Multi-Factor Authentication Interception

T1111

Technique.View on attack.mitre.org

About this technique

Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.

If a smart card is used for multi-factor authentication, then a keylogger will need to be used to obtain the password associated with a smart card during normal use. With both an inserted card and access to the smart card password, an adversary can connect to a network resource using the infected system to proxy the authentication with the inserted hardware token.

Adversaries may also employ a keylogger to similarly target other hardware tokens, such as RSA SecurID. Capturing token input (including a user's personal identification code) may provide temporary access (i.e. replay the one-time passcode until the next value rollover) as well as possibly enabling adversaries to reliably predict future authentication values (given access to both the algorithm and any seed values used to generate appended temporary codes).

Other methods of MFA may be intercepted and used by an adversary to authenticate. It is common for one-time codes to be sent via out-of-band communications (email, SMS). If the device and/or service is not secured, then it may be vulnerable to interception. Service providers can also be targeted: for example, an adversary may compromise an SMS messaging service in order to steal MFA codes sent to users’ phones.

Detection rules0

Rules on DetectionCode tagged with T1111.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software3

Campaigns2

Procedure examples9

Groups4

Used byProcedure example
GroupAPT42

APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens.

GroupChimera

Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS.

GroupKimsuky

Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication.

GroupLAPSUS$

LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.

Software3

Used byProcedure example
Toolevilginx2

evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA.

MalwareSLOWPULSE

SLOWPULSE can log credentials on compromised Pulse Secure VPNs during the `DSAuth::AceAuthServer::checkUsernamePassword`ACE-2FA authentication procedure.

MalwareSykipot

Sykipot is known to contain functionality that enables targeting of smart card technologies to proxy authentication for connections to restricted network resources using detected hardware tokens.

Campaigns2

Used byProcedure example
CampaignLeviathan Australian Intrusions

Leviathan abused compromised appliance access to collect multifactor authentication token values during Leviathan Australian Intrusions.

CampaignOperation Wocao

During Operation Wocao, threat actors used a custom collection method to intercept two-factor authentication soft tokens.

References3

  1. GCN RSA June 2011 Open source
    Jackson, William. (2011, June 7). RSA confirms its tokens used in Lockheed hack. Retrieved November 17, 2024.
  2. Mandiant M Trends 2011 Open source
    Mandiant. (2011, January 27). Mandiant M-Trends 2011. Retrieved January 10, 2016.
  3. Okta Scatter Swine 2022 Open source
    Okta. (2022, August 25). Detecting Scatter Swine: Insights into a Relentless Phishing Campaign. Retrieved February 24, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.