Cloud Accounts

T1078.004

Sub-technique of T1078 Valid Accounts.View on attack.mitre.org

About this technique

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Service or user accounts may be targeted by adversaries through Brute Force, Phishing, or various other means to gain access to the environment. Federated or synced accounts may be a pathway for the adversary to affect both on-premises systems and cloud environments - for example, by leveraging shared credentials to log onto Remote Services. High privileged cloud accounts, whether federated, synced, or cloud-only, may also allow pivoting to on-premises environments by leveraging SaaS-based Software Deployment Tools to run commands on hybrid-joined devices.

An adversary may create long lasting Additional Cloud Credentials on a compromised cloud account to maintain persistence in the environment. Such credentials may also be used to bypass security controls such as multi-factor authentication.

Cloud accounts may also be able to assume Temporary Elevated Cloud Access or other privileges through various means within the environment. Misconfigurations in role assignments or role assumption policies may allow an adversary to use these mechanisms to leverage permissions outside the intended scope of the account. Such over privileged accounts may be used to harvest sensitive data from online storage accounts and databases through Cloud API or other methods. For example, in Azure environments, adversaries may target Azure Managed Identities, which allow associated Azure resources to request access tokens. By compromising a resource with an attached Managed Identity, such as an Azure VM, adversaries may be able to Steal Application Access Tokens to move laterally across the cloud environment.

Detection rules75

Rules on DetectionCode tagged with T1078.004.

Sigma40

RuleLevelLog source
Application AppID Uri Configuration Changeshighazure / NULL
Application URI Configuration Changeshighazure / NULL
AWS IAM S3Browser LoginProfile Creationhighaws / NULL
AWS IAM S3Browser Templated S3 Bucket Policy Creationhighaws / NULL
AWS IAM S3Browser User or AccessKey Creationhighaws / NULL
Azure Subscription Permission Elevation Via ActivityLogshighazure / NULL
Changes To PIM Settingshighazure / NULL
Okta New Admin Console Behaviourshighokta / NULL
PIM Approvals And Deny Elevationhighazure / NULL
Potential MFA Bypass Using Legacy Client Authenticationhighazure / NULL
Sign-in Failure Due to Conditional Access Requirements Not Methighazure / NULL
Sign-ins from Non-Compliant Deviceshighazure / NULL
Temporary Access Pass Added To An Accounthighazure / NULL
Use of Legacy Authentication Protocolshighazure / NULL
User Added To Privilege Rolehighazure / NULL

Splunk35

RuleTypeRiskData source
Abnormally High AWS Instances Launched by UserAnomalyNULL
Abnormally High AWS Instances Launched by User - MLTKAnomalyNULL
Abnormally High AWS Instances Terminated by UserAnomalyNULL
Abnormally High AWS Instances Terminated by User - MLTKAnomalyNULL
Abnormally High Number Of Cloud Infrastructure API CallsAnomalyNULLAWS CloudTrail
Abnormally High Number Of Cloud Instances DestroyedAnomalyNULLAWS CloudTrail
Abnormally High Number Of Cloud Instances LaunchedAnomalyNULLAWS CloudTrail
Abnormally High Number Of Cloud Security Group API CallsAnomalyNULLAWS CloudTrail
ASL AWS Create Policy Version to allow all resourcesTTPNULLASL AWS CloudTrail
AWS Create Policy Version to allow all resourcesTTPNULLAWS CloudTrail CreatePolicyVersion
AWS SetDefaultPolicyVersionTTPNULLAWS CloudTrail SetDefaultPolicyVersion
AWS Successful Single-Factor AuthenticationTTPNULLAWS CloudTrail ConsoleLogin
Azure AD Authentication Failed During MFA ChallengeTTPNULLAzure Active Directory
Azure AD Multiple Failed MFA Requests For UserTTPNULLAzure Active Directory Sign-in activity
Azure AD Service Principal AuthenticationTTPNULLAzure Active Directory Sign-in activity

Groups12

Software6

Campaigns3

Procedure examples21

Groups12

Used byProcedure example
GroupAPT28

APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes.

GroupAPT29

APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange.

GroupAPT33

APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.

GroupAPT5

APT5 has accessed Microsoft M365 cloud environments using stolen credentials.

GroupHAFNIUM

HAFNIUM has abused service principals in compromised environments to enable data exfiltration.

GroupKe3chang

Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts.

GroupLAPSUS$

LAPSUS$ has used compromised credentials to access cloud assets within a target organization.

GroupScattered Spider

Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments.

View all 12 groups examples

Software6

Used byProcedure example
MalwareMini Shai-Hulud

Mini Shai-Hulud has used compromised accounts for Docker Hub and GitHub to publish malicious software packages.

ToolPacu

Pacu leverages valid cloud accounts to perform most of its operations.

ToolPeirates

Peirates can use stolen service account tokens to perform its operations.

ToolROADTools

ROADTools leverages valid cloud credentials to perform enumeration operations using the internal Azure AD Graph API.

MalwareShai-Hulud

Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories.

ToolTruffleHog

TruffleHog has used stolen credentials to log into cloud services to access cloud hosted repositories and other cloud storage solutions to discover sensitive data to include API Keys, tokens and credentials.

Campaigns3

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services.

CampaignC0027

During C0027, Scattered Spider leveraged compromised credentials from victim users to authenticate to Azure tenants.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal.

References4

  1. AWS Identity Federation Open source
    Amazon. (n.d.). Identity Federation in AWS. Retrieved March 13, 2020.
  2. Google Federating GC Open source
    Google. (n.d.). Federating Google Cloud with Active Directory. Retrieved March 13, 2020.
  3. Microsoft Deploying AD Federation Open source
    Microsoft. (n.d.). Deploying Active Directory Federation Services in Azure. Retrieved March 13, 2020.
  4. SpecterOps Managed Identity 2022 Open source
    Andy Robbins. (2022, June 6). Managed Identity Attack Paths, Part 1: Automation Accounts. Retrieved March 18, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.