Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
In some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be present to identify any anomalous activity taking place on their account.
The overlap of permissions for local, domain, and cloud accounts across a network of systems is of concern because the adversary may be able to pivot across accounts and systems to reach a high level of access (i.e., domain or enterprise administrator) to bypass access controls set within the enterprise.
Rules on DetectionCode tagged with T1078 or one of its sub-techniques.
| Used by | Procedure example |
|---|---|
| GroupAkira | Akira uses valid account information to remotely access victim networks, such as VPN credentials. |
| GroupAPT18 | APT18 actors leverage legitimate credentials to log into external remote services. |
| GroupAPT28 | APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder. |
| GroupAPT29 | APT29 has used a compromised account to access an organization's VPN infrastructure. |
| GroupAPT33 | APT33 has used valid accounts for initial access and privilege escalation. |
| GroupAPT39 | APT39 has used stolen credentials to compromise Outlook Web Access (OWA). |
| GroupAPT41 | APT41 used compromised credentials to log on to other systems. |
| GroupAxiom | Axiom has used previously compromised administrative accounts to escalate privileges. |
| Used by | Procedure example |
|---|---|
| MalwareDtrack | Dtrack used hard-coded credentials to gain access to a network share. |
| MalwareDuqu | Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| MalwareIndustroyer | Industroyer can use supplied user credentials to execute processes and stop services. |
| MalwareKinsing | Kinsing has used valid SSH credentials to access remote hosts. |
| MalwareLinux Rabbit | Linux Rabbit acquires valid SSH accounts through brute force. |
| MalwareLP-Notes | LP-Notes has used stolen Windows credentials to log in as the users. |
| MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used valid accounts on the corporate network to escalate privileges, move laterally, and establish persistence within the corporate network. |
| Campaign3CX Supply Chain Attack | During 3CX Supply Chain Attack, AppleJeus has gained access to the 3CX corporate environment through legitimate VPN credentials. |
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used harvested credentials to authenticate against internal APIs, database systems, container registries, and logging infrastructure across targeted networks. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles used compromised VPN accounts. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts. |
| CampaignLeviathan Australian Intrusions | Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions. |
| CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.