Cloud Secrets Management Stores

T1555.006

Sub-technique of T1555 Credentials from Password Stores.View on attack.mitre.org

About this technique

Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.

Secrets managers support the secure centralized management of passwords, API keys, and other credential material. Where secrets managers are in use, cloud services can dynamically acquire credentials via API requests rather than accessing secrets insecurely stored in plain text files or environment variables.

If an adversary is able to gain sufficient privileges in a cloud environment – for example, by obtaining the credentials of high-privileged Cloud Accounts or compromising a service that has permission to retrieve secrets – they may be able to request secrets from the secrets manager. This can be accomplished via commands such as `get-secret-value` in AWS, `gcloud secrets describe` in GCP, and `az key vault secret show` in Azure.

**Note:** this technique is distinct from Cloud Instance Metadata API in that the credentials are being directly requested from the cloud secrets manager, rather than through the medium of the instance metadata API.

Detection rules0

Rules on DetectionCode tagged with T1555.006.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software6

Campaigns0

None recorded.

Procedure examples9

Groups3

Used byProcedure example
GroupHAFNIUM

HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults.

GroupStorm-0501

Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`.

GroupTeamPCP

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.

Software6

Used byProcedure example
MalwareCanisterWorm

CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.

MalwareMini Shai-Hulud

Mini Shai-Hulud has captured credentials stored in cloud secret stores.

ToolPacu

Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module.

MalwareShai-Hulud

Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials.

ToolTruffleHog

TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history.

References5

  1. AWS Secrets Manager Open source
    AWS. (n.d.). Retrieve secrets from AWS Secrets Manager. Retrieved September 25, 2023.
  2. Google Cloud Secrets Open source
    Google Cloud. (n.d.). List secrets and view secret details. Retrieved September 25, 2023.
  3. Microsoft Azure Key Vault Open source
    Microsoft. (2023, January 13). Quickstart: Set and retrieve a secret from Azure Key Vault using Azure CLI. Retrieved September 25, 2023.
  4. Permiso Scattered Spider 2023 Open source
    Ian Ahl. (2023, September 20). LUCR-3: SCATTERED SPIDER GETTING SAAS-Y IN THE CLOUD. Retrieved September 25, 2023.
  5. Sysdig ScarletEel 2.0 2023 Open source
    Alessandro Brucato. (2023, July 11). SCARLETEEL 2.0: Fargate, Kubernetes, and Crypto. Retrieved September 25, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.