Compromise Accounts

T1586

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating accounts (i.e. Establish Accounts), adversaries may compromise existing accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona.

A variety of methods exist for compromising accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, brute forcing credentials (ex: password reuse from breach credential dumps), or paying employees, suppliers or business partners for access to credentials. Prior to compromising accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation.

Personas may exist on a single site or across multiple sites (ex: Facebook, LinkedIn, Twitter, Google, etc.). Compromised accounts may require additional development, this could include filling out or modifying profile information, further developing social networks, or incorporating photos.

Adversaries may directly leverage compromised email accounts for Phishing for Information or Phishing.

Detection rules39

Rules on DetectionCode tagged with T1586 or one of its sub-techniques.

Sigma3

Splunk36

RuleTypeRiskData sourceTechnique
ASL AWS Credential Access GetPasswordDataAnomalyNULLASL AWS CloudTrailT1586.003
ASL AWS Credential Access RDS Password resetTTPNULLASL AWS CloudTrailT1586.003
ASL AWS Multi-Factor Authentication DisabledTTPNULLASL AWS CloudTrailT1586.003
AWS Console Login Failed During MFA ChallengeTTPNULLAWS CloudTrail ConsoleLoginT1586.003
AWS Credential Access Failed LoginTTPNULLAWS CloudTrail ConsoleLoginT1586.003
AWS Credential Access GetPasswordDataAnomalyNULLAWS CloudTrail GetPasswordDataT1586.003
AWS Credential Access RDS Password resetTTPNULLAWS CloudTrail ModifyDBInstanceT1586.003
AWS Multi-Factor Authentication DisabledTTPNULLAWS CloudTrail DeleteVirtualMFADevice, AWS CloudTrail DeactivateMFADeviceT1586.003
AWS Multiple Failed MFA Requests For UserAnomalyNULLAWS CloudTrail ConsoleLoginT1586.003
AWS Successful Console Authentication From Multiple IPsAnomalyNULLAWS CloudTrail ConsoleLoginT1586
AWS Successful Single-Factor AuthenticationTTPNULLAWS CloudTrail ConsoleLoginT1586.003
AWS Unusual Number of Failed Authentications From IpAnomalyNULLAWS CloudTrail ConsoleLoginT1586.003
Azure Active Directory High Risk Sign-inTTPNULLAzure Active DirectoryT1586.003
Azure AD Authentication Failed During MFA ChallengeTTPNULLAzure Active DirectoryT1586.003
Azure AD Multi-Factor Authentication DisabledTTPNULLAzure Active Directory Disable Strong AuthenticationT1586.003

Sub-techniques3

IDNameExamples
T1586.001Social Media Accounts2
T1586.002Email Accounts16
T1586.003Cloud Accounts3

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References2

  1. AnonHBGary Open source
    Bright, P. (2011, February 15). Anonymous speaks: the inside story of the HBGary hack. Retrieved March 9, 2017.
  2. Microsoft DEV-0537 Open source
    Microsoft. (2022, March 22). DEV-0537 criminal actor targeting organizations for data exfiltration and destruction. Retrieved March 23, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.