Masquerade Account Name

T1036.010

Sub-technique of T1036 Masquerading.View on attack.mitre.org

About this technique

Adversaries may match or approximate the names of legitimate accounts to make newly created ones appear benign. This will typically occur during Create Account, although accounts may also be renamed at a later date. This may also coincide with Account Access Removal if the actor first deletes an account before re-creating one with the same name.

Often, adversaries will attempt to masquerade as service accounts, such as those associated with legitimate software, data backups, or container cluster management. They may also give accounts generic, trustworthy names, such as “admin”, “help”, or “root.” Sometimes adversaries may model account names off of those already existing in the system, as a follow-on behavior to Account Discovery.

Note that this is distinct from Impersonation, which describes impersonating specific trusted individuals or organizations, rather than user or service account names.

Detection rules1

Rules on DetectionCode tagged with T1036.010.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Windows Builtin Account Name Was ChangedTTPNULLWindows Event Log Security 4781

Groups4

Software2

Campaigns1

Procedure examples7

Groups4

Used byProcedure example
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

GroupDragonfly

Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account.

GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

GroupStorm-1811

Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.

Software2

Used byProcedure example
MalwareFlame

Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available.

MalwareServHelper

ServHelper has created a new user named `supportaccount`.

Campaigns1

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System).

References4

  1. Aquasec Kubernetes Attack 2023 Open source
    Michael Katchinskiy, Assaf Morag. (2023, April 21). First-Ever Attack Leveraging Kubernetes RBAC to Backdoor Clusters. Retrieved July 14, 2023.
  2. Elastic CUBA Ransomware 2022 Open source
    Daniel Stepanic, Derek Ditch, Seth Goodwin, Salim Bitam, Andrew Pease. (2022, September 7). CUBA Ransomware Campaign Analysis. Retrieved August 5, 2024.
  3. Huntress MOVEit 2023 Open source
    John Hammond. (2023, June 1). MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response. Retrieved August 5, 2024.
  4. Invictus IR Cloud Ransomware 2024 Open source
    Invictus IR. (2024, January 11). Ransomware in the cloud. Retrieved August 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.