ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1078×

47 examples

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupIndrik Spider

Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure.

T1078
Valid Accounts
GroupBlackByte

BlackByte has gained access to victim environments through legitimate VPN credentials.

T1078
Valid Accounts
GroupGALLIUM

GALLIUM leveraged valid accounts to maintain access to a victim network.

T1078
Valid Accounts
GroupVolt Typhoon

Volt Typhoon relies primarily on valid credentials for persistence.

T1078
Valid Accounts
GroupAPT41

APT41 used compromised credentials to log on to other systems.

T1078
Valid Accounts
GroupDragonfly

Dragonfly has compromised user credentials and used valid accounts for operations.

T1078
Valid Accounts
GroupmenuPass

menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments.

T1078
Valid Accounts
GroupFIN6

To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes.

T1078
Valid Accounts
GroupFIN7

FIN7 has harvested valid administrative credentials for lateral movement.

T1078
Valid Accounts
GroupSandworm Team

Sandworm Team have used previously acquired legitimate credentials prior to attacks.

T1078
Valid Accounts
GroupAPT18

APT18 actors leverage legitimate credentials to log into external remote services.

T1078
Valid Accounts
GroupScattered Spider

Scattered Spider has used compromised credentials for initial access.

T1078
Valid Accounts
GroupAPT39

APT39 has used stolen credentials to compromise Outlook Web Access (OWA).

T1078
Valid Accounts
GroupUNC3886

UNC3886 has used tools to hijack valid SSH accounts.

T1078
Valid Accounts
GroupAkira

Akira uses valid account information to remotely access victim networks, such as VPN credentials.

T1078
Valid Accounts
GroupOilRig

OilRig has used compromised credentials to access other systems on a victim network.

T1078
Valid Accounts
GroupCarbanak

Carbanak actors used legitimate credentials of banking employees to perform operations that sent them millions of dollars.

T1078
Valid Accounts
GroupSea Turtle

Sea Turtle used compromised credentials to maintain long-term access to victim environments.

T1078
Valid Accounts
GroupSuckfly

Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner.

T1078
Valid Accounts
GroupPOLONIUM

POLONIUM has used valid compromised credentials to gain access to victim environments.

T1078
Valid Accounts
GroupKe3chang

Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts.

T1078
Valid Accounts
GroupLeviathan

Leviathan has obtained valid accounts to gain initial access.

T1078
Valid Accounts
GroupFIN5

FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment.

T1078
Valid Accounts
GroupAPT29

APT29 has used a compromised account to access an organization's VPN infrastructure.

T1078
Valid Accounts
GroupCinnamon Tempest

Cinnamon Tempest has used compromised user accounts to deploy payloads and create system services.

T1078
Valid Accounts
GroupChimera

Chimera has used a valid account to maintain persistence via scheduled task.

T1078
Valid Accounts
GroupSilent Librarian

Silent Librarian has used compromised credentials to obtain unauthorized access to online accounts.

T1078
Valid Accounts
GroupMedusa Group

Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.

T1078
Valid Accounts
GroupStar Blizzard

Star Blizzard has used stolen credentials to sign into victim email accounts.

T1078
Valid Accounts
GroupAxiom

Axiom has used previously compromised administrative accounts to escalate privileges.

T1078
Valid Accounts
GroupAPT28

APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder.

T1078
Valid Accounts
GroupFox Kitten

Fox Kitten has used valid credentials with various services during lateral movement.

T1078
Valid Accounts
GroupLazarus Group

Lazarus Group has used administrator credentials to gain access to restricted network segments.

T1078
Valid Accounts
GroupINC Ransom

INC Ransom has used compromised valid accounts for access to victim environments.

T1078
Valid Accounts
GroupFIN4

FIN4 has used legitimate credentials to hijack email communications.

T1078
Valid Accounts
GroupSilence

Silence has used compromised credentials to log on to other systems and escalate privileges.

T1078
Valid Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.

T1078
Valid Accounts
GroupWizard Spider

Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers.

T1078
Valid Accounts
GroupVOID MANTICORE

VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions.

T1078
Valid Accounts
GroupPlay

Play has used valid VPN accounts to achieve initial access.

T1078
Valid Accounts
GroupThreat Group-3390

Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks.

T1078
Valid Accounts
GroupAPT33

APT33 has used valid accounts for initial access and privilege escalation.

T1078
Valid Accounts
GroupFIN10

FIN10 has used stolen credentials to connect remotely to victim networks using VPNs protected with only a single factor.

T1078
Valid Accounts
GroupFIN8

FIN8 has used valid accounts for persistence and lateral movement.

T1078
Valid Accounts
GroupPittyTiger

PittyTiger attempts to obtain legitimate credentials during operations.

T1078
Valid Accounts
GroupTeamPCP

TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.

T1078
Valid Accounts
GroupShinyHunters

ShinyHunters has used valid high-privileged SSO users as leverage during negotiations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.