Additional Cloud Credentials

T1098.001

Sub-technique of T1098 Account Manipulation.View on attack.mitre.org

About this technique

Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.

For example, adversaries may add credentials for Service Principals and Applications in addition to existing legitimate credentials in Azure / Entra ID. These credentials include both x509 keys and passwords. With sufficient permissions, there are a variety of ways to add credentials including the Azure Portal, Azure command line interface, and Azure or Az PowerShell modules.

In infrastructure-as-a-service (IaaS) environments, after gaining access through Cloud Accounts, adversaries may generate or import their own SSH keys using either the CreateKeyPair or ImportKeyPair API in AWS or the gcloud compute os-login ssh-keys add command in GCP. This allows persistent access to instances within the cloud environment without further usage of the compromised cloud accounts.

Adversaries may also use the CreateAccessKey API in AWS or the gcloud iam service-accounts keys create command in GCP to add access keys to an account. Alternatively, they may use the CreateLoginProfile API in AWS to add a password that can be used to log into the AWS Management Console for Cloud Service Dashboard. If the target account has different permissions from the requesting account, the adversary may also be able to escalate their privileges in the environment (i.e. Cloud Accounts). For example, in Entra ID environments, an adversary with the Application Administrator role can add a new set of credentials to their application's service principal. In doing so the adversary would be able to access the service principal’s roles and permissions, which may be different from those of the Application Administrator.

In AWS environments, adversaries with the appropriate permissions may also use the `sts:GetFederationToken` API call to create a temporary set of credentials to Forge Web Credentials tied to the permissions of the original user account. These temporary credentials may remain valid for the duration of their lifetime even if the original account’s API credentials are deactivated.

In Entra ID environments with the app password feature enabled, adversaries may be able to add an app password to a user account. As app passwords are intended to be used with legacy devices that do not support multi-factor authentication (MFA), adding an app password can allow an adversary to bypass MFA requirements. Additionally, app passwords may remain valid even if the user’s primary password is reset.

Detection rules5

Rules on DetectionCode tagged with T1098.001.

Sigma3

RuleLevelLog source
Added Credentials to Existing Applicationhighazure / NULL
Github Outside Collaborator Detectedmediumgithub / NULL
Okta Identity Provider Createdmediumokta / NULL

Splunk2

RuleTypeRiskData source
Azure AD Service Principal New Client CredentialsTTPNULLAzure Active Directory
O365 Service Principal New Client CredentialsTTPNULLO365

Groups1

Software1

Campaigns2

Procedure examples4

Groups1

Used byProcedure example
GroupStorm-0501

Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method.

Software1

Used byProcedure example
ToolPacu

Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users.

Campaigns2

Used byProcedure example
CampaignC0027

During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals.

References15

  1. Blue Cloud of Death Open source
    Kunz, Bryce. (2018, May 11). Blue Cloud of Death: Red Teaming Azure. Retrieved October 23, 2019.
  2. Blue Cloud of Death Video Open source
    Kunz, Bruce. (2018, October 14). Blue Cloud of Death: Red Teaming Azure. Retrieved November 21, 2019.
  3. Crowdstrike AWS User Federation Persistence Open source
    Vaishnav Murthy and Joel Eng. (2023, January 30). How Adversaries Can Persist with AWS User Federation. Retrieved March 10, 2023.
  4. Demystifying Azure AD Service Principals Open source
    Bellavance, Ned. (2019, July 16). Demystifying Azure AD Service Principals. Retrieved January 19, 2020.
  5. Expel Behind the Scenes Open source
    S. Lipton, L. Easterly, A. Randazzo and J. Hencinski. (2020, July 28). Behind the scenes in the Expel SOC: Alert-to-fix in AWS. Retrieved October 1, 2020.
  6. Expel IO Evil in AWS Open source
    A. Randazzo, B. Manahan and S. Lipton. (2020, April 28). Finding Evil in AWS. Retrieved June 25, 2020.
  7. GCP SSH Key Add Open source
    Google. (n.d.). gcloud compute os-login ssh-keys add. Retrieved October 1, 2020.
  8. Lacework AI Resource Hijacking 2024 Open source
    Detecting AI resource-hijacking with Composite Alerts. (2024, June 6). Lacework Labs. Retrieved July 1, 2024.
  9. Mandiant APT42 Operations 2024 Open source
    Ofir Rozmann, Asli Koksal, Adrian Hernandez, Sarah Bock, and Jonathan Leathery. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved May 28, 2024.
  10. Microsoft Entra ID App Passwords Open source
    Microsoft. (2023, October 23). Enforce Microsoft Entra multifactor authentication with legacy applications using app passwords. Retrieved May 28, 2024.
  11. Microsoft SolarWinds Customer Guidance Open source
    MSRC. (2020, December 13). Customer Guidance on Recent Nation-State Cyber Attacks. Retrieved December 17, 2020.
  12. Permiso Scattered Spider 2023 Open source
    Ian Ahl. (2023, September 20). LUCR-3: SCATTERED SPIDER GETTING SAAS-Y IN THE CLOUD. Retrieved September 25, 2023.
  13. Rhino Security Labs AWS Privilege Escalation Open source
    Spencer Gietzen. (n.d.). AWS IAM Privilege Escalation – Methods and Mitigation. Retrieved May 27, 2022.
  14. SpecterOps Azure Privilege Escalation Open source
    Andy Robbins. (2021, October 12). Azure Privilege Escalation via Service Principal Abuse. Retrieved April 1, 2022.
  15. Sysdig ScarletEel 2.0 Open source
    SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. (2023, July 11). SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. Retrieved July 12, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.