.003.
| Used by | Procedure example |
|---|---|
| GroupKimsuky | Kimsuky has collected credentials from a fake Google account login page. |
| GroupWinter Vivern | Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information. |
| Used by | Procedure example |
|---|---|
| MalwareIceApple | The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials. |
| MalwareWARPWIRE | WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP. |
| Used by | Procedure example |
|---|---|
| CampaignCutting Edge | During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered. |
| CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.