Sub-technique of T1555 Credentials from Password Stores.View on attack.mitre.org
Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
Secrets managers support the secure centralized management of passwords, API keys, and other credential material. Where secrets managers are in use, cloud services can dynamically acquire credentials via API requests rather than accessing secrets insecurely stored in plain text files or environment variables.
If an adversary is able to gain sufficient privileges in a cloud environment – for example, by obtaining the credentials of high-privileged Cloud Accounts or compromising a service that has permission to retrieve secrets – they may be able to request secrets from the secrets manager. This can be accomplished via commands such as `get-secret-value` in AWS, `gcloud secrets describe` in GCP, and `az key vault secret show` in Azure.
**Note:** this technique is distinct from Cloud Instance Metadata API in that the credentials are being directly requested from the cloud secrets manager, rather than through the medium of the instance metadata API.
Rules on DetectionCode tagged with T1555.006.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupHAFNIUM | HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults. |
| GroupStorm-0501 | Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`. |
| GroupTeamPCP | TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure. |
| Used by | Procedure example |
|---|---|
| MalwareCanisterWorm | CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has captured credentials stored in cloud secret stores. |
| ToolPacu | Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module. |
| MalwareShai-Hulud | Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials. |
| ToolTruffleHog | TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.