Account Manipulation

T1098

Technique with 7 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

In order to create or manipulate accounts, the adversary must already have sufficient permissions on systems or the domain. However, account manipulation may also lead to privilege escalation where modifications grant access to additional roles, permissions, or higher-privileged Valid Accounts.

Detection rules107

Rules on DetectionCode tagged with T1098 or one of its sub-techniques.

Sigma41

RuleLevelLog sourceTechnique
Active Directory User Backdoorshighwindows / NULLT1098
Added Credentials to Existing Applicationhighazure / NULLT1098.001
Anomalous User Activityhighazure / NULLT1098
App Granted Privileged Delegated Or App Permissionshighazure / NULLT1098.003
AWS User Login Profile Was Modifiedhighaws / NULLT1098
Bulk Deletion Changes To Privileged Account Permissionshighazure / NULLT1098
Cisco Local Accountshighcisco / NULLT1098
Enabled User Right in AD to Control User Objectshighwindows / NULLT1098
ESXi Admin Permission Assigned To Account Via ESXCLIhighlinux / process_creationT1098
Password Change on Directory Service Restore Mode (DSRM) Accounthighwindows / NULLT1098
Powerview Add-DomainObjectAcl DCSync AD Extend Righthighwindows / NULLT1098
Privileged User Has Been Createdhighlinux / NULLT1098
User Added To Highly Privileged Grouphighwindows / process_creationT1098
Windows LAPS Credential Dump From Entra IDhighazure / NULLT1098.005
A New Trust Was Created To A Domainmediumwindows / NULLT1098

Splunk66

RuleTypeRiskData sourceTechnique
ASL AWS IAM Delete PolicyHuntingNULLASL AWS CloudTrailT1098
ASL AWS IAM Failure Group DeletionAnomalyNULLASL AWS CloudTrailT1098
ASL AWS IAM Successful Group DeletionHuntingNULLASL AWS CloudTrailT1098
AWS IAM Delete PolicyHuntingNULLAWS CloudTrail DeletePolicyT1098
AWS IAM Failure Group DeletionAnomalyNULLAWS CloudTrail DeleteGroupT1098
AWS IAM Successful Group DeletionHuntingNULLAWS CloudTrail DeleteGroupT1098
Azure AD Admin Consent Bypassed by Service PrincipalTTPNULLAzure Active Directory Add app role assignment to service principalT1098.003
Azure AD Application Administrator Role AssignedTTPNULLAzure Active Directory Add member to roleT1098.003
Azure AD FullAccessAsApp Permission AssignedTTPNULLAzure Active Directory Update applicationT1098.002 T1098.003
Azure AD Global Administrator Role AssignedTTPNULLAzure Active Directory Add member to roleT1098.003
Azure AD New MFA Method RegisteredTTPNULLAzure Active Directory Update userT1098.005
Azure AD PIM Role AssignedTTPNULLAzure Active DirectoryT1098.003
Azure AD PIM Role Assignment ActivatedTTPNULLAzure Active DirectoryT1098.003
Azure AD Privileged Role AssignedTTPNULLAzure Active Directory Add member to roleT1098.003
Azure AD Privileged Role Assigned to Service PrincipalTTPNULLAzure Active Directory Add member to roleT1098.003

Sub-techniques7

IDNameExamples
T1098.001Additional Cloud Credentials4
T1098.002Additional Email Delegate Permissions5
T1098.003Additional Cloud Roles5
T1098.004SSH Authorized Keys7
T1098.005Device Registration4
T1098.006Additional Container Cluster Roles0
T1098.007Additional Local or Domain Groups11

Groups5

Software3

Campaigns1

Procedure examples9

Groups5

Used byProcedure example
GroupHAFNIUM

HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts.

GroupLazarus Group

Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account.

GroupScattered Spider

Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere.

GroupTeamPCP

TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.

GroupVOID MANTICORE

VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.

Software3

Used byProcedure example
MalwareCalisto

Calisto adds permissions and remote logins to all users.

ToolMimikatz

The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The LSADUMP::ChangeNTLM and LSADUMP::SetNTLM modules can also manipulate the password hash of an account without knowing the clear text value.

MalwareShai-Hulud

Shai-Hulud has modified GitHub account settings for private repositories and changed them to public.

Campaigns1

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network.

References1

  1. FireEye SMOKEDHAM June 2021 Open source
    FireEye. (2021, June 16). Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise. Retrieved September 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.