Adversary-in-the-Middle

T1557

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

For example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware. Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens (Steal Application Access Token) and session cookies (Steal Web Session Cookie). Downgrade Attacks can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm.

Adversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in Transmitted Data Manipulation. Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to impair defenses and/or in support of a Network Denial of Service.

Detection rules30

Rules on DetectionCode tagged with T1557 or one of its sub-techniques.

Sigma20

RuleLevelLog sourceTechnique
Potential SMB Relay Attack Tool Executioncriticalwindows / process_creationT1557.001
Attempts of Kerberos Coercion Via DNS SPN Spoofinghighwindows / process_creationT1557.001
HackTool - ADCSPwn Executionhighwindows / process_creationT1557.001
HackTool - Impacket Tools Executionhighwindows / process_creationT1557.001
Local Privilege Escalation Indicator TabTiphighwindows / NULLT1557.001
Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulationhighwindows / NULLT1557.003
RottenPotato Like Attack Patternhighwindows / NULLT1557.001
Suspicious Child Process of Notepad++ Updater - GUP.Exehighwindows / process_creationT1557
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofinghighwindows / dns_queryT1557.001
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Networkhighzeek / NULLT1557.001
Uncommon File Created by Notepad++ Updater Gup.EXEhighwindows / file_eventT1557
WinDivert Driver Loadhighwindows / driver_loadT1557.001
ISATAP Router Address Was Setmediumwindows / NULLT1557
Notepad++ Updater DNS Query to Uncommon Domainsmediumwindows / dns_queryT1557
Potential PetitPotam Attack Via EFS RPC Callsmediumzeek / NULLT1557.001

Splunk10

RuleTypeRiskData sourceTechnique
Cisco ASA - Packet Capture ActivityAnomalyNULLCisco ASA LogsT1557
Detect ARP PoisoningTTPNULLCisco IOS LogsT1557.002
Detect IPv6 Network Infrastructure ThreatsTTPNULLCisco IOS LogsT1557.002
Detect Port Security ViolationTTPNULLCisco IOS LogsT1557.002
Detect Rogue DHCP ServerTTPNULLCisco IOS LogsT1557
DNS Kerberos CoercionTTPNULLSuricata, Sysmon EventID 22T1557.001
Windows Credential Target Information Structure in CommandlineTTPNULLSysmon EventID 1T1557.001
Windows Kerberos Coercion via DNSTTPNULLWindows Event Log Security 4662, Windows Event Log Security 5136, Windows Event Log Security 5137T1557.001
Windows Short Lived DNS RecordTTPNULLWindows Event Log Security 5136, Windows Event Log Security 5137T1557.001
Windows Theme File Creation in Unusual LocationAnomalyNULLSysmon EventID 11T1557.001

Sub-techniques4

IDNameExamples
T1557.001Name Resolution Poisoning and SMB Relay7
T1557.002ARP Cache Poisoning2
T1557.003DHCP Spoofing0
T1557.004Evil Twin1

Groups3

Software5

Campaigns1

Procedure examples9

Groups3

Used byProcedure example
GroupKimsuky

Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website.

GroupMustang Panda

Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload.

GroupSea Turtle

Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture.

Software5

Used byProcedure example
MalwareDok

Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic.

Toolevilginx2

evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens.

MalwareKali365

Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions.

MalwareLine Runner

Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed.

ToolNPPSPY

NPPSPY opens a new network listener for the mpnotify.exe process that is typically contacted by the Winlogon process in Windows. A new, alternative RPC channel is set up with a malicious DLL recording plaintext credentials entered into Winlogon, effectively intercepting and redirecting the logon information.

Campaigns1

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device.

References9

  1. Rapid7 MiTM Basics Open source
    Rapid7. (n.d.). Man-in-the-Middle (MITM) Attacks. Retrieved March 2, 2020.
  2. Token tactics Open source
    Microsoft Incident Response. (2022, November 16). Token tactics: How to prevent, detect, and respond to cloud token theft. Retrieved December 26, 2023.
  3. ad_blocker_with_miner Open source
    Kuzmenko, A.. (2021, March 10). Ad blocker with miner included. Retrieved October 28, 2021.
  4. dns_changer_trojans Open source
    Abendan, O. (2012, June 14). How DNS Changer Trojans Direct Users to Threats. Retrieved October 28, 2021.
  5. mitm_tls_downgrade_att Open source
    praetorian Editorial Team. (2014, August 19). Man-in-the-Middle TLS Protocol Downgrade Attack. Retrieved December 8, 2021.
  6. taxonomy_downgrade_att_tls Open source
    Alashwali, E. S., Rasmussen, K. (2019, January 26). What's in a Downgrade? A Taxonomy of Downgrade Attacks in the TLS Protocol and Application Protocols Using TLS. Retrieved December 7, 2021.
  7. tlseminar_downgrade_att Open source
    Team Cinnamon. (2017, February 3). Downgrade Attacks. Retrieved December 9, 2021.
  8. ttint_rat Open source
    Tu, L. Ma, Y. Ye, G. (2020, October 1). Ttint: An IoT Remote Access Trojan spread through 2 0-day vulnerabilities. Retrieved October 28, 2021.
  9. volexity_0day_sophos_FW Open source
    Adair, S., Lancaster, T., Volexity Threat Research. (2022, June 15). DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.