Web Portal Capture

T1056.003

Sub-technique of T1056 Input Capture.View on attack.mitre.org

About this technique

Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.

This variation on input capture may be conducted post-compromise using legitimate administrative access as a backup measure to maintain network access through External Remote Services and Valid Accounts or as part of the initial compromise by exploitation of the externally facing web service.

Detection rules0

Rules on DetectionCode tagged with T1056.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software2

Campaigns2

Procedure examples6

Groups2

Used byProcedure example
GroupKimsuky

Kimsuky has collected credentials from a fake Google account login page.

GroupWinter Vivern

Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information.

Software2

Used byProcedure example
MalwareIceApple

The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials.

MalwareWARPWIRE

WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP.

Campaigns2

Used byProcedure example
CampaignCutting Edge

During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered.

CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled.

References1

  1. Volexity Virtual Private Keylogging Open source
    Adair, S. (2015, October 7). Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence. Retrieved March 20, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.