Valid Accounts

T1078

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

In some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be present to identify any anomalous activity taking place on their account.

The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.

Detection rules208

Rules on DetectionCode tagged with T1078 or one of its sub-techniques.

Sigma102

RuleLevelLog sourceTechnique
Win Susp Computer Name Containing Samtheadmincriticalwindows / NULLT1078
Account Created And Deleted Within A Close Time Framehighazure / NULLT1078
Activity From Anonymous IP Addresshighazure / NULLT1078
Application AppID Uri Configuration Changeshighazure / NULLT1078.004
Application URI Configuration Changeshighazure / NULLT1078.004
Atypical Travelhighazure / NULLT1078
AWS IAM S3Browser LoginProfile Creationhighaws / NULLT1078.004
AWS IAM S3Browser Templated S3 Bucket Policy Creationhighaws / NULLT1078.004
AWS IAM S3Browser User or AccessKey Creationhighaws / NULLT1078.004
Azure AD Threat Intelligencehighazure / NULLT1078
Azure Login Bypassing Conditional Access Policieshighm365 / NULLT1078
Azure Subscription Permission Elevation Via ActivityLogshighazure / NULLT1078.004
Azure Subscription Permission Elevation Via AuditLogshighazure / NULLT1078
Changes To PIM Settingshighazure / NULLT1078.004
External Remote SMB Logon from Public IPhighwindows / NULLT1078

Splunk106

RuleTypeRiskData sourceTechnique
Abnormally High AWS Instances Launched by UserAnomalyNULLT1078.004
Abnormally High AWS Instances Launched by User - MLTKAnomalyNULLT1078.004
Abnormally High AWS Instances Terminated by UserAnomalyNULLT1078.004
Abnormally High AWS Instances Terminated by User - MLTKAnomalyNULLT1078.004
Abnormally High Number Of Cloud Infrastructure API CallsAnomalyNULLAWS CloudTrailT1078.004
Abnormally High Number Of Cloud Instances DestroyedAnomalyNULLAWS CloudTrailT1078.004
Abnormally High Number Of Cloud Instances LaunchedAnomalyNULLAWS CloudTrailT1078.004
Abnormally High Number Of Cloud Security Group API CallsAnomalyNULLAWS CloudTrailT1078.004
ASL AWS Create Policy Version to allow all resourcesTTPNULLASL AWS CloudTrailT1078.004
ASL AWS CreateAccessKeyHuntingNULLT1078
ASL AWS SAML Update identity providerTTPNULLASL AWS CloudTrailT1078
AWS Bedrock Invoke Model Access DeniedTTPNULLAWS CloudTrailT1078
AWS Create Policy Version to allow all resourcesTTPNULLAWS CloudTrail CreatePolicyVersionT1078.004
aws detect attach to role policyHuntingNULLT1078
aws detect permanent key creationHuntingNULLT1078

Sub-techniques4

IDNameExamples
T1078.001Default Accounts7
T1078.002Domain Accounts35
T1078.003Local Accounts21
T1078.004Cloud Accounts21

Groups47

Show 23 more

Software7

Campaigns11

Procedure examples65

Groups47

Used byProcedure example
GroupAkira

Akira uses valid account information to remotely access victim networks, such as VPN credentials.

GroupAPT18

APT18 actors leverage legitimate credentials to log into external remote services.

GroupAPT28

APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder.

GroupAPT29

APT29 has used a compromised account to access an organization's VPN infrastructure.

GroupAPT33

APT33 has used valid accounts for initial access and privilege escalation.

GroupAPT39

APT39 has used stolen credentials to compromise Outlook Web Access (OWA).

GroupAPT41

APT41 used compromised credentials to log on to other systems.

GroupAxiom

Axiom has used previously compromised administrative accounts to escalate privileges.

View all 47 groups examples

Software7

Used byProcedure example
MalwareDtrack

Dtrack used hard-coded credentials to gain access to a network share.

MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

MalwareIndustroyer

Industroyer can use supplied user credentials to execute processes and stop services.

MalwareKinsing

Kinsing has used valid SSH credentials to access remote hosts.

MalwareLinux Rabbit

Linux Rabbit acquires valid SSH accounts through brute force.

MalwareLP-Notes

LP-Notes has used stolen Windows credentials to log in as the users.

MalwareSeaDuke

Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials.

Campaigns11

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network.

Campaign3CX Supply Chain Attack

During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials.

CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks.

CampaignC0032

During the C0032 campaign, TEMP.Veles used compromised VPN accounts.

CampaignHomeLand Justice

During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts.

CampaignLeviathan Australian Intrusions

Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions.

CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks.

View all 11 campaigns examples

References3

  1. CISA MFA PrintNightmare Open source
    Cybersecurity and Infrastructure Security Agency. (2022, March 15). Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and “PrintNightmare” Vulnerability. Retrieved March 16, 2022.
  2. TechNet Credential Theft Open source
    Microsoft. (2016, April 15). Attractive Accounts for Credential Theft. Retrieved June 3, 2016.
  3. volexity_0day_sophos_FW Open source
    Adair, S., Lancaster, T., Volexity Threat Research. (2022, June 15). DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.